Privacy Policy
How SingThem collects, processes and protects your data.
At SingThem we create personalized songs using artificial intelligence. To do so, we need to process some data about you and, in some cases, about the person the song is dedicated to. This policy explains in detail what we collect, why, for how long and with whom we share it. It is meant to be read end to end: if anything is unclear, write to privacy@cookthem.com.
1. Introduction
This Privacy Policy describes how SingThem (hereinafter "SingThem", "we" or "the Service") processes personal data when you use our web app (singthem.com), our Android app available on Google Play, our iOS app available on the App Store, and the associated services. Your account, credits and songs are the same across all SingThem modes (CookThem, WooThem, HypeThem, PrankThem, ThankThem and CelebrateThem).
This policy applies to all users, registered or not. If you create an account you also accept our Terms of Use. If you do not agree with any of these points, please do not use the Service.
Use of the Service implies knowledge and acceptance of this policy. The effective date appears in the header of this document; future changes will be communicated via a prominent notice in the app and, if they affect registered users, also by email.
2. Data controller
The controller of your personal data is the owner of the SingThem project. For any questions related to this policy, exercising your rights, or security incidents, you can contact us at:
Email: privacy@cookthem.com Web: https://singthem.com Mailing address: Spain (EU).
If you reside in the European Union or the European Economic Area, you have the right to file a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the supervisory authority of your country of residence.
3. Data we collect
We collect only the data strictly necessary to provide the Service, grouped in the following categories:
Account data: when you sign up we collect your email address, a username and, if you authenticate via Google or Apple, the unique identifier those providers give us. If you sign up with email and password, we store the password hashed with bcrypt — never in plain text.
Device identification data: to enforce the free anonymous limit (one free song per device) we generate a browser/device fingerprint via FingerprintJS Pro. This fingerprint is not directly personal data, but lets us identify you stably. We also store the platform type (web/iOS/Android) and, on native apps, the Firebase Cloud Messaging token to send you push notifications.
Usage data: we record usage events (visited pages, song creation actions, purchases, errors) via Google Analytics 4 with consent. These data are used in aggregate to improve the product.
User-generated content: descriptions of the person the song is for, requested tone, social media profiles you provide (Instagram, LinkedIn, YouTube), generated lyrics, and resulting audio files. If you choose to upload photos (for example, of the person the song is dedicated to), we also process those images to analyse them, inspire the lyrics and, if you enable the AI cover, generate the cover image. Only upload photos you have the right to share.
Payment data: when you make a purchase, your card details NEVER pass through our servers. They are processed directly by Stripe (web) or Apple/Google through RevenueCat (native apps). We only store the transaction identifier and the status of your subscription.
Communication data: if you write to support, we store the message content, your email and the date; when we send songs by email or WhatsApp, we keep send identifiers for audit purposes.
4. Legal basis for processing
We process your data on one of the following legal bases set out in the General Data Protection Regulation (GDPR, EU 2016/679):
Performance of a contract (Art. 6.1.b): to provide you with the Service, manage your account and process your purchases, we need to process essential account and payment data.
Consent (Art. 6.1.a): commercial communications, non-essential analytics cookies and personalized marketing are based on your consent, which you can withdraw at any time.
Legitimate interest (Art. 6.1.f): fraud detection (FingerprintJS Pro), Service security and product improvement rest on our legitimate interest, duly balanced against your rights.
Legal obligation (Art. 6.1.c): we retain tax and transaction information for the periods required by Spanish and European laws (typically 6 years for accounting data).
5. Sharing with third parties
To operate the Service we share strictly necessary data with the following data processors. All of them are bound by contracts that guarantee equivalent security measures and, where applicable, Standard Contractual Clauses (SCCs) for international transfers:
Google Cloud / Google Analytics 4 (USA): product usage analytics. Receives navigation events and anonymized identifiers when you accept analytics cookies.
FingerprintJS Pro (EU/USA): device identification to detect fraud and apply the free song limit. Receives the browser's technical fingerprint.
Google Gemini (Google, USA) and OpenAI (USA): AI lyrics generation and photo analysis. Google Gemini is our primary provider and OpenAI is used as a fallback when Gemini is unavailable. They receive the description you write, the requested tone and, if you upload them, your photos. They do not receive your email or account data.
Kie.ai (kie.ai), the provider through which we use Suno's music models: music generation and, if you enable the AI cover, cover image generation. For the music it receives the lyrics, the title and the musical style. For the cover it receives the lyrics and the title and, if you uploaded photos, temporary signed links that allow it to download those photos for a limited time. It does not receive your email or account data.
Apify (EU/USA): scraping of public profiles (Instagram, LinkedIn, YouTube) when you provide them. Receives only the public username.
Stripe (EU/USA): web payment processing. Receives the payment method and tax data necessary for the transaction.
RevenueCat (USA): in-app purchase management on iOS and Android. Receives user identifiers and purchase events.
Apple Inc. and Google LLC: processing of in-app purchases and receipt validation. Each applies their own privacy policy.
Firebase Cloud Messaging (Google, USA): push notification delivery to native apps.
Resend (EU/USA): transactional email delivery (verification, password recovery, song notifications).
Twilio / WhatsApp Business (USA): WhatsApp song delivery when you explicitly request it.
Cloud infrastructure providers: backend hosting and file storage. The photos you upload, audio files and covers are stored with cloud storage providers (currently Cloudflare R2, an object storage service).
Cloudflare (USA/global): CDN, web frontend serving and object storage (Cloudflare R2) for photos, audio files and covers.
