Privacy Policy
Last updated: April 2026
1. Data Controller
The data controller for personal data processed through MySongAI is:
Email: support@mysongai.app
2. Data We Collect
When you use MySongAI, we collect the following personal data:
- Order data: the data you provide in the order form — recipient name, occasion, relationship, personal memories, and music preferences (genre, language, performance style, and other options). All fields except song language are optional. Required to generate your personalized song.
- Contact data: your email address, used for order delivery, confirmation, and customer support.
- Account data: name and email if you sign in with Google OAuth, or email and a hashed password if you register directly. Passwords are never stored in plaintext.
- Payment data: payment is processed entirely by Stripe. We receive only a confirmation — we never store or see your card details.
- Technical data: our cloud infrastructure providers automatically create request logs (IP address, browser type, timestamps) for security and diagnostics. Retention follows their respective policies (typically from a few hours to several days). We do not store these logs in our own databases.
3. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR): processing your order data and email to generate and deliver your song.
- Legitimate interests (Art. 6(1)(f) GDPR): request logs created by our infrastructure providers for security and diagnostic purposes.
- Legal obligation (Art. 6(1)(c) GDPR): order data linked to payments retained for the period required by applicable tax law. Customer invoices are issued and retained by Stripe as merchant of record.
4. Third-Party Processors
To operate the service we use a limited set of trusted third-party processors. Data is shared only to the extent necessary to fulfil your order:
- Payment processor — handles payment transactions as an independent data controller. Your card details go directly to the payment provider; we never see or store them.
- AI generation providers — your order details (recipient name, occasion, notes) are passed to AI services to generate the lyrics and audio for your song.
- Email delivery provider — your email address is shared solely to send order confirmations and song delivery notifications.
- Cloud infrastructure providers — we use cloud hosting and storage services to run the platform and store generated audio files.
- Google OAuth — optional authentication (independent controller; only used if you choose to sign in with Google).
Some processors are based in the United States. Transfers to the US are made under appropriate safeguards, including EU Standard Contractual Clauses or the EU–US Data Privacy Framework where applicable.
5. Data Retention
- Order data and generated songs: retained for the duration of the service or until a deletion request is received.
- Account data (Google OAuth or email/password): retained while your account is active.
- Order data linked to payments: retained for the period required by applicable tax law.
- Request logs: created and retained by our infrastructure providers according to their policies (typically from a few hours to several days). We do not store them in our own databases.
You can request deletion of your personal data at any time (see Section 7).
6. Cookies & Tracking
We use essential cookies for authentication (session tokens) and store your language preference in localStorage. We use Google Analytics 4 to analyze website traffic. Google Analytics may use cookies. More information: Google Privacy Policy (policies.google.com/privacy).
7. Your Rights (GDPR)
If you are in the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right of access — request a copy of the data we hold about you
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your personal data ("right to be forgotten")
You can delete your orders directly from your account (delete button in the dashboard). Once deleted, the player link stops working and the generated audio files are permanently removed and cannot be recovered. The only remaining copy is the MP3 file sent to your email address.
- Right to restriction — request that we limit processing of your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, email us at support@mysongai.app. We will respond within 30 days.
You also have the right to lodge a complaint with the data protection authority in your country.
8. Children's Privacy
MySongAI is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact us immediately and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date above. We encourage you to review this page periodically.
10. Contact
For privacy questions or to exercise your rights, contact us at: support@mysongai.app