← Back to home

Privacy Policy

Last updated: October 7, 2026 (rev. 16)

1. Controller & Contact
Leon Ulicnik
songbrain ai / Smoke-Oh Studios
Liebrütistrasse 44, 4303 Kaiseraugst, Switzerland
Email: info [at] songbrain [dot] ai (also for all data-protection requests)

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP / revDSG) and — where it applies to users in the EU/EEA — the GDPR. References to GDPR articles in this policy state the legal basis for EU/EEA users; the same principles are applied under the FADP. This notice also serves as the information required by Art. 19 FADP: for every recipient outside Switzerland we name the country and the safeguard used (section 5).

2. Overview of Data Processing
We process personal data only to the extent necessary to provide and improve our service. We do not sell your data to third parties. Below is a summary of what we collect, why, and how long we keep it.

3. Data We Collect

a) Account & Authentication
When you create an account, we store your email address and authentication credentials via Supabase Auth. This data is required to identify you, manage your account, and secure access to your analyses.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

b) Uploaded Audio Files
When you submit a song for analysis, your audio file is temporarily stored on our servers for processing. The file passes through our analysis pipeline (tempo, key, genre, lyrics, instruments, virality, etc.) and the resulting analysis data is stored as a JSON report linked to your account. As part of the pipeline, copies of the audio leave our servers only to the sub-processors listed in section 5 and only for these steps: a compressed copy to Google (Gemini) for audio understanding, a downsampled mono copy to Groq for lyrics transcription, a short excerpt (up to 1 MB) to ACRCloud for release recognition, and — only when a song is hard to transcribe — a mono copy to Replicate for vocal separation. No name, e-mail or account identifier travels with the audio. The original upload is deleted within 24 hours (section 6).
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

c) Analysis Results
The results of each analysis (tempo, key, loudness, genre classification, lyrics transcription, instrument detection, virality prediction, etc.) are stored and linked to your account so you can access them at any time.

Lyrics.The transcribed lyrics of your song are stored with the analysis and used to find the strongest moments, to evaluate the writing, to interpret the song's story for reel visuals and to render lyric captions in reels. If audio recognition identifies the upload as a released track by an established artist and you have not confirmed that you are its rights holder, the transcript is not stored — only language and word counts are kept. You can delete the stored lyrics of all your analyses at once in Settings → Privacy (or ask us to delete them for a single song); deleting the analysis or your account removes them as well.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

d) Credits & Payment Data
We track your credit balance (credits purchased and credits used) and your subscription tier. Purchases are sold and processed by Polar Software Inc. as Merchant of Record. At checkout, Polar collects your email address, billing country and — where required for tax purposes — your billing address and VAT ID, and uses them to calculate the applicable tax and issue your invoice. We do not store credit card numbers or full payment details on our servers — only the transaction reference, the product purchased, the credit amount or subscription status, and a timestamp received via webhook.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

e) API Access Requests
If you request API access, we collect your email address and optionally your company name and intended use case. This data is used solely to evaluate your request and contact you about API access.
Legal basis: Art. 6(1)(a) GDPR — your consent.

f) Server Logs
Our hosting providers (Vercel for the website and the web app, Cloudflare at the network edge of our API, Hetzner Online GmbH in Germany for the application backend — see section 5) may collect technical data such as IP addresses, browser type, and access timestamps. This data is used for security and debugging purposes only.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in security and stability.

g) Anonymous Usage Statistics (Vercel Web Analytics)
We use Vercel Web Analytics to understand how visitors interact with our landing page (page views, referrer domain, country, device type, browser). This service is cookieless: no cookies are set, nothing is written to or read from your device, no cross-site tracking takes place, and no individual user profiles are created. By Vercel, IP addresses are processed only briefly server-side (hashed for bot detection) and are never stored. We also count clicks on some buttons (for example "Upload") as anonymous custom events in the same tool.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in measuring reach and improving our service. No consent banner is required because no information is stored on or read from your device — under the Swiss FADP (revDSG) and general EU consent principles, consent is only needed where data is stored on or read from your device or where processing cannot rest on another legal basis; neither is the case here.

Demo upload IP logging. One exception applies on our anonymous song comparison at /try: because there is no account behind the request, we briefly record the requesting IP address on the demo record for the duration of the 24-hour auto-delete window so we can identify and rate-limit abuse (mass uploads, automated cost-amplification) and make sure only the uploading visitor can finish the comparison. The IP is hard-deleted together with the rest of the demo after 24 hours and never returned to user-facing surfaces.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in protecting the Service from abuse.

First-party product analytics. In addition, we record product usage events on our own servers to understand and improve how Songbrain is used — for example which features are opened, which page referred you to us (referrer / UTM parameters and, if present in the link you clicked, an ad click ID such as gclid — we do not send anything back to ad networks), your country (derived once from the request at our network edge; the IP address itself is never stored for analytics), and, for logged-in accounts, which analyses and downloads belong to your account. Within a single browser session a random session identifier is kept in sessionStorage (deleted automatically when the session ends — it is not a cookie, does not persist and cannot recognize you across visits). When you sign up, we keep the first page and campaign parameters that brought you to us ("first-touch source") with your account so we know which channels work. No data is shared with third parties and no advertising profiles are created. Usage events are deleted after 13 months (section 6).

