App Privacy Policy
Surfans Music Privacy Policy
Publication Date: 2026/9/2
Updated Date: 2026/9/2
Effective Date: 2026/9/2
Special Notice: The Surfans Music Privacy Policy (hereinafter referred to as “this Policy”) applies only to the Surfans Music products and/or services provided to you by Shenzhen Hengmaolong Technology Co., Limited (hereinafter referred to as “we,” “us,” or “our”). Before using this software, please read this Policy carefully and make sure that you fully understand and accept all of its terms; otherwise, please do not install, launch, or use it. Important content concerning sensitive personal information and your rights and interests in personal information is highlighted for your particular attention. If you are a minor under the age of 18, please read and fully understand this Policy in the company of your guardian and obtain your guardian’s consent before using the products and/or services.
This Policy will help you understand the following:
- Definitions and Interpretations
- How We Collect and Use Your Personal Information
- How We Use Cookies and Similar Technologies
- How We Entrust Processing and Share, Transfer, or Publicly Disclose Your Personal Information
- How We Protect Your Personal Information
- How We Store Your Personal Information
- How You May Exercise Your Rights to Manage Your Personal Information
- How We Protect Minors’ Personal Information
- How We Update This Policy
- How to Contact Us
I. Definitions and Interpretations
- Surfans Music Products and/or Services: the music playback and related functions and services provided to users by the Surfans Music App (hereinafter referred to as “this Software”), subject to the functions actually made available in the product, hereinafter collectively referred to as “the Services.”
- Developer: Shenzhen Hengmaolong Technology Co., Limited, the operator of this Software. For registered address/usual office address, contact telephone number, and other entity information, please refer to the business registration records and the contact details published in Section X of this Policy.
- User: a user who downloads, installs, launches, and uses the products and/or services, more commonly referred to as “you” in this Policy.
- Personal Information: various kinds of information recorded electronically or otherwise that can identify a natural person, either independently or in combination with other information. For the avoidance of doubt, personal information includes, but is not limited to, sensitive personal information.
- Sensitive Personal Information: personal information that, once leaked, illegally provided, or misused, may endanger personal or property safety and is highly likely to result in damage to personal reputation or physical or mental health, discriminatory treatment, or similar harm. Sensitive personal information that may be involved in this Software includes, but is not limited to, account/password information that you configure and store locally, device crash logs, and precise location information when a webpage within the App requests location access, subject to the functions you actually use.
- De-identification/Anonymization: the process of technically processing personal information so that the personal information subject cannot be identified or re-identified without the use of additional information.
- Unique Device Identifier: a string of characters embedded or generated by a device manufacturer or operating system that can be used to identify the corresponding device, such as Android ID or OAID.
II. How We Collect and Use Your Personal Information
We collect and use your personal information for the purposes described below in accordance with the principles of lawfulness, legitimacy, and necessity.
Special Note: When you install and launch this Software for the first time, a pop-up will prompt you to read this Policy and the User Agreement. Before you click “Agree,” we will not formally initialize third-party SDKs, such as Umeng, that need to collect device identifiers. However, to ensure basic operation and stability, this Software may enable local crash capture and Bugly exception reporting before you give consent; the relevant processing is limited to technical information necessary to safeguard service security. Third-party SDKs such as Umeng Analytics will be initialized only after you click “Agree.”
1. Information You Provide or That Is Generated Locally While We Provide Products and/or Services
1.1 To provide our basic business functions, you need only provide the basic personal information necessary for the corresponding function, except where laws, regulations, or normative documents impose special requirements. If you refuse to provide the information or grant authorization, we will be unable to provide the corresponding service. Please note that if you provide another person’s personal information, you must ensure that you have obtained that person’s consent.
(1) Local Music and Media File Information
To provide music playback and related services, this Software reads, indexes, and processes, locally on your device, the audio files you choose to scan or import and their metadata, such as file name, duration, album, artist, and cover art. This information is primarily stored locally on your device to build a local music library and is not uploaded to our servers by default.
(2) Network Access and Device Connection Information
When you use functions such as online music access, LAN device discovery, or casting provided by this Software, information that you enter or that the system automatically obtains—including server addresses, access paths, usernames, passwords or app-specific passwords, names/models/network addresses of nearby devices, and playable media information—will be stored locally on your device or used only within the local network to establish connections, read media files, or complete playback control. We do not upload these credentials to our business servers; connections to servers or nearby devices that you specify are made directly by your device.
