Skip to content

Privacy Policy

Last updated 2 October 2026

We collect the minimum needed to run your account and generate your tracks. We do not sell your data and we do not train models on your content.

Scaffold notice — Phase 1. This document is the structural shell of our policy and is pending review by counsel before public launch. It is published here so the product surface, navigation and footer links are complete and testable.

1.What we collect

  • Account data — your email address, subscription tier, credit balance and Whop membership identifier.
  • Content — the prompts and lyrics you submit, the audio generated from them, and the structure and metadata attached to each track.
  • BYOK credentials — your Google and ElevenLabs API keys, encrypted at rest with AES-256-GCM. We never return them to a browser and never write them to logs.
  • Billing data — handled by Whop as merchant of record. We receive a membership identifier and status, never your card number.
  • Operational data — request timestamps, generation status, error codes, latency and coarse region. Used for debugging and abuse prevention.

2.What we deliberately do not collect

  • Raw payment card data — that stays with our payment processor.
  • Third-party advertising identifiers or cross-site trackers.
  • Your microphone, camera or local files.
  • Plaintext copies of your BYOK keys, at any point after they are encrypted.

3.Sub-processors

Your content is transmitted to the following processors only as needed:

  • Vercel — application hosting, edge routing and audio blob storage.
  • Neon — managed PostgreSQL holding accounts, prompts and generation records.
  • Upstash — QStash job delivery and Redis rate limiting.
  • Google (Gemini / Lyria) and ElevenLabs — generative audio providers. A prompt is sent to whichever provider serves the engine you select.
  • Whop — checkout, subscriptions and payment processing.

When BYOK is active, your prompt is sent to the provider using your credentials and is governed by your own agreement with that provider.

4.Retention

  • Prompts and generated audio: kept until you delete them, so that your library persists.
  • Encrypted BYOK keys: kept until you delete them or close your account.
  • Credit ledger entries: seven years, to satisfy accounting obligations.
  • Operational logs: ninety days.

5.Your rights

Depending on where you live you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. We honour these requests globally, not only where legally required.

You can export or delete everything from account settings, or by emailing privacy@heysong.app. We respond within 30 days. We do not charge for a first request in a twelve-month period.

6.Security

  • TLS in transit for every request.
  • AES-256-GCM envelope encryption for stored provider credentials.
  • Signature verification on every inbound webhook (QStash and Whop).
  • Least-privilege database credentials, with pooled runtime access separated from migration access.
  • Access to production data is limited to personnel who need it, and is logged.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant authority without undue delay.

7.International transfers and children

We process data in the regions our providers operate in, which may be outside your country of residence. Where required we rely on standard contractual clauses.

HeySong is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

8.Contact

Data protection enquiries: privacy@heysong.app.