Duplicate-account check. The same session identifier is used for one more purpose: if a new account is created in a browser tab in which a different account was used shortly before, we link the two accounts internally, count the person once in our statistics and do not grant the free signup credits a second time. We use no cookie, no device fingerprint and no other identifier for this — a new browser session is not recognised.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in understanding and improving our product and in preventing abuse of the free credits. You can object at any time via info [at] songbrain [dot] ai (Art. 21 GDPR); usage events tied to your account are deleted together with the account (Section 8).

h) Email Communications
We send you transactional emails that are necessary to operate your account: signup confirmation, password reset, magic-link login, email-change confirmation, and account invitations. These are delivered via our email-infrastructure provider Resend (see section 5).
We also send a small number of onboarding e-mails to new accounts about the analyses and reels you already created (for example a recap of your first result, or a reminder that your finished videos are waiting); some of them also point to Premium or a credit pack. You also get a message when a video you ordered (for example an AI video) is ready, and — if you ask for it at upload — one reminder to add your release link once the song is out. If you opt in via Settings, we send notifications when an analysis is finished, leaderboard updates or product news. (Settings also lists playlist-placement notifications; the playlist programme is paused, so none are sent at the moment.) Every such e-mail carries a one-click unsubscribe link and a standard List-Unsubscribe header; you can also switch the "marketing" preference off in Settings. We do not use open-tracking pixels. Links in our e-mails carry a campaign parameter, so we only learn thatsome recipient clicked a link when the page it leads to is opened.
Legal basis: Art. 6(1)(b) GDPR for transactional emails — performance of a contract. Art. 6(1)(f) GDPR / Art. 3(1)(o) Swiss UCA for onboarding e-mails to existing customers about the service they use, with opt-out at any time. Art. 6(1)(a) GDPR for optional notifications and product updates — your consent.

i) Performance Tab — Tracking Your Posted Videos
In the "Performance" tab you can paste the public URL of a TikTok, Instagram or YouTube video you posted with your song, or save your public channel handles so we can find such posts for you. We then read the public data of those posts at intervals for a limited period: view, like, comment and share counts, the posting date, the caption, hashtags and the audio label the platform shows. For TikTok and Instagram this is done through Apify (section 5), for YouTube through the YouTube Data API. We store the counts as a time series next to your analysis so you can see which moment of your song performed, and we use the pairing "song moment → posted video → outcome" to calibrate our scoring.

To explain why a post did well or not, we let an AI model (Anthropic Claude, section 5) look at the post's public cover image and a few still frames, its caption and hashtags and the text of a small number of its public comments (at most a few, each shortened to 280 characters), together with your song's analysis. Commenter and creator usernames are not stored in clear text: they are dropped or replaced by salted hashes (pseudonymised) before storage, and bios, avatars and profile links of other creators are discarded. If a post we found for you is not yours or you no longer want it tracked, remove the link in the app.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (the tracking you requested); Art. 6(1)(f) GDPR for the pseudonymised use in scoring calibration. Third parties whose public data appears in these records may object via info [at] songbrain [dot] ai.

j) ML Training Consent (Optional)
You can optionally allow us to use the anonymized results of your analyses (audio features, derived classifications, lyrics transcripts) to train and improve our internal AI models. This is strictly opt-in via your account Settings, can be withdrawn at any time, and applies retroactively when withdrawn (we stop using your past data for future training runs). The original audio file itself is never used for training and is deleted after analysis as described in section 6.
Legal basis: Art. 6(1)(a) GDPR — your consent. Withdrawable at any time under Art. 7(3) GDPR without affecting the lawfulness of prior processing.

k) Public Music-Industry Data for Model Calibration
To calibrate and improve our Virality Score model we continuously collect publicly available metadata about released music from third-party platforms. Specifically:

Spotify Web API (public catalog). Using application-level credentials (no user OAuth), we read public track metadata (title, artist name, ISRC, release date, album art URL), the daily popularity value (0–100) Spotify exposes for each track, and the Spotify-listed genre tags for each artist. We re-poll the same track periodically over time to build a popularity-over-time series — exactly the kind of public chart-tracking that services such as Chartmasters, Chartmetric or Soundcharts also perform on the same API endpoints. No personal data of the artists beyond what is already on their public Spotify catalog page is processed.

Public chart datasets. We additionally ingest publicly available historical chart datasets (e.g. weekly Spotify chart positions aggregated by independent researchers and published on Kaggle under permissive licences). These datasets do not contain personal data — they list tracks, artists and positions, all already in the public domain on Spotify Charts.