(3) Personalized Display Settings
When you set cover art, playback-page styles, or related personalized displays, image files selected from your photo album and the processed display data will be stored locally on your device.
(4) App Settings and Preference Information
To retain your playback preferences, this Software records settings locally, such as sound-effect parameters, playback-related switches, notification styles, language selections, and scanning rules. This information is generally stored only on your device.
1.2 To provide higher-quality products and/or services, we may collect the following information when you use extended functions. Refusing to provide it will not affect your normal use of the basic business functions under Section 1.1, but you may be unable to obtain the corresponding extended experience:
- App updates: When you proactively check for updates and confirm installation, this may involve app-version information and the downloading and installation of an installation package;
- System sharing: When you use the system sharing function to share crash logs or other content, the relevant content will be provided to the target app in accordance with your action;
- In-app webpages: When you browse webpages within this Software, the relevant pages may request camera, microphone, or location permissions according to their own rules.
You understand and agree that the services above may require you to enable the corresponding system permissions on your device. You may view and disable permissions in system settings. Enabling any permission means that you authorize us to collect and use the relevant information to provide the corresponding service. Disabling a permission means that you withdraw that authorization; we will no longer continue collecting or using the relevant information on the basis of that permission and will be unable to provide the corresponding service. Your decision to disable a permission does not affect information collected or used previously on the basis of your authorization.
For further clarity regarding the permissions invoked by this Software, they are summarized below:
| System Permission | Corresponding Business Function | Purpose of Permission | When Permission Is Requested |
|---|---|---|---|
| Network (wireless data) | Checking for updates, online music access, LAN device communication, etc. | Communicate with servers or nearby devices | When a function requiring network access is used |
| View network/Wi-Fi status | Network availability checks, LAN-related functions, and basic capabilities of third-party SDKs | Identify network connection status | When a function requiring network access is used or after the relevant SDK is initialized |
| Change Wi-Fi multicast state | Discover nearby playback devices on the LAN | Discover and connect to nearby devices | When the related device-discovery/connection function is first used |
| Storage/media (audio and images) | Scan local music, read cover art, save personalized display images, and cache media information | Read or save media files selected by you | Requested as needed at first launch or when scanning, selecting images, or similar functions are first used |
| Access to all files (Android 11 and later) | Scan and read music files on the device | Access music files in a scoped-storage environment | Requested as needed at first launch or the first music scan |
| Notifications | Playback-control notifications and background-playback reminders | Display media playback notifications | Requested as needed when playback notifications must be displayed |
| Foreground service/wake lock | Keep background playback and related services running | Ensure continuous playback and service stability | When background playback or a related service begins running |
| Install application packages | In-app updates | Install an update package after your confirmation | When you proactively check for an update and confirm installation |
| Camera | Taking photos on in-app webpages and certain system file/image-selection scenarios | Invoke the camera as required by a webpage or system component | Requested as needed when the relevant page or function is triggered |
| Microphone | Audio recording on in-app webpages | Invoke the microphone as required by a webpage function | When a webpage requests audio-recording permission |
| Location (precise/approximate) | Location services on in-app webpages | Obtain location as required by a webpage function | When a webpage requests location permission |
Note: The core music-playback functions of this Software mainly rely on local processing and do not proactively request precise location permissions such as GPS for advertising or user-profiling purposes. Location permission is triggered only as needed when a webpage you browse proactively requests it.
2. Personal Information We Proactively Collect While Providing Products and/or Services
Subject to applicable laws and regulations, to ensure your normal use of the Services, improve your experience, and maintain normal service operation, we may collect and use the following information generated during your use:
2.1 Device and App Information
When you use this Software, we may receive and record relevant device and app information to ensure version compatibility, update distribution, and service stability, including but not limited to the app package name, app version number, device model, operating-system version, device manufacturer, network access method and status, and IP address. After you agree to this Policy and the Umeng SDK is initialized, unique device identifiers, such as Android ID and OAID, may also be obtained through third-party SDKs. For details, refer to the third-party SDK description in Section IV of this Policy.
