Developer Platform Terms
These Terms apply to your (the “Developer”) use of the MEMOMIND simulator, App workspace, Web console, SDKs, APIs, testing, application review, and distribution capabilities. These Terms constitute an agreement between you and Shenzhen Qinglai Innovative Intelligent Technology Co., Ltd. (“MEMOMIND”).
Before using MEMOMIND platform services, you shall read these Terms fully and carefully, paying particular attention to provisions in bold, which may concern limitations or exclusions of liability. After reading, you may choose whether to accept these Terms. If you accept on behalf of an organization, that organization is also bound by these Terms
1. Definitions
1.1. “Developer Platform” includes the simulator, workspaces, consoles, SDKs, APIs, testing, review, distribution, and maintenance resources provided by MEMOMIND, and other related tools or services that MEMOMIND may provide from time to time;
1.2. “Platform Data” or “Platform-Provided Data” means data obtained through MEMOMIND-authorized interfaces;
1.3. “Developer Content” includes applications, code, icons, descriptions, documentation, and other submitted materials;
1.4. “Review Source Materials” means application source code, scripts, configuration files, manifests, interface and resource files, dependency and version information, build information, and other technical materials reasonably required for review that the simulator, workspace, or other development tools automatically include in the application package when the Developer packages an application for review, within the scope described in the submission interface and technical documentation. Packaging alone does not cause MEMOMIND to receive Review Source Materials. Only when the Developer separately submits the application for review are the application package and its Review Source Materials uploaded to MEMOMIND. Local Developer files not included in the application package are not Review Source Materials.
1.5. “Platform-Provided Data” means user or device data obtained by the Developer through MEMOMIND-authorized APIs, SDKs, devices, Webhooks, or other authorized means.
1.6. “Developer-Collected Data” means data submitted directly by users to the application and data independently produced, generated, or collected by the application, excluding Platform-Provided Data. The Developer shall manage Platform-Provided Data and Developer-Collected Data separately in accordance with applicable law and these Terms and, where applicable, declare, notify, and disclose them separately.
2. Registration Requirements
2.1. The Developer shall provide and maintain truthful, accurate, and complete name, address, contact, registration, and control-relationship information, and other supporting materials reasonably requested by MEMOMIND.
2.2. Before applying for store publication, using sensitive permissions, or accessing other high-risk capabilities, the Developer shall complete entity verification as required by MEMOMIND. If verification cannot be completed, or the verification information has expired, become invalid, or materially changed, MEMOMIND may, according to the risk, suspend or restrict publication or updates of the relevant applications or use of high-risk interfaces.
2.3. The Developer is responsible for the activities of its employees, contractors, agents, and other account members and shall take measures consistent with reasonable industry security standards, including, without limitation, implementation of least privilege, multifactor authentication, and prompt revocation of access. Sharing, disclosure, transfer, or recording in logs, public code repositories, or user-accessible client code is prohibited.
2.4. For a merger, acquisition, entity migration, change in actual control, or other material change that may affect the Developer's entity eligibility, qualifications, or risk profile, the Developer shall notify MEMOMIND before the change and complete reverification as required by MEMOMIND, and complete reverification or resubmit the relevant applications as required by MEMOMIND.
2.5. The Developer must not impersonate an entity, misappropriate or fabricate an entity's identity, buy, sell, rent, or otherwise transfer accounts, share privileged credentials, bypass verification, use affiliated entities to evade platform restrictions, or otherwise circumvent these Terms. On discovering compromised account credentials, unauthorized access, or another event that may affect Developer Platform security, the Developer shall immediately notify MEMOMIND and take necessary measures to prevent further harm.
3. Development Tool Usage Rules
3.1. Subject to compliance with these Terms, MEMOMIND grants the Developer limited, nonexclusive, nontransferable, nonsublicensable, and revocable access to the Developer Platform solely to design, develop, test, submit, and maintain applications compatible with MEMOMIND devices.
3.2. The Developer shall comply with MEMOMIND's technical documentation, interface scope, rate limits, compatibility requirements, and testing rules. Without lawful authorization, real user data must not be used in simulators, logs, sample data, test accounts, or other development and testing environments.
3.3. MEMOMIND processes account, project, device-environment, configuration, error, and performance data necessary to provide development tools, safeguard platform security, authenticate identity, troubleshoot, and provide technical support in accordance with applicable law and the developer privacy policy or relevant privacy notices.
3.4. Nonessential telemetry collected for product improvement, personalization, or new-feature analysis shall have separate choices and subsequently changeable settings when the product actually supports them. Until the relevant mechanisms are enabled, this provision must not be interpreted as authorizing MEMOMIND to collect such nonessential data.
