Privacy Policy for Musicra - AI Song Generator
*Last Updated: January 9, 2026*
## Introduction
Welcome to Musicra ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").
Please read this Privacy Policy carefully. By using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our App.
This Privacy Policy complies with Apple App Store Guidelines, the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Children's Online Privacy Protection Act (COPPA).
## 1. Information We Collect
### 1.1 Device and Authentication Information
*Device Identification:*
• We generate and store a unique device identifier (10-100 characters) to associate your account and songs with your device
• This identifier is stored locally on your device (via AsyncStorage) and on our servers (Firebase Firestore)
• Device model, operating system version, app version, language, and region settings
• Account creation timestamp and last active timestamp
*Apple ID (Optional):*
• Apple ID may be linked to your account for subscription management and purchase restoration
• Used to sync subscriptions across devices
• Never used for authentication or required for basic app usage
### 1.2 User-Generated Content and Activity
*Content You Create:*
• Song prompts and original text inputs submitted for AI generation
• Generated music files, album artwork, and lyrics
• Song metadata including title, artist, genre, duration, mood, tempo, energy level, instruments, and production style
• User preferences including display name (optional), favorite genres, and notification settings
• Tags and categorization you apply to songs
*Activity and Engagement Data:*
• Song generation history (pending, processing, completed, and failed tasks)
• Song play counts and playback activity
• Songs you like or unlike
• Songs you download or share
• Collections you create
• App usage patterns and feature interactions
• Onboarding completion status
### 1.3 Subscription and Payment Information
*Subscription Data:*
• Subscription plan type (Free, Weekly, Yearly)
• Subscription status, activation date, and expiration date
• Credit balance and usage history
• Promotional credits applied to your account
*Transaction Records:*
• Transaction IDs from Apple's In-App Purchase system
• Purchase timestamps and receipt data
• Product IDs and pricing information
• Payment method type (processed by Apple)
• Subscription renewal history
*Important:* We do NOT store your payment card details. All payment processing is handled entirely by Apple's secure In-App Purchase system.
### 1.4 Automatically Collected Information
*Usage Analytics:*
• Session duration and frequency of app usage
• Feature interactions and navigation patterns
• Paywall impressions and subscription conversion events (via Superwall)
• App performance metrics and loading times
• Error logs and crash reports for debugging
*Technical Information:*
• API request logs and response times
• Generation task status and processing times
• Credit deduction and refund events
• Background audio playback activity
### 1.5 Information We Do NOT Collect
We are committed to minimal data collection. We do NOT collect:
• *Email addresses or phone numbers* (not required for basic app usage)
• *Location data or GPS coordinates* (never tracked)
• *Microphone access or audio recordings* (we generate music, not record it)
• *Camera access or photos* (except album artwork for generated songs)
• *Contacts or address book* (never accessed)
• *Social media account credentials* (except when you choose to share songs)
• *Biometric data* (fingerprints, Face ID data)
• *Health or fitness data*
• *Browsing history outside the app*
## 2. How We Use Your Information
We use the collected information for the following lawful purposes:
### 2.1 Core Service Functionality
• *Music Generation*: Process your prompts using Suno API to generate AI music
• *Library Management*: Store, organize, and retrieve your generated songs
• *Playback*: Enable audio playback with background audio support
• *Authentication*: Identify your device to provide personalized content
• *Credit Management*: Track and manage your credit balance and subscription
• *Subscription Processing*: Handle subscription purchases, renewals, and expirations via Superwall and Apple In-App Purchase
### 2.2 Service Improvement and Development
• *Analytics*: Understand usage patterns to improve features and user experience
• *Performance Optimization*: Monitor app performance, loading times, and API response rates
• *Feature Development*: Identify popular features and develop new capabilities
• *Bug Fixes*: Diagnose and resolve technical issues, crashes, and errors
• *A/B Testing*: Test new features with subsets of users to optimize experience
### 2.3 Customer Support
• *Troubleshooting*: Investigate and resolve technical issues you report
• *Communication*: Respond to support requests and feedback
• *Account Management*: Assist with subscription issues, credit inquiries, and account deletion
### 2.4 Business Operations
• *Payment Processing*: Manage transactions, refunds, and subscription renewals
• *Fraud Prevention*: Detect and prevent unauthorized access, abuse, and fraudulent activity
• *Legal Compliance*: Comply with legal obligations, tax requirements, and financial recordkeeping
• *Terms Enforcement*: Enforce our Terms and Conditions and prevent violations
• *Security*: Protect the app, our systems, and users from security threats
### 2.5 Communications (With Your Consent)
• *Push Notifications*: Send song generation completion alerts, subscription reminders, and important updates
• *In-App Messages*: Provide feature announcements, tips, and promotional offers
• *App Ratings*: Request app ratings and reviews (optional, via expo-store-review)
You can opt out of non-essential communications through app settings or device notification preferences.
