Last updated: October 7, 2026 (rev. 16)
1. Controller & Contact
Leon Ulicnik
songbrain ai / Smoke-Oh Studios
Liebrütistrasse 44, 4303 Kaiseraugst, Switzerland
Email: info [at] songbrain [dot] ai (also for all data-protection requests)
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP / revDSG) and — where it applies to users in the EU/EEA — the GDPR. References to GDPR articles in this policy state the legal basis for EU/EEA users; the same principles are applied under the FADP. This notice also serves as the information required by Art. 19 FADP: for every recipient outside Switzerland we name the country and the safeguard used (section 5).
2. Overview of Data Processing
We process personal data only to the extent necessary to provide and improve our service. We do not sell your data to third parties. Below is a summary of what we collect, why, and how long we keep it.
a) Account & Authentication
When you create an account, we store your email address and authentication credentials via Supabase Auth. This data is required to identify you, manage your account, and secure access to your analyses.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
b) Uploaded Audio Files
When you submit a song for analysis, your audio file is temporarily stored on our servers for processing. The file passes through our analysis pipeline (tempo, key, genre, lyrics, instruments, virality, etc.) and the resulting analysis data is stored as a JSON report linked to your account. As part of the pipeline, copies of the audio leave our servers only to the sub-processors listed in section 5 and only for these steps: a compressed copy to Google (Gemini) for audio understanding, a downsampled mono copy to Groq for lyrics transcription, a short excerpt (up to 1 MB) to ACRCloud for release recognition, and — only when a song is hard to transcribe — a mono copy to Replicate for vocal separation. No name, e-mail or account identifier travels with the audio. The original upload is deleted within 24 hours (section 6).
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
c) Analysis Results
The results of each analysis (tempo, key, loudness, genre classification, lyrics transcription, instrument detection, virality prediction, etc.) are stored and linked to your account so you can access them at any time.
Lyrics.The transcribed lyrics of your song are stored with the analysis and used to find the strongest moments, to evaluate the writing, to interpret the song's story for reel visuals and to render lyric captions in reels. If audio recognition identifies the upload as a released track by an established artist and you have not confirmed that you are its rights holder, the transcript is not stored — only language and word counts are kept. You can delete the stored lyrics of all your analyses at once in Settings → Privacy (or ask us to delete them for a single song); deleting the analysis or your account removes them as well.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
d) Credits & Payment Data
We track your credit balance (credits purchased and credits used) and your subscription tier. Purchases are sold and processed by Polar Software Inc. as Merchant of Record. At checkout, Polar collects your email address, billing country and — where required for tax purposes — your billing address and VAT ID, and uses them to calculate the applicable tax and issue your invoice. We do not store credit card numbers or full payment details on our servers — only the transaction reference, the product purchased, the credit amount or subscription status, and a timestamp received via webhook.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
e) API Access Requests
If you request API access, we collect your email address and optionally your company name and intended use case. This data is used solely to evaluate your request and contact you about API access.
Legal basis: Art. 6(1)(a) GDPR — your consent.
f) Server Logs
Our hosting providers (Vercel for the website and the web app, Cloudflare at the network edge of our API, Hetzner Online GmbH in Germany for the application backend — see section 5) may collect technical data such as IP addresses, browser type, and access timestamps. This data is used for security and debugging purposes only.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in security and stability.
g) Anonymous Usage Statistics (Vercel Web Analytics)
We use Vercel Web Analytics to understand how visitors interact with our landing page (page views, referrer domain, country, device type, browser). This service is cookieless: no cookies are set, nothing is written to or read from your device, no cross-site tracking takes place, and no individual user profiles are created. By Vercel, IP addresses are processed only briefly server-side (hashed for bot detection) and are never stored. We also count clicks on some buttons (for example "Upload") as anonymous custom events in the same tool.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in measuring reach and improving our service. No consent banner is required because no information is stored on or read from your device — under the Swiss FADP (revDSG) and general EU consent principles, consent is only needed where data is stored on or read from your device or where processing cannot rest on another legal basis; neither is the case here.