3.5. The Developer may access interfaces only within technical documentation and approved scope. It must not exceed rate or field limits, scrape in bulk, interfere with authentication, probe resources unrelated to its application, evade security controls, or use the Developer Platform to build services that substantially replace the MEMOMIND Developer Platform, core services, or other restricted functions.
3.6. MEMOMIND may modify, deprecate, suspend, or replace development tools, interfaces, or related functions for security, compliance, technical upgrades, product adjustments, or other reasonable reasons. For material nonemergency changes, MEMOMIND will provide reasonable technical documentation or notice considering developers' migration needs. Changes necessary for urgent security risks, vulnerability remediation, or prevention of material harm may take effect immediately. The Developer shall promptly monitor notices, technical documentation, and version requirements and is responsible for keeping up with version and compatibility requirements.
3.7. Suggestions or vulnerability reports submitted to MEMOMIND do not transfer the Developer's preexisting intellectual property. Unless otherwise agreed in writing, MEMOMIND may use such feedback to evaluate, maintain, or improve the Developer Platform without disclosing the Developer's confidential information or violating applicable law, but may not rely on such feedback to use Platform-Provided Data or the Developer's other confidential information.
4. Application Distribution Channels and Review Status
4.1. Applications may use: (a) test distribution, only to authorized test accounts; (b) Developer self-distribution, with prominent disclosure to users that publication review has not been completed; or (c) reviewed store distribution. MEMOMIND may enable or restrict channels according to product capabilities, region, and risk.
4.2. Applications that have not passed MEMOMIND publication review must not be published in the store as reviewed applications.
4.3. The Developer must not expressly or implicitly represent that MEMOMIND has approved, certified, recommended, endorsed, or guaranteed applications it uses independently. The Developer is independently responsible for providing, displaying, enabling, operating, updating, and supporting such applications and for resulting compliance, security, privacy, intellectual-property, product, and user disputes. If a Developer's self-distributed application causes any harm to MEMOMIND or a third party, the Developer shall bear full liability for damages.
4.4. Even if an application is self-distributed, MEMOMIND may still restrict interfaces, revoke permissions, block execution, or take other necessary measures if it causes or may cause risks to the platform, devices, users, or third parties.
4.5. Test distribution shall be limited to Developer-authorized testers and devices and use prominent testing labels. It must not serve as disguised public distribution. The Developer shall fully explain the application's test nature, potentially involved data, risks, confidentiality, and feedback arrangements to testers.
4.6. Version identifiers, features, permissions, backends, and data purposes for each distribution channel shall match the corresponding declarations. The Developer must not use links, QR codes, remote configuration, or other means to direct users from a declared version to undisclosed features.
5. Application Submission, Version Changes, and Maintenance
5.1. When applying to publish an application in the MEMOMIND store, the Developer shall submit entity information, features, devices and regions, test accounts, data flows, permissions, retention periods, service providers, processing locations, cross-border mechanisms, AI use, remote configuration, support channels, and other reasonable information consistent with the actual version for MEMOMIND review.
5.2. MEMOMIND may conduct material verification, static and dynamic testing, privacy and security assessments, UI checks, malware and vulnerability scans, dependency and open-source license checks, and other reasonably necessary review. The Developer understands that the simulator, workspace, or other development tools automatically include Review Source Materials when packaging an application for review, but packaging itself does not transmit the package or materials to MEMOMIND. Only when the Developer separately chooses and confirms submission for review are the package and its Review Source Materials uploaded and received by MEMOMIND. The submission interface and technical documentation shall explain reasonably clearly that the package includes source materials. By submitting for review, the Developer authorizes MEMOMIND to receive and process these materials under these Terms. MEMOMIND may, to the extent reasonably necessary, require supplementary build instructions, software bills of materials, test accounts, test summaries, data-flow descriptions, or other review evidence, but shall not require code or materials unrelated to the application under review.
5.3. Based on review results, MEMOMIND may approve, approve conditionally, require remediation, or reject. Review confirms only the state of a specific version and declared use at the time of review. It does not constitute MEMOMIND's joint development, operation, agency, certification, guarantee, or continuing compliance certification of the application. Except as otherwise mandatorily required by applicable law, the Developer independently bears responsibilities and obligations for application design, development, operation, content, features, user support, data processing, intellectual property, and other related matters.
5.4. New permissions, changes in data purposes or recipients, introduction of AI, or material changes to core features, regions, or data flows require renewed declaration and review before implementation. Hot updates, remote configuration, or prompts must not be used to evade review.
