CCYPC Members

Privacy policy

What the CYPC Members app collects, why, and what we never do with it.

Last updated 25 September 2026

PRIVACY
Privacy policy

Your privacy.

We only collect what we need to run CYPC and keep people safe. We never sell your information and we never use it for adverts. This policy explains exactly what we hold, what it's for and your rights under UK data protection law (UK GDPR and the Data Protection Act 2018).

Last updated 20 September 2026

What we collect
WhereWhat we keepWhy
Visiting the siteWhich page was opened and the hour. No names, no IP addresses, no tracking cookies.To count visits and see which pages help.
ChatYour messages, a random chat ID, and a phone number only if you choose to give one.To answer you and to keep you safe.
Polls & questionsYour answer and a random device code so each device answers once. Not your name.To count views fairly.
Report a concernYour name, phone number, what happened, where, and when.So the safeguarding lead can act and contact you.
Event sign-upsYour name and the contact details you give.To know who's coming and contact you about it.
Email updatesYour email address.To tell you about events. Unsubscribe any time.
Members portalYour name, email (for sign-in codes and mail), sign-in times and device, RSVPs, chat, notes, inbox messages, profile picture and wallpaper.To run the portal and keep accounts secure.
CYPC SearchThat you accepted the search rules, and when. How many web searches and pages you've opened today (numbers only). Your searches themselves are never saved. If a search is blocked under the search rules, your name and the time are recorded, but not what you typed.To keep search safe, fair and inside our monthly limit.
Website requests & Admin CodesYour name, the website, your reason, how long you asked for, and the organiser's decision. If you use an Admin Code: your name, the website, the time and which organiser made the code.So organisers can decide fairly and keep a record of what was unlocked.
Member emailEvery member gets a [email protected] address. Emails sent and received through it are stored so they show in the portal. Organisers can read CYPC email to keep members safe.To give members a safe email address.
Face ID / fingerprint sign-in (optional)If a member turns it on, we keep the public half of a passkey their device creates, a short device name such as “iPhone”, and when it was last used. The private half never leaves their device, and their face or fingerprint is never sent to us and never stored. Removing the device here, or in their phone's passkey settings, ends it.So members can sign in without typing their member key.
Writing from another inboxA member who has verified an inbox with us can write to their own CYPC send address from it. We check the message really came from that verified inbox, then send it on from their CYPC address and store it in their Sent folder like any other CYPC email. Messages from anywhere else are discarded.So members can write CYPC email from the inbox they already use.
Forwarding a copy (optional)If a member switches it on, we keep the address they choose (checked with a one-time code) and send a copy of email that arrives for them to it. It is one way: replies sent from that address do not come back to CYPC. They can pause or remove it at any time, and removing it deletes the address.So members can see their CYPC email in an inbox they already check.
Phone notifications (optional)If a member turns them on, we keep the notification address their phone or browser gives us, a random device token and a short device name such as “iPhone (Safari)”. The notification we send contains no message text at all; the app asks us what to show once it arrives. Turning notifications off, or removing the app, deletes the device.To tell a member when email arrives, without putting their email through anyone else’s servers.
Email settingsA member’s own choices for their mailbox: sender pictures on or off, preview lines, how careful the junk filter should be, quiet hours, a short signature, and any senders they have blocked. Kept only for that member.So the mailbox works the way each member wants.
Gmail sync (optional)If a member switches it on, we keep the personal email address they choose (checked with a one-time code) and send a copy of their CYPC email to it. Replies they send from there go out from their CYPC address and are stored like any other CYPC email. They can switch it off or disconnect at any time, and disconnecting deletes the address.So members can read and reply to CYPC email in the app they already use.
Password vaultOnly scrambled (encrypted) data. Your passwords are locked on your device with your master password before anything is sent. We never receive your master password and can't read, recover or reset anything in your vault. If you choose "Autofill", the vault makes an import file for your own device's password manager; it's created on your device and never sent to CYPC. If you turn on a PIN, your device keeps a locked copy of your vault key and CYPC keeps a matching half plus a check value for the PIN (never the PIN itself); neither half can open your vault on its own, and 5 wrong PINs switch it off.So you can keep your passwords in one safe place.
Survey siteYour answers, your school, and a random device code. Not your name.To report what young people think.
How it's handled
01

Who's responsible

CYPC, the Crawley Young Persons Council, supported by Crawley Borough Council. Contact us about your data at [email protected].