Demo upload IP logging. One exception applies on our anonymous song comparison at /try: because there is no account behind the request, we briefly record the requesting IP address on the demo record for the duration of the 24-hour auto-delete window so we can identify and rate-limit abuse (mass uploads, automated cost-amplification) and make sure only the uploading visitor can finish the comparison. The IP is hard-deleted together with the rest of the demo after 24 hours and never returned to user-facing surfaces.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in protecting the Service from abuse.
First-party product analytics. In addition, we record product usage events on our own servers to understand and improve how Songbrain is used — for example which features are opened, which page referred you to us (referrer / UTM parameters and, if present in the link you clicked, an ad click ID such as gclid — we do not send anything back to ad networks), your country (derived once from the request at our network edge; the IP address itself is never stored for analytics), and, for logged-in accounts, which analyses and downloads belong to your account. Within a single browser session a random session identifier is kept in sessionStorage (deleted automatically when the session ends — it is not a cookie, does not persist and cannot recognize you across visits). When you sign up, we keep the first page and campaign parameters that brought you to us ("first-touch source") with your account so we know which channels work. No data is shared with third parties and no advertising profiles are created. Usage events are deleted after 13 months (section 6).
Duplicate-account check. The same session identifier is used for one more purpose: if a new account is created in a browser tab in which a different account was used shortly before, we link the two accounts internally, count the person once in our statistics and do not grant the free signup credits a second time. We use no cookie, no device fingerprint and no other identifier for this — a new browser session is not recognised.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in understanding and improving our product and in preventing abuse of the free credits. You can object at any time via info [at] songbrain [dot] ai (Art. 21 GDPR); usage events tied to your account are deleted together with the account (Section 8).
h) Email Communications
We send you transactional emails that are necessary to operate your account: signup confirmation, password reset, magic-link login, email-change confirmation, and account invitations. These are delivered via our email-infrastructure provider Resend (see section 5).
We also send a small number of onboarding e-mails to new accounts about the analyses and reels you already created (for example a recap of your first result, or a reminder that your finished videos are waiting); some of them also point to Premium or a credit pack. You also get a message when a video you ordered (for example an AI video) is ready, and — if you ask for it at upload — one reminder to add your release link once the song is out. If you opt in via Settings, we send notifications when an analysis is finished, leaderboard updates or product news. (Settings also lists playlist-placement notifications; the playlist programme is paused, so none are sent at the moment.) Every such e-mail carries a one-click unsubscribe link and a standard List-Unsubscribe header; you can also switch the "marketing" preference off in Settings. We do not use open-tracking pixels. Links in our e-mails carry a campaign parameter, so we only learn thatsome recipient clicked a link when the page it leads to is opened.
Legal basis: Art. 6(1)(b) GDPR for transactional emails — performance of a contract. Art. 6(1)(f) GDPR / Art. 3(1)(o) Swiss UCA for onboarding e-mails to existing customers about the service they use, with opt-out at any time. Art. 6(1)(a) GDPR for optional notifications and product updates — your consent.
i) Performance Tab — Tracking Your Posted Videos
In the "Performance" tab you can paste the public URL of a TikTok, Instagram or YouTube video you posted with your song, or save your public channel handles so we can find such posts for you. We then read the public data of those posts at intervals for a limited period: view, like, comment and share counts, the posting date, the caption, hashtags and the audio label the platform shows. For TikTok and Instagram this is done through Apify (section 5), for YouTube through the YouTube Data API. We store the counts as a time series next to your analysis so you can see which moment of your song performed, and we use the pairing "song moment → posted video → outcome" to calibrate our scoring.
To explain why a post did well or not, we let an AI model (Anthropic Claude, section 5) look at the post's public cover image and a few still frames, its caption and hashtags and the text of a small number of its public comments (at most a few, each shortened to 280 characters), together with your song's analysis. Commenter and creator usernames are not stored in clear text: they are dropped or replaced by salted hashes (pseudonymised) before storage, and bios, avatars and profile links of other creators are discarded. If a post we found for you is not yours or you no longer want it tracked, remove the link in the app.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (the tracking you requested); Art. 6(1)(f) GDPR for the pseudonymised use in scoring calibration. Third parties whose public data appears in these records may object via info [at] songbrain [dot] ai.
j) ML Training Consent (Optional)
You can optionally allow us to use the anonymized results of your analyses (audio features, derived classifications, lyrics transcripts) to train and improve our internal AI models. This is strictly opt-in via your account Settings, can be withdrawn at any time, and applies retroactively when withdrawn (we stop using your past data for future training runs). The original audio file itself is never used for training and is deleted after analysis as described in section 6.
