要約を作成する場合、または翻訳や新しいコンテンツ作成を補助するために履歴、字幕、
翻訳、参照コンテキストを明示的に選択した場合、選択した内容はアプリに設定されたキーで
Google Geminiへ送信されるプロンプトまたはシステム指示に含まれることがあります。当社の
ユーザーデータ保存サーバーへこれらの内容を送信することはありません。
TikTokは広告アトリビューションのため、TikTok Business SDKが端末上で生成した
アプリインスタンスIDおよびIPベースの概算位置情報を受領する場合があります。本アプリはTikTok
Business SDKによるAndroid広告IDの収集を無効にしています。TikTokによるデータ保管期間および
利用方法は
TikTokプライバシーポリシー
に従います。
Google PlayのGenerative AI Appsポリシー(2024年4月)が要求する、不適切な
AIコンテンツをユーザーがアプリ内でフラグ立てできる仕組みへの準拠のため、ブログエディタには
報告ボタンを設けています。お客様が能動的にタップすると、本アプリは
HTTPS POSTで当社furuCRMサポートエンドポイントへ以下を送信します:
Effective date: 24 June 2026 · Last updated: 23 July 2026
Quick summary. Talk with Mozart supports an app-provided Free Key or your own
Gemini API key and does not require an account. It captures audio only while a session is live
and sends content directly to Google Gemini using the key configured in the App. Transcripts,
history, glossary entries, meeting photos, reference context, and files you actively choose are
stored or processed on your device. We do not run a backend that stores your meetings, and we do
not sell personal data.
1. Who we are
Talk with Mozart (the “App”) is published by furuCRM.
The App is a real-time speech translator that records short segments of microphone audio, sends
them to Google Gemini Live API for translation, and displays the result back to you.
This policy describes what Talk with Mozart collects and how it treats that data.
By installing and using the App you agree to this policy. The App does not require account
creation. We do not run a backend that stores your audio, transcripts, translations, glossary,
translation history, meeting photos, reference context, selected TXT files, or generated blog
content. The App connects to our endpoints for configuration, Free Key allocation, and
user-initiated AI content reports. If you do not agree, please uninstall the App.
3. Data we collect, and how
The categories below reflect the App's actual code paths.
3.1 Audio (microphone)
The App captures PCM-16 audio at 16 kHz only while a translation session is
active (you tapped Start). Capture stops immediately when you tap
End, leave the screen, or revoke microphone permission.
Audio chunks are streamed over a TLS-encrypted WebSocket to
Google Gemini Live API (generativelanguage.googleapis.com)
using the key configured in the App. We do not store, log, or proxy this audio
on any server we operate.
Audio is never written to disk. It is held in memory only long enough to be sent and
is dropped immediately when text-to-speech (TTS) is playing back, to avoid feedback.
3.2 Transcripts and translations
The text produced by Gemini (original transcription + translation) is shown on
screen and saved on your device:
Per-session lines in a Hive box named transcripts.
A SQLite database live_translate_history.db holds the full
history of meetings (date, language pair, summary, action items).
These records are stored in the App's private storage area, protected by Android
sandboxing and by the operating system's security/encryption mechanisms where available.
They are not synced to any cloud and never leave the device unless you explicitly use a
processing or sharing feature.
When you create a summary or actively select a piece of history, transcript, translation,
or reference context to support translation or new content generation, the selected content
may be included in the prompt or system instruction sent to Google Gemini using the key
configured in the App. We do not send this content to our own user-data storage servers.
3.3 Glossary entries
Terms you add through the Glossary screen are stored in the same on-device SQLite database
in the glossary table. When you import CSV or choose a TXT context file, the App
reads only the file you selected through the document picker. It does not access your entire
storage, photos, or file library.
When glossary entries or reference context selected by you are available, relevant items
may be sent to Google Gemini using the key configured in the App as part of a system instruction,
session prompt, glossary-application step, or context-based content generation step. Other
than Google Gemini for this feature processing, we do not send your glossary to any third
party.
3.4 Gemini API keys (Free Key and your own API key)
Both key types are stored using flutter_secure_storage, which on Android writes to
EncryptedSharedPreferences backed by the Android Keystore.
Your own API key: a key you enter is sent only in TLS requests directly to
Google's API; we do not receive it.
Free Key: when you tap Try free, the App sends its app name,
platform, and app version to our Free Key endpoint. Our Salesforce key pool returns a Gemini
key and allocation-record ID, which the App stores securely. We manage the allocation record
but do not receive meeting content. Each Free Key conversation is limited to five minutes and
does not include an AI summary.
3.5 Sharing (Android share menu)
When you choose to share a summary or translation, the App passes only your selected content
to Android's standard share menu. You choose the destination each time; no furuCRM server is
involved.
3.6 Analytics (Firebase Analytics)
The App uses Firebase Analytics (Google LLC) to understand feature use.
Events are not associated with an in-app account and do not contain transcript or translation
text.
Events may include screen views, target language, session duration, translation-count and
feature-use values, share channel, and limited error diagnostics.
Firebase automatically collects: an app-instance ID, device model,
OS version, language, and country (from IP, approximate). The App currently does not use
Firebase Crashlytics or Firebase Performance Monitoring.
3.7 Advertising (Google AdMob)
When the remote killswitch enables ads, the App shows AdMob native ads on Home,
History, and Summary screens and an occasional interstitial after a session ends.
Ads are never shown during a live translation session.
AdMob may access the Android Advertising ID (AD_ID) to deliver
relevant ads and measure performance. You can reset or delete this ID in
Settings → Google → Ads.
3.8 Ad attribution (Meta App Events SDK)
Solely to measure the performance of Meta advertising campaigns, the App sends a small
number of custom events (prefixed mwz_*) to the Meta App Events SDK.
Examples: mwz_onboarding_start, mwz_translation_session_start,
mwz_translation_session_60s, mwz_summary_generated,
mwz_action_items_generated, mwz_glossary_imported,
mwz_share_sent, mwz_api_key_screen_view,
mwz_api_key_saved.
Each event carries the event name and, depending on the event type, may include the platform,
app version, and
coarse bucketed values (e.g. duration_bucket,
count_bucket, target_language_code) only.
Audio, transcripts, translations, summary text, glossary contents, your Gemini API
key, and any personally identifying information are never included.