2.2 Log and Crash Information
When you use this Software, we may automatically collect usage information and save it as logs, including the software version number, network status, access date and time, operation records, crash stacks, and exception logs, in order to compile usage statistics, troubleshoot faults, and optimize the Services. Relevant crash information may be reported through components such as Bugly.
2.3 Usage Behavior Information
After you agree to this Policy, we may use analytics SDKs to collect behavior information such as page visits and feature usage for the purpose of analyzing product performance and improving the user experience. This information generally does not include the contents of your music files.
3. Data Processing Description
Please be aware that, in accordance with applicable laws and regulations, we may technically process your personal information so that an individual user cannot be precisely identified from it, and may conduct anonymized or de-identified research or statistical analysis on the processed information to improve product functions and service capabilities.
III. How We Use Cookies and Similar Technologies
This Software mainly runs as an Android client. We do not use our own cookies to deliver personalized advertisements to you. When you view the User Agreement, the Privacy Policy, or other pages through an in-app web component, the relevant pages may use standard browser or web-component technologies. Where third-party pages are involved, their published rules apply.
IV. How We Entrust Processing and Share, Transfer, or Publicly Disclose Your Personal Information
1. Entrusted Processing
To provide capabilities such as app update checks, exception monitoring, and statistical analysis, we may entrust the following types of partners to process relevant information. We will enter into strict agreements with, or require protective measures no less stringent than this Policy from, the companies, organizations, and individuals entrusted to process your personal information, and will limit the purposes and scope of processing.
- Cloud-service and business-system operators: When you use functions such as checking for updates within the App, we may submit the app package name, version number, language, device model, manufacturer, and similar information to a business server to determine whether a new version is available. The actual service domain name is subject to the implemented service.
- Exception-monitoring service providers: To troubleshoot crashes, we may entrust service providers such as Bugly to process technical information such as device information and crash logs.
- Statistical-analysis service providers: After you agree to this Policy, we may entrust statistical-analysis service providers such as Umeng to process device identifiers, usage behavior, and related information.
2. Sharing
We do not share your personal information with companies, organizations, or individuals other than the service providers for this product, except in the following circumstances:
- Sharing with your explicit consent;
- Sharing under statutory circumstances: as required by laws and regulations, for litigation or dispute resolution, or in response to lawful requests from administrative or judicial authorities;
- Sharing with affiliated companies: only to achieve the purposes stated in this Policy, sharing information necessary to provide the Services among affiliated companies and requiring them to adopt protective measures no less stringent than those in this Policy;
- Third-party SDKs and public interfaces: Certain capabilities of this Software are provided by cooperating third parties through SDKs or public APIs. Please read the list below carefully. We conduct security monitoring of integrated SDKs and endeavor to restrict them to obtaining only the information necessary to implement their functions. By clicking “Agree” to this Policy, you also authorize and agree that the relevant SDKs may obtain and process permissions and information as described in the table below.
| SDK/Component Name | Type | Company/Provider | Purpose/Scenario | Permissions Obtained | Types of Personal Information | Privacy Policy Link |
|---|---|---|---|---|---|---|
| Umeng+ Analytics/Base Library (common, asms) | Data analytics/base component | Umeng Tongxin (Beijing) Technology Co., Ltd. | Statistical analysis, basic anti-fraud, and service-stability assurance (initialized after you agree to this Policy) | Network permission, access to network/Wi-Fi status, etc. | Device information (Android ID, OAID, etc.), network information, IP address, device model, operating-system version, app version, etc. (subject to the official description) | https://www.umeng.com/page/policy |
| Bugly SDK | Exception monitoring | Shenzhen Tencent Computer Systems Company Limited | Capture and report app crashes and exception information for fault identification and repair | Network permission | Device information, crash stacks, log information, etc. (subject to Bugly’s official description) | Bugly SDK Privacy Protection Statement |
| OkHttp | Network communication dependency | Square, Inc. | Provide HTTP/HTTPS network-request capabilities | Network permission | Technical information generated during network requests, such as IP address and request destination; it generally does not separately collect users’ business personal information | The privacy policy of the business SDK to which it belongs applies |
Umeng+ Disclosure Reference Clause: Our product integrates the Umeng+ SDK. The Umeng+ SDK needs to collect your device MAC address; unique device identifiers, including IMEI/Android ID/OAID/IDFA/OPENUDID/GUID; SIM-card IMSI information; and similar data to provide statistical-analysis services. It may also conduct regional statistics based on network information such as IP addresses to improve report accuracy and provide basic anti-fraud support. This Software does not use precise-location permission for its core business and does not proactively collect your precise geographical location for music playback. For details, see: https://www.umeng.com/page/policy.
