## privacy
Privacy Policy
$ last updated: 2026-07-22
This policy explains what personal data SongAPI ("we") collects when you use songapi.dev, the dashboard at console.songapi.dev, and the API at api.songapi.dev, why we collect it, and the choices you have. We are the data controller for the data described here.
01Data we collect
- Account data — your email address and, if you sign in with GitHub or Google, the basic profile information those providers share (name, avatar). We never see your passwords for those services.
- Billing data — payments are processed by Stripe. We store your credit balance, transaction history, and a reference to your Stripe customer; card numbers are held by Stripe, not us.
- Content data — the prompts, lyrics, style descriptions, and audio you submit to the API, and the audio and metadata generated in response.
- Usage data — API request logs (endpoint, timestamp, key used, status, credits consumed), webhook delivery logs, and IP addresses for security and rate limiting.
- Analytics data — on the marketing site and dashboard we use DataFast, which sets a visitor cookie to measure page views, referrers, and which visits convert to signups and purchases. See the cookie policy.
02How we use it
- To provide the Service: authenticate you, process generations, deliver webhooks, bill credits.
- To secure the Service: fraud and abuse prevention, rate limiting, debugging.
- To communicate: transactional email (magic links, receipts, service notices).
- To improve the product: aggregate usage and conversion analytics.
We do not sell your personal data, and we do not use your prompts or generated audio to train models.
03Who processes it
| Processor | Purpose | Data involved |
|---|---|---|
| Supabase | Authentication and database hosting | Account data, content metadata, usage records |
| Stripe | Payment processing | Billing data, email |
| DigitalOcean | Application hosting | Request logs, IP addresses |
| Upstream generation providers | Rendering your music requests | Prompts, lyrics, uploaded audio — never your identity or account details |
| DataFast | Web analytics and revenue attribution | Visitor cookie, page views, referrer |
Requests forwarded to upstream generation providers are keyed by internal job identifiers only; providers do not receive your email or account information.
04Retention
- Account and billing records are kept while your account exists, and afterwards as required for tax and accounting law.
- Generation records (prompts, output metadata, audio references) are kept while your account exists so your history stays available.
- Generated audio files are hosted on provider content delivery networks and may expire there after a limited period — download output you want to keep.
- Request and security logs are retained for a limited operational window.
- When you delete your account from the dashboard, your account data, keys, webhooks, and generation history are deleted.
05Security
All traffic is encrypted in transit (TLS). API keys are stored as SHA-256 hashes and shown in full exactly once, at creation. Database access is protected by row-level security; privileged operations run only on the server.
06Your rights
Depending on where you live (including under the GDPR and CCPA), you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. Most of this is self-service: your data is visible in the dashboard, usage is exportable, and account deletion is available in settings. For anything else, email us and we will respond within the legally required timeframe. You also have the right to complain to your local supervisory authority.
07International transfers
Our infrastructure providers may process data in the United States and other countries. Where data leaves the EEA or UK, transfers rely on safeguards such as standard contractual clauses implemented by our processors.
08Changes
We may update this policy from time to time. Material changes will be announced by email or a dashboard notice before taking effect; the date at the top always reflects the latest revision.
09Contact
Privacy questions and data requests: [email protected].