Meta may receive an app-instance ID generated by the SDK on your device, the Android
Advertising ID, and an IP-derived approximate location for ad attribution purposes.
Meta's data retention and use
are governed by the
Meta Privacy Policy.
3.9 Ad attribution (TikTok Business SDK)
Solely to measure the performance of TikTok advertising campaigns, the App sends the
same custom events (mwz_* prefix) that it sends to the
Meta App Events SDK in parallel to the TikTok Business SDK. Event content and bucketing
rules are identical to §3.8. Audio, transcripts, translations, summary text,
glossary contents, your Gemini API key, and any personally identifying
information are never included.
The TikTok Business SDK only activates when a TikTok App ID
issued by TikTok Events Manager is delivered via our remote configuration endpoint.
Because TikTok issues the App ID only after the app is live on Google Play, pre-launch
builds and builds where the ID is not yet configured always run in dormant mode
(no event delivery).
TikTok may receive an app-instance ID generated by the SDK on your device and an IP-derived
approximate location for ad attribution purposes. The App disables Android Advertising ID
collection in the TikTok Business SDK. TikTok's data retention
and use are governed by the
TikTok Privacy Policy.
3.10 Remote configuration
On launch, the App makes a GET request to a configuration endpoint to fetch
feature flags, frequency caps for ads, the privacy URL, and the support email.
The request does not include audio, transcripts, translations, glossary entries,
translation history, Gemini API key, or user account information. Like any normal HTTPS
connection, the endpoint or network infrastructure may receive standard technical
information such as an IP address, but we do not use that information to identify users
or combine it with translation content.
3.11 Peer-to-peer sharing — Google Nearby Connections
The Peer feature uses Google's Nearby Connections API
over Bluetooth Classic / BLE / Wi-Fi LAN / Wi-Fi Aware to discover nearby devices.
Only the translated text segments you choose to broadcast are sent directly to the paired
device. No server is involved and we do not see this traffic.
Host / Viewer mode: one host device (with mic + Gemini access)
can broadcast captions and translations to nearby viewer devices. Viewer devices
do not need a Gemini API key. Hosts advertise with a HOST::
name prefix and only accept viewers they invite; viewers only request connections to
HOST:: endpoints.
Display name: the user-set display name (up to 32 characters) configured
in Settings is shown to peers during pairing. If unset, the OS device name
(Settings.Global.DEVICE_NAME on Android 12+ or Build.MODEL on
older OS) is used. The display name is stored only inside the app sandbox (Hive box
settings) and is never sent to our servers.
3.12 TXT files, reference context, and AI blog generation
Some features may let you enter text hints, select pieces of history, select reference
context, or attach a TXT file to support content generation, such as drafting a blog post
or improving translation quality.
When you tap the Write blog button on the summary screen, the session's
summary text + transcript are sent over HTTPS to Google Gemini (2.5 Flash model) under
the key configured in the App to draft a blog post. Anything you type in the optional
"Hint for the AI" field and the contents of a TXT file you choose may be sent along too
so the model can adapt the tone, angle, and background context.
When you actively choose a TXT file through the document picker, the App reads only the
selected file. The TXT content may be used as context and sent to Google Gemini under
the key configured in the App together with the relevant prompt or content-generation request.
The App does not automatically scan folders, access your entire device storage, save TXT
file paths, keep a long-term copy of TXT content in SQLite/Hive after the operation completes,
or send TXT files or TXT content to our own user-data storage servers unless you actively save
or share that content through an App feature.
The draft is persisted on the device in the same SQLite database (the blog_draft
column of the meetings table) so re-opening the editor does NOT re-call Gemini —
this saves your API tokens. Drafts are NOT synced to Google Drive or any cloud.
While you edit the draft, changes are auto-saved to local SQLite roughly 1 second after
your last keystroke. Persistence stays entirely on the device.
3.13 AI content reports
To comply with Google Play's Generative AI Apps policy (April 2024),
which requires an in-app mechanism for users to flag offensive AI content, the App provides
a Report button on the Blog editor. When you actively tap it, the App
sends via HTTPS POST to our furuCRM support endpoint the following:
An excerpt of up to 190 characters of the AI content being reported
App name, version, target language, AI provider ("Google Gemini")
The request does NOT include: the full AI content, your Gemini API key, any account
information, contacts, location, or other translation content. Any field without data is
sent as the literal string "N/A".
Purpose: to comply with Google Play policy; to improve content safety by reviewing reports
and tuning prompts/filters.
Retention: reports are kept for up to 90 days in our furuCRM support system, after which
they are deleted. Reports are not shared with third parties outside the internal content
review system.
3.14 Meeting photos
When you tap the camera button during a live session, or long-press it to choose an existing
image, the App processes only the photo you capture or select.
The image, capture time, dimensions, file size, and any note you add are stored in app-scoped
storage and linked to that meeting's local history. Photos are not sent to furuCRM, Google
Gemini, Firebase, AdMob, Meta, or TikTok.
You can delete an individual photo or its meeting in the App. Clearing app data or
uninstalling the App removes the locally stored photos.
4. Data we do not collect
We do not require an account. We have no username, email, password, or profile data about you.
We do not collect contacts, calendar, SMS, call logs, or precise GPS location. The App does
not scan your entire storage or photo library; it reads only files or photos you actively
choose.
We do not record or upload audio outside the live Gemini session.
We do not sell personal data. We do not share data with data brokers.
5. Why we process this data
Category
Purpose
Legal basis (GDPR)
Microphone audio
Provide live translation (core function)
Performance of contract (Art. 6(1)(b))
Transcripts, glossary, reference context, selected files and meeting photos
Local app functionality, translation, summaries, blog content generation, and meeting history
Performance of contract
Firebase Analytics
Aggregate product analytics
Legitimate interest (Art. 6(1)(f))
AdMob
Display ads to support the free tier
Consent (Art. 6(1)(a)) where required by GDPR
Remote configuration
Toggle features, frequency caps, killswitches
Legitimate interest
6. Third-party services
When you use the App, the following independent services may receive data. Each operates under its own privacy policy.
Service
What it receives
Their policy
Google Gemini API
Microphone audio, glossary entries, system prompt, text to translate or summarize, referenced history, reference context, text hints, selected TXT content, blog-generation requests, and generated text. Sent directly using the configured Free Key or your own API key after you use the relevant feature.