5.5. Published applications shall remain compatible with MEMOMIND devices and the Developer Platform, and their contact details, privacy policies, terms of use, and other user notices shall remain valid. The Developer shall promptly fix high-risk vulnerabilities that may materially affect users, devices, or the platform. Before terminating application services, discontinuing support for major features, or becoming unable to meet data-processing obligations, it shall give MEMOMIND and affected users advance notice as required by applicable law or reasonably necessary.
5.6. Regardless of the permitted distribution channel used, the Developer is the independent provider of the third-party application and independently bears responsibility for its features, content, support, legality, privacy, security, intellectual property, and related disputes with any user or third party.
5.7. Review does not preclude MEMOMIND from conducting automated detection, spot checks, rereview, or requiring resubmission after publication for security, compliance, technical, or operational needs. The Developer shall retain reproducible build, version, dependency, testing, and change records and provide application-related evidence upon reasonable request.
5.8. The Developer shall provide effective and readily accessible contacts or channels for customer service, privacy, data security, and intellectual property, and promptly respond to reasonable application-related requests from users and MEMOMIND. For possible major interruptions, feature discontinuation, or inability to continue data obligations, the Developer shall provide affected users reasonable advance notice according to applicable law and the circumstances.
5.9. Application details, screenshots, demonstrations, review solicitations, and other promotional information must not be false or misleading or conceal material limitations, conditions, or risks affecting users. The Developer must not make claims about safety, health, performance, compatibility, compliance, or an official MEMOMIND relationship that cannot reasonably be substantiated, or expressly or implicitly represent that MEMOMIND certifies, recommends, endorses, or guarantees applications it has not approved.
5.10. The Developer acknowledges and agrees that review imposes staffing and financial burdens on MEMOMIND. If review requests are excessively frequent for reasons attributable to the Developer, MEMOMIND may take measures such as requiring the Developer to pay review service fees or suspending or terminating publication review. The Developer independently bears resulting responsibility. If MEMOMIND charges review service fees, it shall specify the rates and applicable circumstances in advance and issue lawful, valid invoices in accordance with applicable law and the Developer's truthful, accurate, and valid invoicing information. The Developer bears responsibility arising from incorrect, incomplete, or invalid invoicing information.
6. Personal Information and Data Protection
6.1. When registering, applying to use the Developer Platform, or applying for related services, the Developer shall provide necessary information as required by MEMOMIND and ensure it is truthful, accurate, complete, lawful, and valid. MEMOMIND's then-current privacy policy and other applicable privacy notices govern its processing of Developers' personal information in providing the platform and related services. If the Developer directly collects or processes users' personal information or other protected data through an application, it is independently responsible under applicable law and its own privacy policy. MEMOMIND's privacy policy must not be interpreted as covering the Developer's independent processing.
6.2. Before download, installation, activation, or collection of relevant data begins, each user-facing application shall provide, as required by applicable law, an accurate, complete, clear, readily accessible, and continuously valid application-specific privacy policy and applicable terms of use, with continued access in the application or another reasonable location. Actual collection, processing, sharing, and other data activities, and actual application features and limitations, shall remain consistent with those policies and terms and the information declared to and reviewed by MEMOMIND.
6.3. For personal information and other legally protected data directly collected by the Developer, the Developer shall independently determine and ensure an appropriate legal basis and meet necessary notice, consent, opt-out, and other legal obligations. MEMOMIND's provision of Platform Data must not be interpreted as authorization for, or assumption of responsibility for, how the Developer subsequently receives, accesses, uses, analyzes, stores, shares, transfers, or otherwise processes it. The Developer bears the corresponding responsibility for processing after obtaining Platform Data under applicable law and these Terms.
6.4. The Developer shall provide appropriate channels for data-subject rights and complaints under applicable law, including, where applicable, access, correction, deletion, restriction, portability, objection, and consent withdrawal, and complete identity verification and responses within legal deadlines. If the Developer receives user requests, regulatory demands, or other notices involving MEMOMIND, MEMOMIND Platform Data, or MEMOMIND processing activities, it shall promptly notify and cooperate with MEMOMIND to the extent permitted by applicable law. Without express authorization, the Developer must not make commitments, confirmations, or other binding statements to users or regulators on MEMOMIND's behalf.
6.5. If suspected violations of applicable law in the Developer's collection, processing, storage, transfer, or security measures lead to regulatory investigations, inquiries, penalties, or other enforcement, the Developer shall actively cooperate and promptly address them as required by law, and promptly notify MEMOMIND to the extent legally permitted. The Developer independently bears liability arising from its own unlawful or noncompliant conduct.