02

Our legal reasons

We use your information because it's needed to run CYPC and its services (legitimate interests), because you've agreed to it (for example email updates, or giving a phone number in the chat), or to protect someone's safety (vital interests and safeguarding duties).

03

Who can see it

Only approved CYPC organisers and staff, and the safeguarding lead for reports and concerns. If someone may be at risk, we may share information with Crawley Borough Council, children's services or the police. That's the only time it leaves CYPC.

04

Services we use

Our data is stored in Google (Google Workspace, Sheets and Apps Script). Chat messages are processed by Google's Gemini AI to write replies. Emails are sent through Google and our email provider, Resend. Web searches in CYPC Search are sent to Brave Search by our server, without your name, account or IP address, and results and pages are kept in Google's temporary memory for up to 30 minutes to make search faster. Reader view (the default) is fetched by our server, including the page's pictures, so the website doesn't see your device at all. If a website won't let our server in, the page address (never your name) is passed to Jina Reader, a service that loads the page and returns a clean copy. In Live view, the page's pictures, videos and code load straight from the website, so that website can see your device's internet address, as with normal browsing. The site is hosted by Tiiny Host. Fonts load from Google Fonts. These companies process data for us and aren't allowed to use it for their own purposes.

05

Stored on your device

We save a few small settings in your browser: a random device code, your text-size choice, and which polls you've answered. Members also get a sign-in key and, unless they turn it off or use Incognito, their recent searches. None of it is used for tracking or adverts, and clearing your browser removes it.

06

How long we keep it

Only as long as we need it. Members' accounts are removed when they leave CYPC. Email sign-ups are deleted when you unsubscribe. Safeguarding records are kept for as long as the council's safeguarding procedure requires.

07

Photos

We only publish photos of young people when a consent form has been given. If you want a photo of you taken down, email us and we'll remove it.

08

Your rights

You can ask to see the information we hold about you, correct it, delete it, or object to how we use it. Email [email protected] and we'll reply within one month. Some safeguarding records can't be deleted if we need them to keep someone safe.

09

Complaints

If you're unhappy with how we've handled your information, tell us first. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

See also our Terms of service, Search rules and Safeguarding pages.

How the CYPC Members app uses Google account data

Two optional features in the members app connect to a Google account. Both are switched off unless a member turns them on, and both can be disconnected at any moment.

Sending email from your own Gmail

If a member chooses to connect their Google account, CYPC asks Google for one permission only: https://www.googleapis.com/auth/gmail.send, which allows sending a message on their behalf. CYPC also reads the email address of the account (openid and userinfo.email) so it can show the member which account is connected.

Google account data obtained through these scopes is used only to send the message the member wrote, and is never transferred to anyone else, never used for advertising, never used to train any model, and never sold.

Limited Use of Google user data

CYPC Members' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, in relation to data obtained through the Gmail API:

CYPC Members requests the narrowest scope that achieves the feature. It asks for gmail.send only, which grants the ability to send and nothing else: it confers no ability to read, search, download, label, modify or delete anything in the member's mailbox.

Syncing CYPC email to a personal inbox

If switched on, CYPC sends a copy of email arriving at the member's cypc.co.uk address to a personal inbox they verify with a one-time code. This uses no Google permissions at all: it is ordinary email. Replies sent back to CYPC go out from the member's CYPC address.

Phone notifications

If a member turns notifications on, we store the notification address their browser provides, a random device token and a short device name such as "iPhone". The notification carries no message text.

Face ID and fingerprint sign-in

If a member turns this on, their device creates a passkey. We store only the public half. The private half never leaves their device, and their face or fingerprint is never sent to us and never stored.

Keeping information safe, and how long we keep it

Information is held in Google Workspace services belonging to the Crawley Young Persons Council and is reachable only by CYPC organisers. Member email, sign-in records and portal content are kept while the member is with CYPC, and removed within twelve months of them leaving unless a safeguarding record has to be kept longer.

Your rights

Under UK GDPR you can ask what we hold about you, ask for it to be corrected or deleted, and object to how it is used. Write to [email protected] or speak to any CYPC organiser. If you are not happy with our answer you can complain to the Information Commissioner's Office at ico.org.uk.

Who to contact

Crawley Young Persons Council, supported by Crawley Borough Council, Town Hall, The Boulevard, Crawley RH10 1UZ. Email [email protected].