This data is used only for internal model calibration and as a comparison baseline for analyses you submit. It is not used for personalized advertising, profiling of individual artists, or any decision that produces legal or similarly significant effects under Art. 22 GDPR. It is never resold or republished in raw form.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in calibrating our analytics model against the public music-industry landscape, weighed against the practically nil impact on individual artists whose publicly released catalog metadata is processed at the same level of detail as on any public chart site.

l) In-app Support Messages and E-mails You Send Us
The Service includes an in-app inbox where you can send messages to our team (bug reports, feedback, questions) and where our team can reply to you. For each thread we store the subject, the message bodies, timestamps, sender role (you or admin), and per-side unread counters. Members of our team with administrator access can read every thread in order to provide support and to investigate misuse of the messaging channel. We do not use the content of these messages for any other purpose, do not sell or share it with third parties, and do not feed it into our analysis or training pipelines.

Where you contact support, where we need to investigate a technical issue with one of your analyses, or for periodic quality-assurance sampling, members of our team with administrator access may also open your individual analysis results read-only (audio features, scores, moments, lyrics evaluation, recommendations). Such cross-user accesses are recorded in our GDPR audit log (see section 6) with the timestamp, the admin's identifier, and the analysis that was viewed. Administrators cannot modify your data via this path and never download or share your audio outside what the Service requires to operate.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (handling your support request). Where the messages or analyses are accessed to investigate abuse of the Service or for quality assurance, Art. 6(1)(f) GDPR — our legitimate interest in keeping the Service safe and reliable.

E-mails you send us. If you write to one of our addresses (for example hello, info or support [at] songbrain [dot] ai), your e-mail is stored in our mailbox at IONOS (section 5). Because that mailbox also receives a lot of automated mail and advertising, an automated assistant sorts new e-mails so that real requests are not missed. It first looks only at sender and subject and sets aside invoices, system notifications and mail from no-reply addresses without reading their text. For the remaining e-mails it sends the sender, recipient, date, subject and text to Anthropic (section 5) — without attachments, without the earlier messages quoted below a reply, and shortened to about 6,000 characters. Anthropic's model only assigns a category (for example reply to our message, customer question, business inquiry, advertising, automatic reply) and writes a one- or two-sentence summary. It does not answer you and does not decide anything about you; every reply comes from a person. For e-mails that need a reply, our founder receives a short internal notification in our team chat (Slack, section 5) with sender, subject and that summary. Links in e-mails are never opened automatically and attachments are not processed. We keep a record of sender, subject, date, category and summary (not the e-mail text) for 12 months.
Legal basis: Art. 6(1)(b) GDPR where you write to us as a customer or about a contract; otherwise Art. 6(1)(f) GDPR — our legitimate interest in answering relevant e-mails promptly and filtering unsolicited advertising. You can object at any time (Art. 21 GDPR): say so in your e-mail and we will handle your messages without this automated sorting.

m) TikTok Integration (Login Kit & Content Posting API)
Not available to users yet: posting to TikTok from Songbrain is still in TikTok's app review. Until it is switched on, you download your videos and post them yourself, and no data is exchanged with TikTok for this feature. The following describes how it will work once it is enabled.

If you connect your TikTok account, TikTok sends us — with your authorisation on TikTok's consent screen — your TikTok open ID and union ID, display name, username, avatar URL and profile link, plus an access token and a refresh token that let us act for you. We store these on our own servers, use the profile fields only to show you which account you are posting to and to build the public link to a posted video, and use the tokens only to query the posting options TikTok offers for your account and to publish videos you explicitly choose to post.

For each post we transmit to TikTok the rendered video file (which contains your song), the caption, the privacy level and interaction settings you chose, the commercial-content disclosure if you enabled it, and — for templates whose visuals are AI-generated — TikTok's "AI-generated content" flag. We store the publish ID TikTok returns, the processing status, and the public video ID once the post is live, so we can show you the result and track its performance (section 3(i)). We do not read your TikTok inbox, followers or other videos.

TikTok processes your data as an independent controller under its own privacy policy. You can revoke our access at any time in Settings ("Disconnect TikTok"), which also revokes the token at TikTok and deletes the stored profile data, or in TikTok under "Manage app permissions". Deleting your Songbrain account does the same. Videos already posted remain on TikTok until you delete them there.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (the posting you requested). Retention: until you disconnect or delete your account; records of posts that never completed are deleted after 30 days.

n) Public Leaderboard & Viral Radar (opt-in)
Your songs are private by default. Only if you switch on "show on leaderboard" for a song (this requires the song's public Spotify link) do we publish it on the public leaderboard and on the per-genre Viral Radar pages of songbrain.ai: song title, the artist name you entered, cover, genre, Virality Score, its strongest moments, song length, analysis date and the Spotify link. Your e-mail address and account details are never shown. You can switch the setting off per song at any time; the song then disappears from the app leaderboard immediately and from the Viral Radar pages with their next update. Deleting the analysis or your account has the same effect.
Legal basis: Art. 6(1)(a) GDPR — your consent (the opt-in per song), withdrawable at any time.