6.6. The Developer shall comply with these Terms and all laws and regulations applicable to its applications and processing activities, and adopt technical and organizational measures appropriate to the types, quantities, and risks of the data processed to protect personal information and other protected data. Where the Developer's breach of these Terms, applicable law, or its own processing obligations causes a data breach, unauthorized access, unlawful processing, or another data-security incident, it shall bear the corresponding legal responsibility. If such conduct directly causes MEMOMIND or a third party losses, claims, administrative penalties, or reasonable rights-enforcement costs, the Developer shall bear corresponding compensation liability to the extent permitted by applicable law.
7. Platform Data Usage Rules
7.1. Platform-Provided Data may be used only to: (a) provide, operate, maintain, or secure declared features for the requesting user; (b) analyze the application in aggregated, deidentified, or anonymized forms that cannot identify individuals or devices; or (c) meet applicable legal obligations. Use for any other purpose requires MEMOMIND's prior written approval and compliance with applicable law.
7.2. Unless MEMOMIND has given prior written approval and applicable law permits it, the Developer must not use Platform-Provided Data for:
(a) training, fine-tuning, adjusting, testing, validating, or evaluating any AI or machine-learning model;
(b) selling, renting, licensing, trading, pledging, or otherwise providing Platform-Provided Data or derived data to third parties;
(c) data brokering, advertising targeting or profiling, or marketing unrelated to the user's request; or
(d) other purposes unrelated to the application features declared to and approved by MEMOMIND.
7.3. The Developer must not use Platform-Provided Data for:
(a) creating or supporting tools or services for surveillance, law enforcement, intelligence, or similar purposes;
(b) discriminatory profiling, classification, or decision-making based on legally protected personal characteristics;
(c) inferring a user's undisclosed true identity or other sensitive attributes without clear notice and an appropriate legal basis;
(d) reidentifying deidentified or anonymized data, or attempting to recover deleted, hidden, or deidentified information;
(e) combining it with other data sources to create cross-context personal or device profiles beyond declared application features;
(f) bulk scraping, bulk export, or otherwise circumventing platform data-access, frequency, or technical limits; or
(g) bypassing or weakening the user's withdrawal of authorization, deletion, reset, permission restrictions, or other data controls.
7.4. When requesting Platform Data, APIs, data fields, or permissions, the Developer shall explain the required features, specific data, user value, purposes, frequency, recipients, processing locations, retention periods, and user controls. Granted permissions must not be used beyond declared features.
7.5. MEMOMIND may reclaim, restrict, suspend, or adjust APIs, data fields, or permissions that have long been unused, are no longer necessary, lack continuing entity or permission verification, or present security, privacy, or compliance risks, for data minimization, security, compliance, product adjustments, or other reasonable reasons. Inactivity periods and permission-management requirements follow MEMOMIND's permission rules or technical documentation issued from time to time. These Terms do not mean that any API, data field, or permission automatically expires after 90 consecutive days of nonuse, unless the relevant rules expressly provide otherwise
7.6. Where applicable law requires, or a valid user request for deletion, withdrawal of authorization, or similar action takes effect, the Developer shall, within the legally required period, delete or irreversibly anonymize data that no longer has a lawful processing basis if any of the following occurs:
(a) the user deletes their account;
(b) the user withdraws the relevant authorization, leaving the Developer without a legal basis for continued processing;
(c) the user makes a valid deletion request under applicable law;
(d) the application is delisted or the relevant feature is discontinued;
(e) MEMOMIND sends a lawful deletion notice under applicable law or a valid deletion mechanism; or
(f) the data is no longer necessary for the Developer to provide declared features.
The Developer shall ensure that service providers entrusted to process the relevant Platform-Provided Data delete or anonymize it as required.
If retention is needed for statutory retention obligations, establishing or exercising legal claims, dispute resolution, or another lawful reason, the Developer may retain data to the necessary extent with appropriate access restrictions, security, and segregation. It shall promptly delete or irreversibly anonymize the data when the retention period ends or its legal basis ceases.
7.7. Any feature that creates, modifies, deletes, sends, uploads, shares, or changes external account or system state shall be accurately identified as a write operation and, where appropriate, provide preview, confirmation, permission scope, undo, or remediation mechanisms. Sending data outside the current application's boundary is also a write operation.
7.8. Unless the Developer has successfully completed the applicable authentication process and obtained the user's express authorization, the Developer must not solicit or require direct disclosure of brand-account passwords, multifactor authentication codes, access tokens, API keys, private keys, or other authentication secrets. User identifiers, access tokens, application keys, and other credentials may be provided only to service providers necessary for application operation. The Developer shall ensure those providers are bound by appropriate written contracts, use security measures no lower than reasonable industry standards, and access and process the information only as necessary for their services. The Developer must not store authentication secrets in public code repositories, client-accessible code, logs, debugging information, or other inadequately protected environments
8. Application Security, Content, AI, and Special-Category Requirements
8.1. The Developer shall implement risk-appropriate secure development, access control, encryption, key management, logging, vulnerability and patch management, supply-chain measures, backup and recovery, business continuity, and secure deletion.
