Last updated: May 12, 2026 (rev. 3)
1. Controller & Contact
Leon Ulicnik
songbrain ai / Smoke-Oh Studios
Bahnhofstr. 27, 24837 Schleswig, Germany
Email: info [at] songbrain [dot] ai
2. Overview of Data Processing
We process personal data only to the extent necessary to provide and improve our service. We do not sell your data to third parties. Below is a summary of what we collect, why, and how long we keep it.
a) Account & Authentication
When you create an account, we store your email address and authentication credentials via Supabase Auth. This data is required to identify you, manage your account, and secure access to your analyses.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
b) Uploaded Audio Files
When you submit a song for analysis, your audio file is temporarily stored on our servers for processing. The file passes through our analysis pipeline (tempo, key, genre, lyrics, instruments, virality, etc.) and the resulting analysis data is stored as a JSON report linked to your account.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
c) Analysis Results
The results of each analysis (tempo, key, loudness, genre classification, lyrics transcription, instrument detection, virality prediction, etc.) are stored and linked to your account so you can access them at any time.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
d) Credits & Payment Data
We track your credit balance (credits purchased and credits used). Payment transactions are processed by LemonSqueezy. We do not store credit card numbers or full payment details on our servers — only the transaction reference, purchased credit amount, and timestamp received via webhook.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
e) Waitlist
If you sign up for our Early Access waitlist, we collect your email address solely to notify you when Songbrain becomes available.
Legal basis: Art. 6(1)(a) GDPR — your consent.
f) API Access Requests
If you request API access, we collect your email address and optionally your company name and intended use case. This data is used solely to evaluate your request and contact you about API access.
Legal basis: Art. 6(1)(a) GDPR — your consent.
g) Server Logs
Our hosting providers (Vercel for the landing page, our own server for the application) may collect technical data such as IP addresses, browser type, and access timestamps. This data is used for security and debugging purposes only.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in security and stability.
h) Anonymous Usage Statistics (Vercel Web Analytics)
We use Vercel Web Analytics to understand how visitors interact with our landing page (page views, referrer domain, country, device type, browser). This service is cookieless: no cookies are set, nothing is written to or read from your device, no cross-site tracking takes place, and no individual user profiles are created. IP addresses are processed only briefly server-side (hashed for bot detection) and are never stored.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in measuring reach and improving our service. No consent banner is required because no information is stored on or read from your device (TTDSG § 25).
i) Email Communications
We send you transactional emails that are necessary to operate your account: signup confirmation, password reset, magic-link login, email-change confirmation, and account invitations. These are delivered via our email-infrastructure provider Resend (see section 5).
Optionally — and only if you explicitly opt in via your account Settings — we send notification emails when one of your songs is added to a curated Spotify playlist, weekly leaderboard updates, or product news. You can change these preferences at any time and unsubscribe with one click via the link in any such email.
Legal basis: Art. 6(1)(b) GDPR for transactional emails — performance of a contract. Art. 6(1)(a) GDPR for optional notifications and product updates — your consent.
j) ML Training Consent (Optional)
You can optionally allow us to use the anonymized results of your analyses (audio features, derived classifications, lyrics transcripts) to train and improve our internal AI models. This is strictly opt-in via your account Settings, can be withdrawn at any time, and applies retroactively when withdrawn (we stop using your past data for future training runs). The original audio file itself is never used for training and is deleted after analysis as described in section 6.
Legal basis: Art. 6(1)(a) GDPR — your consent. Withdrawable at any time under Art. 7(3) GDPR without affecting the lawfulness of prior processing.
During our pre-launch phase, the public leaderboard at app.songbrain.ai/leaderboard displays a curated selection of publicly available Spotify tracks together with placeholder Virality Scores and Best Moments. These scores are not the result of an actual Songbrain analysis — they exist solely so visitors can see how the leaderboard will look once the platform opens publicly.
What this means in practice:
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in demonstrating the product to potential users prior to launch. No personal data of the artists shown is processed beyond what is publicly available via Spotify's public catalog API.
We use the following third-party services to operate Songbrain. Each acts as a data processor on our behalf and only processes what is necessary for the listed purpose:
International Data Transfers
Where data is transferred outside the EU/EEA (in particular to the United States), it is protected either by the EU-US Data Privacy Framework (DPF) where the recipient is certified, by the EU Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, or by equivalent safeguards under Art. 46 GDPR. We assess each provider individually and supplement transfer mechanisms with technical and organizational measures (encryption in transit, access controls, data minimization) where appropriate.
Under the General Data Protection Regulation, you have the following rights:
To exercise any of these rights, contact us at info [at] songbrain [dot] ai. We will respond within 30 days.
8. How to Request Data Deletion
You can request complete deletion of your account and all associated data by sending an email to info [at] songbrain [dot] aiwith the subject line "Data Deletion Request". We will delete all your personal data, analysis results, and account information within 30 days, except where retention is required by law (e.g., payment records under German tax regulations).
9. Cookies
This website does not use tracking cookies, advertising cookies, or analytics cookies. Only technically necessary cookies may be set by our hosting providers (Vercel, Supabase) to ensure functionality and security (e.g., session tokens for authentication). These are strictly necessary and do not require consent under GDPR.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. This includes encrypted data transmission (TLS/SSL), secure authentication via Supabase, and restricted access to our servers.
Songbrain's analysis pipeline uses AI/machine-learning systems to produce the results you see (genre classification, virality score, best-moment detection, lyrics evaluation, instrument recognition). These outputs are generated by automated systems — not by human review — and are intended as guidance, not as definitive musical judgement.
What this means for you:
11. Right to Lodge a Complaint
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. The competent authority for us is:
Independent State Centre for Data Protection Schleswig-Holstein (Unabhängiges Landeszentrum für Datenschutz, ULD)
Holstenstraße 98, 24103 Kiel, Germany
Website: datenschutzzentrum.de
12. Changes to This Privacy Policy
We may update this privacy policy from time to time. The current version is always available on this page with the date of the last update shown at the top.