Privacy Policy
Last updated: April 23, 2026
1. Information We Collect
We collect information you provide directly: your email address, display name, username, and the content you create (song prompts, lyrics, evaluations). We also collect usage data including session activity, feature usage, and performance metrics.
2. How We Use Your Information
Your information is used to: provide and improve the Service; store your songs, evaluations, and upgrades; personalize your experience; communicate with you about your account; and analyze usage patterns to improve service quality and features.
3. AI Processing
Your prompts, lyrics, and evaluations are sent to third-party AI providers (currently Anthropic) for processing. These providers have their own privacy policies and their own no-training commitments for API traffic.
We do not train any evaluation or generation models on your creative content. Not our models, not third-party models. If we ever offer an opt-in research or training program, it will be a separate, clearly labeled, revocable consent flow — never a default, never implied. Your silence is never consent.
Your songs, evaluations, and refined drafts are stored privately in your account and are not shared with other users unless you explicitly make a song public (via the dashboard visibility toggle or share link).
4. Data Storage
Your data is stored securely using Supabase (hosted on AWS). Authentication is handled through Supabase Auth with support for Google OAuth and magic link email authentication.
5. Payment Processing
Payments are processed by Stripe, Inc. When you subscribe or purchase credit packs, your payment information (card number, billing address) is collected and processed directly by Stripe — we do not store your full card details on our servers. Stripe may collect additional information as described in their Privacy Policy. We receive only a partial card identifier (last 4 digits), transaction status, and Stripe customer ID to manage your subscription.
6. Data Sharing
We do not sell your personal data. We share data only with: service providers necessary to operate the Service (Supabase, Vercel, Anthropic, Google (authentication via OAuth), Stripe (payment processing)); and as required by law.
7. Your Rights and Data Retention
You may access, correct, or delete your personal data at any time through your account settings. You may request a full export of your data or complete account deletion by contacting us.
Song deletion. Deleting a song removes it from your account immediately. Associated evaluations and refinement history are deleted alongside it. Aggregate craft-telemetry rows (composite score, prosody warning count, emotional-arc classification, etc.) remain in our internal metrics pipeline to support the public craft-metrics report, but they carry no reference to your identity, song title, or lyric content — only genre-level and build-level slices, and only when a slice exceeds a 30-row minimum threshold.
Account deletion. On full account deletion we purge: your profile, all songs and evaluations linked to your account, your API keys, your session state, and any personalization data. We retain billing records (Stripe transaction metadata) as required by tax and audit law, and anonymized aggregate telemetry as described above.
8. Cookies
We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies.
9. Security
We implement industry-standard security measures including encrypted connections (HTTPS), secure authentication tokens, and row-level database security. However, no system is 100% secure.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the Service.
11. Contact
For privacy-related questions, contact us at privacy@songforgeai.com.