[Legal · Privacy]

Privacy Policy

Last Updated: August 17, 2026

Mezmur LLC ("Mezmur," "we," "us," or "our") respects your privacy. This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you visit our website at mezmur.tech, interact with our marketing campaigns (including QR-code mailers), use our 3D walkthrough showcases, or engage our consulting services.

Mezmur LLC is a limited liability company headquartered in Phoenix, Arizona. Our services include AI operations consulting, Generative Engine Optimization (GEO), photoreal 3D scanning (Gaussian Light Capture), and marketing automation.

1. Information We Collect

1.1 Information You Provide Directly

  • Name and email (optional): When you arrive via a QR campaign landing page (/welcome), a modal invites you to share your full name and email. Both fields are optional. If provided, we use them to follow up about our services.
  • Voice messages: You may record a voice message through our in-browser voice widget. Your audio is transcribed on your device using an on-device speech recognition model (running via WebAssembly or WebGPU). The transcript is sent to us; the raw audio is sent to our object storage only if you are not located in a state with biometric voice statutes (currently Illinois, Texas, and Washington). See Section 4 for details.
  • Email in voice messages: You may optionally provide an email address alongside a voice message so we can reply.
  • Correspondence: When you contact us at welcome@mezmur.tech, we retain the content of your communications.
  • Consulting engagement data: If you engage our consulting services, we may collect business information, workflow documentation, system access credentials, and project-related materials you share with us.

1.2 Information We Collect Automatically

  • Visit data: When you arrive via a QR campaign link (/go/{code}), we record a visit row containing a random token (stored in your browser's localStorage), the campaign code, a timestamp, and your user-agent string.
  • IP address and coarse geolocation: We derive your IP address from HTTP headers. We also derive city-level geolocation (city, region, postal code, country) from edge network geo headers. This is approximate, carrier-grade location data, not GPS-precise.
  • Dwell and engagement metrics: On our QR landing page, we track how long the page is visible (seconds_visible), how long you are actively interacting (active_seconds, capped at 30 minutes), and whether you launched the 3D viewer.
  • First-party analytics: We use first-party web analytics for aggregate pageview counting.
  • Third-party analytics and advertising data: We use Google Analytics, Microsoft Clarity, and the Meta Pixel on our public pages. These tools use cookies and similar technologies to collect device information (browser, operating system, screen size), usage information (pages viewed, clicks, scrolls, taps, mouse movement, time on page), approximate location, and the site events described in Section 10. Microsoft Clarity additionally records session replays (a reconstruction of how you interacted with a page) and generates heatmaps. Our internal operations portal is excluded from all third-party tracking. See Section 10 for details, cookie names, and opt-out options.
  • Cookies and local storage: We use localStorage to store a random visit token (mz-visit) and a session flag (mz-welcome-seen). Cookies set by our third-party analytics and advertising partners are described in Section 10.

1.3 Information We Receive from Third Parties

  • Campaign partners: If you arrive via a referral or affiliate link, we may receive basic information from the referring partner.
  • Authentication: Our internal operations portal uses a third-party authentication provider. This provider processes login credentials for authorized admin users only. No public visitor data is shared with the authentication provider.

2. How We Use Your Information

We use your personal information for the following purposes:

  • To provide and improve our services: Deliver consulting engagements, process 3D scan data, and produce deliverables.
  • To track campaign performance: Attribute QR scans to mail campaigns, measure engagement, and optimize marketing spend.
  • To advertise our services: Measure the performance of our advertising and build audiences for advertising on third-party platforms (for example, showing follow-up ads to people who have visited our site). You can opt out of this — see Sections 9 and 10.
  • To follow up with leads: Contact individuals who provide their name, email, or voice message through our welcome modal.
  • To communicate: Respond to inquiries, send service updates, and deliver project materials.
  • To secure our platform: Detect fraud, prevent abuse, and protect against unauthorized access.
  • To improve our website: Analyze aggregate usage patterns, page performance, and visitor engagement.
  • To comply with legal obligations: Respond to lawful requests from authorities and meet regulatory requirements.