Legal basis: Art. 6(1)(a) GDPR — your consent. Withdrawable at any time under Art. 7(3) GDPR without affecting the lawfulness of prior processing.
k) Public Music-Industry Data for Model Calibration
To calibrate and improve our Virality Score model we continuously collect publicly available metadata about released music from third-party platforms. Specifically:
Spotify Web API (public catalog). Using application-level credentials (no user OAuth), we read public track metadata (title, artist name, ISRC, release date, album art URL), the daily popularity value (0–100) Spotify exposes for each track, and the Spotify-listed genre tags for each artist. We re-poll the same track periodically over time to build a popularity-over-time series — exactly the kind of public chart-tracking that services such as Chartmasters, Chartmetric or Soundcharts also perform on the same API endpoints. No personal data of the artists beyond what is already on their public Spotify catalog page is processed.
Public chart datasets. We additionally ingest publicly available historical chart datasets (e.g. weekly Spotify chart positions aggregated by independent researchers and published on Kaggle under permissive licences). These datasets do not contain personal data — they list tracks, artists and positions, all already in the public domain on Spotify Charts.
This data is used only for internal model calibration and as a comparison baseline for analyses you submit. It is not used for personalized advertising, profiling of individual artists, or any decision that produces legal or similarly significant effects under Art. 22 GDPR. It is never resold or republished in raw form.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in calibrating our analytics model against the public music-industry landscape, weighed against the practically nil impact on individual artists whose publicly released catalog metadata is processed at the same level of detail as on any public chart site.
l) In-app Support Messages and E-mails You Send Us
The Service includes an in-app inbox where you can send messages to our team (bug reports, feedback, questions) and where our team can reply to you. For each thread we store the subject, the message bodies, timestamps, sender role (you or admin), and per-side unread counters. Members of our team with administrator access can read every thread in order to provide support and to investigate misuse of the messaging channel. We do not use the content of these messages for any other purpose, do not sell or share it with third parties, and do not feed it into our analysis or training pipelines.
Where you contact support, where we need to investigate a technical issue with one of your analyses, or for periodic quality-assurance sampling, members of our team with administrator access may also open your individual analysis results read-only (audio features, scores, moments, lyrics evaluation, recommendations). Such cross-user accesses are recorded in our GDPR audit log (see section 6) with the timestamp, the admin's identifier, and the analysis that was viewed. Administrators cannot modify your data via this path and never download or share your audio outside what the Service requires to operate.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (handling your support request). Where the messages or analyses are accessed to investigate abuse of the Service or for quality assurance, Art. 6(1)(f) GDPR — our legitimate interest in keeping the Service safe and reliable.
E-mails you send us. If you write to one of our addresses (for example hello, info or support [at] songbrain [dot] ai), your e-mail is stored in our mailbox at IONOS (section 5). Because that mailbox also receives a lot of automated mail and advertising, an automated assistant sorts new e-mails so that real requests are not missed. It first looks only at sender and subject and sets aside invoices, system notifications and mail from no-reply addresses without reading their text. For the remaining e-mails it sends the sender, recipient, date, subject and text to Anthropic (section 5) — without attachments, without the earlier messages quoted below a reply, and shortened to about 6,000 characters. Anthropic's model only assigns a category (for example reply to our message, customer question, business inquiry, advertising, automatic reply) and writes a one- or two-sentence summary. It does not answer you and does not decide anything about you; every reply comes from a person. For e-mails that need a reply, our founder receives a short internal notification in our team chat (Slack, section 5) with sender, subject and that summary. Links in e-mails are never opened automatically and attachments are not processed. We keep a record of sender, subject, date, category and summary (not the e-mail text) for 12 months.
