Privacy policy
What the CYPC Members app collects, why, and what we never do with it.
Last updated 25 September 2026
Your privacy.
We only collect what we need to run CYPC and keep people safe. We never sell your information and we never use it for adverts. This policy explains exactly what we hold, what it's for and your rights under UK data protection law (UK GDPR and the Data Protection Act 2018).
Last updated 20 September 2026
Who's responsible
CYPC, the Crawley Young Persons Council, supported by Crawley Borough Council. Contact us about your data at [email protected].
Our legal reasons
We use your information because it's needed to run CYPC and its services (legitimate interests), because you've agreed to it (for example email updates, or giving a phone number in the chat), or to protect someone's safety (vital interests and safeguarding duties).
Who can see it
Only approved CYPC organisers and staff, and the safeguarding lead for reports and concerns. If someone may be at risk, we may share information with Crawley Borough Council, children's services or the police. That's the only time it leaves CYPC.
Services we use
Our data is stored in Google (Google Workspace, Sheets and Apps Script). Chat messages are processed by Google's Gemini AI to write replies. Emails are sent through Google and our email provider, Resend. Web searches in CYPC Search are sent to Brave Search by our server, without your name, account or IP address, and results and pages are kept in Google's temporary memory for up to 30 minutes to make search faster. Reader view (the default) is fetched by our server, including the page's pictures, so the website doesn't see your device at all. If a website won't let our server in, the page address (never your name) is passed to Jina Reader, a service that loads the page and returns a clean copy. In Live view, the page's pictures, videos and code load straight from the website, so that website can see your device's internet address, as with normal browsing. The site is hosted by Tiiny Host. Fonts load from Google Fonts. These companies process data for us and aren't allowed to use it for their own purposes.
Stored on your device
We save a few small settings in your browser: a random device code, your text-size choice, and which polls you've answered. Members also get a sign-in key and, unless they turn it off or use Incognito, their recent searches. None of it is used for tracking or adverts, and clearing your browser removes it.
How long we keep it
Only as long as we need it. Members' accounts are removed when they leave CYPC. Email sign-ups are deleted when you unsubscribe. Safeguarding records are kept for as long as the council's safeguarding procedure requires.
Photos
We only publish photos of young people when a consent form has been given. If you want a photo of you taken down, email us and we'll remove it.
Your rights
You can ask to see the information we hold about you, correct it, delete it, or object to how we use it. Email [email protected] and we'll reply within one month. Some safeguarding records can't be deleted if we need them to keep someone safe.
Complaints
If you're unhappy with how we've handled your information, tell us first. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
See also our Terms of service, Search rules and Safeguarding pages.
How the CYPC Members app uses Google account data
Two optional features in the members app connect to a Google account. Both are switched off unless a member turns them on, and both can be disconnected at any moment.
Sending email from your own Gmail
If a member chooses to connect their Google account, CYPC asks Google for one permission only: https://www.googleapis.com/auth/gmail.send, which allows sending a message on their behalf. CYPC also reads the email address of the account (openid and userinfo.email) so it can show the member which account is connected.
- CYPC cannot read, search, delete or label any message in the member's Gmail. The send-only permission does not allow it.
- CYPC never receives or stores a Google password.
- We store the member's Google email address and the permission token Google issues. Nothing else from the Google account is stored.
- A message sent this way is also saved in the member's CYPC Sent folder, because CYPC organisers keep oversight of member email for safeguarding.
- Disconnecting in the app withdraws the permission at Google immediately and deletes the stored token and address. A member can also remove it at myaccount.google.com/permissions.
Google account data obtained through these scopes is used only to send the message the member wrote, and is never transferred to anyone else, never used for advertising, never used to train any model, and never sold.
Limited Use of Google user data
CYPC Members' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, in relation to data obtained through the Gmail API:
- We use the data only to provide the feature the member switched on, which is sending an email they wrote and pressed Send on.
- We do not transfer the data to others, except as necessary to provide that feature, to comply with applicable law, or as part of a merger or acquisition with the member's consent.
- We do not use the data for serving advertising of any kind, including retargeting or personalised advertising.
- We do not allow humans to read the data, unless we have the member's express consent for a specific message, it is necessary for security purposes such as investigating abuse, to comply with applicable law, or the data is aggregated and anonymised.
- We do not use the data to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models. The message content a member sends is never used for any such purpose.
CYPC Members requests the narrowest scope that achieves the feature. It asks for gmail.send only, which grants the ability to send and nothing else: it confers no ability to read, search, download, label, modify or delete anything in the member's mailbox.
Syncing CYPC email to a personal inbox
If switched on, CYPC sends a copy of email arriving at the member's cypc.co.uk address to a personal inbox they verify with a one-time code. This uses no Google permissions at all: it is ordinary email. Replies sent back to CYPC go out from the member's CYPC address.
Phone notifications
If a member turns notifications on, we store the notification address their browser provides, a random device token and a short device name such as "iPhone". The notification carries no message text.
Face ID and fingerprint sign-in
If a member turns this on, their device creates a passkey. We store only the public half. The private half never leaves their device, and their face or fingerprint is never sent to us and never stored.
Keeping information safe, and how long we keep it
Information is held in Google Workspace services belonging to the Crawley Young Persons Council and is reachable only by CYPC organisers. Member email, sign-in records and portal content are kept while the member is with CYPC, and removed within twelve months of them leaving unless a safeguarding record has to be kept longer.
Your rights
Under UK GDPR you can ask what we hold about you, ask for it to be corrected or deleted, and object to how it is used. Write to [email protected] or speak to any CYPC organiser. If you are not happy with our answer you can complain to the Information Commissioner's Office at ico.org.uk.
Who to contact
Crawley Young Persons Council, supported by Crawley Borough Council, Town Hall, The Boulevard, Crawley RH10 1UZ. Email [email protected].