AI and Machine Learning

We use on-device AI for voice transcription and may use AI-powered tools (including large language model providers) to assist in consulting engagements and content production. We do not use your personal information to train generalized, public AI models. Any AI subprocessors we engage are contractually limited to providing the specific service you are using, and your data is not used to improve their general models.

3. How We Share Your Information

We may share your information with the following categories of service providers and third parties:

3.1 Service Providers and Subprocessors

CategoryPurposeData Shared
Website hosting providerWebsite hosting and edge analyticsIP, request headers, pageview counts
Database hosting providerPostgreSQL database hostingVisit records, lead data, voice transcripts
Object storage providerStorage for voice audioVoice audio files (WAV), object metadata
Text-to-speech providerGreeting audio generationScript text only (no user personal data)
API hosting providerBackend API hosting (ops portal)Authenticated API requests from admin portal
Authentication providerAuthentication for admin portalAdmin credentials (authorized users only)
CDN providerOn-device model downloadNo personal data (model file fetch)
Web analytics providers (Google Analytics, Microsoft Clarity)Usage analytics, session replay, heatmapsDevice and usage data, pseudonymous cookie identifiers, IP address, interaction recordings
Advertising partners (Meta)Ad measurement and retargeting audiencesSite event data (pageviews, lead submissions), cookie identifiers, IP address, user-agent

We require our service providers to protect your information consistent with this Privacy Policy and applicable law. We do not sell your personal information for money. However, some of the analytics and advertising tools above involve disclosures that qualify as "sharing" under certain U.S. state privacy laws — see Section 9.2 for details and your opt-out rights.

3.2 Other Disclosures

  • Business transfers: In the event of a merger, acquisition, or asset sale, your information may be transferred as a business asset.
  • Legal compliance: We may disclose your information to law enforcement or government authorities if required by law or if we believe disclosure is necessary to protect our rights, property, or safety.
  • With your consent: We may share information with third parties when you direct us to do so.

4. Voice Messages and Biometric Data

Voice messages involve special considerations:

  • On-device transcription: Audio is transcribed in your browser using an on-device speech recognition model. The transcript text is sent to our server; transcription does not require audio to leave your device.
  • Audio storage: If you are not in Illinois, Texas, or Washington, we may store a 16kHz mono WAV file of your voice message in our object storage provider. A retention job deletes the audio file after a defined period, and the database retains only a deletion timestamp.
  • Biometric state gating: Visitors located in Illinois, Texas, or Washington (states with biometric privacy statutes) receive transcript-only processing. No audio is stored for these visitors.
  • Inference results: We may run demographic inference on stored voice audio (age estimate, gender estimate, sentiment). These are aggregate demographic labels only. We do not store voiceprints, voice embeddings, or any biometric identifiers that could uniquely identify you by your voice.
  • Your choice: Voice messages are optional. You are not required to leave one, and you can request deletion of any voice message and associated data at any time.

5. 3D Scanning and Spatial Data

When you engage our 3D scanning services (Gaussian Light Capture):

  • On-site capture: We capture images and/or video of your physical space. If drone capture is used indoors, see Section 7 of our Terms of Service for drone-related liability terms.
  • Processing: Captured data is processed into Gaussian splat models (3D walkthroughs). Raw capture data may be retained for a limited period to allow reprocessing.
  • Deliverables: You own your physical space and the right to the captured representation. We retain a license to use the processed walkthrough for our portfolio and marketing unless you opt out in writing.
  • Incidental capture: During scanning, images may incidentally capture people, artwork, or proprietary information in the space. You are responsible for ensuring you have the right to capture the scanned space and for notifying occupants before scanning.