3.5 Reference Tracks on the Leaderboard

The public leaderboard at app.songbrain.ai/leaderboard ranks songs that users have analyzed with Songbrain and opted in to publish. Alongside those entries it shows a set of publicly released reference tracks per genre. Reference tracks carry no rank and no Virality Score; they are displayed in a visually reduced style purely as genre context, so that a board with few analyzed songs still gives a sense of the field.

What this means in practice:

  • Track data shown— song title, artist name, album art, and Spotify track ID — is publicly available metadata fetched from Spotify's public catalog.
  • No evaluation — reference tracks are not analyzed, scored or ranked, and their presence does not represent any endorsement or evaluation of the track or artist.
  • If you are an artist and would like your track removed from the reference set, email info [at] songbrain [dot] ai with the subject line "Leaderboard reference removal" and we will remove it within 7 days.
  • Ranks and scores on the leaderboard are shown exclusively for tracks that have actually been analyzed by our pipeline and whose owner opted in.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in giving analyzed songs meaningful genre context. No personal data of the artists shown is processed beyond what is publicly available via Spotify's public catalog API.

3.6 Developer API (api.songbrain.ai)

When a developer uses the Songbrain API or its MCP endpoint, we process:

  • Account & keys: the account that owns the key, a name for each key, and a one-way hash of the key (the key itself is never stored). We also record when each key was created and last used, how many requests it made, and its webhook signing secret.
  • What is submitted: the audio file (or the URL it was fetched from), and optionally a title, an artist name, your own reference id and a webhook URL.
  • Usage records: which song was submitted with which key, when, whether it was free or paid, and the webhook delivery status.
  • Technical data: the IP address is used in memory only, for rate limiting, and is not stored in the API records.

The audio goes through the same analysis steps and processors as an upload in the app (section 5: Hetzner, Cloudflare, Google Gemini, Groq, Anthropic). Results go back only to the key holder: as an API response, or as a signed notice to the webhook URL they provided. API audio is not used to train models and is never published. It does not appear on the leaderboard, in playlists or in Viral Radar.

Retention. The uploaded file is deleted within 24 hours. A compressed preview is kept for 30 days. The analysis result is kept until the developer deletes it (DELETE /v1/songs/{id}, which removes the audio and the analysis immediately) or deletes their account. Key and usage records are kept for as long as the account exists, and billing records as long as the law requires.

Roles.For the developer's own account data, Songbrain is the controller. If the developer submits audio or metadata of their own users, the developer is the controller for it and Songbrain processes it on their behalf, only to deliver the result, under the data processing agreement at songbrain.ai/dpa, which applies to every API account automatically. The current list of sub-processors is at songbrain.ai/security. People whose audio was submitted through a third-party product should contact that product first. We will help it answer access and deletion requests.

Legal basis: Art. 6(1)(b) GDPR (performing the API contract with the developer); for data submitted on behalf of third parties, Art. 28 GDPR (processing on behalf of the developer).

4. Data We Do NOT Collect
  • We do not use tracking cookies, cross-site tracking, or advertising cookies (no Google Analytics, no Facebook Pixel). The cookieless usage statistics described in section 3(g) do not identify individual users.
  • We do not build advertising profiles or share data with ad networks.
  • We do not store your full payment details (handled entirely by Polar).
  • We do not retain uploaded audio files longer than necessary for analysis.
5. Third-Party Services & Data Processors

We use the following third-party services to operate Songbrain. Most act as data processors on our behalf and only process what is necessary for the listed purpose; where a provider acts as an independent controller (Polar for payments, TikTok, Google for "Sign in with Google", and the YouTube player once you load it), its entry says so or the provider's own privacy policy applies:

  • Supabase Inc.(US, with EU-region data storage) — Authentication, user account management, encrypted profile storage. Data is stored in Supabase's EU region. Transfer safeguard for any access from the US: Standard Contractual Clauses in Supabase's Data Processing Addendum.
  • Resend Inc.(US) — Email infrastructure. Delivers all transactional and opt-in notification emails on our behalf. Resend processes recipient address, subject, and message body to deliver the email, and reports back whether it was delivered. Transfer safeguard: Standard Contractual Clauses in Resend's Data Processing Addendum (and the Data Privacy Framework where Resend is certified).
  • Anthropic PBC (US) — AI text-processing for genre interpretation, lyric analysis, result enhancement and the visual storyboard prompts of your reels and AI videos. We send text-based metadata (track title, artist name where you provided one, lyric transcripts, classifier outputs). For the Performance tab (section 3(i)) we additionally send the public cover image, a few still frames, caption, hashtags and short comment excerpts of a post you linked. To sort e-mails you send us (section 3(l)) we send their sender, subject and text (without attachments). We do not send raw audio files to Anthropic. Anthropic's API does not use submitted data to train its models; API inputs are retained by Anthropic for up to 30 days for abuse monitoring. Transfer safeguard: EU-U.S. and Swiss-U.S. Data Privacy Framework certification plus Anthropic's Data Processing Addendum.
  • Google LLC(US, with EU/US data centres) — Gemini audio analyser. A compressed copy of your uploaded audio (MP3 preview, no filename, no artist info) is sent to Google's Gemini API for an independent audio-based classification (genre, sub-genre, instruments, vocal style, tempo, mood). This is part of the analysis service itself and runs on every upload. Gemini text models additionally receive the transcribed lyrics (up to the first ~2,500 characters) and analysis metadata to interpret the song's story and to pick lyric phrases for reel captions, and Gemini image models receive text prompts to create cover art and some reel visuals — never your audio, name or e-mail for these steps. Google's paid API tier does notuse submitted content to train its models, per Google's Gemini API Terms; Google may retain API inputs for up to 55 days for abuse monitoring. Transfer safeguard: Google Cloud Data Processing Addendum with Standard Contractual Clauses; Google LLC is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework. This is distinct from "Sign in with Google" below — different Google service, different legal entity contract, different data flow.
  • Spotify AB (Sweden, parent in US) — Public Web API only (application credentials, no user OAuth, no Spotify login):
    (i) Public catalog reads.When you paste the Spotify link of your release, we read that track's public metadata (title, artist, cover art). We also poll track metadata and the daily popularity value of publicly released tracks to calibrate our Virality Score model — see section 3(k).
    (ii) Curated playlists — paused. Our curated Spotify playlist programme is currently paused, so no tracks are added to playlists. If it resumes, only the Spotify track ID and the target playlist ID would be sent — no personal data beyond what is already public on your Spotify artist page.
  • YouTube (Google Ireland Ltd., parent Google LLC, US) — Embedded explainer videos on www.songbrain.ai. The player is not loaded until you click the preview image (the preview itself is served from our own domain). On click, the video is loaded from youtube-nocookie.com and your IP address and device information are transmitted to Google; Google may set cookies once you interact with the player. Your click is stored locally as consent for all YouTube embeds on this site and can be revoked under any player. Legal basis: consent, Art. 6(1)(a) GDPR.
  • Kaggle (Alphabet Inc., US) — One-shot ingestion of publicly published historical music-chart datasets (e.g. weekly Spotify chart positions aggregated by independent researchers under permissive licences). Used as historical baseline for model calibration. We read the dataset, we do not send your personal data to Kaggle; the only request we make is the authenticated dataset download.
  • ACRCloud Pte. Ltd. (Singapore, with EU/US edge endpoints) — Audio recognition to detect whether an upload is an already released track (copyright gate, attribution). We send a short audio sample — up to the first 1 MB of your file, typically the first seconds of the song, not the full audio file — to ACRCloud's recognition service. Processing takes place via ACRCloud's EU endpoint (identify-eu-west-1.acrcloud.com); the excerpt is used to compute a fingerprint and is not linked to your account. Transfer safeguard: Standard Contractual Clauses (Singapore is not an adequate country under Swiss or EU law).
  • Apify Technologies s.r.o. (Czech Republic, EU) — Two uses: (i) reading the public data of the TikTok and Instagram posts and channels you link in the Performance tab (section 3(i)); (ii) occasional, manually started research scrapes of public TikTok posts for our own trend research, where no data of yours is involved (pseudonymised as in section 3(i); not currently used in your Virality Score). In case (i) we send Apify the public URL or handle you gave us; Apify returns the public post metrics and profile data of that channel. Data Processing Addendum in place; processing in the EU.
  • Groq, Inc.(US) — lyrics transcription (Whisper large-v3). A downsampled mono copy (16 kHz FLAC) of your complete uploaded song is sent to Groq's transcription API to extract the lyrics with word-level timestamps. No name, email or account identifier is attached to the request, and per Groq's API terms the audio is not retained after the response is returned. Data is transferred under a Data Processing Agreement incorporating the EU Standard Contractual Clauses. See Groq's privacy policy.