Legal basis: Art. 6(1)(b) GDPR where you write to us as a customer or about a contract; otherwise Art. 6(1)(f) GDPR — our legitimate interest in answering relevant e-mails promptly and filtering unsolicited advertising. You can object at any time (Art. 21 GDPR): say so in your e-mail and we will handle your messages without this automated sorting.
m) TikTok Integration (Login Kit & Content Posting API)
Not available to users yet: posting to TikTok from Songbrain is still in TikTok's app review. Until it is switched on, you download your videos and post them yourself, and no data is exchanged with TikTok for this feature. The following describes how it will work once it is enabled.
If you connect your TikTok account, TikTok sends us — with your authorisation on TikTok's consent screen — your TikTok open ID and union ID, display name, username, avatar URL and profile link, plus an access token and a refresh token that let us act for you. We store these on our own servers, use the profile fields only to show you which account you are posting to and to build the public link to a posted video, and use the tokens only to query the posting options TikTok offers for your account and to publish videos you explicitly choose to post.
For each post we transmit to TikTok the rendered video file (which contains your song), the caption, the privacy level and interaction settings you chose, the commercial-content disclosure if you enabled it, and — for templates whose visuals are AI-generated — TikTok's "AI-generated content" flag. We store the publish ID TikTok returns, the processing status, and the public video ID once the post is live, so we can show you the result and track its performance (section 3(i)). We do not read your TikTok inbox, followers or other videos.
TikTok processes your data as an independent controller under its own privacy policy. You can revoke our access at any time in Settings ("Disconnect TikTok"), which also revokes the token at TikTok and deletes the stored profile data, or in TikTok under "Manage app permissions". Deleting your Songbrain account does the same. Videos already posted remain on TikTok until you delete them there.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (the posting you requested). Retention: until you disconnect or delete your account; records of posts that never completed are deleted after 30 days.
n) Public Leaderboard & Viral Radar (opt-in)
Your songs are private by default. Only if you switch on "show on leaderboard" for a song (this requires the song's public Spotify link) do we publish it on the public leaderboard and on the per-genre Viral Radar pages of songbrain.ai: song title, the artist name you entered, cover, genre, Virality Score, its strongest moments, song length, analysis date and the Spotify link. Your e-mail address and account details are never shown. You can switch the setting off per song at any time; the song then disappears from the app leaderboard immediately and from the Viral Radar pages with their next update. Deleting the analysis or your account has the same effect.
Legal basis: Art. 6(1)(a) GDPR — your consent (the opt-in per song), withdrawable at any time.
The public leaderboard at app.songbrain.ai/leaderboard ranks songs that users have analyzed with Songbrain and opted in to publish. Alongside those entries it shows a set of publicly released reference tracks per genre. Reference tracks carry no rank and no Virality Score; they are displayed in a visually reduced style purely as genre context, so that a board with few analyzed songs still gives a sense of the field.
What this means in practice:
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in giving analyzed songs meaningful genre context. No personal data of the artists shown is processed beyond what is publicly available via Spotify's public catalog API.
When a developer uses the Songbrain API or its MCP endpoint, we process:
The audio goes through the same analysis steps and processors as an upload in the app (section 5: Hetzner, Cloudflare, Google Gemini, Groq, Anthropic). Results go back only to the key holder: as an API response, or as a signed notice to the webhook URL they provided. API audio is not used to train models and is never published. It does not appear on the leaderboard, in playlists or in Viral Radar.
Retention. The uploaded file is deleted within 24 hours. A compressed preview is kept for 30 days. The analysis result is kept until the developer deletes it (DELETE /v1/songs/{id}, which removes the audio and the analysis immediately) or deletes their account. Key and usage records are kept for as long as the account exists, and billing records as long as the law requires.
Roles.For the developer's own account data, Songbrain is the controller. If the developer submits audio or metadata of their own users, the developer is the controller for it and Songbrain processes it on their behalf, only to deliver the result, under the data processing agreement at songbrain.ai/dpa, which applies to every API account automatically. The current list of sub-processors is at songbrain.ai/security. People whose audio was submitted through a third-party product should contact that product first. We will help it answer access and deletion requests.
Legal basis: Art. 6(1)(b) GDPR (performing the API contract with the developer); for data submitted on behalf of third parties, Art. 28 GDPR (processing on behalf of the developer).