MongoDB Atlas (EU/USA): primary database.
We do not sell your personal data. We do not share it with third-party advertisers. We do not perform automated profiling with significant legal consequences for you.
6. Retention periods
We keep your data only as long as necessary to fulfill the purposes described in this policy and to meet legal obligations:
Account data: while your account is active. If you delete your account, we anonymize identifying data immediately (see section 7).
Generated songs: kept linked to your account until you delete it. After deletion, the content remains accessible through its public link but is detached from your identity.
Payment data: 6 years from the last transaction to comply with Spanish accounting and tax obligations (Spanish General Tax Law).
Technical and security logs: 90 days in CloudWatch before automatic archive or purge.
Processed webhook events: 90 days (automatic TTL in MongoDB) to prevent duplicate payments.
Temporary copies at AI providers: the providers that generate content may temporarily retain the generated files before we copy them to our own storage. For example, Kie.ai keeps generated audio for up to 14 days and result links for about 24 hours. The signed links to your photos that we share with Kie.ai expire automatically after a short time.
7. Your rights
GDPR and Spanish law grant you the following rights over your personal data:
Access: you may request a copy of the data we hold about you.
Rectification: you may correct inaccurate data directly from your profile or by writing to privacy@cookthem.com.
Erasure ("right to be forgotten"): you may delete your account from the "Delete account" option in your profile. Deletion is immediate and anonymizes your email, username, OAuth identifiers and authentication tokens. Songs are kept without any link to your identity.
Restriction: you may ask us to restrict processing while a rectification is verified.
Portability: you may request your data in a structured format (JSON) by writing to privacy@cookthem.com.
Objection: you may object to processing based on legitimate interest.
Consent withdrawal: you may withdraw consent for analytics cookies or commercial communications at any time without affecting the lawfulness of prior processing.
To exercise any of these rights write to privacy@cookthem.com from the email associated with your account. We will respond within one month.
8. Minors
The Service is not directed to children under 13 and we do not knowingly collect data from minors below that age. In Spain, consent for processing data of minors under 14 requires authorization from parents or guardians.
If we discover that we have collected data from a minor without proper authorization, we will delete it as soon as possible. If you believe a minor has given us data, write to privacy@cookthem.com.
Some modes, such as CookThem, may contain adult humor. We recommend usage from age 16 due to content sensitivity.
9. International transfers
Some of our data processors (Google, OpenAI, Kie.ai, Stripe, Cloudflare, etc.) are located in the United States or other countries outside the European Economic Area.
These transfers rely on recognized legal mechanisms: either Adequacy Decisions of the European Commission (when applicable), or Standard Contractual Clauses (SCCs) signed with the provider, complemented by additional technical and organizational measures (encryption in transit and at rest, access controls).
You may request a copy of the safeguards applied by writing to privacy@cookthem.com.
10. Security
We apply reasonable technical and organizational measures to protect your data: HTTPS/TLS encryption on all communications, passwords stored with bcrypt, secrets managed in AWS Systems Manager Parameter Store with SSE encryption, access control via IAM roles, log auditing in CloudWatch, and periodic dependency reviews.
No security measure is foolproof. In the event of a breach affecting your personal data and posing a risk to your rights, we will notify you without undue delay and, where applicable, report it to the Spanish Data Protection Agency within 72 hours.
11. Changes to this policy
We may update this policy to reflect legal changes or Service evolution. When changes are substantial:
We will bump the version and effective date visible in the header.
We will publish a prominent in-app notice for at least 30 days.
If you opted into communications, we will send you a summary email.
Continued use of the Service after the new version takes effect implies acceptance of the changes.
12. Using SingThem from AI assistants
You can connect SingThem to AI assistants such as ChatGPT or Claude (as an app or connector) to create, listen to, manage and send your songs from the conversation, by text or by voice. This section explains what changes in that case.
Sign-in and permissions: you sign in on our own page, never inside the assistant, so it never sees your password. You choose what the assistant may do (for example, see your songs, create songs with your credits or send songs on your behalf). Each access lasts one hour and is only renewed automatically if you allow staying connected; that renewal permission expires after 30 days without use.
What the assistant sends us: only what each action needs — the details of the song you ask for (names, stories, style, lyrics), the photos you choose to attach, the recipients when you ask us to send a song, and the language of the conversation. We do not receive the rest of your conversation.
What we send back: the information about your songs that you ask for (titles, lyrics, status, covers, temporary links to listen or download) and your available credits. That information becomes part of your conversation and is processed by the assistant provider (OpenAI for ChatGPT, Anthropic for Claude) under its own privacy policy, as is your voice if you use voice mode. SingThem does not control how they keep your conversations.
In-chat interface: some answers show a small SingThem interface (player, gallery, creation form) inside the assistant. It runs isolated by the assistant, uses no cookies or analytics, and only talks to our server through the assistant. Photos you upload from it go directly to our storage through temporary signed links.
Usage metrics: for each action we keep daily counters (which action, which assistant, whether it worked and how long it took), without the content of the request or your identity, and we delete them after 90 days.
Disconnecting: you can disconnect SingThem at any time in the assistant's settings; from then on it no longer uses the access, which expires on its own. You can also write to us to revoke it immediately. Your account and songs remain in SingThem; to delete them, use the account deletion option (section 7).
13. Contact
For any privacy-related question, exercise of rights or security incidents: privacy@cookthem.com.
For general support: support@cookthem.com.
Supervisory authority in Spain: Agencia Española de Protección de Datos, www.aepd.es.