In addition to the SDKs listed in the table above, this Software also uses the following common capability components, mainly to complete local functions or business communications and generally triggered as needed after you agree to this Policy or use the corresponding function:
- Network-request component: HTTPS communications such as update checks;
- Local-storage component: Stores settings, playback queues, music-library indexes, network-access configurations, and business caches;
- Permission and notification component: Requests system permissions as needed and displays notifications;
- Image-loading component: Loads cover art, skins, and online images;
- Web-display component: Displays agreement pages or external links.
3. Transfer
We do not transfer your personal information to any company, organization, or individual, except in the following circumstances:
- Transfer with your explicit consent;
- Transfer where required by applicable laws and regulations, legal procedures, or mandatory administrative or judicial requirements;
- In the event of a merger, acquisition, bankruptcy liquidation, or similar transaction involving a transfer of personal information, we will require the new holder to remain bound by this Policy; otherwise, we will require it to obtain your authorization and consent again.
4. Public Disclosure
We publicly disclose your personal information only in the following circumstances:
- With your explicit consent or based on your proactive choice;
- Where required by law, legal proceedings, litigation, or mandatory requirements of competent government authorities.
5. Exceptions to Prior Authorization and Consent for Sharing, Transfer, or Public Disclosure of Personal Information
Prior authorization and consent are not required for sharing, transferring, or publicly disclosing your personal information in the following circumstances:
- Where directly related to our performance of obligations prescribed by laws and regulations;
- Where directly related to national security or national-defense security;
- Where directly related to public safety, public health, or major public interests;
- Where directly related to criminal investigation, prosecution, trial, or enforcement of judgments;
- Where necessary to protect your or another individual’s vital lawful rights and interests, such as life or property, and it is difficult to obtain the individual’s consent;
- Personal information that you have voluntarily disclosed to the public;
- Personal information collected from lawfully and publicly disclosed sources, such as lawful news reports or government information disclosure.
Please be aware that, under applicable law, sharing or transferring de-identified personal information does not constitute external sharing, transfer, or public disclosure of personal information if the data recipient is unable to restore the information and re-identify the personal information subject. The storage and processing of such data therefore do not require separate notice to or consent from you.
V. How We Protect Your Personal Information
- We attach great importance to user privacy and personal-information protection and will take reasonable measures to protect your personal information. Except as otherwise provided by laws and regulations or this Policy, we will not disclose or reveal your personal information to third parties without your permission, and we will use reasonable encrypted storage and transmission methods, such as SSL/TLS, to protect relevant information.
- For sensitive information such as account passwords stored locally by you, we recommend using dedicated passwords, changing them regularly, and keeping your device secure to prevent loss or unauthorized access.
- We will take reasonable and practicable measures to ensure that irrelevant personal information is not collected and will retain your personal information only for the period necessary to achieve the purposes described in this Policy, unless a longer retention period is required or permitted by law.
- The Internet is not an absolutely secure environment. Please safeguard your device and related configurations and assist us in ensuring secure use.
- If a personal-information security incident unfortunately occurs, we will, in accordance with applicable laws and regulations, promptly inform you of the basic circumstances and possible impact of the incident, the measures we have taken or will take, and recommendations that you may independently follow to prevent and reduce risks. Where it is difficult to notify individuals one by one, we will issue a notice in a reasonable and effective manner and report the incident as required by regulators.
VI. How We Store Your Personal Information
The products and/or services are intended for users in different countries and regions, including the United States. To the extent permitted by applicable law, we will collect, use, store, and process personal information according to the actual needs of providing the products and/or services and will take reasonable measures to protect the security of your personal information.
1. Storage Location
Your local music library, playlists, playback records, network-access configurations, personalized-display data, and most settings are primarily stored locally on your device. Information uploaded to servers through functions such as update checks, exception reporting, and statistical analysis is, in principle, stored on servers located within the People’s Republic of China. Exceptions apply where laws and regulations expressly provide otherwise, where your explicit authorization has been obtained, or where you proactively connect to an overseas server or access an overseas webpage.
