Privacy Policy
Last updated: April 15, 2026
1. Data We Collect
- Email address and profile information (via email/password, Google, or GitHub authentication)
- Transaction history (credit purchases and usage)
- Spotify URLs submitted for processing
- Usage logs and analytics data
2. Data We Do NOT Collect
- Raw audio files — all audio is processed in ephemeral containers and destroyed immediately
- Credit card details — all payments are handled securely by Stripe
- Tracking cookies — we only use functional authentication cookies
3. Third-Party Services
We share data with the following services as necessary:
- Supabase — Database and authentication
- Stripe — Payment processing
- Vercel — Hosting and analytics
- Google/GitHub — OAuth authentication
- OpenAI — Translation processing
- YouTube — Audio source for processing
4. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data (data portability)
- Object to certain processing activities
5. Cookies
We use only functional cookies required for authentication (Supabase auth cookies). We do not use third-party tracking or advertising cookies.
6. Data Retention
- Account data is retained until you request deletion
- Job results are automatically purged after 24 hours
- Transaction records are retained for legal and financial compliance
7. CCPA Disclosure
Under the California Consumer Privacy Act, you have the right to know what personal information we collect and how it is used. We do not sell your personal information to third parties.
8. Data Security
We implement industry-standard security measures including encryption in transit (TLS), encrypted databases, and Row Level Security (RLS) policies.
9. Contact
For data protection inquiries, contact us at privacy@lyricai.io.