Migu Short Drama SDK Privacy Policy
Updated: July 20, 2026
Effective: July 20, 2026
Welcome to our products and services!
Migu Digital Media Co., Ltd. (hereinafter referred to as "we" or "Migu") is the operating entity of the "Migu Short Drama SDK" (hereinafter referred to as "this SDK"). The company's registered address is: Room 101, 1st Floor, Building 1, Xixi Yin Zuo, Xihu District, Hangzhou, Zhejiang Province. We are fully aware of the importance of your personal information and will strictly protect your personal information and privacy in accordance with laws and regulations including the Civil Code of the People's Republic of China and the Personal Information Protection Law of the People's Republic of China. We hereby formulate this Privacy Policy (hereinafter referred to as "this Policy"). Please read and understand it carefully before using the services related to this SDK, and confirm your agreement before use; if you do not agree with this Policy, please do not use the services of this SDK. Key content is indicated in bold for your special attention.
This Privacy Policy applies to all functions and services provided by the "Migu Short Drama SDK".
If you have any questions, opinions, or suggestions regarding this Policy, you may contact us via our personal information protection officer at kfsupport_migu@139.com. We will verify your identity and reply within fifteen (15) days.
Table of Contents
I. Definitions and Explanation of Terms
II. What Personal Information We Collect
III. How We Use Your Personal Information
IV. How We Use Cookies and Similar Technologies
V. How We Share, Transfer, and Publicly Disclose Your Personal Information
VI. How We Store and Protect Your Personal Information
VII. Your Rights
VIII. Protection of Minors
IX. How Your Personal Information Is Transferred Globally
X. How This Policy Is Updated
XI. How to Contact Us
I. Definitions and Explanation of Terms
Personal Information: Information recorded in electronic or other forms that, alone or combined with other information, can identify a specific natural person or reflect their activities, such as device information, media files, operation records, etc.
Personal Sensitive Information: Information that, once leaked, may endanger personal and property safety or harm personal dignity, such as images/videos containing portraits, audio recorded by microphones, etc.
Unique Device Identifier: A unique character string embedded by the device manufacturer used to identify the device.
De-identification: The process of processing personal information such that a specific natural person cannot be identified without the use of additional information.
Anonymization: The process of technical processing of personal information such that the subject of the personal information cannot be identified, and the processed information cannot be restored. Information obtained after anonymization of personal information does not constitute personal information.
II. What Personal Information We Collect
This SDK strictly follows the "minimum necessary" principle, collecting only information required to implement functions. Refusing to provide non-essential information does not affect the use of other functions. Sensitive permissions require your explicit authorization and are invoked only when using the corresponding functions.
(I) Basic Business Functions
To ensure the operation of core video viewing functions, the following information needs to be collected. If you refuse to provide the following information, it will affect your continued use of the basic functions of the Migu Short Drama SDK.
Core Function | Information Type Collected | Collection Method |
Video Viewing | Viewing History | Automatically collected during use |
(II) Extended Business Functions
To provide you with better services, we need to collect the following relevant information. We collect the following information only when you actively use optional functions. Refusing to provide it means you cannot use the optional functions, but it does not affect the core functions:
Optional Function | Information Type Collected | Collection Method |
Add to Follow List | Follow (series-tracking) records | Automatically collected during use |
Subscribe to Membership | Membership validity period | Automatically collected during use |
Purchase Episodes | Episode purchase records | Automatically collected during use |
Interactive Features | Like records | Automatically collected during use |
(III) Device Permission Invocation
To provide you with convenient and high-quality services, we may invoke certain permissions of your device. This SDK invokes device permissions through the host application. You may turn off permissions in your device settings; after turning them off, only the corresponding function will be unavailable. You understand and agree that enabling the following permissions means you agree that we may collect and use the personal information involved in such permissions to implement the corresponding business functions, and disabling permissions means you withdraw your consent, and we will no longer continue to collect and use such personal information. Your decision to disable permissions will not affect the processing of personal information previously carried out based on your consent.