2. Retention Period
Generally, local data remains on your device while you use the product, until you proactively delete it, uninstall the App, or reset the database. Server-side information necessary for update checks, exception troubleshooting, and statistical analysis will be retained for the shortest period necessary to achieve the relevant purpose, unless otherwise provided by laws and regulations.
When our products or services cease operation, we will notify you through push notifications, announcements, or similar means and will delete personal information retained on our servers within a reasonable period, unless otherwise provided by laws and regulations.
VII. How You May Exercise Your Rights to Manage Your Personal Information
In accordance with relevant laws, regulations, and standards of China, we safeguard your exercise of the following rights regarding your personal information:
1. Access, Correct, and Delete Your Information
- You may view and manage local playlists, playback records, scan paths, network-access configurations, skins, and cover art within this Software, subject to the functions actually available;
- You may clear the local music library and related data through functions such as “Reset Database” in “Settings”;
- You may contact us using the contact details in Section X of this Policy to submit an access, correction, or deletion request.
You may request that we delete personal information in any of the following circumstances: our processing of personal information violates laws or regulations; we collect or use your personal information without obtaining your consent; our processing violates our agreement with you; you no longer use our products or services; or we no longer provide products or services to you.
2. Change the Scope of Authorization and Consent or Withdraw Authorization
You may change the scope of authorization or withdraw authorization by disabling device functions, disabling permissions in system settings, uninstalling this Software, or similar means. Please be aware that each business function requires certain basic permissions or information to operate. After you withdraw consent or authorization, we will be unable to continue providing the service corresponding to the withdrawn consent or authorization and will cease processing the corresponding personal information. Your decision to withdraw consent or authorization will not affect personal-information processing previously carried out on the basis of your authorization.
3. Account Cancellation
The current version of Surfans Music is primarily intended for local use and does not provide an account system requiring registration and login. If a later version provides account functionality, we will separately explain how to cancel an account. You may also contact us using the contact details in Section X of this Policy for assistance.
4. Responding to Your Requests
To protect security, we may first require you to verify your identity and will process your request after successful verification. We will respond within a reasonable period after verification, in principle no more than 15 business days. We generally do not charge fees for reasonable requests. For repeated requests or requests exceeding reasonable limits, we may charge an appropriate cost-based fee or refuse the request, depending on the circumstances.
We will be unable to respond to your request in the following circumstances: where it relates to our performance of obligations prescribed by laws and regulations; where it is directly related to national security or national-defense security; where it is directly related to public safety, public health, or major public interests; where it is directly related to criminal investigation, prosecution, trial, or enforcement of judgments; where we have sufficient evidence that you are acting with subjective malice or abusing your rights; where necessary to protect your or another individual’s vital lawful rights and interests, such as life or property, and it is difficult to obtain the individual’s consent; where responding would cause serious harm to the lawful rights and interests of you or another individual or organization; or where trade secrets are involved.
VIII. How We Protect Minors’ Personal Information
We attach great importance to protecting minors’ personal information. We regard anyone under the age of 18 as a minor. If you are a minor, before downloading, installing, or using the products and/or services, you should read this Policy in the company of your guardian and obtain your guardian’s consent. If you are the guardian of a minor and have questions concerning the personal information of the minor under your guardianship, please contact us using the contact details set out in Section X.
For personal information of children under the age of 14 that may be involved, we will strictly comply with the Provisions on the Cyber Protection of Children’s Personal Information and other applicable laws and regulations when storing, using, or disclosing such information. We will not retain it beyond the period necessary to achieve the purposes of collection and use and will delete or anonymize it upon expiration.
IX. How We Update This Policy
We may revise this Policy from time to time. When changes occur, we will present the new Policy to you during a version update and explain its effective date. Please read the revised content carefully. If you continue using the Services, you agree that we may process your personal information in accordance with the updated Policy. We will provide a more prominent notice for material changes.
X. How to Contact Us
If you have any questions, comments, or suggestions concerning this Policy or personal-information protection, please contact us through the following methods:
Email: help@surfans.net
Developer Entity: Shenzhen Hengmaolong Technology Co., Limited
Contact Address: Room 218, Building D1, Huameiju Business Center, Xinhu Road, Bao'an Central District, Shenzhen, China
Under normal circumstances, we will respond within 15 business days after receiving your inquiry and verifying your identity.