Legal
Privacy Policy
This policy explains what LyricPatch receives, why it is used, who processes it, and when project data is deleted.
1. Information we collect
Account information
When you sign in, we receive your email address, authentication provider identifier, age confirmation, policy acceptances, account timestamps, and security signals. Google provides only the profile information shown during its consent flow.
Signup-free agent sessions create a separate internal owner identity without a website login or email address. We process session and API credentials, delegated eligibility and policy attestations, access and credit limits, and associated x402 purchase and credit-ledger records to secure that session and its private projects. Keep your session secret privately: it can recover access to the session, and a lost secret has no email recovery. Payment records are not public login credentials.
Project content
We process uploaded audio, filenames, technical audio properties, selected regions, separated stems, transcripts, corrected and target lyrics, generated previews, edit manifests, and exports. Project content may contain voices or other personal information about you or people whose audio you control.
Transactions and usage
We keep credit-ledger entries, job statuses, generation duration, purchase records, Stripe customer and checkout references, refund status, security logs, device/network information, abuse-prevention signals, and product analytics. We do not receive full payment-card numbers from Stripe.
2. How we use information
- authenticate accounts, grant promotional credits, and keep balances accurate;
- upload, decode, separate, transcribe, synthesize, blend, and export your project;
- secure the service, prevent free-credit farming, investigate abuse, and enforce policies;
- process purchases, deliver receipts, restore failed reservations, and resolve support requests;
- measure aggregate product reliability and conversion; and
- comply with legal obligations and respond to valid rights complaints.
We do not train machine-learning models on uploaded audio, stems, transcripts, lyrics, previews, or exports. We do not retain reusable voice embeddings.
To understand how new accounts find LyricPatch, we use a first-party, seven-day cookie containing the first public landing page, referring website hostname, and limited campaign labels. We do not collect referring-page contents, full referrer URLs, search terms, or advertising click identifiers. We honor Global Privacy Control and Do Not Track signals for this attribution. Missing information is reported as unknown.
At successful signup, we also record a coarse device category, country when supplied by our network provider, and a keyed, pseudonymous network identifier to help investigate repeated free-credit claims. Raw IP addresses and full browser user-agent strings are not stored in this signup report. A shared network is not proof of shared identity and does not automatically suspend an account or remove credits. Signup reports are owner-only; network identifiers are removed after 30 days and signup context after 90 days. Existing account, legal, payment, and credit-record retention remains unchanged.
3. Project retention
Audio, stems, transcripts, lyrics, previews, generations, and exports are scheduled for automatic deletion 24 hours after project creation, including when a project is incomplete. Signed download links expire sooner. Account details, purchases, credit-ledger records, legal acceptances, abuse reports, and records needed for tax, fraud, dispute, or legal compliance may be retained for longer.
Content-free operational records, such as processing status and elapsed time, are kept for up to 90 days. Anonymous daily reliability totals are kept for one year. These reports do not contain audio, lyrics, signed download links, or project manifests. Financial-record retention is unchanged.
4. Service providers
LyricPatch uses providers acting on our instructions: Hostinger VPS infrastructure for the website and API; Supabase for authentication and database services; Cloudflare for private R2 storage, Turnstile abuse prevention, and outbound tunnel routing; Modal for short-lived audio generation and CPU export jobs; OpenAI for optional selected-clip transcription; RunPod as a dormant rollback inference provider; Stripe for checkout; and SendGrid for transactional email. Providers may process data in the United States and other places where they operate.
When you choose “Find the words for me,” we send OpenAI only your selected 0.1–6 second audio clip, not the whole song, project details, or private download links. OpenAI returns the detected words. We use its transcription API without opting in to model-training data sharing. Temporary source-audio caching on our server avoids repeat transfers and remains subject to project deletion and expiry.
An agent can instead supply its own timestamped transcript and target phrase for local phrase matching. That operation does not send your song or transcript to an external transcription provider, does not independently verify the supplied words against audio, and does not persist the submitted transcript or matches. If a match is used to create an edit, the selected timing and lyrics become ordinary project content under the retention policy above. Any transcription performed by your chosen agent is separate from LyricPatch; review its data-processing terms and authorize media sharing before use.
5. When information is shared
Authorized LyricPatch administrators may privately review a specific active project to investigate a rights complaint or assist with customer support. This requires a verified owner account, authenticator verification, and a recorded reason. Access is time-limited and audited without retaining copies of the song or lyrics in audit records. Review does not make your project public, grant other customers access, or extend its deletion schedule. Already expired or deleted project content is not available for review.
We share information with service providers to operate LyricPatch, with professional advisers under confidentiality, in a business transaction subject to appropriate safeguards, when you direct us to, or when reasonably necessary to comply with law, protect rights and safety, investigate fraud, or enforce policies. We do not sell personal information or share it for cross-context behavioral advertising.
6. Cookies and analytics
Authentication and security cookies keep you signed in and help prevent abuse. Our owner reports use account, upload, successful-generation, prepared-export, and payment records to understand product usage. Optional first-party signup attribution is described above; we do not use advertising pixels, session replay, cross-site fingerprinting, or recordings of your editing activity for these reports. Preparing an export is not tracked as a confirmed download.
To find product problems, we record content-free outcomes of authenticated free-credit claims, generation requests, and checkout creation, including broad error categories. If you choose to rate a preview, we save only whether it was useful and its internal version identifier. These owner-only records expire after 90 days and do not affect your credits. Your browser may also keep your unfinished words and editing place in same-tab session storage until project expiry so you can return after checkout; no lyrics are sent to Stripe or added to checkout URLs.
We use Google Analytics across our website and product screens to understand traffic sources and engagement. Google processes visit, browser/device and approximate location information and may store analytics cookies for up to 180 days. We report generic page names such as Editor and Account, not private project identifiers, authentication codes, checkout identifiers, lyrics or audio. Referrers are reduced to their website origin, and only bounded campaign values are included. Automatic outbound-link, download-link, search, form and browser-history capture are disabled. We disable advertising signals and personalization and honor browser Global Privacy Control and Do Not Track signals. There is no analytics consent popup. Detailed conversion and usage records remain in the owner-only reports described above. You may also use browser tracking protection or Google’s Analytics opt-out tool.
7. Security
We use private object storage, short-lived signed URLs, encrypted transport, tenant-scoped random object keys, restricted service credentials, access controls, and automatic deletion. No security measure is perfect. Contact [email protected] if you believe an account or project is at risk.
8. Your choices and rights
You can delete a project from the Studio, request account deletion, unsubscribe from optional marketing, and ask to access, correct, or delete eligible personal information. Depending on where you live, you may have additional rights to receive a copy, restrict or object to processing, appeal a denial, or use an authorized agent. We may verify identity before acting.
9. Children
LyricPatch is for verified users aged 18 or older and is not directed to children. If we learn that a minor submitted personal information, we will take reasonable steps to delete it.
10. Changes and contact
We may update this policy as the service or law changes. Material changes will be posted with a new effective date. Privacy requests may be sent to [email protected].
Operator: Bigbee Solutions LLC, d/b/a LyricPatch
Mailing address: 3202 N 27th St, Phoenix, AZ 85016