Permission Name (Mainstream Systems) | Invocation Scenario | Purpose of Use | Special Note |
Network Permission | Video Viewing | Video stream pulling | None |
(IV) Third-Party SDK Information Statement
To ensure the stable operation of this SDK or to implement specific functions (sharing), third-party SDKs may be integrated. If you use such services provided by third parties, you agree that they will process your information directly. We will strictly review third parties, sign security agreements, and restrict the scope of information use. Currently, the Migu Short Drama SDK does not share personal information with any third-party SDK.
III. How We Use Your Personal Information
Providing Services: Ensure SDK compatibility, implement video playback, adding to follow list, liking, subscribing to membership, and purchasing episodes, to ensure your normal use of short drama viewing services.
Optimizing Product Experience: Improve service experience and content supply by analyzing video viewing behavior. In addition, we anonymize the collected personal information; the processed data cannot identify your identity and may be used for legitimate purposes such as product analysis and industry research.
Ensuring Security: Identify abnormal usage behavior, prevent risks such as network attacks and fraud, protect content security, and ensure stable service operation; meanwhile, retain logs and conduct security audits as required by laws and regulations.
Other Purposes: If information is to be used for purposes not specified in this Policy, a pop-up will be used to seek your separate consent in advance.
You fully understand that we do not need to obtain your authorization and consent to process personal information in the following circumstances:
(1) Necessary for the conclusion or performance of a contract to which the individual is a party, or necessary for human resources management carried out in accordance with lawfully formulated labor rules and regulations and lawfully signed collective contracts;
(2) Necessary for the performance of statutory duties or statutory obligations;
(3) Necessary to respond to a public health emergency, or in an emergency situation to protect the life, health, and property safety of natural persons;
(4) Processing personal information within a reasonable scope for the purpose of implementing news reporting, public opinion supervision, and other acts for the public interest;
(5) Processing personal information that individuals make public themselves or otherwise lawfully make public within a reasonable scope in accordance with the provisions of this Law;
(6) Other circumstances stipulated by laws and administrative regulations.
IV. How We Use Cookies and Similar Technologies
Cookies and Similar Technologies: We do not use cookies to collect or store your personal information. However, to ensure the normal operation of core functions (such as temporarily saving viewing history to ensure viewing experience), we store necessary temporary data in your device's local database.
Token Authentication Technology: When you log in to the host application, the server generates a Token (resource credential). When you use the functions of this SDK, you need to carry the Token for identity verification to ensure that only authorized users can use subscription membership, episode purchase, paid episode viewing, adding to follow list, and collection services.
V. How We Share, Transfer, and Publicly Disclose Your Personal Information
(I) Sharing
We will not proactively share your personal information with any company, organization, or individual. Sharing occurs only in the following circumstances, and security protection measures will be taken:
Your Explicit Consent: After your active authorization, necessary information will be shared only with the third parties you designate, and the scope of sharing is subject to your consent.
Sharing with Affiliated Companies: To jointly provide services, de-identified personal information may be shared with affiliated companies controlled by, controlling, or under common control with Migu. If an affiliated company changes the purpose of using personal information, it must re-seek your consent.
Sharing with Authorized Partners: Some functions may be provided by authorized partners, and de-identified personal information will be shared with them to ensure function compatibility. We will share your personal information only for legitimate, proper, necessary, specific, and explicit purposes, and will only share personal information necessary to provide the services. Meanwhile, we will conduct security assessments of relevant sharing acts and recipients, and sign corresponding agreements with them, such as data processing agreements, requiring them to process your personal information in accordance with this Policy and any other relevant confidentiality and security measures. Our partners have no right to use the shared personal information for any other purposes.
Legal Requirements: According to legal and regulatory provisions, or statutory circumstances such as court judgments and administrative organ requirements, information is shared within the necessary scope, and you will be informed as much as possible (except where prohibited by law).
Anonymized information shared with third parties cannot be used by the receiving third party to re-identify the natural person subject of such information.
Transfer
We will not transfer your personal information to any company, organization, or individual, except in the following circumstances:
1. Transfer with explicit consent: After obtaining your explicit consent, we will transfer your personal information to other parties;
2. In the event of a merger, acquisition, or bankruptcy liquidation, where personal information transfer is involved, we will inform you of the name and contact information of the recipient and require the new company or organization holding your personal information to continue to be bound by this personal information protection policy; otherwise, we will require that company or organization to re-seek your authorization and consent.