8.2. Applications must not contain malware, backdoors, spyware, ransomware, unauthorized mining, phishing, fraud, spam, official impersonation, or features that evade security measures.
8.3. Applications must not provide unlawful, infringing, terrorist or extremist content, content harmful to minors, or inappropriate violent or adult content.
8.4. For applications directed at minors or involving medical care, health, news, publishing, finance, biometrics, identity verification, or other regulated activities, the Developer shall obtain the legally required licenses, approvals, filings, registrations, certifications, or other qualifications before providing the features and supply evidence as required by MEMOMIND. The Developer independently bears responsibility for any consequences of failure to obtain relevant filing documents. It is liable for, and shall compensate in full, any losses caused to MEMOMIND or any third party by breach of these Terms.
8.5. Applications offering AI shall accurately disclose, under applicable law and MEMOMIND declaration requirements, the main AI models or providers used, input/output data types, retention, use for model training or improvement, degree of automation, and principal associated risks. The Developer shall take reasonable, risk-based safeguards against prompt injection, sensitive-data leakage, access beyond the authorized scope, unauthorized external actions, and other conduct potentially causing material harm to users or third parties. AI output not appropriately verified must not be presented as certain, accurate, or professionally authoritative conclusions. Human review, user confirmation, correction, or appeal mechanisms shall be provided where required by law or reasonably necessary for the application's risk.
8.6. Applications involving sensitive features such as cameras, microphones, precise location, health, biometrics, contacts, calendars, or third-party accounts shall request access only as needed when actively triggered by the user. Misleading UI, repeated prompts, default enablement, technical bypasses, or other means must not evade OS or MEMOMIND permission controls or user denial/withdrawal mechanisms.
8.7. On discovering a security incident or material vulnerability affecting an application, platform, device, user, or Platform Data, the Developer shall promptly report it to MEMOMIND and take reasonable measures to preserve evidence, contain impact, remediate vulnerabilities, and prevent escalation. The Developer shall meet applicable legal breach and security-incident notification obligations and reasonably cooperate with MEMOMIND in risk assessment, investigation, containment, and remediation. Specific obligations concerning personal-information handlers, entrusted processors, or other allocations of data-protection responsibility follow the applicable data processing agreement (DPA) between the parties and applicable law.
8.8. Applications directed at, or potentially used by, minors shall implement age- and risk-appropriate design, defaults, guardian mechanisms, content governance, and data minimization. They must not exploit age-related vulnerabilities, perform improper profiling, or induce disclosures.
8.9. For features involving medical care, health, finance, identity, biometrics, employment, education, public services, or other potentially significant effects on individuals, the Developer shall clearly explain their purposes, limitations, accuracy, and risks according to applicable law and actual application risk, and provide human review, user confirmation, correction, or appeal channels where legally required or reasonably necessary. Unverified AI output, or output without appropriate human review, must not be presented as medical diagnoses, treatment advice, financial decisions, identity-verification results, or other conclusions with definitive legal, professional, or factual effect.
8.10. The Developer shall establish public or readily discoverable vulnerability-reporting channels, receive reports in good faith, protect information needed for reporting, and promptly remediate, mitigate, and give affected parties necessary explanations according to risk.
9. External Interfaces and Third-Party Services
9.1. The Developer may use cloud, analytics, mapping, AI, and other service providers, but shall conduct due diligence and define processing purposes, data scope, security and confidentiality obligations, and exit mechanisms through written agreements or other legally binding arrangements.
9.2. The Developer shall maintain a list of service providers and downstream providers, recording contacts, services, data categories and approximate scale, purposes, processing locations, cross-border mechanisms, and contractual protections. Where Platform-Provided Data is involved, MEMOMIND may, to the extent reasonably necessary, require relevant provider information and supporting materials based on security, privacy, or compliance risk assessments.
9.3. If a provider violates platform requirements or creates security or legal risks, MEMOMIND may require the Developer to stop providing Platform Data to that provider or implement alternative safeguards. Before adding recipients, providers, or processing regions, or materially changing data purposes, the Developer shall make declarations or undergo renewed review as required by MEMOMIND.
9.4. The Developer shall ensure that providers cease processing and delete data upon service termination, a valid user deletion request, a lawful MEMOMIND deletion signal, or when data is no longer necessary.
9.5. Application privacy policies and review materials shall identify provider names or categories, services, data received, purposes, locations, cross-border mechanisms, and available policy links as required by law. Generic labels such as “partners” do not justify undisclosed data sharing.