  • Replicate, Inc.(US, processing in US) — two narrowly-scoped AI jobs: (1) image generation (Flux.1-Schnell) for the auto-generated album cover when ACRCloud finds no commercial match and you haven't pasted a Spotify URL, and for the storyboard and AI-video images used in your generated reels — we send only a short text prompt assembled from your analysis metadata (genre, mood, style descriptors), never your name, email or any personal identifier; (2) vocal stem separation (Demucs) — when a song is hard to transcribe and the full-mix transcription comes back sparse, a downsampled mono copy of your audio is uploaded to Replicate and processed to isolate the vocals for a more accurate second transcription pass. Generated files are fetched back over HTTPS and stored on our infrastructure. Data is processed under Replicate's Standard Contractual Clauses. See Replicate's privacy policy.
  • Luma AI, Inc.(US) — generative video for the optional AI video ("Premium AI video", available to every account for credits) only. If you explicitly order one, short text/image prompts derived from your analysis (and the generated still frames) are sent to Luma's API to render the video shots. Your audio file, name and email are never sent. Luma's API terms exclude training on customer inputs and outputs; transfer safeguard: Standard Contractual Clauses. Not used for the standard template reels, which render on our own infrastructure.
  • fal.ai (Features and Labels, Inc.)(US) — AI image generation (FLUX models) for the visuals of storyboard-style reels, used as an alternative to Replicate when needed. We send only a text prompt assembled from your analysis metadata and lyric themes — never your audio, name, e-mail or any account identifier. fal.ai's Data Processing Addendum excludes training on customer content; transfer safeguard: Standard Contractual Clauses.
  • Deezer S.A. (France), MetaBrainz Foundation (MusicBrainz, US) and Apple Inc. (iTunes Search API, US) — Public music-catalogue lookups by ISRC, title and artist to verify the attribution of a recognised release and to fetch public cover art and release metadata. We send only catalogue identifiers or the recognised title/artist, never your audio or personal data.
  • TikTok (TikTok Technology Limited, Ireland, for users in the EEA/UK/Switzerland; TikTok Pte. Ltd., Singapore, and TikTok Inc., US, otherwise) — Login Kit and Content Posting API for the optional "Post to TikTok" feature described in section 3(m). TikTok is an independent controller of your TikTok account and of the videos you publish there; see TikTok's privacy policy. Our exchange of data with TikTok is governed by TikTok's Developer Terms and Data Sharing Agreement, which incorporate the EU and Swiss Standard Contractual Clauses for transfers.
  • YouTube Data API (Google LLC, US) — Public statistics (views, likes, comments) of the YouTube videos and channels you link for performance tracking (section 3(i)). We send the public video or channel ID only. Use of this API is subject to the YouTube API Services Terms and Google's privacy policy.
  • Cloudflare, Inc.(US, with EU edge presence) — DNS for songbrain.ai and its subdomains, and proxy / WAF in front of api.songbrain.ai. Cloudflare processes HTTP request metadata (IP address, user-agent, request path, response status) for DDoS mitigation, bot filtering, and TLS termination at the edge. Data is processed under Cloudflare's EU Standard Contractual Clauses. See Cloudflare's privacy policy.
  • Google LLC(US) — Optional "Sign in with Google" OAuth login. If you choose this method, we receive your email address, name, and profile picture from Google. You can revoke this access at any time via your Google Account settings.
  • Polar Software Inc. (US) — Merchant of Record for credit packs, Premium subscriptions and Release Passes: checkout, card processing, tax calculation, invoicing and refunds. Polar acts as an independent controller for the purchase transaction and collects your email address, billing country and, where required, billing address and VAT ID. We do not store credit card numbers or full payment details — Polar sends us only a transaction reference, the product purchased, the credit amount or subscription status, and a timestamp via webhook. See Polar's privacy policy.
  • IONOS SE (Germany, EU) — Domain registration and our mailboxes. Inbound emails sent to addresses on our domain (e.g. hello [at] songbrain [dot] ai) are stored on IONOS mail servers in Germany.
  • Slack Technologies (US; Slack Technologies Ltd., Ireland, for the EU) — our internal team chat. Our monitoring assistants post short operational notifications there for our team: for example that a new account was created or a purchase was made (username or name, product, amount), and — for e-mails that need a reply — sender, subject and a short summary (section 3(l)). No audio, no analysis results and no full e-mail texts. Transfer safeguard: EU-U.S. and Swiss-U.S. Data Privacy Framework certification and Slack's Data Processing Addendum with Standard Contractual Clauses.
  • Hetzner Online GmbH (Germany, EU) — Server hosting and infrastructure. Our application backend (api.songbrain.ai), the analysis pipeline, and all stored audio files, previews, rendered videos and analysis results run on servers operated by Hetzner in a data centre in Nuremberg, Germany. Where this policy refers to "our servers" or "our own infrastructure", it means these Hetzner servers under our exclusive control.
  • Vercel Inc.(US) — Hosting of the public website (songbrain.ai) and of the web app's user interface (app.songbrain.ai). Vercel delivers the pages and processes request metadata (IP address, user-agent) to do so; your analyses, audio and videos are not stored there. The application backend (api.songbrain.ai) runs on servers hosted by Hetzner Online GmbH in Germany (see above). Transfer safeguard: Standard Contractual Clauses and the EU-U.S. Data Privacy Framework where Vercel is certified.
  • Vercel Web Analytics (US, processing in EU) — Cookieless, anonymous reach measurement on the landing page (page views, referrer, country, device). No individual profiles, no cross-site tracking.

