ZZ Music Privacy Policy
Thank you for using ZZ Music ("the App", "we", "us", or "our"). We take your privacy and personal data protection seriously. Please read this Privacy Policy carefully before using our software to understand how your data is collected, handled, and protected.
1. Information We Collect and Purpose
We adhere to strict data minimization principles and only collect data strictly necessary for core functionality and licensing:
- Device Identifier (Android ID / UUID): Used solely for the 30-day Pro trial counter, online activation-code verification, and device migration authentication. This identifier is never linked to any personal identity.
- Device Information and Usage Telemetry: To perform product analytics, measure feature usage, and diagnose compatibility and stability issues, the app submits a form-encoded report to our own statistics endpoint (zzmusic.zzxia.vip) at startup or when your level increases. The reported fields are: device identifier (Android ID), event type (first install / active), install time, report timestamp, app version, operating system name and OS version (for example, the Android release), device brand, device model, and basic usage metrics (growth level, level name, cumulative play count, activity percentage, and play count over the rolling last 3 days). Metrics such as the cumulative play count are accumulated from your own playback activity on the device.
- IP Address: when our server receives a telemetry request, it records the IP address that sent the request. This record is used only for endpoint rate limiting and abuse prevention (for example, traffic inflation or automated attacks). It is not used for user profiling or for cross-site tracking.
Please note that because the device identifier and the IP address can consistently point to the same device over time, the telemetry described above is not fully anonymous data. We use it only for product analytics and security protection, we do not link it to your real-world identity, and we do not use it for advertising.
2. System Permissions and Usage
- Audio & Media Read Permission (READ_MEDIA_AUDIO / READ_EXTERNAL_STORAGE): Used solely to scan, index, and play local audio files (MP3, FLAC, WAV, APE, M4A, etc.) and embedded cover artwork on your device. The app does not request all-files access such as MANAGE_EXTERNAL_STORAGE; it relies only on the standard media read permissions.
- Audio Recording / Microphone Permission (RECORD_AUDIO / FOREGROUND_SERVICE_MICROPHONE): Used only when you actively enable the voice assistant or wake-word feature ("Mambo"). The default speech-recognition mode is offline recognition, in which audio is analyzed on-device only by a lightweight ONNX acoustic model, never leaves your device, and is neither stored nor uploaded. If you yourself switch the speech-recognition mode to "online" and enter your own third-party LLM API key, the app records a short audio clip, encodes it to WAV in memory and sends it directly — the recording is never written to disk — and then sends that clip to the third-party provider you selected (for example, Google Gemini or Alibaba Cloud DashScope) in order to transcribe it. Online recognition is off by default and takes effect only after you enable it and configure your own key.
- Camera Permission (CAMERA): Used solely to scan QR codes in order to import or export LAN P2P share codes and pairing information. The app does not take photos or record video through the camera and does not upload any images.
- Notifications & Foreground Service (POST_NOTIFICATIONS / FOREGROUND_SERVICE / FOREGROUND_SERVICE_MEDIA_PLAYBACK): Used to render ongoing playback controls in the system notification shade and lock screen for smooth background listening.
- Network and Network State Permissions (INTERNET / ACCESS_WIFI_STATE / ACCESS_NETWORK_STATE): Required for online lyric retrieval, online cover artwork lookup, WebDAV/Aliyun Cloud direct transfers and sync, P2P local sharing, and license verification. Network and Wi-Fi state are read to determine whether you are currently on a local network, so that the app can choose between a direct transfer and a relayed transfer.
- External Storage Write Permission (WRITE_EXTERNAL_STORAGE, Android 12 and below only): Used to write download caches and cover images to device storage.
3. Data Flows and Third-Party Services
- Online lyric and cover matching: When you use the online lyrics or online cover features, the app sends the song title and artist name to third-party lyric and cover lookup services (NetEase Cloud Music, QQ Music, Kugou Music, Kuwo Music, and the Apple iTunes Search API) for the sole purpose of matching lyrics and artwork. No device identifier, audio content, or listening history is sent in this process.
- Optional online speech recognition: As described in Section 2, a recorded audio clip is sent to the third-party provider you selected only when you actively enable online recognition and enter your own API key. In offline recognition mode, no audio data leaves your device.
- Files the app writes: downloaded cache files are written to the app's external files directory (removed when the app is uninstalled); cover images and caches are written to the ZZBondCache folder inside the device's public Downloads directory, which is readable by other apps on the device and can be deleted by you at any time. We state explicitly that the cover cache is not kept in private sandbox storage.
- P2P direct LAN sharing: LAN transfers connect directly between this app and the receiving device and travel over plaintext HTTP within the local network; the data does not pass through our servers. Because this channel uses neither transport encryption nor access authentication, please use this feature only on a home or office network you trust.
- Optional "burn after reading" relay sharing: when you actively choose this sharing mode, the file to be shared is temporarily uploaded to and stored on the developer's server, and the server deletes that temporary file after roughly 10 minutes or once the recipient has finished downloading it. Please do not use this mode to share sensitive or private files.
4. Data Protection & Security Commitments
We explicitly commit that:
- Your audio files are uploaded to a server only when you actively choose the "burn after reading" relay sharing mode. Otherwise the app does not upload or back up your private audio files, documents, contacts, or photos, and its file scanning is limited to audio files.
- The app contains no third-party advertising SDK, and we will never sell, lease, or share your data with third-party advertisers or data brokers.
- The security of cloud drive (WebDAV, Aliyun Drive, etc.) sync connections depends on the server you configure yourself; we recommend always using HTTPS addresses and keeping your access tokens safe.
- LAN P2P sharing uses plaintext HTTP; do not use it on public or untrusted networks.
- If you wish to access, correct, or delete the telemetry statistics associated with your device identifier, or if you have other questions about this policy, please contact us through our official channels.
5. Policy Updates and Contact Us
As our features evolve, we may update this policy from time to time; the "Last updated & Effective Date" shown on this page governs the current version. If you have any questions or feedback regarding this Privacy Policy, feel free to contact us via our official website:
Official Website: https://zzmusic.zzxia.vip