6. Data Retention

Data typeRetention period
Visit records (IP, geolocation, user-agent)90 days from visit
Lead data (name, email from welcome modal)Duration of engagement + 90 days
Voice transcriptsDuration of engagement + 90 days
Voice audio (object storage)30 days from recording, then deleted
Voice inference resultsDuration of engagement + 90 days
Dwell time / QR tracking data90 days from visit
Consulting engagement dataDuration of engagement + 7 years (tax/legal records)
Campaign data (mail drops, codes)7 years (campaign performance records)
Admin portal access logs1 year
Anonymized/aggregated dataIndefinitely (cannot be linked to you)

Data collected by our third-party analytics and advertising tools (Section 10) is retained by those providers under their own retention policies; the cookie lifetimes in Section 10 indicate how long their identifiers persist in your browser.

You may request earlier deletion of your data at any time (see Section 9).

7. Data Security

We implement administrative, technical, and physical safeguards to protect your information:

  • Encryption: Data in transit uses TLS/HTTPS. Database and object storage are managed by providers with encryption at rest.
  • Access controls: The operations portal is gated by third-party authentication. Database and storage access is limited to authorized personnel.
  • Admin systems excluded from tracking: Our internal operations portal is excluded from all third-party analytics, advertising pixels, and session recording, so lead and client data viewed by our staff is never captured by those tools.
  • No 100% guarantee: No system is perfectly secure. If we become aware of a data breach affecting your personal information, we will notify affected individuals as required by applicable law.

8. Children's Privacy

We do not knowingly collect personal information from children under 16. If we learn that we have collected information from a child under 16, we will delete it as soon as possible. If you believe we have collected information from your child, please contact us at privacy@mezmur.tech.

9. Your Privacy Rights

9.1 All Visitors

You have the right to:

  • Request access to the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your personal information.
  • Object to or restrict certain processing of your data.
  • Withdraw consent for processing based on consent (without affecting prior processing).
  • Receive a copy of your data in a portable format.

To exercise these rights, contact us at privacy@mezmur.tech. We may ask for information to verify your identity before fulfilling your request. We will respond within 45 days.

9.2 California Residents (CCPA/CPRA)

California residents have the right to:

  • Know what personal information is collected, the sources, the business purpose, and the categories of third parties with whom it is shared.
  • Request deletion of personal information.
  • Correct inaccurate personal information.
  • Opt out of the "sale" or "sharing" of personal information.

Sale and sharing: Mezmur does not sell your personal information for money. However, we use third-party analytics and advertising cookies (Google, Microsoft Clarity, and the Meta Pixel) that transmit identifiers and activity data to those providers, and some of these disclosures may constitute "sharing" for cross-context behavioral advertising under the CCPA/CPRA. The categories involved are: identifiers (cookie IDs, IP address) and internet or network activity (pages viewed, interactions with our site).

Right to opt out of sharing: You may opt out at any time by:

  • Enabling the Global Privacy Control (GPC) signal in your browser or a browser extension — we honor GPC as a valid opt-out of sharing.
  • Using the vendor and industry opt-out tools listed in Section 10.
  • Emailing privacy@mezmur.tech with the subject "Opt Out of Sharing."

We do not use or disclose sensitive personal information for purposes beyond providing the services you request. We do not knowingly sell or share the personal information of consumers under 16 years of age.

To submit a verifiable consumer request, contact privacy@mezmur.tech. Authorized agents may submit requests on behalf of a California resident with written permission.

9.3 Other U.S. State Residents

Residents of states with comprehensive privacy laws (including but not limited to Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) have rights substantially similar to those described above. We do not sell personal data for money, and we do not profile individuals through automated means for decisions with legal or similarly significant effects. Our use of third-party advertising cookies may constitute "targeted advertising" under some of these laws; you may opt out using any of the methods described in Sections 9.2 and 10, including the Global Privacy Control signal.

9.4 European Economic Area, United Kingdom, and Switzerland

If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR, UK GDPR, or Swiss nFADP:

  • Access, rectification, erasure, restriction, objection, and data portability.
  • Withdraw consent at any time (without affecting prior lawful processing).
  • Lodge a complaint with your local data protection authority.