International Data Transfers
Where data is transferred outside Switzerland and the EU/EEA (in particular to the United States and Singapore), it is protected either by the EU-U.S. and Swiss-U.S. Data Privacy Framework (DPF) where the recipient is certified, by the EU Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 as recognised by the Swiss FDPIC with the Swiss annex, or by equivalent safeguards under Art. 46 GDPR / Art. 16 FADP. The safeguard used for each provider is named in its entry above. We assess each provider individually and supplement transfer mechanisms with technical and organizational measures (encryption in transit, access controls, data minimization) where appropriate.

6. Data Retention
  • Account data: Stored as long as your account is active. Deleted upon account deletion request.
  • Anonymous demo uploads (/try): Visitors can analyse and compare up to five songs without signing up. The full demo — uploaded audio, working copies, separation stems, generated cover, comparison record and the analysis results — is hard-deleted from disk 24 hours after upload. Nothing is retained unless the visitor creates an account and explicitly claims the analysis during that window, at which point the standard logged-in retention rules below apply.
  • Uploaded audio files: Automatically deleted within 24 hours of analysis completion. This includes the original upload, the resampled working copy used by the analysis pipeline, source separation stems (drums, bass, vocals, other), and any rendered audio exports. One exception: a small compressed playback preview (≈3 MB MP3) is kept for 30 days (Free/Early-Access accounts) or 365 days (Premium subscribers) after analysis so that you and our support team can replay the result from your dashboard. The preview is deleted by a daily sweeper at the end of that window. Account deletion erases the preview immediately.
  • Failed, cancelled and removed uploads: An analysis that fails or that you cancel is deleted completely within 48 hours. When you remove a song from your dashboard, its audio and rendered videos are deleted within 24 hours; the analysis record stays listed in Settings → Privacy until you delete it there.
  • Analysis results: Stored as long as your account is active, or until you delete the individual analysis. Transcribed lyrics of a recognised third-party release are never stored (section 3(c)); your own lyrics can be deleted per analysis at any time.
  • Linked posts and performance data: Video links you submit and the public metrics we collect for them are kept while your account exists or until you remove the link; polling of a post stops automatically after a limited period.
  • TikTok connection: Tokens and profile data are kept until you disconnect the account or delete your Songbrain account; records of posts that never completed are deleted after 30 days.
  • Generated reels (videos): The short-form videos rendered from your song (previews and HD exports) contain your song as their audio track. They are stored alongside the analysis so you can re-download them, and are deleted as soon as the playback-preview retention window above expires (30 days for Free/Early-Access accounts, 365 days for Premium subscribers) or when you delete the track, the album, or your account — whichever comes first.
  • YouTube HD videos: Full-length 16:9 videos are kept for 30 days after rendering and their short previews for 7 days; after that you can render them again (a video you already paid for is re-rendered free of charge).
  • Payment records: Retained for the legally required period (10 years under Art. 958f of the Swiss Code of Obligations — retention of business records).
  • E-mails you send us: Kept in our mailbox as long as needed to handle your request and any follow-up correspondence; deleted on request unless we must keep them as business records. The sorting record (sender, subject, date, category, summary; section 3(l)) is deleted after 12 months.
  • API access requests: Stored until your request is processed or you request deletion.
  • Server and edge logs: Request logs at our network edge (Cloudflare) and on the landing-page host (Vercel) are kept by those providers for their standard short periods (up to 30 days). Application logs on our own servers record request paths, status codes and timestamps for debugging; they contain no request bodies, are never used for profiling and are rotated on a rolling basis.
  • Product usage events: First-party usage events (section 3(g)) and reel-download markers are deleted after 13 months by a daily sweeper; ledger-type records (that you signed up, purchased, or received a given onboarding e-mail) are kept for the life of the account so they are never repeated.
  • Storyboard feedback: Free-text feedback you give on a generated storyboard is kept for 12 months and then deleted.
  • Activity feed entries: The in-app timeline of your actions (uploads, refunds, genre corrections, credit top-ups, etc.) is kept for 90 days and then auto-deleted by a daily sweeper. Account deletion erases the remaining entries immediately.
  • In-app support messages: Threads in your inbox (bug reports, feedback, admin replies) are kept for 12 months after the last message in the thread, then auto-deleted by a daily sweeper. The clock resets every time either side replies — a still-active conversation will not vanish under you. Account deletion erases all of your threads and their messages immediately.
  • Backups: Our production data is backed up daily. Only the three most recent daily backups are kept; older ones are permanently deleted, so a backup never outlives its data by more than about 72 hours. When you exercise your right to erasure (Art. 17 GDPR), we remove your data from the live system immediately; backups are not actively edited, but your data ages out of them within that window. Restores from backup re-apply pending erasure markers so previously deleted accounts are not resurrected.
  • GDPR audit log (Art. 30): We retain a minimal record of privacy-impacting actions you take (data export, account deletion, consent changes) and of administrator read-access to your analyses for 3 years from the action, as evidence of our compliance with your requests; a daily sweeper deletes older entries. This log contains only your user ID, the action type, timestamp, IP and user-agent — never the content of your data.
7. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the following rights:

  • Right of access (Art. 15) — Request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16) — Correct inaccurate or incomplete data.
  • Right to erasure(Art. 17) — Request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing (Art. 18) — Limit how we use your data.
  • Right to data portability (Art. 20) — Receive a copy of the personal data you have provided to us in a structured, machine-readable format (JSON). The export contains: account information, profile fields, notification preferences, credits ledger (balance, total purchased, refill timestamps), uploaded file metadata, consent records, release-platform links you entered, support messages you sent, genre-feedback inputs you submitted, and your activity log. This right does not extend to data derived or inferred by our analysis pipeline (e.g. virality score, genre classification, moments, lyrics evaluation, embeddings, model outputs): per EDPB guideline WP242 rev.01, inferred data is outside the scope of Art. 20, and the underlying models and feature engineering are protected as trade secrets under Recital 63 GDPR. Payment card details are processed by Polar and never reach our servers.
  • Right to object (Art. 21) — Object to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7(3)) — Withdraw any previously given consent at any time.