## 3. Data Storage and Security
### 3.1 Where Your Data is Stored
*Local Device Storage (AsyncStorage):*
• Device ID
• Onboarding and app rating completion flags
• Apple ID (if linked)
• User preferences and audio configuration settings
• Encrypted by your device's operating system
*Cloud Database (Firebase Firestore):*
• Device profiles with credits and subscription data
• Song generation tasks and history
• Generated song metadata (title, genre, duration, etc.)
• User activity (likes, plays, shares)
• Subscription purchase history
• Hosted in the United States (Google Cloud infrastructure)
*Media Storage (Cloudinary CDN):*
• Generated audio files (MP3 format)
• Album artwork images (JPEG/PNG format)
• Distributed globally via Content Delivery Network for fast access
• Temporary files automatically deleted after successful upload
*Backend Server (Vercel):*
• API request logs and webhook callbacks
• Suno API key management and rotation
• Hosted in the United States
### 3.2 Security Measures
We implement industry-standard security practices to protect your data:
*Data Encryption:*
• All data transmitted between the app and our servers is encrypted using HTTPS/TLS (SSL)
• Data at rest is encrypted on Firebase and Cloudinary servers
• Local device storage is encrypted by iOS/Android operating systems
*Access Controls:*
• Device ID validation (10-100 character requirement)
• Firebase ID token verification for user endpoints
• Admin authentication for privileged operations
• CORS (Cross-Origin Resource Sharing) restrictions on backend
*API Security:*
• API key rotation and rate limiting
• Automatic blacklisting of compromised keys (401/429 error detection)
• Request size limits (10MB maximum)
• Helmet.js security headers on backend
*Infrastructure Security:*
• Secure hosting on Vercel (SOC 2 compliant)
• Firebase security rules restricting unauthorized access
• Regular security updates and dependency patches
• Environment variable protection for sensitive credentials
*Monitoring and Response:*
• Error logging and crash reporting for anomaly detection
• Webhook signature validation for Suno API callbacks
• Credit deduction middleware to prevent abuse
• Account deletion procedures for compromised accounts
*Limitations:*
No method of transmission over the internet or electronic storage is 100% secure. While we implement commercially reasonable security measures, we cannot guarantee absolute security. You use the app at your own risk.
## 4. Data Sharing and Disclosure
### 4.1 Third-Party Service Providers
We share your information with the following trusted third-party services essential for app functionality:
*Firebase (Google Cloud)*
• *Purpose*: Database (Firestore), real-time database, and authentication services
• *Data Shared*: Device ID, song metadata, generation tasks, user activity, subscription data, all Firestore collections
• *Data Processing*: Stores and retrieves data for app functionality
• *Location*: United States
• *Privacy Policy*: [Firebase Privacy Policy](https://firebase.google.com/support/privacy)
*Apple Inc.*
• *Purpose*: In-app purchase processing, App Store services, subscription management
• *Data Shared*: Transaction IDs, purchase receipts, subscription status, Apple ID (if linked), product IDs
• *Data Processing*: Handles all payment processing, subscription renewals, and purchase restoration
• *Location*: United States
• *Privacy Policy*: [Apple Privacy Policy](https://www.apple.com/legal/privacy/)
These service providers have access to your information only to perform tasks on our behalf and are obligated not to disclose or use it for other purposes.
### 4.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
### 4.3 Business Transfers
If we are involved in a merger, acquisition, or asset sale, your information may be transferred. We will provide notice before your information is transferred and becomes subject to a different Privacy Policy.
### 4.4 What We DON'T Do
We will never:
• *Sell your personal information* to third parties, data brokers, or advertisers
• *Share your data with advertisers* for targeted advertising
• *Use your data for marketing* without your explicit consent
• *Share your generated songs publicly* without your permission (songs are private by default)
• *Rent or lease your information* to any third party
• *Share your prompts or content* with other users without permission
• *Provide data to social networks* except when you explicitly choose to share songs
## 5. Your Data Rights and Controls
You have comprehensive rights regarding your personal data:
### 5.1 Access Rights
• *View Your Data*: Access all generated songs, generation history, and account information through the app's Library and Profile screens
• *Check Credits*: View your credit balance and usage history via /api/generate/credits endpoint
• *Subscription Status*: View current subscription, purchase history, and renewal dates
• *Device Profile*: Access detailed statistics about your account via the Profile section
### 5.2 Modification Rights
• *Update Profile*: Edit your display name, preferences, and notification settings anytime
• *Edit Songs*: Modify song metadata, titles, tags, and categorization
• *Manage Preferences*: Change favorite genres, onboarding visibility, and app settings
### 5.3 Deletion Rights
• *Delete Individual Songs*: Remove songs one-by-one using the delete button in the Library (calls DELETE /api/songs/:id )
• *Delete Your Account*: Complete account deletion available via:
- In-app: Use "Delete Account" option in Profile settings ( DELETE /api/devices/account )
- Email: Contact support at [musicraai404@gmail.com]
• *What Gets Deleted*: All device data, songs, generation history, likes, subscriptions, and associated metadata are permanently erased within 30 days
• *What Is Retained*: Transaction records for legal/tax compliance (minimum 7 years as required by law)
### 5.4 Portability Rights
• *Export Your Data*: Request a complete copy of your data in machine-readable format (JSON)
• *Download Songs*: Save generated music files to your device (coming soon)
• *Share Songs*: Export songs via social media, messaging, or email
### 5.5 Opt-Out Rights
• *Analytics*: Disable Superwall analytics tracking in app settings
• *Push Notifications*: Disable notifications via iOS/Android system settings or in-app preferences
• *Marketing*: Opt out of promotional messages (we don't send unsolicited marketing)
• *Data Sale*: We don't sell data, so no opt-out needed
### 5.6 How to Exercise Your Rights
*In-App Actions:*
• Profile → Settings → Delete Account
• Library → Select Song → Delete
• Profile → Edit Profile → Update Information
*Contact Support:*
• Email: [musicraai404@gmail.com]
• Response Time: Within 7 business days for most requests, 30 days for complex requests
• Verification: We may ask you to verify your device ID for security purposes
## 6. Children's Privacy
Our App is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will delete such information from our systems.
