User Privacy Policy
Version: v2.0
Applicable Regions: Mainland China, European Union, United States, Japan, South Korea, Southeast Asia, and other regions
Company: Shenzhen Maono Technology Co., Ltd.
Release Date: [2026-5-12]
Effective Date: [2026-5-12]
Thank you for using Maono AI microphones, audio interfaces, and other hardware products and companion software applications (hereinafter "Products" or "this Service"). This Policy is formulated and published by Shenzhen Maono Technology Co., Ltd. (hereinafter "we," "us," or "the Company") to explain how we collect, use, store, share, and protect your personal information, as well as the rights you have regarding your personal information. Please read this Policy carefully before using our Products. By using our Products, you are deemed to have agreed to this Policy. After updates to the Privacy Policy and feature rules, your continued use is deemed acceptance of the latest version. If you do not agree, please immediately stop using and deactivate your account.
0. Definitions and Scope
This Policy applies to the following products and services:
- All Maono microphones, audio interfaces, and other hardware devices;
- Companion desktop software (PC / Mac client);
- Companion mobile applications (iOS / Android App);
- Cloud services (speech transcription, speech translation, smart summarization, AI Agent, etc.);
- Official website and related online services.
Key terms used in this Policy are defined as follows:
"Personal Information" means any information relating to an identified or identifiable natural person recorded electronically or otherwise, excluding anonymized information.
"Voice Data" means audio recording files and their metadata (duration, sample rate, etc.) collected or uploaded by users through microphones.
"Transcription Text" means text content generated by converting Voice Data through speech recognition (ASR).
"Speaker Diarization Labels" means session-level temporary labels generated within a single recording by unsupervised clustering algorithms to distinguish different speakers (e.g., "Speaker A," "Speaker B"), containing no persistent voiceprint features and deleted with the recording after the session ends.
"Voice Cloning Data" means audio samples actively uploaded by users to clone their own voice and the resulting synthetic voice models (requires separate user authorization).
"AI-Generated Content" means text or voice content generated by the AI features of our Products (TTS voice playback, smart summarization, translation, etc.).
1. What Personal Information Do We Collect?
We collect your personal information only as reasonably necessary to operate our business, provide you with products and services, or comply with laws.
1.1 Information You Actively Provide
- Account registration information: mobile phone number, email address, username, password (encrypted storage);
- Real-name authentication information (Mainland China): name, ID number (used solely for legally required real-name verification, encrypted storage, not used for other purposes);
- Voice recordings: audio content recorded through your device microphone (source for ASR transcription and speaker diarization);
- Voice cloning samples: if you use the voice cloning feature, the samples of your own voice you upload (requires separate authorization);
- Warranty registration information: when you register for warranty on our website, we collect your name, email address, and product serial number;
- Survey and event information: when you participate in our surveys, contests, or promotions, we collect the response information you provide;
- User feedback and customer service communications: text, screenshots, etc. submitted by you through customer service channels;
- Testimonials: if you provide us with product experience or testimonials, such content will become public information (see Section 7 for details).
1.2 Information Automatically Collected During Product Operation
- Device information: device model, operating system version, unique device identifiers (IMEI / Android ID / IDFV, etc.), audio interface serial number;
- Network information: IP address, network type (WiFi / 4G / 5G);
- Website usage data: when you visit our website, we collect de-identified information (IP address, operating system, browser, pages visited) for website analytics;
- Logs and diagnostic information: crash logs, feature usage records, error reports (used for product improvement, containing no voice content);
- Location information (coarse): used only to determine data processing node jurisdiction, not for precise location tracking.
1.3 Important Notice: We Do Not Collect Voiceprint Biometrics
The Speaker Diarization feature of our Products does not extract or store persistent voiceprint feature vectors, and does not build cross-session personal voiceprint profiles. This feature only distinguishes and labels different speakers' utterances within a single recording session; intermediate vectors are immediately released after clustering computation and are not written to any database. Accordingly, this feature does not, under ordinary circumstances, constitute biometric data processing under GDPR Article 9, BIPA, or PIPL Article 28.
1.4 Consequences of Not Providing Personal Information
Where lawful and practicable, we offer users the option to remain anonymous or use pseudonyms. However, in certain circumstances, if you do not provide us with personal information, we may be unable to provide you with the requested services. For example, you must register an account to use cloud-based AI features, and must provide contact information to receive warranty services.