Advertising ID, IP address, ad interactions, device type, diagnostic information, and device/account identifiers processed by Google for ad delivery, ad performance measurement, analytics, and fraud prevention. Subject to AdMob's EU and CCPA compliance flows.
Configuration: static app identifier and standard HTTPS technical data such as IP. Free Key: app name, platform, and app version; returns a Gemini key and allocation ID. AI report: only when you tap Report, an AI-content excerpt, reason, notes, and app metadata.
Covered by this policy.
Android share menu (optional, user-initiated)
Only the content you choose to share; you select the destination.
Your chosen destination's terms.
7. Advertising
7.1 Where ads appear
Native ads on the Home idle screen, History list, and Summary screen.
Interstitial ads only after a translation session has fully ended.
No ads during live capture, no app-open ads, no sticky banners.
7.2 Personalised vs. non-personalised ads
We use Google AdMob to display ads. Depending on your region, applicable law, and Google AdMob
configuration, ads may be delivered as personalised ads, non-personalised ads, or limited ads,
and additional consent choices may be required where applicable. You can reset or delete the
Android Advertising ID in Settings → Google → Ads. The current App build does
not provide its own in-app consent-management screen. Accordingly, in the EEA, UK, Switzerland,
or any other region where consent is required, the App must not request personalised ads until
an appropriate Google-certified consent-management flow is available; advertising must instead
remain disabled or be limited to an ad-serving mode that satisfies the applicable requirements.
7.3 Children
The App is not directed to children and is not designed specifically for children under 13 or
the minimum age required by applicable law in your region. We do not intentionally show ads
to children.
8. Android permissions
Permission
Why the App needs it
RECORD_AUDIO
Capture the microphone for live translation.
CAMERA
Capture slide photos only when you tap the camera icon inside a live session. Photos are saved to app-scoped storage on your device and are never uploaded to our servers or sent to Gemini.
INTERNET
Stream audio to Gemini and fetch remote configuration.
WAKE_LOCK
Keep the screen / CPU awake during a live session.
Google Nearby Connections peer sharing — Wi-Fi discovery for the same feature. Declared with neverForLocation so no location is inferred.
ACCESS_COARSE_LOCATION, ACCESS_FINE_LOCATION
Required by Android 12 and older as an OS-level side-effect of BLE scanning. The App does not read your GPS or use your location for any product feature.
com.google.android.gms.permission.AD_ID
Lets AdMob read the Advertising ID for ad delivery. You can reset/delete the ID anytime in Android Settings.
9. Data retention and deletion
On-device data (API key, transcripts, glossary, history, summary content,
meeting photos, and related settings) lives only on your phone until you delete it from within the App,
clear app data, or uninstall. TXT files or context files you choose are read only for the
relevant operation and are not kept as a long-term copy in SQLite/Hive unless you actively
save that content through an App feature.
Uninstalling the App removes app-scoped local data. We do not store meeting
content on our servers, but Free Key allocation records, AI content reports, and standard server
access logs may remain for the periods needed for their stated purposes.
Firebase Analytics data is retained for the period configured in our
Firebase project (default 14 months) and then deleted automatically.
AdMob retention follows Google's policies.
Meta App Events and TikTok Business Events follow their
respective providers' retention policies and controls.
AI content reports are retained for up to 90 days.
Free Key issuance information: When you choose the free trial, we store the
issuance ID, issuance time, key status, and technical information needed to operate the
service, provide support, and prevent abuse. This information does not include audio, meeting
content, captions, transcripts, translations, or meeting photos. We delete or anonymise it
when it is no longer needed for these purposes, unless continued retention is required for
legal, security, or abuse-prevention reasons.
Google Gemini retention follows the terms applicable to your Google account
when using your own API key, or to the Google project behind the Free Key we provide.
10. Your rights (GDPR, CCPA, and similar laws)
You may at any time:
Consent to AI data sharing — on first launch, an in-app onboarding
screen explicitly discloses what data is sent to Google Gemini, who receives it, and for what
purpose. Translation features are locked until you tap the “I Agree” button.
This consent is captured in-app and is separate from this Privacy Policy.
Withdraw AI consent — Settings → “AI Data Sharing”
→ “Revoke consent” revokes consent in one tap. Revocation also clears your
Gemini API key from the device — without a key, no data can be sent to Gemini.
Alternatively, Settings → API Key → Clear has the same effect (clearing the key
automatically revokes AI consent).
Access local meeting data via History, Glossary, and Settings. Contact us regarding
analytics, advertising, Free Key allocation, or AI-report data within our control.
Delete a session in History, delete glossary entries, or clear the entire app data
from Android Settings.
Withdraw analytics: currently, you can stop future analytics events by uninstalling the App.
We may add a direct analytics control in the App's Settings in a future version.
Manage personalised ads by resetting or deleting the Android Advertising ID in
Settings → Google → Ads, or through consent choices shown by Google AdMob
where applicable in your region.
For Meta advertising attribution, you may reset or delete the Android Advertising ID and use
Meta's privacy controls. Android Advertising ID collection is disabled in the TikTok SDK.
The current App does not include a
dedicated opt-out switch for these SDKs. Uninstalling the App stops future event transmission.
Contact us to exercise rights concerning data within our control.
Request information or lodge a complaint by emailing
app-support@furucrm.com. We will respond within
30 days.
EEA/UK residents may lodge a complaint with their national Data Protection Authority.
California residents have additional rights under CCPA/CPRA: rights
to know, delete, correct, opt out of sale or sharing, and non-discrimination. We do not sell
personal information. Transfers to advertising and attribution providers are described in
Sections 3 and 6. Exercise applicable opt-out rights through Android or provider controls, or
contact us.
11. Children's privacy
Talk with Mozart is not directed to children and is not designed specifically for children
under 13 or the minimum age required by applicable law in your region. We do not knowingly
collect personal data from children. If you believe a child has provided personal data to
the App, please contact us so we can help process or delete data within our control.
12. Security
All network requests use HTTPS / TLS 1.2 or higher.
The configured Gemini API key is stored in Android EncryptedSharedPreferences
via flutter_secure_storage, backed by the Android Keystore.
Transcripts and history are stored in the App's private storage, isolated from
other apps by Android sandboxing.
We do not run a backend that centrally stores audio, transcripts, translations, glossary
entries, translation history, reference context, selected TXT files, generated blog content,
or Gemini API keys, so there is no central database containing that content on our side.