Our lawful bases for processing are:

  • Contractual necessity: To provide services you have requested.
  • Legitimate interests: To operate and improve our business, detect fraud, and secure our platform.
  • Consent: For optional activities like marketing communications, voice message recording, and non-essential cookies.
  • Legal obligation: To comply with applicable laws and regulations.

Where required by applicable law (including ePrivacy rules), we set non-essential cookies and similar tracking technologies only with your consent, and you may withdraw that consent at any time.

For international data transfers, we rely on Standard Contractual Clauses and applicable adequacy mechanisms.

9.5 Arizona Residents

As an Arizona-based business, we process personal information in accordance with Arizona state law. Arizona residents may contact the Arizona Attorney General's office for privacy-related complaints.

10. Cookies and Tracking Technologies

10.1 First-Party Storage

  • localStorage: A random visit token (mz-visit) to link campaign visits to form submissions. A session flag (mz-welcome-seen) to avoid showing the welcome modal twice.
  • First-party web analytics: Aggregate pageview tracking via first-party analytics. No cross-site identifiers.

You can clear localStorage by clearing your browser's site data for mezmur.tech.

10.2 Third-Party Analytics and Advertising Tools

We use the following third-party tools on our public pages. Our internal operations portal is excluded from all of them.

ToolProviderWhat it doesTypical cookies (lifetime)Provider policy & opt-out
Google AnalyticsGoogle LLCUsage analytics: pageviews, events, device info, approximate location_ga, _ga_* (up to 2 years)Privacy policy · Ad settings · GA opt-out
Microsoft ClarityMicrosoft CorporationSession replay (reconstruction of clicks, scrolls, taps, mouse movement), heatmaps, usage analytics_clck, _clsk (session/replay); MUID, ANONCHK, SM, CLID (Microsoft identifiers, up to ~13 months)Privacy statement · Ad settings
Meta PixelMeta Platforms, Inc.Advertising measurement and retargeting audiences_fbp (~90 days), _fbcPrivacy policy · Ad preferences

Events we send to these tools: page views, the campaign code from a QR scan, lead form submissions, the fact that a voice message was submitted (and its duration), and 3D viewer launches. We do not send them your name, your email address, or the contents or transcript of your voice message.

Session replay: Microsoft Clarity records how you interact with a page and reconstructs it as a session replay. Text you type into form fields is masked by default. Microsoft may also use data collected by Clarity for its own purposes, including advertising, as described in Microsoft's privacy statement. Similarly, Meta may use data collected by the Pixel for its own purposes, including improving its advertising products, as described in Meta's privacy policy.

10.3 Your Choices

  • Global Privacy Control (GPC): We honor GPC browser signals as a valid opt-out of the "sharing" of personal information where required by law.
  • Vendor opt-outs: Use the links in the table above, or the industry tools at aboutads.info/optout and optout.networkadvertising.org.
  • Browser controls: You can block or delete cookies in your browser settings and clear site data for mezmur.tech at any time. Blocking these cookies does not affect your ability to use our website.
  • Do Not Track: Legacy DNT signals never gained an industry-standard meaning, and we do not respond to them; we honor the Global Privacy Control signal instead.

11. International Data Transfers

Mezmur is based in Phoenix, Arizona, USA. Your data is processed and stored in the United States by our service providers. If you access our site from outside the United States, your data will be transferred to and processed in the United States. We take reasonable steps to ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses where applicable.

12. Third-Party Links

Our website may contain links to third-party websites (e.g., font providers, CDN providers, authentication services). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

13. Privacy Policy Updates

We may update this Privacy Policy from time to time. We will update the "Last Updated" date at the top of this page. For material changes, we will post a notice on our website. Your continued use of our website after changes are posted constitutes acceptance of the updated policy.

14. Contact Us

For privacy questions, data requests, or to exercise your privacy rights:

  • Email: privacy@mezmur.tech
  • Mail: Mezmur LLC, ATTN: Privacy, c/o Registered Agents Inc., 4539 N 22nd St, Ste R, Phoenix, AZ 85016, USA

We will respond to all substantive privacy inquiries within 45 days.

© 2026 Mezmur LLC. All rights reserved.