Skip to content
SongDrop SongDrop
  • Home
  • Privacy
  • Terms
  • Contact

Privacy Policy

Last updated:

SongDrop ("we", "our", or "the app") turns a short message you write into a song. This Privacy Policy explains what we collect, why, who else receives it, and what control you have.

1. Information We Collect

The message you write

  • Your message — sent over an encrypted connection to our own server, and from there to the music provider that writes the song. We do not keep the text.
  • The style you choose — the genre and mood you pick, or the style you describe in your own words.

Service records

Our server writes one record per song we accept, so we can meter what the service costs us and stop abuse. That record cannot hold your message. It contains:

  • An event ID and timestamp.
  • Your subscription identifier, and which kind it is — the anonymous identifier described below. In a fallback used only when subscription checking is unavailable, a one-way keyed hash of your IP address is used instead — never the address itself.
  • Message length and style length — character counts. Not the text.
  • Model, audio format and unit cost.
  • Outcome — whether the request succeeded, the provider's status code, and the provider's ID for the generated song.
  • Analytics ID and request ID.

Songs

  • Saved songs — stored only on your device, alongside a small index recording each song's title, when you saved it, and which file it points to. These are never uploaded to us.
  • The title of a saved song — this is the message you wrote, and the audio file is named after its opening words. Both stay on your phone.

Product analytics

  • A random analytics identifier — generated on your device.
  • Derived event properties — a message's character count and a coarse length band, whether a genre, a mood, a custom style or none was chosen, how long a song took, and, on failure, a fixed label such as "moderation blocked" or "rate limited". Never the message itself.
  • Survey answers — the app asks two one-question surveys: how you heard about us, and, if you cancel, why. We record which option you chose and, where an option opens a text box, what you typed into it. Those boxes are the only free text in the app that reaches analytics, none accepts more than 200 characters, and nothing you wrote as a message can reach them.
  • Your subscription identifier — carried on every event, so a purchase can be joined to the activity that led to it.
  • Device context — device type, name and manufacturer, operating system and version, app version and build, language and time zone.
  • App lifecycle and screen names — when the app is installed, opened and put into the background, and which screen you are on, by fixed screen name.

Anything capable of carrying what you wrote is stripped before an event is sent. Automatic capture of taps and screen contents is switched off, and session recording is not used.

Subscriptions

  • An anonymous subscription identifier — generated by our subscription provider on first use. It is not derived from your device, your Apple ID, or anything about you.
  • Entitlement status — whether a subscription is active and when it expires. We never see or store your payment details; purchases are handled entirely by Apple or Google.
  • The analytics identifier — passed to the subscription provider as an attribute.

Install attribution

We measure which of our adverts bring people to the app. That is done for us by Singular, on iOS only, and it begins only after you have answered the tracking prompt described in Section 5. Singular passes what it collects on to the advertising networks we buy ads from — currently Meta (Facebook and Instagram) and TikTok — so each can tell us which of its own adverts worked.

  • The advertising identifier (IDFA) — only if you allowed tracking. If you declined, or have not been asked, it is never read.
  • The vendor identifier (IDFV) — an identifier Apple gives us for your device, which is reset when you delete the app. Collected either way.
  • That the app was installed, and that it was opened — the install and one record per launch. Not what you did once it was open.
  • Your subscription identifier — the same anonymous identifier described above.
  • Two purchase events — that a free trial began, or that a paid subscription began. Each carries the store's product identifier and nothing else. No amount of money is ever sent.
  • Apple's attribution postbacks — copies of the SKAdNetwork and AdAttributionKit postbacks Apple sends to the advertising network. Apple composes these; we do not choose their contents.
  • Device context and IP address — device model, operating system and app version, language, and the address the records arrive from.

Nothing you write reaches it: no message, no style, no lyrics, no song title. Neither does anything from the product analytics above. Renewals, trial conversions and restored purchases send nothing at all.

Device and technical information

  • IP address — received by our server when routing your request, and used to apply rate limits. Where an address is used as a usage key, it is stored only as a one-way keyed hash.
  • Approximate location from IP — our analytics provider derives an approximate country and region from the address events arrive from. This is not device location; see Section 3.

2. How We Use Your Information

  • To generate the song you asked for, and to deliver it to your device.
  • To check that a subscription is active before generating a song, and to restore a subscription you have already paid for.
  • To meter what each subscription costs us, apply fair-use limits, and reconcile our provider invoices.
  • To prevent abuse and enforce our Terms of Service.
  • To understand how the app is used, so we can improve it.
  • To measure which of our own adverts bring people to the app.
  • To send the reminders you have allowed, which are scheduled entirely on your device.

We do not sell your personal information, and we do not use it to target adverts at you or to build a profile of you. There is no advertising inside SongDrop. The identifiers described under "Install attribution" above are shared with our measurement partner for one purpose only: telling us which of our adverts led to an install. We do not use your messages or your songs to train machine-learning models.

3. What We Never Collect

  • Your name, email address, phone number or password — the app has no sign-up.
  • The text of your messages, in any record we keep.
  • Copies of your songs, beyond the short-lived one described in Section 4. Songs are generated, delivered to you and saved on your device; where we have to hold the audio for your phone to fetch, it is deleted after three days and we keep nothing after that.
  • Your contacts, photos, calendar or device location. The app requests none of these permissions. Our audio-playback library adds a microphone permission string to the iOS build, but SongDrop never records audio and never asks for microphone access.
  • Payment details of any kind. Those go to Apple or Google, never to us.
  • Who you send songs to. Sharing happens through your device's own share sheet.