1.5 Recruitment-Related Information
When you apply to join our company, and during our employment relationship with employees, we may also collect the following information:
- Job applications: when you apply for a position with us (whether directly or through a recruitment agency), we will collect your name, email address, mailing address, phone number, and information about your qualifications, work history, and background;
- Employee management: when we employ you, we will collect information necessary to manage the employment relationship, including personal contact details, qualification certificates, work history, performance information, compensation information, and health information relevant to the position or workplace safety.
The above recruitment and employee information is used solely for human resources management purposes and will not be shared with the third-party service providers listed in Section 4 of this Policy, nor used for training or improvement of products or AI features.
2. How Do We Use Your Personal Information?
|
Processing Purpose |
Specific Use |
Legal Basis |
|
Provision of core AI services |
Speech recognition (ASR) transcription, multilingual translation, speaker diarization labeling, smart summarization, AI Agent conversation |
Performance of contract; where no written contract exists, your actual use of our Products is deemed your explicit consent to our collection and processing of this information. |
|
Voice cloning (only when authorized) |
Clone and generate your personalized voice model for use in your designated dubbing / broadcasting scenarios |
Your separate explicit consent; your actual use of this feature is deemed your explicit consent to our collection and processing of this information. |
|
Product security and anti-fraud |
Detection of abnormal logins and non-compliant usage behavior |
Legitimate interests (security protection) |
|
Product improvement and R&D |
Statistical analysis of anonymized / de-identified data to improve recognition accuracy; identifiable data is not used for model training |
Anonymized statistics, not involving personal data processing |
|
Marketing and promotion |
Sending you product information, offers, and promotions (email / SMS / App push) where you have consented |
Your explicit consent (revocable at any time) |
|
Legal compliance |
Satisfying compliance obligations under applicable laws and regulations in China, EU, US, etc. |
Performance of legal obligations |
|
Customer service |
Responding to your inquiries, warranty claims, complaints, and feedback |
Performance of contract; where no written contract exists, your actual use of our Products is deemed your explicit consent to our collection and processing of this information. |
We will not use your personal information for purposes not listed in this Policy. If we need to use information for a new purpose, we will obtain your prior consent.
3. Data Storage Location and Retention Periods
3.1 Storage Regions
- Mainland China users: stored on servers within Mainland China (Alibaba Cloud / Tencent Cloud domestic nodes); no cross-border transfer unless otherwise required by law, or with separate user consent and completion of statutory data export procedures, in compliance with PIPL and the Data Export Security Assessment Measures;
- EU users: voice data and related processing completed on EU-based nodes (Frankfurt AWS / GCP), not transferred outside the EU, compliant with GDPR requirements;
- US users: data stored on US-based AWS nodes, compliant with CCPA and other applicable regulations;
- Japan / South Korea users: data stored in Asia-Pacific nodes; cross-border transfer will be notified in advance and comply with local regulatory requirements;
- Southeast Asia users (Indonesia / Vietnam): data processed preferentially in Asia-Pacific nodes, satisfying local data localization requirements.
3.2 Retention Periods
|
Data Type |
Retention Period |
Basis |
|
Original voice recordings |
Automatically deleted within 24 hours after recording completion |
GDPR data minimization / product design commitment |
|
ASR transcription text & speaker diarization labels |
Account lifetime + 30 days after account deactivation |
User access and export rights |
|
Clustering intermediate vectors (Embeddings) |
Not persistently stored; immediately released after in-memory computation completes |
Does not trigger voiceprint biometric data determination |
|
Voice cloning models |
Upon user active deletion or immediate deletion after account deactivation |
User authorization scope |
|
Account registration information |
Deleted within 30 days after account deactivation (except portions required to be retained by law; longer retention periods required by applicable regional laws shall prevail) |
PIPL / GDPR / CCPA |
|
Website statistical data |
De-identified statistical data retained for a maximum of 24 months |
Operational analytics needs |
|
Logs and diagnostic information |
Automatically purged after 90-day rolling retention |
Operational need minimization |
|
Customer service communication records |
3 years after issue resolution, or as required by law |
Legal obligations |
4. Information Sharing and Third-Party Service Providers
We do not sell your personal information to third parties. In the following circumstances, we may share necessary personal information with service providers that have undergone our rigorous security review; we reserve the right to change third-party service providers based on business needs, and changes will be promptly posted on our official website:
|
Service Category |
Specific Service Provider |
Shared Purpose |
Safeguards |
|
Cloud computing and servers |
AWS / Azure / Alibaba Cloud / Huawei Cloud |
Data storage and computation |
Data Processing Agreement (DPA) in place; prohibited from using data for model training |
|
Speech recognition (ASR) |
Volcengine (Mainland China); Azure (other regions) |
Speech-to-text processing |
DPA constraints; data not exported outside the region |
|
Large language model (LLM) |
Qwen (Mainland China); GPT (other regions) |
Smart summarization, AI Agent conversation |
Only transcription text transmitted (no original voice data); DPA constraints; data not exported outside the region |
|
Payment service providers |
Alipay / WeChat Pay / Apple Pay |
Subscription fee payment |
Only necessary transaction information transmitted |
|
Marketing partners |
Email service providers (e.g., SendGrid, etc.) |
Marketing email / SMS sending (only with your consent) |
DPA constraints; may not be used for other purposes |
|
Security auditing |
Third-party security assessment agencies |
Network security assurance |
Confidentiality agreement in place; no access to user data |
As a matter of principle, we do not provide speaker diarization intermediate vectors (Embeddings) to any third party, nor do we permit ASR / LLM service providers to use your voice data for their model training. Where required by law (e.g., lawful requests by judicial authorities), we may disclose necessary information to relevant government agencies in accordance with the law.
