PrimiLab Privacy Policy
Effective date: 2026-04-13 · Last updated: 2026-08-27
This Policy is issued by the PrimiLab Team, which belongs to Beijing Prime Beyond Technology Co., Ltd ("we" or "us"). We understand how important personal information is to you. We will collect, use, store and share your information in accordance with this Policy and applicable laws and regulations, including the Personal Information Protection Law, the Cybersecurity Law and the Data Security Law of the People's Republic of China.
This Policy, together with the PrimiLab Terms of Service and the Minors' Personal Information Protection Rules, constitutes the complete agreement governing your use of the Service. Please read this Policy in full before use, especially the clauses marked in bold. If you do not agree with any part of this Policy, please stop using the Service.
1. Scope
This Policy applies to all scenarios in which you use PrimiLab products and services (including but not limited to the "Micca" app) via mobile clients, our official website or other channels. Third-party products or services (including third-party pages they link to) have their own privacy policies; this Policy does not apply to services provided by third parties.
2. How We Collect and Use Your Personal Information
We collect and use your personal information only for the purposes described in this Policy. To provide the following functions, we may need you to authorize or actively provide the relevant information:
- 1.Account registration and login: phone number or third-party account, nickname and avatar. Used to create your account, verify your identity and protect account security.
- 2.Sticker creation and upload: images or videos and their audio tracks that you actively select, optional capture location (latitude/longitude) and place name, and camera/album/microphone access permissions. Used to display and share your content in collections. If you decline the microphone while recording a video sticker, a silent video sticker is produced and publishing is unaffected.
- 3.Collections and social interaction: the collections you create/join, invitation codes, following relationships and interaction records. Used to enable collection co-building and social features.
- 4.Device and log information: device model, operating system version, Android ID (SSAID), OAID (anonymous device identifier, Android only, used by Umeng+ analytics), IP address, network type, and crash and performance logs. Used to keep the Service running stably, troubleshoot faults, register the device, identify it for push delivery and prevent fraud.
- 5.Customer support: the issue descriptions, contact details and communication records you actively submit to us. Used to respond to and follow up on your requests.
For the device identifiers actually used on Android, we further explain as follows. We do not use these identifiers for targeted marketing, user profiling or personalized advertising:
- •OAID (anonymous device identifier): purpose — used by the Umeng+ analytics SDK for usage analytics and crash attribution, to improve product stability and experience. Method — read on-device by that SDK and transmitted to Umeng's servers. Trigger — when the app launches and initializes the Umeng+ analytics SDK. Shared with — Umeng Tongxin (Beijing) Technology Co., Ltd. We do not use OAID for device registration or push identification, and we do not retain it ourselves on a long-term basis; Umeng's retention period is as stated in its published privacy policy.
- •Android ID (SSAID): purpose — device registration and push identification, to deliver notifications to the device and keep multiple accounts on the same device separate. Method — the app reads the system Android ID and reports it to our servers. Trigger — when the device registers with or reports device information to our servers. Shared with — not shared with any third party; processed only by the servers of Beijing Prime Beyond Technology Co., Ltd. Retention — for as long as the account exists and the device is still used to receive notifications; after account cancellation or deletion of the device record, we delete or anonymize it, except as otherwise required by law.
Where a function requires sensitive personal information (such as location), we will request your authorization separately via means such as a system prompt. You may choose not to authorize it, which will only affect the related function and not your use of other functions that do not rely on that information.
3. List of Device Permissions and Sensors
To provide the corresponding functions, we may request the following device permissions when you actively take an action. Each permission is requested only when you first use the corresponding function, never all at once on launch. You can turn off authorization in your system settings at any time:
- •Camera permission: requested when you actively open the capture screen, to take photos or videos for creating stickers;
- •Microphone permission: requested when you actively record a video sticker, to capture the audio track; if you decline, the App automatically falls back to a silent video sticker and publishing is unaffected;
- •Album/media library permission: to read and save images;
- •Location permission: to record capture location in stickers (you choose precise or approximate location);
- •Notification permission: to push notifications such as account security, collection interactions and system messages;
- •Network access permission: to complete data upload and download.