## 7. Data Retention
We retain your information only as long as necessary to provide services and comply with legal obligations:
### 7.1 Retention Periods by Data Type
| Data Type | Retention Period | Reason |
|-----------|-----------------|---------|
| *Device ID* | While app is active | Account authentication and service delivery |
| *Generated Songs & Prompts* | Until you delete or account deletion | Service functionality and user library |
| *Generation History* | Until account deletion | Service history and support |
| *Subscription Records* | 7 years after transaction | Legal/tax compliance (required by law) |
| *Transaction IDs & Receipts* | 7 years after purchase | Financial recordkeeping and dispute resolution |
| *Usage Analytics* | Up to 2 years | Service improvement and analytics |
| *Error Logs* | 90 days | Debugging and performance optimization |
| *Temporary Files* | Immediately after processing | Deleted after successful Cloudinary upload |
| *API Logs* | 30 days | Security monitoring and troubleshooting |
### 7.2 Deletion Process
*Account Deletion:*
• When you delete your account via DELETE /api/devices/account , we initiate a permanent deletion process
• All personal data (device profile, songs, generation history, likes) is erased within 30 days
• Cloudinary files (audio/images) are deleted from CDN
• Firebase database entries are permanently removed
• Transaction records are anonymized but retained for legal compliance
*Inactive Accounts:*
• Accounts inactive for 3+ years may be automatically deleted after email notification (if email provided)
• You can prevent this by logging in or contacting support
*Legal Holds:*
• Data may be retained longer if required by law, litigation, or investigation
## 8. International Data Transfers
Your information may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction.
If you are located outside the United States and choose to use our App, please note that we transfer your data to the United States and process it there.
## 9. California Privacy Rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
• Right to know what personal information is collected
• Right to know whether personal information is sold or disclosed
• Right to opt-out of the sale of personal information (we do not sell data)
• Right to deletion of personal information
• Right to non-discrimination for exercising your rights
To exercise these rights, contact us at [musicraai404@gmail.com].
## 10. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):
• Right to access your personal data
• Right to rectification of inaccurate data
• Right to erasure ("right to be forgotten")
• Right to restrict processing
• Right to data portability
• Right to object to processing
• Right to withdraw consent
Our legal basis for processing your data:
• Performance of contract (to provide the service)
• Legitimate interests (to improve and secure the service)
• Consent (where applicable)
## 11. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by:
• Posting the new Privacy Policy on this page
• Updating the "Last Updated" date at the top
• Providing an in-app notification for material changes
You are advised to review this Privacy Policy periodically for any changes. Changes are effective when posted.
## 12. Third-Party Links
Our App may contain links to third-party websites or services (e.g., social sharing). We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.
## 13. Analytics and Tracking
We use analytics to understand how users interact with our App:
• Firebase Analytics for usage statistics
• Crash reporting for debugging
• Performance monitoring
You can opt out of analytics through your device settings.
## 14. Cookies and Similar Technologies
Our App does not use cookies. However, our backend services may use similar technologies for session management and authentication.
## 15. Do Not Track Signals
We do not currently respond to "Do Not Track" signals from browsers, as our App does not track users across third-party websites.
## 16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
*General Inquiries:*
• Email: [musicraai404@gmail.com]
• In-App: Use the "Contact Support" feature
*Privacy-Specific Contacts:*
• GDPR Inquiries (EU residents): [musicraai404@gmail.com]
• CCPA Inquiries (California residents): [musicraai404@gmail.com]
• Data Protection Officer: [musicraai404@gmail.com]
*Response Time:* We respond to privacy inquiries within 7 business days, and complete data requests within 30 days as required by law.
## 17. Dispute Resolution
Any disputes relating to this Privacy Policy will be resolved in accordance with the dispute resolution provisions in our Terms and Conditions.
## 18. Severability
If any provision of this Privacy Policy is found to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary so that this Privacy Policy will otherwise remain in full force and effect.
## 19. Your Consent
By using our App, you consent to our Privacy Policy and agree to its terms.
---
*Effective Date:* January 9, 2026
Comments
Post a Comment