9.6. When changing providers or terminating an application, the Developer shall have an exit plan for data export, migration, return, deletion, or lawful segregation, and prevent supply-chain disruption from obstructing user rights or causing loss of control over Platform Data.
10. Intellectual Property and Limited Operational License
10.1. MEMOMIND and its licensors retain rights in the Developer Platform, devices, SDKs, APIs, documentation, trademarks, and related technology. The Developer retains rights in its applications and Developer Content but shall ensure it has the rights and licenses needed to perform these Terms.
10.2. The Developer retains all rights in its applications, Review Source Materials, and other Developer Content. Submission of Review Source Materials does not transfer intellectual property, trade secrets, or ownership to MEMOMIND. The Developer grants MEMOMIND a nonexclusive, royalty-free, nontransferable limited license, allowing entrusted processing under these Terms, solely as necessary to provide the Developer Platform and complete application review, to: (a) receive, transmit, and securely store Review Source Materials; (b) copy, run, compile, parse, scan, and inspect them; (c) make necessary temporary technical transformations for testing, security analysis, compatibility verification, issue reproduction, and review records; and (d) distribute and run published applications, maintain compatibility, investigate security issues, and conduct legally required rereviews. Unless otherwise expressly agreed, this license grants no right to independently develop, commercially exploit, or otherwise dispose of Review Source Materials.
10.3. MEMOMIND may use Review Source Materials only for publication review and remediation verification; detection of malware, vulnerabilities, noncompliant processing, and other security risks; device, OS, SDK, and platform compatibility checks; investigation of user complaints, security incidents, or suspected breaches of these Terms; and compliance with applicable law or lawful official demands. Access is limited to MEMOMIND personnel, affiliates, and entrusted review/security providers with an actual review need and confidentiality obligations. MEMOMIND shall use least privilege, authentication, access records, and other risk-appropriate measures. Without the Developer's separate express consent, MEMOMIND must not use Review Source Materials to develop products that substantially compete with the Developer's application, train general-purpose AI models or models for other customers, publicly sell those materials or license third parties to use them independently, or use them for marketing, product development, or other purposes that are unrelated to review, distribution, security, or compliance. Automated security scanning, code analysis, or review tools may be used, but those tools and their providers remain bound by this provision's purpose, confidentiality, and security limits.
10.4. After application distribution stops, the Section 10.2 license ends for distribution to new users, but may continue as necessary for installed versions, security updates, backups, investigations, disputes, and statutory retention.
10.5. Each party shall use the other's nonpublic technical, business, user, interface, credential, and prerelease information marked confidential or confidential by nature only to perform these Terms, and disclose it only to persons with a need to know who are bound by obligations no less protective than this provision. Exceptions include information lawfully public, previously known, obtained from an entitled third party, or independently developed. For legally compelled disclosure, give prior notice where permitted and limit disclosure to what is necessary. Confidential information excludes:
(a) information lawfully public when disclosed or later made public without the recipient's breach of these Terms;
(b) information the recipient can prove it lawfully knew before disclosure;
(c) information lawfully obtained from a third party entitled to disclose it and not bound by confidentiality; or
(d) information the recipient can prove it independently developed without using or disclosing the other party's confidential information.
If law, a court, or a competent authority requires disclosure, the recipient shall give the discloser prior notice to the extent legally permitted and limit disclosure to the legally necessary scope.
10.6. The Developer warrants that it has obtained necessary rights for applications, Developer Content, trademarks, likenesses, data, and third-party components, and complies with open-source licenses. Open-source components must not cause MEMOMIND proprietary software to become subject to source-disclosure requirements, license changes, or derivative-work treatment, except as otherwise provided by law or agreed by MEMOMIND in writing.
10.7. If an application lets users upload, generate, publish, or share content with others, the Developer shall establish appropriate content-governance mechanisms according to law and risk, including applicable content rules, reporting channels, removal or restriction mechanisms, appeals, and rights-holder contacts, and promptly address infringing, unlawful, harmful, or otherwise rule-violating content as required by law.
10.8. Without MEMOMIND's prior written consent, the Developer must not register, use, or promote names or identifiers confusingly similar to MEMOMIND’s names, trademarks, trade names, domains, or other brand identifiers, or in any way expressly or implicitly represent that it has an official cooperation, authorization, certification, recommendation, investment, control, or other unauthorized relationship with MEMOMIND.
10.9. On request or termination, confidential information shall be returned or securely destroyed, with confirmation on reasonable request. Legally retained copies shall be segregated and remain subject to these obligations. Trade-secret confidentiality continues while legally protected.