5. AI Feature-Specific Notes
5.1 Speech Recognition (ASR) and Multilingual Translation
Voice data is encrypted and uploaded to cloud-based ASR services for transcription; original voice recordings are automatically deleted within 24 hours after transcription is complete. The translation feature processes only transcription text and does not process original audio again. If you choose local offline mode, voice data will be processed entirely on-device and will not be uploaded to the cloud.
5.2 Speaker Diarization
This feature distinguishes and labels different speakers within the same recording (e.g., "Speaker A," "Speaker B"), helping you identify who said what in the transcription results.
Technical implementation guarantees of this feature:
- Clustering computation is performed only in server memory; intermediate vectors (Speaker Embeddings) are immediately released after computation and are not written to any persistent storage;
- Diarization labels are not associated with your account ID, real name, or any identity information;
- Does not have cross-session comparison capability — each new recording is computed independently without reference to historical recordings;
- Your renaming of labels (e.g., changing "Speaker A" to "Host") is a front-end display only and does not trigger any voiceprint enrollment process;
- No persistent voiceprint profile is established; cannot be used for identification purposes.
5.3 Voice Cloning
The voice cloning feature allows you to clone and use your own voice. Before use, you need to:
- Separately read and agree to the Voice Cloning Special Authorization Agreement;
- Confirm that the uploaded voice samples are your own voice and that you have the legal right to use them;
- Understand that content generated with the cloned voice will be labeled as "AI Synthetic," complying with China's Deep Synthesis Administrative Provisions and the EU AI Act labeling obligations.
Cloning another person's voice is strictly prohibited (in violation of the Administrative Provisions on Deep Synthesis in Internet-Based Information Services and the US NO FAKES Act and related legislation); all economic losses resulting therefrom, including fines and damages, shall be borne solely by you. If we discover any violation, we will immediately terminate the account without assuming any liability and reserve the right to pursue legal action.
5.4 AI-Generated Content Labeling
- TTS voice playback: the AI assistant will play a notification tone or display an "AI Generated" label before responding;
- Voice cloning export files: metadata will note "AI Synthetic," complying with regulatory requirements;
- Smart summarization / translation results: interface will note "Generated by AI, for reference only."
5.5 Multi-Person Recording Scenarios
For multi-person recordings, you are responsible for ensuring that all participants have given informed consent, and you shall independently bear legal liability. When you use our Products for multi-person conversation recording (such as podcast interviews, meeting minutes), the Product will also notify all participants via a pop-up or voice prompt before recording begins that the recording will be transcribed and speakers will be distinguished. In US states with all-party consent requirements such as California and Illinois, you must confirm that all participants have given informed consent before starting the recording.
6. Marketing Information and Direct Marketing
If you consent to receive information about our products or services, we may use your personal information to send you marketing communications, including offers and promotions. This may include contacting you by phone, SMS, email, or App push notification.
You may opt out of receiving marketing information at any time:
- Email and SMS: use the "unsubscribe" option included in the message;
- App push: disable marketing push in App "Settings > Notifications";
- Phone: inform the caller that you no longer wish to receive marketing calls;
- Contact us directly (see Section 16 "Contact Us").
We also work with online advertising partners to show you marketing messages on other websites and social media. If you do not wish to see targeted advertising, you may change your Cookie preferences on our website to disable advertising cookies.
