Trust center

Security & your data

What happens to a song after you send it to the Songbrain API, who helps us process it, and how we protect it. In plain words; the binding versions are the Privacy Policy (§3.6), the Terms (§17) and the Data Processing Addendum.

🗑️
Audio deleted within 24 h

The uploaded file is gone a day after the analysis.

🚫
Never used for training

API audio trains no model, ours or anyone else's.

🔒
Never sold, never published

No leaderboard, no playlists, no charts, no data brokers.

🛡️
Hosted in Germany

API, workers and storage run on Hetzner servers in the EU.

Data handling & retention

Uploaded audio file
How long: Deleted within 24 hours
Notes: Used only to produce the analysis.
Compressed audio preview
How long: 30 days
Notes: Deleted earlier with DELETE /v1/songs/{id}.
Analysis result
How long: Until you delete it
Notes: DELETE /v1/songs/{id} removes audio and analysis at once. Closing the account deletes everything.
API keys
How long: Until revoked
Notes: Stored only as SHA-256 hashes. We can't read your key.
Usage records
How long: While the account exists
Notes: Which song, which key, when, free or paid, webhook status. Billing records as long as the law requires.
IP address
How long: Not stored
Notes: Held in memory only, for rate limiting.
Test-mode songs
How long: Nothing to keep
Notes: "test": true sends no audio through the pipeline and returns example data.

Results you have fetched are yours to keep (Terms §17.4). Deleting a song at Songbrain does not reach into your systems.

What we never do

Infrastructure & security measures

Current availability and incidents: songbrain.ai/status.

Sub-processors

These companies process data for API songs on our behalf. We tell key owners by email at least 30 days before we add or replace one.

Hetzner Online GmbH
Purpose: Hosting of the API, the analysis workers and storage
Data: Audio, analysis results
Location: Germany (EU)
Cloudflare, Inc.
Purpose: Proxy, TLS and DDoS protection in front of the API
Data: Request metadata, data in transit
Location: Global edge
Google LLC (Gemini API)
Purpose: Audio understanding: genre, instruments, description, story
Data: Audio, lyrics
Location: USA / global
Groq, Inc.
Purpose: Lyrics transcription (Whisper)
Data: Audio
Location: USA
Anthropic PBC (Claude API)
Purpose: Text enhancement of the analysis
Data: Lyrics and analysis text (no audio)
Location: USA
Supabase, Inc.
Purpose: Accounts and sign-in
Data: Email address, account id
Location: EU region
Polar Software, Inc.
Purpose: Payments, as merchant of record
Data: Billing details
Location: USA / EU
Resend, Inc.
Purpose: Transactional email (for example the low-balance notice)
Data: Email address
Location: USA
Vercel, Inc.
Purpose: Hosting of the website and the developer console
Data: Request metadata
Location: Global edge

Transfers outside Switzerland and the EU/EEA are covered by the EU Standard Contractual Clauses (with the Swiss annex) or the EU-U.S. and Swiss-U.S. Data Privacy Framework where the provider is certified. Details per provider are in Privacy Policy §5. Polar acts as merchant of record and processes payment data as its own controller.

Data Processing Addendum (DPA)

If you send audio or data of your own users, you are the controller and we process it for you. Our Data Processing Addendum (GDPR Art. 28 and Swiss FADP) covers that. It applies automatically to API use, as part of the Terms, so there is nothing to sign. A countersigned PDF is available on request.

Responsible disclosure

Found a vulnerability? Email support@songbrain.aiwith the subject "Security", the steps to reproduce and, if you have it, a request id. We aim to answer within 3 working days and keep you posted until it is fixed. Please test only against your own account, don't access other people's data, don't degrade the service, and give us a reasonable time to fix before you publish. We won't take legal action against research done in good faith under these rules.

Contact

Security and data-protection questions: support@songbrain.ai. Formal data-protection requests can also go to the controller contact named in the Privacy Policy.

Developer resources