Last updated: August 5, 2026 (rev. 10)
1. Controller & Contact
Leon Ulicnik
songbrain ai / Smoke-Oh Studios
Liebrütistrasse 44, 4303 Kaiseraugst, Switzerland
Email: info [at] songbrain [dot] ai
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP / revDSG) and — where it applies to users in the EU/EEA — the GDPR. References to GDPR articles in this policy state the legal basis for EU/EEA users; the same principles are applied under the FADP.
2. Overview of Data Processing
We process personal data only to the extent necessary to provide and improve our service. We do not sell your data to third parties. Below is a summary of what we collect, why, and how long we keep it.
a) Account & Authentication
When you create an account, we store your email address and authentication credentials via Supabase Auth. This data is required to identify you, manage your account, and secure access to your analyses.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
b) Uploaded Audio Files
When you submit a song for analysis, your audio file is temporarily stored on our servers for processing. The file passes through our analysis pipeline (tempo, key, genre, lyrics, instruments, virality, etc.) and the resulting analysis data is stored as a JSON report linked to your account.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
c) Analysis Results
The results of each analysis (tempo, key, loudness, genre classification, lyrics transcription, instrument detection, virality prediction, etc.) are stored and linked to your account so you can access them at any time.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
d) Credits & Payment Data
We track your credit balance (credits purchased and credits used). Payment transactions are processed by Polar. We do not store credit card numbers or full payment details on our servers — only the transaction reference, purchased credit amount, and timestamp received via webhook.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
e) API Access Requests
If you request API access, we collect your email address and optionally your company name and intended use case. This data is used solely to evaluate your request and contact you about API access.
Legal basis: Art. 6(1)(a) GDPR — your consent.
f) Server Logs
Our hosting providers (Vercel for the landing page, Hetzner Online GmbH in Germany for the application backend — see section 5) may collect technical data such as IP addresses, browser type, and access timestamps. This data is used for security and debugging purposes only.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in security and stability.
g) Anonymous Usage Statistics (Vercel Web Analytics)
We use Vercel Web Analytics to understand how visitors interact with our landing page (page views, referrer domain, country, device type, browser). This service is cookieless: no cookies are set, nothing is written to or read from your device, no cross-site tracking takes place, and no individual user profiles are created. By Vercel, IP addresses are processed only briefly server-side (hashed for bot detection) and are never stored.
Demo upload IP logging. One exception applies on our anonymous demo flow at /try: because there is no account behind the request, we briefly record the requesting IP address on the demo job record for the duration of the 1-hour auto-delete window so we can identify and rate-limit abuse (mass uploads, automated cost-amplification). The IP is hard-deleted together with the rest of the job after 1 hour and never returned to user-facing surfaces. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in protecting the Service from abuse.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in measuring reach and improving our service. No consent banner is required because no information is stored on or read from your device — under the Swiss FADP (revDSG) and general EU consent principles, consent is only needed where data is stored on or read from your device or where processing cannot rest on another legal basis; neither is the case here.
First-party product analytics. In addition, we record product usage events on our own servers to understand and improve how Songbrain is used — for example which features are opened, which page referred you to us (referrer / UTM parameters), your country (derived once from the request at our network edge; the IP address itself is never stored for analytics), and, for logged-in accounts, which analyses and downloads belong to your account. Within a single browser session a random session identifier is kept in sessionStorage (deleted automatically when the session ends — it is not a cookie, does not persist and cannot recognize you across visits). No data is shared with third parties and no advertising profiles are created.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in understanding and improving our product. You can object at any time via privacy@songbrain.ai (Art. 21 GDPR); usage events tied to your account are deleted together with the account (Section 8).
h) Email Communications
We send you transactional emails that are necessary to operate your account: signup confirmation, password reset, magic-link login, email-change confirmation, and account invitations. These are delivered via our email-infrastructure provider Resend (see section 5).
Optionally — and only if you explicitly opt in via your account Settings — we send notification emails when one of your songs is added to a curated Spotify playlist, weekly leaderboard updates, or product news. You can change these preferences at any time and unsubscribe with one click via the link in any such email.
Legal basis: Art. 6(1)(b) GDPR for transactional emails — performance of a contract. Art. 6(1)(a) GDPR for optional notifications and product updates — your consent.
j) ML Training Consent (Optional)
You can optionally allow us to use the anonymized results of your analyses (audio features, derived classifications, lyrics transcripts) to train and improve our internal AI models. This is strictly opt-in via your account Settings, can be withdrawn at any time, and applies retroactively when withdrawn (we stop using your past data for future training runs). The original audio file itself is never used for training and is deleted after analysis as described in section 6.
Legal basis: Art. 6(1)(a) GDPR — your consent. Withdrawable at any time under Art. 7(3) GDPR without affecting the lawfulness of prior processing.
k) Public Music-Industry Data for Model Calibration
To calibrate and improve our Virality Score model we continuously collect publicly available metadata about released music from third-party platforms. Specifically:
Spotify Web API (public catalog). Using application-level credentials (no user OAuth), we read public track metadata (title, artist name, ISRC, release date, album art URL), the daily popularity value (0–100) Spotify exposes for each track, and the Spotify-listed genre tags for each artist. We re-poll the same track periodically over time to build a popularity-over-time series — exactly the kind of public chart-tracking that services such as Chartmasters, Chartmetric or Soundcharts also perform on the same API endpoints. No personal data of the artists beyond what is already on their public Spotify catalog page is processed.
