Privacy Policy
This Privacy Policy explains how Voice to Song (AI Music) collects and uses personal data when you use the website, create an account, upload audio, generate or edit music, purchase credits, or contact support.
Effective date: August 20, 2026
1. Who we are
Voice to Song is an online service for voice-assisted AI music creation and editing.
The data controller is an individual entrepreneur registered in Georgia. Full registration details are published on the Legal Information page.
For privacy requests, contact [email protected] and include enough detail for us to identify your account without sending unnecessary sensitive credentials.
2. Scope
This Policy applies to processing connected with:
- the website and related pages
- user accounts and authentication
- voice and audio upload
- music and lyrics generation
- the music editor and exports
- purchase and use of prepaid credits
- customer support communications
3. Data we collect
Account data
Depending on how you sign in, we may process:
- user identifier
- email address
- display name, if provided
- authentication-related identifiers supplied by our authentication provider (Clerk)
We do not receive or store your account password from the authentication provider in ordinary email/password flows handled by that provider.
User-provided content
- prompts and generation settings
- lyrics and song titles
- voice recordings and uploaded audio
- generated tracks and project files needed for the editor
- editing instructions and export requests
- support messages you send us
Service and technical data
- request and job identifiers
- generation and processing status
- credit transaction records
- timestamps related to account and job activity
- diagnostic and security logs needed to operate and protect the service
We do not intentionally collect advertising identifiers, precise geolocation, or device fingerprinting for ads. Platform hosting logs may include IP addresses or similar connection metadata as part of ordinary infrastructure operation.
Payment data
When online payments are enabled, payments are processed by Flitt. We may receive payment or order identifiers, amount, currency, status, timestamps, and other information needed for reconciliation and refunds.
We do not receive or intentionally store full card numbers, CVV/CVC codes, banking passwords, or OTP codes.
Payment-related data is used to complete purchases, reconcile payments, and process eligible refunds. While online payments are not enabled in a given environment, payment transactions may be absent.
4. Why we process data
We process personal data to:
- create and maintain your account
- provide generation, voice processing, and editor features
- store projects and deliver downloads or renders you request
- process credits and purchases
- prevent abuse, fraud, and security incidents
- diagnose errors and improve reliability
- respond to support requests
- comply with applicable legal obligations
We do not use your content for direct advertising campaigns in the current product.
We may correlate technical logs with job identifiers to investigate generation failures, credit accounting errors, and security incidents. This is done to support the service, not to build advertising profiles.
5. Legal grounds
Depending on your location and the activity involved, processing may be based on performance of the service agreement, consent where required (for example certain voice processing confirmations), legitimate interests in operating and securing the service, and compliance with applicable legal obligations.
This Policy describes our practices in plain language. It is not a claim of certification under every privacy regime worldwide, and applicable law may differ by user and place of service.
If applicable law grants additional rights or imposes stricter requirements, those requirements prevail over this Policy to the extent they cannot be limited by contract.
6. AI and voice processing
Voice and other audio may be transmitted to external service providers to perform the processing you request. Prompts, lyrics, and audio may be processed by external AI providers to generate or transform content.
Data is shared for performing the requested function and operating the service. You must not upload another person’s voice without permission.
External providers process data under their own contractual and privacy terms. Their retention and model-training practices may differ. We aim to configure providers in a privacy-conscious manner where available.
Consent to a specific processing step does not transfer ownership of your voice to the service.
Voice verification and related consent confirmations may be required before certain generation features become available. Those confirmations document permission to process the submitted voice for the requested music workflow.
Voice samples may be sent to a third-party voice-processing provider to create an AI voice profile. The provider may create derived voice representations, embeddings, or model data from the sample.
Turning off a personal AI voice in the music creation flow only stops using that voice for new generations. It is not a deletion request: the voice profile, provider Vocal ID, and source sample remain. With the voice off, you can keep generating with the standard AI vocal. Turning it back on reuses the same ready personal AI voice without a new cloning charge.
Account deletion is initiated from profile settings. After confirmation, local use stops immediately: generation, voice upload, and purchases are blocked. The original voice sample is purged from our storage, and a request to delete related voice data is registered with the external AI provider. Provider-side deletion may be processed asynchronously. We do not promise immediate physical erasure from the provider or from operational backups, or from records we must retain by law.
Final account deletion completes after related provider deletion requests are confirmed (or if no provider ticket was required). Turning off a personal voice never starts account deletion.
7. Service providers and transfers
We use categories of service providers such as:
- authentication provider
- cloud hosting and worker infrastructure
- database provider
- object storage provider
- AI generation and voice-processing providers
- payment provider (when online payments are enabled)
Some providers may be located outside Georgia and outside your country of residence. We do not promise a specific international-transfer mechanism beyond what is available under our provider contracts and applicable law.
We do not publish a fixed list of every sub-processor name in this MVP Policy because generation and voice-processing vendors may change through our provider abstraction. Categories above reflect the roles that process data in production architecture.
Optional application monitoring configuration may be enabled in some deployments. If enabled, diagnostic event data needed to detect errors can be processed by the configured monitoring vendor under that vendor’s terms.
8. Data retention
Account data is retained while your account remains active and as needed to provide the service.
Projects and audio remain available while they are accessible to you in the product or otherwise needed to deliver the service.
Payment and accounting records may be retained longer where required by law.
Logs and backups may persist for a limited operational period. A deletion request does not necessarily erase data immediately from backups or from records we must keep by law.
Exact retention schedules will be refined after MVP validation. Until then, we retain data only as long as reasonably needed for the purposes described in this Policy or required by law.
When a track or project is deleted from the product interface, associated files may remain briefly in operational backups before they age out.
9. Security
We apply reasonable technical and organisational measures, including authenticated access controls, transport security where supported by the relevant systems, monitoring, and backups.
No method of transmission or storage is completely secure. Absolute security cannot be guaranteed.
Access to production systems is limited to personnel and automated services that need it to operate the product. Users access their own projects through authenticated sessions provided by the authentication provider.
10. User rights
Subject to applicable law, you may request information about processing, access, correction, deletion, restriction or objection where applicable, and withdrawal of consent where processing is based on consent. You may also contact a competent authority if you believe your rights were violated.
Requests should be sent to the support email listed below. We may need to verify your identity. We do not promise to complete every request immediately where verification, technical limits, or legal exceptions apply.
11. Account and content deletion
Account deletion is initiated from profile settings via the Delete account button and requires confirmation.
Some data may be retained as needed for accounting, fraud prevention, dispute resolution, legal compliance, or limited backup recovery windows.
Disabling a personal AI voice only stops using it for new generations and is not itself a data deletion request.
When you delete your account, we immediately block further use, purge local source audio according to our deletion flow, and register a provider deletion request. Provider-side deletion is processed separately, may take additional time, and is tracked as a separate status. We do not claim that provider-side voice data is deleted instantly or from all backup systems.
Final account deletion completes after related provider deletion requests are processed. Turning off a personal voice never starts account deletion.
12. Children
The service is not intended for children who cannot lawfully consent to the processing of their data or enter into the applicable agreement without permission from a parent or guardian.
13. Changes
We may update this Privacy Policy. Material changes will be shown on the website or communicated through another reasonable channel. We do not promise email notice for every update.
14. Contact
For privacy requests, personal data requests, and account deletion questions, contact [email protected].
Full trader / controller registration details: Legal Information.
See also Terms of Service and Refund Policy.