Public Disclosure
We will publicly disclose your personal information only in the following circumstances:
1. After obtaining your explicit consent;
2. Disclosure based on law: We may publicly disclose your personal information to entities holding mandatory documents in circumstances where there are mandatory requirements under law, legal proceedings, litigation, or government authorities. When the above circumstances occur, we will require the disclosure requester to produce the corresponding valid legal documents and take security protection measures complying with legal and industry standards for the disclosed information.
Cessation of Operations
If we cease operating a product or service, we will promptly stop collecting your personal information. We will send you a notice of cessation of operations individually or by way of announcement, and will delete or anonymize the personal information we hold related to the discontinued product or service, except where laws and regulations provide otherwise.
VI. How We Store and Protect Your Personal Information
(I) Storage Method and Retention Period
Storage Location: This SDK adopts a collaborative deployment model with the host application. Relevant data will be stored on server addresses designated by the host application operator, and the specific storage location is determined by the host application operator according to its compliance requirements. For product analysis and statistics, we will transmit some anonymized user behavior data to servers located within the People's Republic of China for processing. Please rest assured that such information is anonymized and does not involve the identification of any personal information.
Retention Period: Except as otherwise provided by laws and regulations, information is retained only for the period necessary to implement the functions. When your personal information exceeds the above retention period, we will delete or anonymize it. If you uninstall the host application or proactively delete the above information, we will retain your existing personal information for the shortest period stipulated by laws and regulations. During the shortest retention period required by laws and regulations, except as otherwise provided by laws and regulations, we will stop processing/using your personal information beyond storage and necessary security protection measures.
(II) Security Protection Measures
1. We collect, use, store, and transmit user information under the "minimization" principle, and inform you of the purposes and scope of information use through user agreements and privacy policies. We will establish information security protection systems in strict accordance with relevant legal and regulatory requirements, and adopt technical measures and other necessary measures to protect the security of your personal information.
2. We adopt dedicated data security technical measures
We will adopt security protection measures that meet industry standards, including establishing reasonable institutional norms and security technologies to prevent your personal information from unauthorized access, use, and modification, and to avoid data damage or loss. Network services adopt multiple encryption technologies. For example, in some services, we will use encryption technologies (such as SSL) to protect your personal information and adopt encryption technologies to encrypt and store your personal information.
When personal information is in use, such as for personal information display and personal information correlation calculation, we will adopt multiple data masking technologies to enhance the security of personal information during use. Strict data access permission control and multi-factor authentication technologies are adopted to protect personal information and prevent data from being used in violation of regulations.
3. We adopt other security measures
(1) We manage and regulate the storage and use of personal information by establishing data classification and grading systems, data security management norms, and data security development norms;
(2) We exercise comprehensive security control over data through confidentiality agreements with personnel who have access to personal information, as well as monitoring and audit mechanisms;
(3) We also hold security and privacy protection training courses to strengthen employees' awareness of the importance of protecting personal information and their security awareness;
(4) We only allow personnel who need to know such personal information to access your personal information, and have established strict access permission controls and monitoring mechanisms. We also require all personnel who may have access to your personal information to fulfill corresponding confidentiality obligations. Failure to fulfill these obligations may result in legal liability.
(III) Handling of Security Incidents
1. Please understand: The internet environment is not 100% secure. We will do our best to ensure the security of any information you send to us. However, due to technical limitations and various possible malicious means, even if we have taken various security measures as required by laws and regulations, it is impossible to guarantee 100% information security at all times.
2. We will formulate emergency plans for cybersecurity incidents, promptly handle security risks such as system vulnerabilities, computer viruses, network attacks, and network intrusions. When an incident endangering cybersecurity occurs, we will immediately activate the emergency plan, take corresponding remedial measures, and report to the relevant competent authorities as required.
