Back to SongPrompterAI

Privacy Policy

Effective Date: 1 March 2026 Last Updated: 1 March 2026

This Privacy Policy explains how SongPrompterAI ("the Service"), operated by Jamie Boyd trading as SongPrompterAI ("we", "us", "our"), collects, uses, and protects your personal data when you use our website and service at songprompter.ai.

We are committed to protecting your privacy and handling your data transparently, in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller

The data controller for personal data collected through the Service is:

Jamie Boyd Trading as SongPrompterAI Email: [email protected]

2. What Data We Collect

2.1 Account Data

When you register for an account, we collect:

  • Email address (required) — used for account identification, login, and service communications.
  • Password (required) — immediately hashed using bcrypt encryption. We never store or have access to your plaintext password.
  • Display name (optional) — a name you choose to identify yourself within the Service.

2.2 Subscription Data

When you subscribe or purchase credits, our payment processor Polar (polar.sh) handles all payment information. We receive and store:

  • Polar customer ID — an identifier assigned by our payment processor.
  • Polar subscription ID — identifies your subscription for billing management.
  • Subscription status and tier — whether your subscription is active and which plan you are on.

We do not collect, process, or store your credit card number, bank account details, billing address, or any other payment card data. All payment processing is handled entirely by Polar.

2.3 Song Generation Data

When you use the Service to generate lyrics, we store:

  • Genre selected — the musical genre you chose.
  • Topic — the song topic you provided.
  • Brief — the freeform text description you submitted.
  • Generated output — the lyrics, style prompt, and title suggestions produced by the Service.
  • Generation metadata — the number of attempts, generation time, and quality metrics.
  • Your rating — if you choose to rate a generated song.

2.4 Technical Data

We collect limited technical data necessary to operate the Service:

  • Login timestamps — when you last logged in.
  • Account creation date — when your account was created.

We do not collect your IP address for profiling or tracking purposes. We do not use cookies, tracking pixels, or advertising technology.

We use Plausible Analytics (plausible.io), a privacy-first, cookie-free analytics service. Plausible does not collect any personal data, does not use cookies, and is fully compliant with UK GDPR, PECR, and ePrivacy. All data is aggregated — no individual visitors are tracked. For details, see the Plausible Data Policy.

2.5 Server Logs

Our hosting infrastructure (Railway) automatically generates server logs that may temporarily contain your email address in authentication-related log entries. These logs are retained for a limited period (typically 30 days) for operational and debugging purposes and are not used for profiling or marketing.

3. How We Use Your Data

We use your data for the following purposes:

Purpose Data Used Legal Basis (UK GDPR)
Provide the Service (account management, song generation) Email, password hash, display name, song data Article 6(1)(b) — Performance of contract
Process payments and manage subscriptions Email, Polar IDs, subscription status Article 6(1)(b) — Performance of contract
Send important service communications (account changes, security alerts) Email Article 6(1)(b) — Performance of contract
Maintain and improve the Service Generation metadata, aggregated usage statistics Article 6(1)(f) — Legitimate interest
Detect and prevent abuse Account activity patterns Article 6(1)(f) — Legitimate interest
Comply with legal obligations Account data, transaction records Article 6(1)(c) — Legal obligation

We do not use your data for marketing, profiling, automated decision-making, or selling to third parties.

4. Data Sharing

We share your data only with the following third-party processors, and only to the extent necessary to operate the Service:

Processor Purpose Data Shared Location
Polar (polar.sh) Payment processing (Merchant of Record) Email address (for checkout sessions) EU/US
Railway (railway.app) Application hosting and database All account and song data (encrypted at rest) US
DeepInfra (deepinfra.com) AI model inference Song genre, topic, and brief (no account data) US
Cloudflare (cloudflare.com) DNS, CDN, and DDoS protection IP addresses (transient, not stored by us) Global
Plausible (plausible.io) Privacy-first website analytics No personal data (aggregated page views only, no cookies) EU

We do not sell, rent, or otherwise make your personal data available to any other third parties.

International transfers: Some of our processors operate outside the UK. Where data is transferred internationally, it is protected by appropriate safeguards including Standard Contractual Clauses and the processor's own data protection commitments.

5. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specifically:

  • Account data — retained while your account exists. Deleted upon account closure request. Accounts inactive for 2 years (no login) may be automatically deleted unless an active subscription exists.
  • Song data — retained while your account exists. You may delete individual songs at any time through the Service. Song data is deleted when your account is deleted.
  • Subscription data — retained for the duration of your subscription plus any period required for tax and accounting records (typically 6 years under UK law).
  • Server logs — retained for approximately 30 days by our hosting provider.

6. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access — You may request a copy of the personal data we hold about you.
  • Right to rectification — You may request correction of inaccurate personal data.
  • Right to erasure — You may request deletion of your personal data ("right to be forgotten").
  • Right to data portability — You may request your data in a structured, machine-readable format.
  • Right to restrict processing — You may request that we limit how we use your data.
  • Right to object — You may object to processing based on legitimate interest.
  • Right to withdraw consent — Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

7. Data Security

We take reasonable technical and organisational measures to protect your personal data, including:

  • Passwords are hashed using bcrypt before storage.
  • All data is transmitted over HTTPS (TLS encryption).
  • Database access is restricted to the application via internal networking.
  • JWT authentication tokens expire after a limited period.
  • The application uses CORS restrictions to prevent unauthorised cross-origin requests.

No system is completely secure. While we take reasonable precautions, we cannot guarantee the absolute security of your data.

8. Children

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will delete it promptly.

9. Cookies and Local Storage

The Service does not use HTTP cookies.

The Service uses browser localStorage (client-side storage on your device) for the following purposes:

Item Purpose Contains PII
sp_theme Remembers your light/dark theme preference No
sp_access_token Authentication session token Yes (contains email)
sp_refresh_token Token renewal Yes (contains user ID)
sp_user_email Displays your email in the interface Yes

localStorage data is stored only on your device and is not transmitted to third parties. You can clear this data at any time through your browser settings. For more details, see our Cookie Policy.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice within the Service. The "Last Updated" date at the top of this page indicates when the policy was most recently revised.

11. Complaints

If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office Website: https://ico.org.uk Telephone: 0303 123 1113

12. Contact

For any questions about this Privacy Policy or your personal data, contact us at:

Email: [email protected] Website: https://songprompter.ai

Terms of Service · Privacy Policy · Cookie Policy · Acceptable Use
© 2026 SongPrompterAI