10.10. Before submission, the Developer shall inspect the review package and remove unrelated code and materials. Review Source Materials must not include production passwords, private keys, access tokens, inadequately protected API keys, real user data, or third-party confidential materials the Developer lacks authority to disclose to MEMOMIND. If Review Source Materials need to include personal data, the Developer shall notify MEMOMIND in advance. The parties shall determine their data-protection roles according to the actual processing. Where MEMOMIND processes on behalf of the Developer, data processing terms matching the actual roles shall apply or be separately signed before processing begins.
10.11. MEMOMIND retains Review Source Materials only as long as reasonably necessary for the purposes in these Terms. For withdrawn, rejected, or unpublished applications, MEMOMIND shall, as a general rule, delete the Review Source Materials no later than [90] days after the relevant review or remediation ends. If the Developer resubmits the same or a substantially identical version within that period and review is ongoing, MEMOMIND may retain them as necessary for review. For published applications, MEMOMIND may retain necessary materials while the version continues to be distributed through MEMOMIND and shall, as a general rule, delete them no later than [180] days after that version's distribution stops. Backups may remain under MEMOMIND's normal backup and disaster-recovery mechanisms, but must not be used for review, product development, commercial exploitation, or purposes unrelated to backup, security recovery, or legal obligations. They remain subject to these Terms' confidentiality and security requirements. Where security investigations, disputes, legal preservation, regulatory investigations, or lawful official demands require extended retention, MEMOMIND may retain relevant materials as necessary. After that purpose ends, it shall promptly delete them or render them unrecoverable using reasonable security procedures.
11. Continuing Compliance Obligations
11.1. For applications using Platform-Provided Data, sensitive permissions, or other high-risk capabilities, the Developer shall, at MEMOMIND's reasonable request, have a person authorized to represent it reconfirm, within the period specified by MEMOMIND, processing purposes, permission necessity, recipients and providers, retention/deletion arrangements, security measures, and other continuing-compliance information. Except for security incidents, regulatory requirements, or other urgent risks, the period specified by MEMOMIND shall, as a general rule, not exceed thirty (30) days. If confirmation or necessary materials are not provided on time, MEMOMIND may, according to risk, suspend or restrict data, permissions, APIs, or other capabilities and defer application updates or publication.
11.2. For applications involving sensitive data, minors, high-risk AI, biometrics, large-scale surveillance, or major incidents, MEMOMIND may, based on law, platform rules, and risk, require application-related data-protection impact assessments, security assessments or evidence, provider/subcontractor materials, compliance qualifications, test results, or other reasonable specialized assessments. Unless otherwise required by law, regulators, or urgent security risks, requests shall be proportionate to the risk.
11.3. MEMOMIND may verify continuing compliance through questionnaires, interviews, remote verification, and application-limited system or control spot checks. For security incidents, regulatory requirements, credible complaints, or reasonable grounds to believe a material risk exists, MEMOMIND may take necessary expedited verification measures proportionate to risk and promptly notify the Developer where reasonably practicable.
11.4. MEMOMIND may require remediation, restrict features or traffic, stop downloads or interfaces, revoke permissions, delist applications, block execution, suspend or terminate accounts, and require deletion of Platform Data with evidence.
11.5. Except for urgent security, illegality, or other circumstances unsuitable for advance notice, MEMOMIND will, where reasonably practicable, explain the main reasons for its measures and applicable remediation directions. The Developer may appeal, provide supplementary explanations, or request rereview through designated channels. As a general rule, an appeal or rereview does not automatically suspend measures already taken by MEMOMIND, but MEMOMIND may restore all or some features according to risk and remediation.
11.6. The Developer must not use new accounts, affiliates, changed application identifiers, or other means to evade restrictions, suspension, delisting, or termination under these Terms. If controlled affiliates or other accounts under its actual control participate, MEMOMIND may take necessary measures based on actual control, affiliation, and risk.
11.7. The Developer shall retain permission declarations, processing records, privacy-policy versions, consent evidence, provider lists, deletion records, security controls, build records, and incident materials to demonstrate continuing compliance. Retention periods shall be proportionate to risk, law, and platform rules.
11.8. MEMOMIND normally prioritizes questionnaires, certifications, independent audit summaries, and remote verification. Risk-proportionate specialized inspections occur only for security incidents, regulatory requirements, credible complaints, or reasonable suspicion of material breach, and MEMOMIND shall avoid requesting unrelated third-party data or legally privileged materials.
11.9. The Developer shall remediate within the specified or another reasonable period and provide retesting, deletion, or completion evidence. MEMOMIND's review, acceptance, approval, or absence of objection to submitted materials does not reduce the Developer's responsibilities under these Terms and applicable law, or guarantee continuing application compliance, security, or absence of other risks.