7. User Testimonials
From time to time, we collect users' experiences and stories about our products and publish them on our website. When we do so, we inform users that their submitted content will become public information and that we reserve the right to make reasonable edits as necessary.
Copyright in the text and/or images in user testimonials remains with the author. Users grant us a free, universal, irrevocable worldwide license to use such text and/or images on our website, across all online promotional channels, offline promotional materials, official channels, and cooperative promotional channels across all scenarios.
8. Data Security
- Transmission encryption: all voice data and personal information transmissions are encrypted;
- Storage encryption: static data is stored with encryption;
- Access control: strict employee permission management; only authorized personnel may access user data, subject to confidentiality agreements;
- Employee training: regular personal information protection training for employees;
- System security: firewalls, intrusion detection, and virus scanning tools to prevent unauthorized access;
- Regular security audits: periodic penetration testing and security assessments;
- Data isolation: data of users from different regions is stored in independent, securely isolated environments;
- Data minimization: personal information is retained only as necessary for business or legal requirements, and promptly deleted or de-identified when no longer needed.
Despite our rigorous technical measures, internet transmission cannot be guaranteed to be 100% secure. In the event of a data security incident, we will promptly notify you as required by applicable law.
9. Your Privacy Rights
Depending on the laws of your region, you may enjoy some or all of the following rights:
|
Right |
Specific Content |
|
Right to be informed |
Understand the purposes, methods, and scope of our collection and use of your personal information |
|
Right of access |
View the personal information we hold about you (you can view transcription history and speaker labels on the App's "My Recordings" page) |
|
Right to rectification |
Request correction of inaccurate personal information |
|
Right to deletion |
Request deletion of personal information (you can delete recording sessions item by item in the App, delete all data with one click, or trigger full deletion by deactivating your account) |
|
Right to data portability |
Export transcription text and speaker labels in machine-readable format (TXT / SRT / VTT / JSON) |
|
Right to withdraw consent |
Withdraw consent for cloud processing of voice data at any time (you may continue using local offline features after withdrawal) |
|
Right to object |
Speaker diarization is an optional feature that can be turned off in Settings; turning it off does not affect basic ASR functionality |
|
Right to object to marketing |
Object to receiving marketing information at any time, using the unsubscribe link in the message or by contacting us directly |
To exercise the above rights, please use the self-service options on the App's "Settings > Privacy & Data" page, or send an email to ltysun@maono.com. We will respond within 15 business days (Mainland China) / 30 days (EU GDPR) / 45 days (US CCPA) / within 45 business days (other countries/regions).
Fee Note
There is no charge for making a privacy rights request. If a request is manifestly repetitive, exceeds reasonable frequency, or requires provision of materials manifestly beyond the normal scope of processing, we may charge a reasonable fee; we will inform you of the estimated amount in advance for your decision on whether to proceed.
10. Children's Privacy Protection
Our Products are intended for adult users. Use of the Software by minors must comply with the age and guardian consent requirements set forth in Section 4.2 of the Maono Software End User License Agreement. We do not knowingly collect personal information from minors. If we discover that we have inadvertently collected personal information from a minor, we will promptly delete the relevant information. If you are a minor's guardian and discover that we have collected their personal information, please contact us promptly.
11. Cookies and Tracking Technologies
Our App, website, and web-based services use necessary cookies and local storage to maintain your login status and preference settings. We use these technologies to help the website function properly, personalize the content you see, and understand how the website is used.
- Necessary cookies: maintain login status and basic functionality; cannot be disabled;
- Analytics cookies: used for website visit statistics (de-identified); can be disabled in Cookie preferences;
- Advertising cookies: we do not use third-party advertising tracking cookies.
You may manage Cookie preferences in your browser or App settings, but disabling necessary cookies may affect the normal use of product functions.
12. Third-Party Links and Platforms
Our Products may contain links to third-party websites or services. We are not responsible for the privacy practices of third parties, and we recommend that you read their privacy policies before accessing third-party services.
13. Region-Specific Provisions
13.1 Mainland China — Special Provisions (PIPL)
- Data localization: personal information of Mainland China users is stored on domestic servers; cross-border transfer will be separately notified and must satisfy the CAC's data export security assessment requirements;
- Real-name system: in accordance with the Cybersecurity Law of the People's Republic of China, real-name registration must be completed before providing AI services in Mainland China;
- Generative AI filing: the large language models used by our Products' AI conversation feature have completed generative AI service filing with the CAC;
- Deep synthesis filing: the speech synthesis algorithms used in the voice cloning feature have completed deep synthesis algorithm filing for internet information services;
- Personal information processing rules: this Privacy Policy serves as the publicly available personal information processing rules for our Products in accordance with the Personal Information Protection Law of the People's Republic of China.