13. International data transfers
When you use the App, data may be processed by Google LLC and its sub-processors,
which can include data centres in the United States and other countries. Google relies
on Standard Contractual Clauses (SCCs) and EU–US Data Privacy Framework where
applicable. Please review Google's policies for details.
14. Policy changes and contact information
We may update this Policy when we add new features or when applicable law changes. We will
notify you of material changes through an in-app notice or on the Google Play product page.
If you have any privacy-related questions or concerns, please contact our development team at:
Ngày hiệu lực: 24/06/2026 · Cập nhật lần cuối: 23/07/2026
Tóm tắt nhanh. Talk with Mozart hỗ trợ Free Key do Ứng dụng cung cấp hoặc
Gemini API key của riêng bạn và không yêu cầu tài khoản. Ứng dụng chỉ ghi âm khi phiên đang chạy
và gửi nội dung trực tiếp tới Google Gemini bằng key được cấu hình trong Ứng dụng. Bản ghi, lịch sử,
từ điển, ảnh cuộc họp, ngữ cảnh tham chiếu và các tệp bạn chủ động chọn được lưu hoặc xử lý trên
thiết bị. Chúng tôi không vận hành backend lưu nội dung cuộc họp và không bán dữ liệu cá nhân.
1. Chúng tôi là ai
Talk with Mozart (sau đây gọi là “Ứng dụng”) được phát hành bởi
furuCRM. Ứng dụng là trình dịch giọng nói thời gian thực: ghi các đoạn ngắn
âm thanh từ mic, gửi đến Google Gemini Live API để dịch và hiển thị kết quả lên màn hình.
Chính sách này mô tả những gì Talk with Mozart thu thập và cách xử lý dữ liệu đó.
Khi cài đặt và sử dụng Ứng dụng, bạn đồng ý với chính sách này. Ứng dụng không yêu cầu tạo tài khoản.
Chúng tôi không vận hành backend để lưu trữ âm thanh, bản ghi, bản dịch, từ điển, lịch sử dịch,
ảnh cuộc họp, ngữ cảnh tham chiếu, tệp TXT bạn chọn hoặc nội dung tạo blog. Ứng dụng kết nối tới
endpoint của chúng tôi để lấy cấu hình, cấp Free Key và nhận báo cáo nội dung AI do bạn chủ động gửi.
Nếu không đồng ý, vui lòng gỡ cài đặt.
3. Dữ liệu chúng tôi thu thập, và bằng cách nào
Các danh mục dưới đây phản ánh đúng các đoạn mã thực tế trong Ứng dụng.
3.1 Âm thanh (mic)
Ứng dụng ghi âm PCM-16 ở 16 kHz chỉ khi phiên dịch đang hoạt động
(bạn đã chạm Bắt đầu). Quá trình ghi dừng ngay khi bạn chạm
Kết thúc, rời màn hình, hoặc thu hồi quyền mic.
Các khối âm thanh được truyền qua WebSocket mã hóa TLS đến
Google Gemini Live API
(generativelanguage.googleapis.com) bằng key được cấu hình trong Ứng dụng.
Chúng tôi không lưu, không ghi log, không trung chuyển âm thanh trên bất kỳ máy chủ nào do chúng tôi vận hành.
Âm thanh không bao giờ được ghi xuống đĩa. Nó chỉ tồn tại trong bộ nhớ đủ lâu để gửi đi và bị hủy ngay khi TTS đang phát, để tránh phản hồi.
3.2 Bản ghi và bản dịch
Văn bản do Gemini tạo (bản gốc + bản dịch) được hiển thị trên màn hình và lưu trên thiết bị:
Các dòng theo phiên trong Hive box tên transcripts.
SQLite database live_translate_history.db lưu toàn bộ lịch sử cuộc họp (ngày, cặp ngôn ngữ, tóm tắt, action items).
Các bản ghi này nằm trong vùng lưu trữ riêng của Ứng dụng, được bảo vệ bởi sandbox của Android
và cơ chế bảo mật/mã hóa của hệ điều hành nếu khả dụng. Chúng không đồng bộ lên bất kỳ đám mây
nào và không rời thiết bị trừ khi bạn chủ động dùng tính năng xử lý hoặc chia sẻ.
Khi bạn tạo tóm tắt hoặc chủ động chọn một đoạn lịch sử, bản ghi, bản dịch hoặc ngữ cảnh tham chiếu
để hỗ trợ phiên dịch hoặc tạo nội dung mới, nội dung bạn chọn có thể được đưa vào prompt hoặc
system instruction gửi tới Google Gemini bằng key được cấu hình trong Ứng dụng. Chúng tôi không gửi các
nội dung này tới máy chủ lưu trữ dữ liệu người dùng của chúng tôi.
3.3 Từ điển
Các thuật ngữ bạn thêm qua màn hình Từ điển lưu trong cùng SQLite database trong bảng
glossary. Khi import CSV hoặc chọn tệp ngữ cảnh TXT, Ứng dụng chỉ đọc đúng tệp
bạn chọn qua bộ chọn tài liệu. Ứng dụng không tự quét toàn bộ bộ nhớ hay thư viện ảnh và chỉ đọc
tệp hoặc ảnh bạn chủ động chọn.
Khi có từ điển hoặc ngữ cảnh tham chiếu do bạn chọn, các mục liên quan có thể được gửi tới
Google Gemini bằng key được cấu hình trong Ứng dụng — như một phần system instruction, prompt của phiên,
bước áp dụng từ điển, hoặc bước tạo nội dung dựa trên ngữ cảnh. Ngoài Google Gemini cho mục đích
xử lý tính năng này, chúng tôi không gửi từ điển của bạn tới bên thứ ba nào khác.
3.4 Gemini API key (Free Key và API key của riêng bạn)
Cả hai loại key được lưu qua flutter_secure_storage, trên Android sẽ ghi vào
EncryptedSharedPreferences được Android Keystore bảo vệ.
Key của riêng bạn: key bạn nhập chỉ được dùng trong yêu cầu TLS trực tiếp tới
API của Google; chúng tôi không nhận key này.
Free Key: khi bạn bấm Dùng thử miễn phí, Ứng dụng gửi tên app,
nền tảng và phiên bản app tới endpoint Free Key. Key pool Salesforce trả về Gemini key và ID
cấp phát để Ứng dụng lưu an toàn. Chúng tôi quản lý bản ghi cấp phát nhưng không nhận nội dung
cuộc họp. Mỗi cuộc trò chuyện dùng Free Key giới hạn 5 phút và không có tóm tắt AI.