4. How Your Songs Are Made and Stored

When you press Create Song, your message and style are sent to our own server, which validates the request, checks your subscription, and forwards it to our music provider.

The finished song is delivered to your device. Until you save it, the app plays it from a link; saving downloads it into the app's storage on your phone.

For most songs that link points at the music provider's own servers and we never hold a copy. For songs made from a short message it points at ours: that provider returns the audio file itself rather than a link to one, so we store the finished song for up to three days so your phone can play, save, edit and share it, after which it is deleted automatically. The link is unguessable and there is no way to browse or search what is stored.

Deleting the app deletes your saved songs. We have no way to restore them: the three-day copy described above is there so your phone can fetch the song, not as a backup, and it is gone after three days whatever you do. Your device's own backup may include them. Keep your own copies of anything that matters.

5. Notifications and Tracking Permission

The app asks once, on first open, whether it may send notifications, and records only whether you agreed. Reminders are scheduled entirely on your device: no push tokens are created and no server sends them. If you tap one, we record an anonymous event noting which of our fixed reminder messages it was.

On iOS you will also see Apple's App Tracking Transparency prompt, once, on first open. It governs the advertising identifier (IDFA). If you allow it, that identifier is shared with Singular, our measurement partner, as set out under "Install attribution" in Section 1. If you decline, it is never read. We record which you chose. Declining limits nothing in the app.

You can turn either permission off at any time in your device settings.

6. Who Else Receives Your Data

We share data with the following providers, only so far as needed to run the app:

  • ElevenLabs, Mureka and WaveSpeedAI — generate the music. One of them receives your message and style as the prompt for the song, chosen by how long your message is, and processes them under its own terms and retention practices.
  • RevenueCat — manages subscriptions. Receives your anonymous subscription identifier, the analytics identifier, store receipts and entitlement status.
  • Apple and Google — process purchases and distribute the app. They receive your payment and account details directly; we never see them.
  • PostHog — product analytics. Receives the anonymous events described in Section 1, including the subscription identifier, device context, and the IP address events arrive from.
  • Singular — advertising measurement, on iOS only. Receives the device identifiers, install and launch records, subscription identifier and two purchase events described in Section 1, and the IP address they arrive from, and forwards them to the advertising networks below.
  • Meta and TikTok — the advertising networks we buy adverts from, on iOS only. Through Singular each receives the device identifiers, the install and launch records, and the two purchase events described in Section 1, so it can tell which installs came from its own adverts. Meta covers Facebook and Instagram. Neither receives any amount of money, and neither receives anything you wrote.
  • Cloudflare — runs our server and holds our service records. Receives request metadata including your IP address.

Each of these providers operates under its own privacy policy. Data may be processed in the United States.

7. Legal Bases

Where the UK or EU GDPR applies, the data controller is , contactable at the address in Section 14, and our lawful bases are:

  • Performance of a contract — generating the song you asked for, and checking your subscription before doing so.
  • Legitimate interests — keeping the service working and affordable: rate limiting, abuse prevention, metering cost, diagnosing failures, and measuring which of our adverts bring people to the app.
  • Consent — notifications and the tracking permission in Section 5. You can withdraw either at any time in your device settings.
  • Legal obligation — retaining transaction records where tax or accounting law requires it.

8. Retention and Deletion

  • Your message — not retained by us. Passed to the music provider and discarded.
  • Generated songs on our server — only for songs made from a short message, and only for three days, then deleted automatically. See Section 4.
  • Saved songs — on your device, until you delete them or remove the app.
  • Service records — kept for 12 months, then deleted.
  • Analytics events — according to our analytics provider's retention settings.
  • Attribution records — according to our measurement partner's retention settings.
  • Subscription records — for the life of the subscription, and as long as tax and accounting rules require.

You can stop most collection yourself at any time: turn off notifications or tracking in your device settings for SongDrop, and delete the app to remove everything stored on your device.

9. Your Rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to how we use it, receive it in a portable form, and complain to your data protection regulator. In the UK that is the Information Commissioner's Office; in the EU it is your national authority. California residents have equivalent rights to know, delete, correct and opt out, and we will not discriminate against you for exercising them.

Because there is no account, we cannot identify you from our records. To make a request about them, email our contact address and include your subscription identifier, which you can copy from the app under Settings → Subscription.

We will respond within one month. If we cannot identify your records from what you send us, we will say so rather than guess.

10. Security

All traffic between the app and our systems is encrypted in transit. Our credentials for the music provider are held server-side and never shipped inside the app. Access to our service records is limited to people who need it to operate the service.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. International Transfers

Our providers operate globally, so your data may be processed outside your country, including in the United States. Where data leaves the UK or the EEA, we rely on the safeguards those providers offer, such as Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

12. Children

SongDrop is not intended for anyone under 13, and you must be at least 13 to use it. We do not knowingly collect personal data from children under 13. If we learn that we have, we will delete it promptly. If you believe a child under 13 is using SongDrop, contact us.

13. Changes to This Policy

We may update this policy. We will change the "Last updated" date above, and where changes are significant we will tell you in the app. Continuing to use SongDrop after a change means you accept the updated policy.

14. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

our contact address

© . All rights reserved.
  • Privacy Policy
  • Terms of Service
  • Contact