We use the following third-party services to operate Songbrain. Most act as data processors on our behalf and only process what is necessary for the listed purpose; where a provider acts as an independent controller (Polar for payments, TikTok, Google for "Sign in with Google", and the YouTube player once you load it), its entry says so or the provider's own privacy policy applies:
International Data Transfers
Where data is transferred outside Switzerland and the EU/EEA (in particular to the United States and Singapore), it is protected either by the EU-U.S. and Swiss-U.S. Data Privacy Framework (DPF) where the recipient is certified, by the EU Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 as recognised by the Swiss FDPIC with the Swiss annex, or by equivalent safeguards under Art. 46 GDPR / Art. 16 FADP. The safeguard used for each provider is named in its entry above. We assess each provider individually and supplement transfer mechanisms with technical and organizational measures (encryption in transit, access controls, data minimization) where appropriate.
Under the General Data Protection Regulation, you have the following rights:
To exercise any of these rights, contact us at info [at] songbrain [dot] ai. We will respond within 30 days.
8. How to Request Data Deletion
You can delete your account and all associated data yourself at any time in Settings → Danger Zone → "Delete account". This immediately removes your analyses, audio files, rendered videos, albums, usage events, support threads, linked posts and their performance data, and your TikTok connection (including revoking our access at TikTok), and then deletes your login. Alternatively, send an email to info [at] songbrain [dot] ai with the subject line "Data Deletion Request" and we will do it for you within 30 days. The only data that survives is what the law requires us to keep (payment records under Art. 958f of the Swiss Code of Obligations, held by Polar) and a salted hash of your e-mail address that prevents the signup bonus from being claimed repeatedly with the same address.
Granular deletion. You do not have to delete your whole account to remove data: deleting a single analysis in Settings → Privacy removes the analysis result, its audio preview, its rendered videos — and, if you had opted in to ML training, the corresponding entry in our ML training archive. Removing a song from your dashboard deletes its audio and videos within 24 hours (section 6). You can also delete the stored lyrics of all your analyses at once. In addition, the "Delete my audio files now" control in your account Settings immediately and permanently deletes all audio files we hold for you, including playback previews and rendered videos/reels, without waiting for the retention windows in section 6.
9. Cookies
This website does not use tracking cookies, advertising cookies, or analytics cookies. Only technically necessary cookies may be set by our hosting providers (Vercel, Supabase) to ensure functionality and security (e.g., session tokens for authentication). In the app we additionally use your browser's local storage for functional settings only: your language and interface preferences, a per-tab session identifier for the first-party usage events in section 3(g), your YouTube-embed consent on the landing page, and pending state while you return from a login or TikTok authorisation. None of this is read by third parties or used to recognise you across sites. These items are strictly necessary or functional and do not require a consent banner under the Swiss FADP or Art. 5(3) of the ePrivacy Directive.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. This includes encrypted data transmission (TLS/SSL), secure authentication via Supabase, and restricted access to our servers.
Songbrain's analysis pipeline uses AI/machine-learning systems to produce the results you see (genre classification, virality score, best-moment detection, lyrics evaluation, instrument recognition). These outputs are generated by automated systems — not by human review — and are intended as guidance, not as definitive musical judgement.
What this means for you:
11. Right to Lodge a Complaint
If you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a supervisory authority. The competent authority at our registered office is:
Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Feldeggweg 1, 3003 Bern, Switzerland
Website: edoeb.admin.ch
If you are located in the EU/EEA, you may also lodge a complaint with the supervisory authority of your habitual residence under the GDPR.
12. Changes to This Privacy Policy
We may update this privacy policy from time to time. The current version is always available on this page with the date of the last update shown at the top.
Rev. 15 (October 6, 2026): automated sorting of e-mails you send us described (section 3(l)), incl. the summary step at Anthropic and a 12-month retention for the sorting record; Slack added as processor for internal team notifications.
Rev. 13 (October 5, 2026): Performance tab and AI-video processing described in more detail (incl. comment excerpts sent to Anthropic), new section on the opt-in leaderboard and Viral Radar, duplicate-account check, TikTok posting marked as not yet available, curated playlists marked as paused and trend scraping as research-only (not part of your score), hosting entries (Vercel, Cloudflare, IONOS) corrected, retention for YouTube HD videos and failed or removed uploads added.