1.Interpretation and Definitions
How to read this document and what the terms mean
1.1 Interpretation
Capitalised terms have the meaning set out below. Singular forms include the plural and references to one gender include all genders. Headings are for convenience only and do not affect interpretation.
1.2 Definitions
- Account — the unique identifier created when you sign up to use the Service.
- Personal Data — information that identifies or could reasonably identify you.
- Service — the AISongGen website, mobile applications, and APIs.
- User Content — the prompts, lyrics, audio references, and generated outputs associated with your Account.
2.Third-Party AI Services and Data Sharing
Which providers we use and what reaches them
2.1 Data Shared and Providers
AISongGen relies on a small number of upstream model providers to handle parts of generation. Your prompts and lyric drafts may be sent to these providers in order to produce a result. We do not share your account email, billing details, or library metadata with them.
2.2 How Third Parties Use Your Data
Each provider operates under its own terms. We select providers that contractually agree not to retain your content beyond the time required to fulfil a request, and not to use it to train their general-purpose models.
2.3 Data Protection and Anonymisation
Where feasible we strip account identifiers from upstream requests so that the third-party provider sees only the content it needs. We monitor provider compliance and rotate providers if their data practices change in ways we are not comfortable with.
3.Use of Your Personal Data
What we collect, why we collect it, and what happens to it
3.1 Types of Data Collected
We collect: account email, hashed authentication tokens, payment metadata (handled by Stripe — we never see your card number), generation prompts, output metadata, and aggregate usage statistics such as request count and generation latency.
3.2 Retention of Your Personal Data
Account data is retained for as long as your account is active and for up to 90 days after deletion to satisfy legal and accounting obligations. Generation prompts and outputs are retained only as long as they are part of your library.
3.3 Transfer of Your Personal Data
Your data is processed on Cloudflare's edge network, which spans multiple regions. Cross-border transfers happen under standard contractual clauses approved by relevant data protection authorities.
3.4 Disclosure of Your Personal Data
We disclose your data only where required by law, where necessary to defend our rights, or where you have given explicit consent. We will notify you of any government data request unless legally prohibited from doing so.
3.5 Security of Your Personal Data
Data in transit is protected by TLS 1.3. Data at rest is encrypted on our managed databases. Access to production systems is gated by hardware-key-based authentication and is logged.
4.Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be announced via email and a banner on the Service at least 14 days before they take effect.
5.Your Choices
You can:
- download an export of all data tied to your account;
- delete generations or your entire account from settings;
- opt out of optional analytics from the same settings page;
- contact us to exercise any right granted by your local data protection law.
6.Contact Us
Privacy questions go to privacy@aisonggen.net. We aim to respond within five working days.
7.Analytics and sub-processors
To understand product usage and improve the Service, we route aggregate, opt-in-able analytics through the following providers. You can decline analytics at any time via the cookie banner — when you decline, no analytics events are sent.
- PostHog Inc. (United States) — product analytics, autocapture of element clicks and pageviews. Session replay is disabled. See PostHog's privacy notice. Data is stored in PostHog's US region and transferred under Standard Contractual Clauses.
- Cloudflare, Inc. (United States / global edge) — Cloudflare Web Analytics for traffic volume and Web Vitals telemetry; no cookies are set. See Cloudflare's privacy notice.
- Google LLC (United States) — Google Tag Manager and Google Analytics 4 for conversion measurement, gated by Google Consent Mode v2 (no data is sent unless you grant analytics consent). See Google's privacy notice.