Public chart datasets. We additionally ingest publicly available historical chart datasets (e.g. weekly Spotify chart positions aggregated by independent researchers and published on Kaggle under permissive licences). These datasets do not contain personal data — they list tracks, artists and positions, all already in the public domain on Spotify Charts.
This data is used only for internal model calibration and as a comparison baseline for analyses you submit. It is not used for personalized advertising, profiling of individual artists, or any decision that produces legal or similarly significant effects under Art. 22 GDPR. It is never resold or republished in raw form.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in calibrating our analytics model against the public music-industry landscape, weighed against the practically nil impact on individual artists whose publicly released catalog metadata is processed at the same level of detail as on any public chart site.
l) In-app Support Messages
The Service includes an in-app inbox where you can send messages to our team (bug reports, feedback, questions) and where our team can reply to you. For each thread we store the subject, the message bodies, timestamps, sender role (you or admin), and per-side unread counters. Members of our team with administrator access can read every thread in order to provide support and to investigate misuse of the messaging channel. We do not use the content of these messages for any other purpose, do not sell or share it with third parties, and do not feed it into our analysis or training pipelines.
Where you contact support, where we need to investigate a technical issue with one of your analyses, or for periodic quality-assurance sampling, members of our team with administrator access may also open your individual analysis results read-only (audio features, scores, moments, lyrics evaluation, recommendations). Such cross-user accesses are recorded in our GDPR audit log (see section 6) with the timestamp, the admin's identifier, and the analysis that was viewed. Administrators cannot modify your data via this path and never download or share your audio outside what the Service requires to operate.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (handling your support request). Where the messages or analyses are accessed to investigate abuse of the Service or for quality assurance, Art. 6(1)(f) GDPR — our legitimate interest in keeping the Service safe and reliable.
During our pre-launch phase, the public leaderboard at app.songbrain.ai/leaderboard displays a curated selection of publicly available Spotify tracks together with placeholder Virality Scores and Best Moments. These scores are not the result of an actual Songbrain analysis — they exist solely so visitors can see how the leaderboard will look once the platform opens publicly.
What this means in practice:
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in demonstrating the product to potential users prior to launch. No personal data of the artists shown is processed beyond what is publicly available via Spotify's public catalog API.
We use the following third-party services to operate Songbrain. Each acts as a data processor on our behalf and only processes what is necessary for the listed purpose:
International Data Transfers
Where data is transferred outside the EU/EEA (in particular to the United States), it is protected either by the EU-US Data Privacy Framework (DPF) where the recipient is certified, by the EU Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, or by equivalent safeguards under Art. 46 GDPR. We assess each provider individually and supplement transfer mechanisms with technical and organizational measures (encryption in transit, access controls, data minimization) where appropriate.
Under the General Data Protection Regulation, you have the following rights:
To exercise any of these rights, contact us at info [at] songbrain [dot] ai. We will respond within 30 days.
8. How to Request Data Deletion
You can request complete deletion of your account and all associated data by sending an email to info [at] songbrain [dot] aiwith the subject line "Data Deletion Request". We will delete all your personal data, analysis results, and account information within 30 days, except where retention is required by law (e.g., payment records under Art. 958f of the Swiss Code of Obligations).
Granular deletion.You do not have to delete your whole account to remove data: deleting a single analysis from your dashboard removes the analysis result, its audio preview, its rendered videos — and, if you had opted in to ML training, the corresponding entry in our ML training archive. In addition, the "Delete my audio files now" control in your account Settings immediately and permanently deletes all audio files we hold for you, including playback previews and rendered videos/reels, without waiting for the retention windows in section 6.
9. Cookies
This website does not use tracking cookies, advertising cookies, or analytics cookies. Only technically necessary cookies may be set by our hosting providers (Vercel, Supabase) to ensure functionality and security (e.g., session tokens for authentication). These are strictly necessary and do not require consent under GDPR.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. This includes encrypted data transmission (TLS/SSL), secure authentication via Supabase, and restricted access to our servers.
Songbrain's analysis pipeline uses AI/machine-learning systems to produce the results you see (genre classification, virality score, best-moment detection, lyrics evaluation, instrument recognition). These outputs are generated by automated systems — not by human review — and are intended as guidance, not as definitive musical judgement.
What this means for you:
11. Right to Lodge a Complaint
If you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a supervisory authority. The competent authority at our registered office is:
Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Feldeggweg 1, 3003 Bern, Switzerland
Website: edoeb.admin.ch
If you are located in the EU/EEA, you may also lodge a complaint with the supervisory authority of your habitual residence under the GDPR.
12. Changes to This Privacy Policy
We may update this privacy policy from time to time. The current version is always available on this page with the date of the last update shown at the top.