In addition to the system permissions above, the App also reads the following sensor information. It is processed only on your device, is not uploaded to our servers, and is not provided to any third party:
- •Device physical orientation (portrait/landscape or rotation state from the system orientation sensor): read when you enter the capture screen to take a photo or video sticker, to correct the preview and the captured result so content is not inverted. Processing consists of reading the current system orientation and using it locally for on-screen presentation only; reading stops when you leave the capture screen. We do not upload, store or otherwise use orientation data.
6. Third-Party SDKs Integrated
To provide basic capabilities such as login, analytics, content storage, SMS verification and location recording, we have integrated the following third-party SDKs into the app. Third-party SDKs are operated independently by their providers, and their personal-information processing is governed by their officially published privacy policies. The full item-by-item list is in the Third-Party Personal Information Sharing List.
- 1.Tencent Weixin Open Platform mobile SDK (via the fluwx plugin): invoked when you choose "Log in with WeChat", to launch the WeChat client, obtain a one-time authorization code, and exchange it with WeChat for public profile data such as OpenID, UnionID, nickname, avatar, gender and region to create/identify your account. The SDK is provided by Tencent Technology (Shenzhen) Co., Ltd.; processing rules are set out in the Weixin Open Platform Developer Agreement and the WeChat privacy policy.
- 2.Umeng+ analytics SDK (umeng_common_sdk): used for usage analytics and crash attribution to improve product stability and experience. On initialization the SDK collects OAID (anonymous device identifier), device and operating system information, network information, and crash and usage records, and transmits them to Umeng's servers. The SDK is provided by Umeng Tongxin (Beijing) Technology Co., Ltd. We do not use OAID for device registration or push identification, and we do not retain it ourselves on a long-term basis; Umeng's retention period is as stated in its published privacy policy.
- 3.Volcengine Object Storage (TOS): used to store the images and sticker files you actively upload.
- 4.Volcengine SMS service: used to send verification-code SMS when you choose phone-number login; your phone number is passed to the carrier.
- 5.Google Play services location (the underlying dependency of the geolocator plugin on some Android devices): after you grant the location permission, used to obtain approximate location for the optional place record on a sticker. The SDK is provided by Google LLC. On Android devices without Google Mobile Services pre-installed (such as Huawei devices), the App automatically falls back to the system's own network location provider and does not depend on Google Play services; no information is shared with Google in that case.
We provide data to third-party SDKs only within a reasonable and necessary scope and assess and supervise their data-processing activities. You have the right to refuse the function corresponding to any SDK, but the related function may become unavailable as a result.
7. Information Storage
- •Storage location: your personal information is by default stored on servers within the territory of the People's Republic of China. Where cross-border provision is genuinely necessary, we will separately obtain your consent and fulfil assessment obligations in accordance with the law.
- •Retention period: we retain your personal information only for the shortest period necessary for the purposes described in this Policy, except as otherwise provided by laws and regulations. After your account is cancelled or your personal information is deleted, we will stop using and delete your related information, unless otherwise required by law.
- •Android ID (SSAID) is retained for as long as the account exists and the device is still used to receive notifications, for device registration and push identification; it is deleted or anonymized after account cancellation or deletion of the device record. OAID is collected by the Umeng+ analytics SDK and transmitted to Umeng; we do not retain it ourselves on a long-term basis, and Umeng's retention period is as stated in its published privacy policy.
8. Information Security
We adopt industry-standard security measures to protect your personal information, including but not limited to transport-layer encryption, access minimization, key and credential management, operation auditing and security drills. We also continuously upgrade our security capabilities to help prevent personal information from being leaked, damaged or lost.
Nevertheless, the internet environment is not absolutely secure. In the unfortunate event of a personal-information security incident, we will, as required by law, promptly inform you of the basic situation of the incident, its potential impact, the measures taken or to be taken, advice on how you can protect yourself and reduce risk, and report to the relevant regulators.
9. Your Rights
Subject to applicable laws and regulations, you may exercise the following rights through in-app settings or the contact information at the end of this Policy:
- •Access and copy your personal information;
- •Correct or supplement inaccurate or incomplete personal information;
- •Delete your personal information (including cancelling your account as described in the "Account Cancellation" section);
- •Withdraw consent previously given;
- •Restrict the processing of specific personal information;
- •Inquire about and understand the rules by which we process your personal information;
- •Obtain personal-information portability where conditions are met.
We will verify your identity upon receiving your request and respond within a reasonable period. For requests that are manifestly unreasonable or repetitive, we may decline them or charge a reasonable cost.