3. In the unfortunate event of a personal information security incident, we will inform you in a timely manner as required by laws and regulations: the basic situation and possible impact of the security incident, the disposal measures we have taken or will take, suggestions for you to prevent and reduce risks on your own, and remedial measures for you. We will promptly inform you of the relevant situation of the incident by email, letter, telephone, or push notification. When it is difficult to inform each individual information subject individually, we will publish an announcement in a reasonable and effective manner. At the same time, we will also proactively report the handling of the personal information security incident to the regulatory authorities as required.
VII. Your Rights
You enjoy the following rights regarding your personal information and may exercise them through the following methods:
1. Right of Access, Right to Correct and Supplement, Right to Copy, Right to Account Deletion
Given that you use the Migu Short Drama SDK services through the host application, and that you do not register/log in to a Migu account when using the services, to ensure the realization of your rights to access, correct, supplement, copy your personal information, and to delete your host application account, we require, in this Privacy Policy and other agreements with the host application, that the host application undertake to provide easy-to-operate implementation methods. If you wish to access, correct, supplement, copy your personal information, or delete your host application account, you should do so through the above-mentioned rights implementation methods provided by the host application. If the host application fails to provide them as promised, you may contact us through the methods in [XI. How to Contact Us], and we will do our best to coordinate, support, and ensure the realization of your above rights.
2. Right to Delete
To ensure the realization of your right to delete your personal information, we require, in this Privacy Policy and other agreements with the host application, that the host application undertake to provide easy-to-operate implementation methods. If you wish to delete your personal information, you should do so through the above-mentioned rights implementation methods provided by the host application. If the host application fails to provide them as promised, you may contact us through the methods in [XI. How to Contact Us] and submit a request to delete your personal information in the following circumstances:
• If we process your personal information in violation of laws and regulations or our agreement with you;
• If our processing purpose has been achieved, cannot be achieved, or is no longer necessary to achieve the processing purpose;
• If we cease to provide the product or service, or the retention period has expired;
• If you withdraw your consent;
• Other circumstances stipulated by laws and administrative regulations.
When you delete information from our services, we may not immediately delete the corresponding information in the backup system, but will delete such information upon backup updates. Please be aware and understand that if the retention period stipulated by laws and administrative regulations or stated in this Privacy Policy has not expired, or if deleting personal information is technically difficult, we will stop processing beyond storage and necessary security protection measures.
3. Right to Withdraw Consent
Each business function requires some basic personal information to be completed. For the collection and use of additionally collected personal information, you may grant or withdraw your authorization and consent at any time.
You may directly disable the device system permissions that we may invoke as stated in this Privacy Policy in the device system, or other authorization settings provided by the host application (if applicable), to change the scope of consent or withdraw your authorization.
When you withdraw your consent, we will not be able to continue providing you with the services corresponding to the withdrawn consent, and will no longer use your corresponding personal information. However, your decision to withdraw consent will not affect the personal information processing previously carried out based on your consent.
4. Restricting the Processing of Your Personal Information
If you need to restrict the processing of your personal information, you may submit an application through the contact method in Article XI of this Policy. We will verify your identity and process it within fifteen (15) days. Restricting the processing of personal information may affect the use of some functions. When you submit your request through the above channels, we will separately inform you of the impact.
5. Transfer of Personal Information
Where technically feasible and data interfaces are matched, we may, upon your request, directly transmit a copy of your personal information to a third party designated by you. You may submit an application to transfer your personal information through the contact method in Article XI of this Policy. We will verify your identity and process it within fifteen (15) days.
6. Constraining Automated Decision-Making of Information Systems
Not applicable.
7. Responding to Your Above Requests
To ensure the security of your account and personal information, when you submit the above requests to us or exercise your statutory rights, we may first verify your identity (such as by adding account verification, requiring you to provide a written request, or other reasonable methods), and then process your request. We will respond within fifteen (15) days. For your reasonable requests, we in principle do not charge fees, but for repeated requests that exceed reasonable limits, we may charge a certain fee. For information not directly related to your identity, information repeatedly applied for without reasonable grounds, or requests that require excessive technical means (such as requiring the development of new systems or fundamental changes to current practices), pose risks to the legitimate rights and interests of others, or are impractical, we may refuse.