3.5 Chia sẻ (menu chia sẻ Android)
Khi bạn chọn chia sẻ tóm tắt hoặc bản dịch, Ứng dụng chỉ chuyển nội dung bạn chọn tới menu
chia sẻ chuẩn của Android. Bạn chọn đích đến mỗi lần; máy chủ furuCRM không tham gia.
3.6 Phân tích (Firebase Analytics)
Ứng dụng dùng Firebase Analytics (Google LLC) để hiểu cách sử dụng tính năng.
Sự kiện không gắn với tài khoản trong app và không chứa nội dung bản ghi hoặc bản dịch.
Sự kiện có thể gồm màn hình đã xem, ngôn ngữ đích, thời lượng phiên, số lượng bản dịch,
giá trị sử dụng tính năng, kênh chia sẻ và thông tin chẩn đoán lỗi giới hạn.
Firebase tự động thu thập: app-instance ID, model thiết bị, phiên bản OS,
ngôn ngữ và quốc gia (từ IP, ước chừng). Ứng dụng hiện không dùng Firebase Crashlytics hoặc
Firebase Performance Monitoring.
3.7 Quảng cáo (Google AdMob)
Khi killswitch từ xa bật quảng cáo, Ứng dụng hiển thị AdMob native ad trên màn hình
Home, Lịch sử, Tóm tắt và thi thoảng interstitial sau khi kết thúc phiên.
Không bao giờ hiển thị quảng cáo trong phiên dịch trực tiếp.
AdMob có thể truy cập Android Advertising ID (AD_ID) để phân phối
quảng cáo phù hợp và đo lường hiệu năng. Bạn có thể reset hoặc xóa ID này trong
Cài đặt → Google → Ads.
3.8 Attribution quảng cáo (Meta App Events SDK)
Chỉ nhằm đo hiệu quả chiến dịch quảng cáo Meta, Ứng dụng gửi một vài custom event
(prefix mwz_*) đến Meta App Events SDK. Ví dụ:
mwz_onboarding_start, mwz_translation_session_start,
mwz_translation_session_60s, mwz_summary_generated,
mwz_action_items_generated, mwz_glossary_imported,
mwz_share_sent, mwz_api_key_screen_view,
mwz_api_key_saved.
Mỗi event chứa tên event và, tùy theo loại event, có thể chứa platform, phiên bản app và các
giá trị bucketed thô (VD: duration_bucket,
count_bucket, target_language_code).
Âm thanh, bản ghi, bản dịch, nội dung tóm tắt, nội dung từ điển, Gemini API key,
và bất kỳ thông tin cá nhân nào đều KHÔNG được gửi kèm.
Meta có thể nhận app-instance ID do SDK tạo trên thiết bị, Android Advertising ID và vị trí
xấp xỉ theo IP cho mục đích attribution quảng cáo. Việc lưu giữ và sử dụng dữ liệu của Meta tuân theo
Chính sách quyền riêng tư của Meta.
3.9 Attribution quảng cáo (TikTok Business SDK)
Chỉ nhằm đo hiệu quả chiến dịch quảng cáo TikTok, Ứng dụng gửi cùng những custom
event (prefix mwz_*) mà nó gửi đến Meta App Events SDK song song sang
TikTok Business SDK. Nội dung event và quy tắc bucketing giống hệt §3.8.
Âm thanh, bản ghi, bản dịch, nội dung tóm tắt, nội dung từ điển, Gemini API key,
và bất kỳ thông tin cá nhân nào đều KHÔNG được gửi kèm.
TikTok Business SDK chỉ được kích hoạt khi TikTok App ID
do TikTok Events Manager cấp được phân phối qua endpoint cấu hình từ xa của chúng tôi.
Vì TikTok chỉ cấp App ID sau khi ứng dụng đã lên Google Play, các bản build trước khi ra mắt
và các bản chưa được cấu hình ID luôn chạy ở chế độ ngủ (không gửi event).
TikTok có thể nhận app-instance ID do SDK tạo trên thiết bị và vị trí xấp xỉ theo IP cho mục
đích attribution quảng cáo. Ứng dụng đã tắt việc thu thập Android Advertising ID trong TikTok
Business SDK. Việc lưu giữ và sử dụng dữ liệu của TikTok tuân theo
Chính sách quyền riêng tư của TikTok.
3.10 Cấu hình từ xa
Khi khởi động, Ứng dụng gửi yêu cầu GET đến endpoint cấu hình để lấy feature flag,
giới hạn tần suất quảng cáo, URL chính sách và email hỗ trợ.
Yêu cầu này không bao gồm âm thanh, bản ghi, bản dịch, từ điển, lịch sử dịch, Gemini API key
hoặc thông tin tài khoản người dùng. Như mọi kết nối HTTPS thông thường, endpoint hoặc hạ tầng
mạng có thể nhận thông tin kỹ thuật tiêu chuẩn như địa chỉ IP, nhưng chúng tôi không dùng thông
tin này để định danh người dùng hoặc kết hợp với nội dung dịch.
3.11 Chia sẻ ngang hàng — Google Nearby Connections
Tính năng Peer dùng Google Nearby Connections API
qua Bluetooth Classic / BLE / Wi-Fi LAN / Wi-Fi Aware để phát hiện thiết bị gần.
Chỉ những đoạn văn bản đã dịch bạn chọn phát đi mới được gửi trực tiếp tới thiết bị ghép cặp.
Không máy chủ nào can dự và chúng tôi không thấy lưu lượng này.
Chế độ Host / Viewer: một máy host (có mic + truy cập Gemini)
có thể broadcast phụ đề và bản dịch tới các máy viewer gần. Máy viewer
không cần Gemini API key. Máy host advertise với tiền tố HOST::
trong tên peer và chỉ chấp nhận các viewer được mời; máy viewer chỉ gửi yêu cầu kết nối tới các
endpoint có tiền tố HOST::.
Tên hiển thị: tên hiển thị tùy chỉnh (tối đa 32 ký tự) trong Cài đặt
sẽ hiển thị cho các peer khi pair. Nếu chưa đặt, tên thiết bị OS
(Settings.Global.DEVICE_NAME trên Android 12+ hoặc Build.MODEL
trên OS cũ hơn) được dùng làm mặc định. Tên hiển thị chỉ lưu trong sandbox của ứng dụng
(Hive box settings) và không gửi tới máy chủ của chúng tôi.