If you provide false information or use product features in violation of rules (such as cloning another person's voice without authorization, failing to obtain informed consent from all participants in a multi-person recording scenario, etc.), resulting in any losses to us, we have the right to recover all losses from you, including but not limited to damages, administrative fines, attorneys' fees, notarial fees, travel expenses, etc.
13.2 EU and UK Users — Special Provisions (GDPR)
- Data controller: Shenzhen Maono Technology Co., Ltd., registered address: No. 1307, 13th Floor, Building 4, Phase II of Tianan Yungu Industrial Park, Gangtou Community, Bantian Street, Longgang District, Shenzhen, China;
- Legal basis for processing: based on GDPR Article 6 (performance of contract, legal obligations, legitimate interests) or Article 9 (explicit consent, applicable only to voice cloning biometric data scenarios);
- Data Protection Impact Assessment (DPIA): we have completed a DPIA for voice data processing, confirming that speaker diarization does not constitute high-risk data processing;
- Right to complain: you have the right to lodge a complaint with the data protection supervisory authority of your member state (e.g., Germany BfDI, France CNIL);
- Cross-border data transfers: where data is transferred outside the EU, it will be done using EU Standard Contractual Clauses (SCCs) or based on an EU Commission adequacy decision.
13.3 US Users — Special Provisions (CCPA / BIPA)
- California user rights (CCPA/CPRA): you have the right to know the categories of personal information we collect (including audio recordings), the purposes of use, and to request deletion and correction;
- Audio data disclosure: the categories of personal information collected by our Products include audio recordings, used for speech recognition transcription and speaker distinction; original recordings are retained for 24 hours;
- Illinois BIPA: the Speaker Diarization feature of our Products does not generate persistent "voiceprints" and is generally not subject to BIPA;
- All-Party Consent States: in states such as California, Illinois, and Washington, please ensure all participants have given informed consent before using multi-person recording features;
- "Do Not Sell" statement: we do not sell or share your personal information with third parties for cross-context behavioral advertising.
13.4 Japan Users — Special Provisions (APPI)
- Where speaker diarization does not generate persistent biometric identifiers, voice data is classified as general personal information under APPI;
- We endeavor to process Japanese users' data on Asia-Pacific regional servers;
- Users have the right to access, correct, and request deletion of personal data.
13.5 South Korea Users — Special Provisions (PIPA)
- Cross-border data transfers: we clearly disclose the destination country, recipients, and safeguards in this Policy;
- Data retention: all personal data deleted within 90 days after account deactivation;
- AI-generated content is labeled in accordance with the draft Korea AI Basic Act guidelines.
13.6 Southeast Asia Users — Special Provisions (PDPA)
- Indonesia / Vietnam: data processed on Asia-Pacific nodes, satisfying local data localization requirements;
- Thailand: compliance with Thailand PDPA, including explicit consent requirements and data subject rights;
- The Privacy Policy is available in Indonesian (Bahasa Indonesia), Thai, Vietnamese, and Malay.
14. Changes to This Policy
We may update this Policy due to changes in laws and regulations, feature iterations, or other reasons. Material changes (such as adding new data collection categories or expanding data sharing scope) will be notified at least 30 days in advance via App push, email, or other means, and we will obtain your confirmation again before they take effect. Your continued use of our Products is deemed acceptance of the updated Policy.
15. Complaints and Dispute Resolution
If you have any concerns about how we handle your personal information, please contact us first, and we will endeavor to resolve them. If you are still dissatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority or resolve the matter through negotiations between the parties (see Section 13 for region-specific provisions).
If the parties are unable to resolve the dispute through negotiation, either party may bring a lawsuit before the people's court with jurisdiction at the location of Shenzhen Maono Technology Co., Ltd. The case acceptance fee, preservation fee, attorneys' fees, enforcement costs, and other reasonable costs arising from the litigation shall be borne by the losing party.
16. Contact Us
If you have any questions about this Policy or wish to exercise your privacy rights, please contact us through the following channels:
- Company name: Shenzhen Maono Technology Co., Ltd.
- Registered address: No. 1307, 13th Floor, Building 4, Phase II of Tianan Yungu Industrial Park, Gangtou Community, Bantian Street, Longgang District, Shenzhen, China
-Official website: [www.maono.com](http://www.maono.com)
- Customer service email: info@maono.com