In the following circumstances, we will be unable to respond to your requests:
1. Related to the performance of obligations stipulated by laws and regulations by the personal information controller;
2. Directly related to national security and defense security;
3. Directly related to public security, public health, and major public interests;
4. Directly related to criminal investigation, prosecution, trial, and execution of judgments;
5. The personal information controller has sufficient evidence that the personal information subject has subjective malice or abuses rights;
6. For the purpose of protecting the major legitimate rights and interests of the life and property of the personal information subject or other individuals, but it is difficult to obtain their own consent;
7. Responding to the request of the personal information subject will cause serious damage to the legitimate rights and interests of the personal information subject or other individuals or organizations;
8. Involving trade secrets.
VIII. Protection of Minors
1. We attach great importance to the protection of minors' personal information. Our products are mainly oriented toward adults and are not specifically designed for children. Given that laws in different regions define the age of children differently, we treat natural persons who have not reached the age threshold for children stipulated by applicable local laws as children. If children use this SDK, their guardians should carefully read this Privacy Policy and obtain the guardian's consent in advance. We will strictly protect minors' personal information in accordance with relevant laws and regulations. Some of our services may require you to provide specific personal information to implement specific functions. If you choose not to provide such information, you may not be able to use the specific functions in the services, but this does not affect your use of other functions in the services.
2. For cases where children's personal information is collected with guardian consent, we will use or disclose such information only within the scope permitted by law, expressly consented to by the guardian, or necessary to protect the child.
3. If we discover that we have collected minors' personal information without prior verifiable guardian consent, we will endeavor to delete the relevant data as soon as possible. We do not collect irrelevant information such as minors' addresses and contact information; their creative content is only processed locally and not uploaded to servers. If a guardian discovers that a minor has provided information without consent, they may contact us for assistance in deletion.
4. If the host application is an application exclusively for minors, we will cooperate with the host application to implement additional protective measures (including content review and usage time limits).
IX. How Your Personal Information Is Transferred Globally
This SDK is deployed along with the host application, and relevant data is stored on server addresses designated by the company of the host application. The specific storage location is determined by the host party according to its compliance requirements. If the storage location of relevant data is outside the People's Republic of China, for the purpose of product analysis and statistics, we will transmit some anonymized user behavior data to servers located within the People's Republic of China for processing. Please rest assured that such information is anonymized and does not involve the identification of any personal information.
We will strictly comply with the relevant laws and regulations of the data export location and within China to carry out the above processing activities. Before transmission, we will adopt necessary technical and management measures such as encrypted transmission and access control, and, in accordance with applicable legal requirements (where applicable), sign Standard Contractual Clauses (SCCs) or adopt other equally adequate safeguards to ensure that your personal information is fully protected during cross-border transmission.
X. How This Policy Is Updated
Due to updates in laws and regulations, SDK function upgrades, and other reasons, this Policy may be revised. The revised privacy policy will be published within the SDK. If core changes such as the scope of information collection and purpose of use are involved, the host application will remind you to read it via a pop-up. Major changes (including new sharing scenarios) will be announced thirty (30) days in advance.
Your continued use of this SDK's services constitutes your agreement to the updated policy; historical versions can be obtained by contacting customer service.
XI. How to Contact Us
We have established a dedicated personal information protection team and a personal information protection officer. We will protect your personal information in accordance with this Privacy Policy. If you have any complaints or reports regarding personal information security, or any questions, opinions, or suggestions regarding your personal information under this Privacy Policy, as well as questions about the privacy measures of this Privacy Policy, you may contact us through the following methods. We will reply to your requests within 15 days.
1. Customer Service Hotline: 10086
2. Email: kfsupport_migu@139.com
3. Company Name: Migu Digital Media Co., Ltd.
4. Registered Address: Room 101, 1st Floor, Building 1, Xixi Yin Zuo, Xihu District, Hangzhou, Zhejiang Province
If you are not satisfied with our reply, you may also seek resolution by filing a lawsuit in a court with jurisdiction over the location of Migu Digital Media Co., Ltd.