3.12 Tệp TXT, ngữ cảnh tham chiếu và tạo nội dung blog
Một số tính năng có thể cho phép bạn nhập gợi ý văn bản, chọn đoạn lịch sử, chọn ngữ cảnh
tham chiếu hoặc đính kèm tệp TXT để hỗ trợ tạo nội dung, ví dụ tạo bản nháp blog hoặc cải
thiện chất lượng phiên dịch.
Khi bạn bấm nút Viết bài blog trên màn hình tóm tắt, văn bản tóm tắt + transcript
của phiên đó được gửi qua HTTPS tới Google Gemini (mô hình 2.5 Flash) bằng key được cấu hình trong Ứng dụng
để sinh ra bản nháp blog. Tùy chọn bạn nhập trong field "Gợi ý cho AI" và nội dung tệp TXT
bạn chọn cũng có thể được gửi kèm để điều hướng phong cách viết, góc nhìn và ngữ cảnh nền.
Khi bạn chủ động chọn tệp TXT qua bộ chọn tài liệu, Ứng dụng chỉ đọc tệp bạn đã chọn.
Nội dung tệp TXT có thể được dùng làm ngữ cảnh và được gửi tới Google Gemini bằng
key được cấu hình trong Ứng dụng cùng với prompt hoặc yêu cầu tạo nội dung tương ứng.
Ứng dụng không tự động quét thư mục, không truy cập toàn bộ bộ nhớ thiết bị, không lưu đường
dẫn tệp TXT, không lưu bản sao nội dung TXT lâu dài vào SQLite/Hive sau khi thao tác hoàn tất,
và không gửi tệp TXT hoặc nội dung tệp TXT tới máy chủ lưu trữ dữ liệu người dùng của chúng tôi,
trừ khi bạn chủ động lưu hoặc chia sẻ nội dung đó thông qua một tính năng của Ứng dụng.
Bản nháp blog được lưu trên thiết bị trong cùng SQLite database (cột blog_draft
của bảng meetings) để lần sau mở lại không phải gọi Gemini sinh lại — tiết kiệm
token. Bản nháp KHÔNG đồng bộ qua Google Drive hay đám mây nào.
Khi bạn chỉnh sửa bản nháp, thay đổi được auto-save vào SQLite local mỗi 1 giây sau lần gõ
cuối, hoàn toàn trên thiết bị.
3.13 Báo cáo nội dung AI
Để tuân thủ chính sách Generative AI Apps của Google Play (tháng 4/2024)
yêu cầu cơ chế in-app cho user flag nội dung AI không phù hợp, Ứng dụng có nút
Báo cáo trên màn hình Viết blog. Khi bạn chủ động bấm nút này, Ứng dụng
gửi qua HTTPS POST tới endpoint hỗ trợ furuCRM các thông tin sau:
Trích đoạn tối đa 190 ký tự của nội dung AI bị báo cáo
Lý do bạn chọn (Không phù hợp / Xúc phạm / Thiếu chính xác / Spam / Khác)
Ghi chú tuỳ chọn bạn nhập (tối đa 500 ký tự)
Tên app, phiên bản, ngôn ngữ đích, nhà cung cấp AI ("Google Gemini")
Yêu cầu KHÔNG bao gồm: full nội dung AI, Gemini API key, thông tin tài khoản, danh sách
contact, vị trí, hay nội dung dịch khác. Mọi field không có dữ liệu được gửi giá trị
"N/A".
Mục đích: tuân thủ chính sách Google Play; cải thiện content safety bằng cách review báo cáo
và điều chỉnh prompt/filter.
Retention: báo cáo được lưu tối đa 90 ngày trong hệ thống hỗ trợ của furuCRM, sau đó tự xoá.
Báo cáo không được chia sẻ với bên thứ ba ngoài hệ thống nội bộ review nội dung.
3.14 Ảnh cuộc họp
Khi bạn chạm nút camera trong phiên trực tiếp hoặc nhấn giữ để chọn ảnh có sẵn, Ứng dụng chỉ
xử lý ảnh bạn chụp hoặc chủ động chọn.
Ảnh, thời gian chụp, kích thước, dung lượng và ghi chú bạn thêm được lưu trong vùng riêng của
Ứng dụng và gắn với lịch sử cuộc họp trên thiết bị. Ảnh không được gửi tới furuCRM, Google Gemini,
Firebase, AdMob, Meta hoặc TikTok.
Bạn có thể xóa từng ảnh hoặc cuộc họp trong Ứng dụng. Xóa app data hoặc gỡ cài đặt sẽ xóa ảnh cục bộ.
4. Dữ liệu chúng tôi không thu thập
Chúng tôi không yêu cầu tài khoản. Không có username, email, mật khẩu, hay hồ sơ về bạn.
Không thu thập danh bạ, lịch, SMS, nhật ký cuộc gọi, hay vị trí GPS chính xác. Ứng dụng không
tự quét toàn bộ bộ nhớ hoặc thư viện ảnh; chỉ đọc tệp hoặc ảnh bạn chủ động chọn.
Không ghi hay tải lên âm thanh ngoài phiên Gemini trực tiếp.
Không bán dữ liệu cá nhân. Không chia sẻ với data broker.
5. Mục đích xử lý dữ liệu
Danh mục
Mục đích
Cơ sở pháp lý (GDPR)
Âm thanh mic
Cung cấp dịch trực tiếp (chức năng cốt lõi)
Thực hiện hợp đồng (Điều 6(1)(b))
Bản ghi, từ điển, ngữ cảnh tham chiếu, tệp đã chọn và ảnh cuộc họp
Chức năng cục bộ, dịch, tóm tắt, tạo blog và lịch sử cuộc họp
Thực hiện hợp đồng
Firebase Analytics
Phân tích sản phẩm tổng hợp
Lợi ích chính đáng (Điều 6(1)(f))
AdMob
Hiển thị quảng cáo hỗ trợ phiên bản miễn phí
Sự đồng ý (Điều 6(1)(a)) nơi GDPR yêu cầu
Cấu hình từ xa
Bật/tắt tính năng, giới hạn tần suất, killswitch
Lợi ích chính đáng
6. Dịch vụ bên thứ ba
Khi bạn dùng Ứng dụng, các dịch vụ độc lập sau có thể nhận dữ liệu. Mỗi bên hoạt động theo chính sách riêng của họ.