12. Changes to the Developer Entity
12.1. The Developer may stop using the Developer Platform by giving MEMOMIND [thirty] days' prior written notice. For a material breach by the Developer, MEMOMIND may require the Developer to cure it within a specified period, generally no less than fifteen (15) days unless otherwise provided here. For serious data or security incidents, material infringement, fraud, evasion of platform measures, bankruptcy or insolvency, applicable legal or regulatory requirements, or other material risks requiring immediate action, MEMOMIND may immediately suspend or terminate services, accounts, or applications without that cure period.
12.2. After termination, the Developer shall cease unauthorized continued API and development-resource use, address delisting, user notices, data export, deletion, complaints, and security, and complete return, deletion, anonymization, or other processing under the DPA and applicable law.
12.3. Platform accounts, applications, or Platform Data must not be transferred to a new entity without authorization. For MEMOMIND-approved transfers, the transferee shall accept applicable terms, complete verification, and resubmit applications where necessary.
12.4. During suspension, the Developer must not continue restricted activities but shall still handle security incidents, user rights, deletion, installed-version risks, and required remediation. MEMOMIND may restore, maintain restrictions, or terminate based on remediation results.
12.5. Termination does not affect accrued rights and liabilities. For installed applications, the parties shall arrange orderly cessation, necessary security updates, and user notices within security, legal, and technical constraints.
13. General Provisions
13.1. The Developer warrants that applications, submitted materials, processing activities, and Developer Content are truthful, lawful, secure, noninfringing, and continuously compliant with these Terms, the separately published Developer Data Sharing and Cross-Border Transfer Agreement (DPA), review rules, and applicable law. The DPA forms part of these Terms and prevails in conflicts concerning data sharing and cross-border matters.
13.2. To the extent permitted by applicable law and the harm is attributable to the Developer, the Developer independently bears liability for third-party claims, regulatory action, and reasonable expenses arising from applications, Developer Content, processing, breach, illegality, or infringement.
13.3. To the extent permitted by applicable law, the Developer Platform is provided “as is” and “as available”. To the extent permitted by applicable law, MEMOMIND is not liable for indirect, incidental, special, punitive, or consequential losses arising out of or relating to these Terms, including lost profits, revenue, goodwill, data, or business interruption.
13.4. These Terms are governed by and construed under the laws of the Hong Kong Special Administrative Region, excluding its conflict-of-laws rules. The parties shall first seek to resolve any dispute arising out of or relating to these Terms through amicable consultation. If consultation fails, the dispute shall be submitted to the Hong Kong International Arbitration Centre (HKIAC) under its then-effective arbitration rules. The seat is Hong Kong, the arbitration language is English, and the award is final and binding on both parties.
13.5. The Developer and MEMOMIND are independent contracting parties. These Terms create no employment, agency, partnership, joint venture, franchise, or similar relationship. Except as expressly provided, neither party may make commitments or assume obligations on the other's behalf.
13.6. The Developer shall comply with export-control, economic-sanctions, and embargo laws applicable to relevant entities, technology, data, regions, and end uses, and must not provide the platform, applications, or Platform Data to prohibited entities, regions, or uses.
13.7. MEMOMIND may amend these Terms for legal, regulatory, security, technical, or business changes. MEMOMIND will provide reasonable advance notice of material adverse changes and obtain renewed acceptance where required by applicable law.
13.8. Confidentiality, intellectual property, data deletion, investigation, compensation, liability, and dispute provisions survive termination according to their nature. MEMOMIND contact: support@memo-mind.com.
13.9. The Chinese and English versions of these Terms shall use the same version number and each constitute a complete text. The Chinese version prevails in mainland China; the English version prevails outside mainland China.
13.10. MEMOMIND shall reasonably notify the Developer after becoming aware of a claim and allow it to lead the defense. Without consent, the Developer must not admit MEMOMIND’s fault, impose nonmonetary obligations on MEMOMIND, or prejudice its rights. MEMOMIND may participate independently in dispute resolution, and the Developer bears full liability for damages, including, without limitation, compensation amounts and lawyers' fees.
13.11. These Terms, the DPA, and expressly incorporated rules constitute the entire agreement concerning the Developer Platform. The Developer must not assign without MEMOMIND’s consent. MEMOMIND may lawfully assign in a merger, restructuring, or relevant business transfer and provide required notice.
13.12. Invalidity of a provision does not affect the remainder. Delay in exercising a right is not waiver. Headings are for convenience and do not define the sections. Delays caused by events beyond reasonable control are excused to the affected extent, but each party shall reasonably mitigate losses and continue performing feasible data-protection, security, and confidentiality obligations.