10. Account Cancellation
The Service uses account registration and login. You may cancel your account at any time. After cancellation, the account immediately becomes invalid and cannot be restored. We will stop providing the Service to that account and will delete or anonymize the related personal information in accordance with this Policy and applicable laws.
In-app cancellation steps:
- 1.Open the "Micca" app and go to Profile;
- 2.Tap "Account & security";
- 3.Tap "Delete account";
- 4.Confirm again by tapping "Deactivate" in the dialog.
After cancellation:
- •The account immediately becomes invalid and can no longer be used to sign in; the same phone number may be used to register a new account;
- •We will delete or anonymize your account information, device records, uploaded content and interaction relationships, except where laws and regulations require retention;
- •Memberships in collections you joined as a member will be removed; collections of which you are the sole owner will be deleted; multi-member collections will be transferred to another member;
- •Cancellation is irreversible. Please consider carefully before confirming.
If you cannot complete cancellation in the app, you may also submit a request via the contact information at the end of this Policy. We will handle it within 15 business days after verifying your identity.
11. Notifications and Targeted Push
To promptly inform you of account security, collection updates, comments, chat and other service messages that concern you, we may send targeted service notifications based on your account, device push credentials and the interaction relationships you actively create. These notifications are service-necessary message reach, not advertising.
We do not use your personal information for targeted marketing, user profiling or personalized advertising, and we do not recommend commercial advertisements based on your browsing or usage behavior.
You may turn off targeted service notifications in any of the following ways. Doing so does not affect your ability to view messages in the app; it only stops the corresponding notifications from being pushed to that device:
- 1.Per collection: turn off message alerts in the corresponding collection chat to stop interaction notifications for that collection;
- 2.System notification permission: turn off this app's notification permission in system settings to stop all service notifications from being pushed to that device.
12. Protection of Children's Personal Information (Under 14)
We attach great importance to protecting children's personal information. We have separately formulated the Minors' Personal Information Protection Rules for the collection, use, storage and sharing of personal information of children under 14. Those Rules apply together with this Policy; where they are inconsistent with this Policy on children's personal information, those Rules prevail.
You can open the Minors' Personal Information Protection Rules from the agreement links at the bottom of the login page in the "Micca" app. You may also read the full text at /en/minors-privacy/ on our website.
For children under 14, we follow these collection and use rules:
- •Guardian consent: before collecting, using, storing, sharing or publicly disclosing a child's personal information, the guardian must read and explicitly agree to this Policy and the Minors' Personal Information Protection Rules;
- •Minimum necessary: we process a child's personal information only within the minimum scope necessary to provide the Service, including account registration and login (phone number or third-party account, nickname and avatar), sticker creation and upload (images or videos the child actively selects and optional location), collections and social interaction, device and log information, and customer-support information actively submitted by the guardian or child;
- •Separate authorization for sensitive information: sensitive personal information such as location, camera, album and microphone is requested from the guardian only when the corresponding function is actively used; refusing authorization does not affect other functions that do not rely on that information;
- •No profiling or marketing: we do not use children's personal information for targeted marketing, user profiling or personalized advertising;
- •Guardian rights: guardians may access, correct or delete a child's personal information, withdraw consent, or cancel the account as described in the "Account Cancellation" section;
- •If we have collected a child's personal information without valid guardian consent, please inform us via the contact information at the end of this Policy and we will delete the relevant information as soon as possible.
If you are a child under the age of 14, please read this Policy and the Minors' Personal Information Protection Rules with your guardian and use the Service and submit personal information only after obtaining your guardian's consent. We do not proactively collect personal information from children under 14 that is unrelated to the services provided.
13. Updates to This Policy
We may revise this Policy in response to changes in laws and regulations, business adjustments or the security situation. The revised version will be published on this page with the update date noted. Where your material rights and interests are affected, we will notify you prominently via in-app notice, push, website announcement and the like. Please review this Policy regularly to stay informed of the latest content.
14. Contact Us
If you have any questions, comments, suggestions or complaints about this Policy, the processing of your personal information or the exercise of your rights, you may contact our personal-information protection officer via:
- •Operator: Beijing Prime Beyond Technology Co., Ltd
- •Email: privacy@primilab.com
- •We will respond within 15 business days after receiving your request and verifying your identity.