Dịch vụ
Nhận gì
Chính sách của họ
Google Gemini API
Âm thanh mic, từ điển, system prompt, văn bản cần dịch hoặc tóm tắt, lịch sử tham chiếu, ngữ cảnh, gợi ý, nội dung TXT đã chọn, yêu cầu tạo blog và văn bản sinh ra. Gửi trực tiếp bằng Free Key đã cấu hình hoặc API key của riêng bạn khi dùng tính năng liên quan.
Advertising ID, địa chỉ IP, tương tác quảng cáo, loại thiết bị, thông tin chẩn đoán, định danh thiết bị/tài khoản do Google xử lý để phân phối quảng cáo, đo lường hiệu năng quảng cáo, phân tích và chống gian lận. Tuân theo quy trình tuân thủ EU và CCPA của AdMob.
Cấu hình: định danh app tĩnh và dữ liệu kỹ thuật HTTPS như IP. Free Key: nhận tên app, nền tảng, phiên bản app; trả Gemini key và ID cấp phát. Báo cáo AI: chỉ khi bạn bấm Báo cáo, nhận trích đoạn AI, lý do, ghi chú và thông tin app.
Thuộc phạm vi chính sách này.
Menu chia sẻ Android (tùy chọn, do người dùng kích hoạt)
Chỉ nội dung bạn chọn; bạn chọn đích đến.
Điều khoản của đích bạn chọn.
7. Quảng cáo
7.1 Vị trí quảng cáo
Native ad trên màn hình Home (chờ), danh sách Lịch sử, và màn hình Tóm tắt.
Interstitial ad chỉ sau khi phiên dịch đã kết thúc hoàn toàn.
Không quảng cáo trong lúc ghi âm live, không app-open ad, không banner cố định.
7.2 Quảng cáo cá nhân hóa vs. không cá nhân hóa
Chúng tôi dùng Google AdMob để hiển thị quảng cáo. Tùy khu vực, luật áp dụng và cấu hình của
Google AdMob, quảng cáo có thể được phân phối dưới dạng personalized ads, non-personalized ads
hoặc limited ads, và có thể yêu cầu lựa chọn đồng ý bổ sung nếu cần thiết. Bạn có thể reset hoặc
xóa Android Advertising ID trong Cài đặt → Google → Ads. Bản build hiện tại không
cung cấp màn hình quản lý đồng ý riêng trong Ứng dụng. Vì vậy, tại EEA, UK, Thụy Sĩ hoặc khu vực
khác yêu cầu sự đồng ý, Ứng dụng không được yêu cầu quảng cáo cá nhân hóa cho đến khi có quy trình
đồng ý phù hợp từ một nền tảng quản lý đồng ý được Google chứng nhận; thay vào đó quảng cáo phải
được tắt hoặc giới hạn ở chế độ phân phối đáp ứng các yêu cầu áp dụng.
7.3 Trẻ em
Ứng dụng không hướng đến trẻ em và không được thiết kế dành riêng cho trẻ em dưới 13 tuổi hoặc
độ tuổi tối thiểu theo luật áp dụng tại khu vực của bạn. Chúng tôi không chủ đích hiển thị quảng cáo
cho trẻ em.
8. Quyền Android
Quyền
Lý do Ứng dụng cần
RECORD_AUDIO
Ghi mic cho dịch trực tiếp.
CAMERA
Chụp lại slide chỉ khi bạn chạm biểu tượng máy ảnh trong phiên dịch. Ảnh được lưu vào bộ nhớ riêng của ứng dụng trên máy và không gửi lên máy chủ của chúng tôi hay Gemini.
Cùng tính năng peer qua Wi-Fi. Khai báo với neverForLocation để không suy luận vị trí.
ACCESS_COARSE_LOCATION, ACCESS_FINE_LOCATION
Android 12 trở xuống cần làm hệ quả phụ của BLE scan ở cấp OS. Ứng dụng không đọc GPS hay dùng vị trí của bạn cho bất kỳ tính năng nào.
com.google.android.gms.permission.AD_ID
Cho AdMob đọc Advertising ID để phân phối quảng cáo. Bạn có thể reset/xóa ID bất cứ lúc nào trong Cài đặt Android.
9. Lưu giữ và xóa dữ liệu
Dữ liệu trên thiết bị (API key, bản ghi, từ điển, lịch sử, nội dung tóm tắt, ảnh cuộc họp
và các thiết lập liên quan) chỉ tồn tại trên điện thoại của bạn cho đến khi bạn xóa từ trong
Ứng dụng, xóa app data, hoặc gỡ cài đặt. Tệp TXT hoặc tệp ngữ cảnh bạn chọn chỉ được đọc để
phục vụ thao tác tương ứng và không được lưu thành bản sao lâu dài trong SQLite/Hive, trừ khi
bạn chủ động lưu nội dung đó thông qua một tính năng của Ứng dụng.
Gỡ cài đặt sẽ xóa dữ liệu trong vùng riêng của Ứng dụng. Chúng tôi không lưu
nội dung cuộc họp, nhưng bản ghi cấp phát Free Key, báo cáo nội dung AI và access log tiêu chuẩn
của máy chủ có thể còn lại trong thời gian cần thiết cho mục đích đã nêu.
Dữ liệu Firebase Analytics được lưu trong thời hạn cấu hình ở project Firebase
của chúng tôi (mặc định 14 tháng) và tự động xóa sau đó.
Lưu trữ AdMob tuân theo chính sách của Google.
Dữ liệu Meta App Events và TikTok Business Events tuân theo
chính sách lưu giữ và cơ chế kiểm soát của từng nhà cung cấp.
Báo cáo nội dung AI được giữ tối đa 90 ngày.
Thông tin cấp Free Key: Khi bạn chọn dùng thử miễn phí, chúng tôi lưu ID cấp
phát, thời điểm cấp, trạng thái key và một số thông tin kỹ thuật cần thiết để vận hành dịch vụ,
hỗ trợ và ngăn lạm dụng. Thông tin này không chứa âm thanh, nội dung cuộc họp, phụ đề, bản ghi,
bản dịch hoặc ảnh cuộc họp. Chúng tôi xóa hoặc ẩn danh thông tin khi không còn cần cho các mục
đích trên, trừ trường hợp cần tiếp tục lưu vì lý do pháp lý, bảo mật hoặc chống lạm dụng.