To exercise any of these rights, contact us at info [at] songbrain [dot] ai. We will respond within 30 days.

8. How to Request Data Deletion
You can delete your account and all associated data yourself at any time in Settings → Danger Zone → "Delete account". This immediately removes your analyses, audio files, rendered videos, albums, usage events, support threads, linked posts and their performance data, and your TikTok connection (including revoking our access at TikTok), and then deletes your login. Alternatively, send an email to info [at] songbrain [dot] ai with the subject line "Data Deletion Request" and we will do it for you within 30 days. The only data that survives is what the law requires us to keep (payment records under Art. 958f of the Swiss Code of Obligations, held by Polar) and a salted hash of your e-mail address that prevents the signup bonus from being claimed repeatedly with the same address.

Granular deletion. You do not have to delete your whole account to remove data: deleting a single analysis in Settings → Privacy removes the analysis result, its audio preview, its rendered videos — and, if you had opted in to ML training, the corresponding entry in our ML training archive. Removing a song from your dashboard deletes its audio and videos within 24 hours (section 6). You can also delete the stored lyrics of all your analyses at once. In addition, the "Delete my audio files now" control in your account Settings immediately and permanently deletes all audio files we hold for you, including playback previews and rendered videos/reels, without waiting for the retention windows in section 6.

9. Cookies
This website does not use tracking cookies, advertising cookies, or analytics cookies. Only technically necessary cookies may be set by our hosting providers (Vercel, Supabase) to ensure functionality and security (e.g., session tokens for authentication). In the app we additionally use your browser's local storage for functional settings only: your language and interface preferences, a per-tab session identifier for the first-party usage events in section 3(g), your YouTube-embed consent on the landing page, and pending state while you return from a login or TikTok authorisation. None of this is read by third parties or used to recognise you across sites. These items are strictly necessary or functional and do not require a consent banner under the Swiss FADP or Art. 5(3) of the ePrivacy Directive.

10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. This includes encrypted data transmission (TLS/SSL), secure authentication via Supabase, and restricted access to our servers.

10.5 Automated Processing & AI Disclosure (EU AI Act Art. 50)

Songbrain's analysis pipeline uses AI/machine-learning systems to produce the results you see (genre classification, virality score, best-moment detection, lyrics evaluation, instrument recognition). These outputs are generated by automated systems — not by human review — and are intended as guidance, not as definitive musical judgement.

What this means for you:

  • All scores and classifications shown in the dashboard are algorithmically produced. They reflect what our models observe in the audio and lyrics, compared with reference data; they do not reflect commercial success guarantees.
  • No decision Songbrain makes about you has legal or similarly significant effects in the sense of Art. 22 GDPR. Virality scoring, leaderboard ordering and suggestions are recommendations — you remain free to use, ignore or override any AI output.
  • You can request human review of any specific result by contacting info [at] songbrain [dot] ai. We will look at the case and explain how the result came about (within the limits of trade-secret protection per Recital 63 GDPR — we can describe the input signals and the reasoning at a high level, but not the model internals).
  • If you submit corrections via the genre-feedback widget, your input may be used (only with your separate ML training consent — see section 3(j)) to improve the models. You can withdraw that consent at any time in Settings.
  • Generated visuals. Cover art, the images of storyboard-style reels and the video shots of the AI video are synthetic content generated by AI models from text prompts. They are not meant to depict real, identifiable persons. Once posting through our TikTok integration is available, we will set TikTok's "AI-generated content" label for such reels automatically; when you publish them yourself, you are responsible for any disclosure your platform or local law requires.

11. Right to Lodge a Complaint
If you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a supervisory authority. The competent authority at our registered office is:

Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Feldeggweg 1, 3003 Bern, Switzerland
Website: edoeb.admin.ch

If you are located in the EU/EEA, you may also lodge a complaint with the supervisory authority of your habitual residence under the GDPR.

12. Changes to This Privacy Policy
We may update this privacy policy from time to time. The current version is always available on this page with the date of the last update shown at the top.

Rev. 15 (October 6, 2026): automated sorting of e-mails you send us described (section 3(l)), incl. the summary step at Anthropic and a 12-month retention for the sorting record; Slack added as processor for internal team notifications.
Rev. 13 (October 5, 2026): Performance tab and AI-video processing described in more detail (incl. comment excerpts sent to Anthropic), new section on the opt-in leaderboard and Viral Radar, duplicate-account check, TikTok posting marked as not yet available, curated playlists marked as paused and trend scraping as research-only (not part of your score), hosting entries (Vercel, Cloudflare, IONOS) corrected, retention for YouTube HD videos and failed or removed uploads added.