Việc lưu giữ của Google Gemini tuân theo điều khoản áp dụng cho tài khoản Google
của bạn khi dùng key riêng, hoặc Google project đứng sau Free Key do chúng tôi cung cấp.
10. Quyền của bạn (GDPR, CCPA, và các luật tương tự)
Bất cứ lúc nào bạn có thể:
Đồng ý chia sẻ dữ liệu với AI — ngay lần khởi động đầu tiên, Ứng dụng
hiển thị màn hình onboarding chuyên biệt cho biết rõ dữ liệu nào được gửi đến Google Gemini,
ai nhận và mục đích gì. Tính năng dịch chỉ được kích hoạt sau khi bạn tap nút “Tôi đồng ý”.
Sự đồng ý này được ghi nhận trực tiếp trong Ứng dụng, không phải trong Chính sách quyền riêng tư này.
Rút lại đồng ý AI — Cài đặt → “Chia sẻ dữ liệu AI”
→ “Rút lại đồng ý” rút lại đồng ý chỉ trong 1 tap. Việc rút lại cũng đồng thời
xóa Gemini API key khỏi thiết bị — không có key, không có dữ liệu nào có thể gửi đến Gemini.
Cách khác: Cài đặt → API Key → Xóa (xóa key cũng tự động rút lại đồng ý AI).
Xem dữ liệu cuộc họp cục bộ qua Lịch sử, Từ điển và Cài đặt. Hãy liên hệ chúng tôi về dữ liệu
analytics, quảng cáo, cấp phát Free Key hoặc báo cáo AI trong phạm vi chúng tôi kiểm soát.
Xóa phiên trong Lịch sử, xóa mục từ điển, hoặc xóa toàn bộ app data từ Cài đặt Android.
Rút lại phân tích — hiện tại, bạn có thể dừng việc gửi sự kiện phân tích trong tương lai
bằng cách gỡ cài đặt Ứng dụng. Chúng tôi có thể bổ sung tùy chọn kiểm soát phân tích trực tiếp
trong phần Cài đặt của Ứng dụng ở các phiên bản sau.
Quản lý quảng cáo cá nhân hóa bằng cách reset hoặc xóa Android Advertising ID trong
Cài đặt → Google → Ads, hoặc qua các lựa chọn đồng ý do Google AdMob hiển thị
nếu áp dụng tại khu vực của bạn.
Đối với attribution quảng cáo của Meta, bạn có thể reset hoặc xóa Android Advertising ID và
sử dụng công cụ quyền riêng tư của Meta. Việc thu thập Android Advertising ID trong TikTok SDK
đã được Ứng dụng tắt. Bản hiện tại của Ứng dụng chưa có công tắc opt-out riêng cho các SDK này.
Gỡ cài đặt Ứng dụng sẽ dừng việc gửi
sự kiện trong tương lai. Hãy liên hệ chúng tôi để thực hiện quyền đối với dữ liệu nằm trong phạm
vi kiểm soát của chúng tôi.
Yêu cầu thông tin hoặc gửi khiếu nại bằng cách email
app-support@furucrm.com. Chúng tôi sẽ phản hồi trong 30 ngày.
Cư dân EEA/UK có thể nộp khiếu nại với Cơ quan Bảo vệ Dữ liệu quốc gia của họ.
Cư dân California có thêm quyền theo CCPA/CPRA: quyền biết, xóa, sửa,
từ chối bán hoặc chia sẻ và không phân biệt đối xử. Chúng tôi không bán thông tin cá nhân.
Việc chuyển dữ liệu tới nhà cung cấp quảng cáo và attribution được mô tả tại Mục 3 và 6.
Bạn có thể thực hiện quyền opt-out áp dụng qua Cài đặt Android, công cụ của nhà cung cấp hoặc liên hệ chúng tôi.
11. Quyền riêng tư của trẻ em
Talk with Mozart không hướng đến trẻ em và không được thiết kế dành riêng cho trẻ em dưới 13 tuổi
hoặc độ tuổi tối thiểu theo luật áp dụng tại khu vực của bạn. Chúng tôi không cố ý thu thập dữ
liệu cá nhân từ trẻ em. Nếu bạn tin rằng trẻ em đã cung cấp dữ liệu cá nhân cho Ứng dụng, vui
lòng liên hệ chúng tôi để được hỗ trợ xử lý hoặc xóa dữ liệu trong phạm vi chúng tôi kiểm soát.
12. Bảo mật
Mọi yêu cầu mạng dùng HTTPS / TLS 1.2 trở lên.
Gemini API key được cấu hình được lưu trong EncryptedSharedPreferences của Android
thông qua flutter_secure_storage, có Android Keystore bảo vệ.
Bản ghi và lịch sử lưu trong vùng riêng của Ứng dụng, cách ly với các app khác qua sandbox Android.
Chúng tôi không vận hành backend để tập trung lưu trữ âm thanh, bản ghi, bản dịch, từ điển,
lịch sử dịch, ngữ cảnh tham chiếu, tệp TXT bạn chọn, nội dung tạo blog hoặc Gemini API key của
người dùng, nên không có cơ sở dữ liệu trung tâm chứa các nội dung này ở phía chúng tôi.
13. Truyền dữ liệu quốc tế
Khi bạn dùng Ứng dụng, dữ liệu có thể được Google LLC và các nhà thầu phụ xử lý, bao gồm
trung tâm dữ liệu tại Hoa Kỳ và các quốc gia khác. Google dựa vào Điều khoản Hợp đồng Tiêu chuẩn (SCC)
và Khung Bảo mật Dữ liệu EU–Mỹ khi áp dụng. Vui lòng xem chính sách của Google để biết chi tiết.
14. Thay đổi chính sách và thông tin liên hệ
Chúng tôi có thể cập nhật Chính sách này khi bổ sung tính năng mới hoặc khi pháp luật áp dụng
có thay đổi. Mọi thay đổi quan trọng sẽ được thông báo thông qua thông báo trong ứng dụng hoặc
trên trang niêm yết tại Google Play.
Nếu bạn có bất kỳ câu hỏi hoặc thắc mắc nào liên quan đến quyền riêng tư, vui lòng liên hệ với
nhóm phát triển của chúng tôi tại: