Privacy Policy
Last updated: October 3, 2026
This Privacy Policy explains what information the Melodo iOS app (the “App”) processes, why, and what choices you have. The App is developed and published by Hanna Freitag (“we”, “us”). We keep data collection to the minimum the App needs to work.
Information the App processes
- Account data. When you sign in with Apple, Google or an emailed link we receive a user identifier and, if you share it, your email address. It keeps your credits, purchases and songs linked to you. We also store the language the App is set to, so notifications reach you in it.
- Song requests you submit. The description, style, any lyrics you type and, if you give it, how a name should be pronounced are sent to Google’s Lyria and Gemini models on Vertex AI to compose the track, its title and its cover. They are used solely to fulfil your request and are not used to train AI models. HD songs and songs sung in your own voice are composed by Mureka instead, which receives the same request and the lyrics and returns the song.
- Photos you choose. When you make a song from a photo, the photo you take or pick is sent once to Google’s Gemini model on Vertex AI, which writes a short description of it for your song. The photo is not stored, not added to your library and not used to train AI models; only the description, which you can edit before sending, becomes part of your song request. When you make a photo slideshow video for a song (a subscription feature), the photos you pick are uploaded to our cloud storage and kept with that song so the video can be made again; they are deleted when you delete the song. The finished slideshow is kept with the song too, and if you send the song as a gift, the gift page shows it to anyone who has the gift link. These photos are not used to train AI models either.
- Chats you share. When you make a song from a chat, the messages you paste or the screenshots you add are sent once to Google’s Gemini model on Vertex AI, which writes a short song description from them. They may contain other people’s messages, so share only what you are entitled to share. The chat is not stored, not added to your library and not used to train AI models; only the description, which you can edit before sending, becomes part of your song request.
- Your voice recording (My voice). If you buy My voice and record yourself singing in the App, the recording (15–30 seconds) is uploaded to our servers. Google’s Gemini model on Vertex AI listens to it once to check that it holds a single voice and no music, and it is then sent to Mureka (Skywork AI Pte. Ltd., Singapore), which makes a voice model from it. We keep the cleaned recording and the identifier of that voice model with your account, so the songs you ask for can be sung in your voice. Your voice is used only for your own songs; it is never used to identify you or to train AI models. Before the recording is sent, you confirm that it is your own voice. Deleting your voice in the App, or deleting your account, removes the recording from our servers, and the voice model is never used again. Mureka keeps data under its own privacy policy and does not currently offer a way for us to delete a voice model it has made. Requests to Mureka, including your recording, pass through each::labs (Eachlabs Inc., United States), which forwards them to Mureka on our behalf, keeps the files only for a limited time (the recording is deleted within an hour) and does not use them to train AI models.
- Generated songs and library. Finished tracks, covers, titles and lyrics are stored in your account so you can play, rename, share and delete them. A song you share by link gets a public page with its title, cover, lyrics and audio until you stop sharing it. When you make a lyric video, it is rendered from your song on our servers, and Google’s Speech-to-Text listens to the song’s audio to time the lines. Deleting a song removes its files; deleting the account removes everything. A song you put in the Community is also listed publicly and for search engines (see Community below).
- Song gifts. When you send a song as a gift, the names and note you add are stored with a private link. Anyone with the link can open the gift page, play and download the song and see those names and the note. We record when the gift is first opened so we can tell you. You can revoke a link at any time, which deletes it.
- Dates and names you add (Occasions). Birthdays, anniversaries and other dates you add, with the name of the person each one is for, are stored in your account so the App can list them and, if you turn reminders on, notify you. If you connect your calendar, the App reads the next year of events on your device and sends only their titles and dates to our servers, where Google’s Gemini model picks out birthdays and anniversaries; all other events are discarded. We also store your country and time zone to show your public holidays and time the reminders. You can delete any date at any time.
- Onboarding answers. The short questionnaire shown before sign-in (what you want to create, how often) is saved to your profile to tailor suggestions.
- Purchase data. Subscription status and credit balance, received from Apple or Google Play via Adapty, or from Stripe for purchases made on the website, where Stripe acts as the seller. Card details never reach us. A one-time My voice purchase is recorded the same way.
- Invitations. Every account gets its own invite link. If you open the App through someone else’s link, we record that they invited you, so the invitation can be credited to them. We never share your email address or your songs with the person who invited you.
- Widget and Live Activity. The title and cover of the song being made are written to a shared area on your device so the home-screen widget and the lock-screen Live Activity can show them. They stay on the device and are not sent anywhere.
- Diagnostics, usage and attribution. Crash reports, device model and OS version, a push-notification token, in-app events such as “song created” (Google Analytics), and — only if you allow tracking — install-attribution data linked to the advertising identifier.
Device permissions
The App asks for access only when a feature needs it. You can change these permissions at any time in iOS Settings; related features will stop working without them.
- Notifications — to tell you when a song is ready and, if you take part in the Community, about comments, replies, mentions, likes, rewards and badges.
- Camera — optional; used only when you choose to take a photo to make a song from it.
- Microphone — optional; used only while you record your voice for My voice.
- Photos — not requested; the system photo picker gives the App only the photos you choose.
- Calendar — optional; read on your device to find birthdays and anniversaries, and only if you connect it.
- Background audio — so a song keeps playing with the screen off. Nothing is recorded.
- Tracking (App Tracking Transparency) — optional; used only to measure which campaigns bring people to the App.
How we use information
- Provide the App’s features you request
- Keep the App reliable: diagnose crashes and fix bugs
- Understand, in aggregate, how features are used so we can improve them
- Process purchases and restore subscriptions
- Reply to your support requests
We do not sell your personal information and do not use it for purposes unrelated to the App.
Third-party services
We rely on the following providers. They process data on our behalf under their own privacy policies:
- Google Firebase (Authentication, Firestore, Storage, Cloud Functions, Cloud Messaging, Crashlytics, Analytics, App Check) — sign-in, storing your account and songs, push notifications, crash reports, usage analytics and abuse protection; storing support requests. Policy
- Google Vertex AI (Lyria, Gemini) — composing songs and cover art from your requests, describing photos you choose and sorting calendar events; drafting replies to support requests, which a person reviews before sending. Policy
- Mureka (Skywork AI Pte. Ltd.) — composing HD songs and songs sung in your own voice, and making your voice model from your recording. Policy
- each::labs (Eachlabs Inc.) — passing requests for HD songs, songs sung in your own voice and voice models on to Mureka on our behalf. Policy
- Google Cloud Speech-to-Text — timing the lines of lyric videos from the song’s audio. Policy
- Adapty — managing subscriptions, credit packs and paywalls. Policy
- AppsFlyer — install attribution, only with your tracking permission for the advertising identifier. Policy
- TikTok (Pixel and Events API; TikTok Pte. Ltd. / TikTok Technology Limited) — advertising measurement for the quiz on our website (quiz.melodo.app) only, not in the App: quiz steps and purchases with hashed identifiers, as described under “Website quiz and TikTok ads”. Policy
- Sign in with Apple / Google Sign-In — signing in to your account. Policy
- Stripe — payments for credits and subscriptions bought on the website. Policy
- Postmark (ActiveCampaign) — sending sign-in emails and our replies to your support requests. Policy
- SendGrid (Twilio) — sending sign-in emails and our replies to your support requests. Policy
- Namecheap Private Email — hosting our support mailbox, support@melodo.app. Policy
Tracking and advertising
The App asks for permission via Apple’s App Tracking Transparency prompt before using your device’s advertising identifier (IDFA) for attribution. If you decline, the IDFA is not accessed. You can change this at any time in Settings → Privacy & Security → Tracking.
Purchases and subscriptions
Payments are processed by Apple through the App Store. We never see or store your payment card details. We receive only the information needed to confirm your purchase or subscription status. Subscriptions renew automatically unless cancelled at least 24 hours before the end of the current period; manage or cancel them in Settings → [your name] → Subscriptions.
Account and deletion
If you create an account, we store the identifier provided by your sign-in method (Apple, Google or email) to keep your content and purchases linked to you. You can delete your account and associated data from within the App or by emailing us; we will complete the deletion within 30 days.
Support requests
When you contact us through the support form in the App, in the web app or on the website, we receive the email address you enter, the topic you choose, your message and any screenshots you attach (up to three). If you are signed in, the request is also linked to your account identifier and includes a snapshot of the account details we need to help you: your credit balance, subscription status and recent failed songs, along with the app version, platform and language. To protect the form from abuse, we store a one-way hash of your network (IP) address, not the address itself, and use it only to limit how many requests can be sent.
We use this information only to answer your request, fix the problem you report, add compensation credits to your account where appropriate and prevent abuse of the form.
Requests and screenshots are stored in Google Firebase (Firestore and Cloud Storage). To help us answer faster, a draft reply may be prepared with Google’s Gemini model on Vertex AI, where Google acts as our processor and does not use the data to train its models; every reply is reviewed and sent by a person. Replies are emailed through Postmark (ActiveCampaign) or SendGrid (Twilio), and our support mailbox, support@melodo.app, is hosted by Namecheap Private Email. When a new request arrives, our team is notified without your email address or the text of your message.
We keep a request for as long as it is needed to handle it and, if it is linked to your account, for as long as the account exists. Deleting your account, in the App or on the account page of the website, also deletes your requests and their screenshots, including requests sent from your account’s email address without signing in. Emails exchanged with support@melodo.app are kept in that mailbox only as long as needed and are deleted on request. If you contacted us without an account, you can ask us to delete your request by writing to support@melodo.app.
Community
If you take part in the Community on our website, where people put songs they have made in a public feed, we process the following: your @tag, the public username you choose, and when you last changed it; the songs you put in the Community, as public copies with their title, lyrics, cover and audio; your likes (which song and when); your comments (the text, when you posted it, the song and the comment you replied to); counters of your activity (songs published, likes given and received, comments, fans, credits earned through the Community) and the badges you have been given; the list of people you have chosen to hide; and moderation records: reports about songs and comments, content we have hidden, and whether your access to the Community is suspended and why. Plays of a Community song are counted as a number only; we do not record who played it.
Some of this is public. A song in the Community, with its title, lyrics, cover and audio, your @tag, your profile page with the songs you have published, your counters and badges, and the likes, comments and play counts on your songs can be seen by anyone, including visitors who are not signed in, and these pages are listed for search engines. If you have a subscription, a crown is shown next to your tag; nothing else about your purchases is shown. Your email address, your account identifier and your other songs are never shown: other people see only a short code derived from your identifier, which cannot be turned back into it, so that they can hide you. Only the author of a song can see who liked it.
We use this information to run the Community: to show songs, likes and comments, order the feed and the weekly charts, award badges and credits for fans, send the notifications you allow (comments, replies, mentions, likes, rewards and badges), let you hide people, handle reports and protect the Community from spam and manipulation. Comments containing links are refused, and how many comments can be posted in a short time is limited. To decide whether a like counts towards an author’s rewards, we check a day later that it is still there, that the person who gave it has made a song, and that their account passed the same checks against abuse as the welcome credits (for example, that it was not refused them for using a reused or disposable email address). These checks only decide whether the like counts.
This data is stored in Google Firebase (Firestore) with the rest of your account. Taking a song out of the Community, stopping its link or deleting the song deletes its likes and comments. You can delete your own comments at any time, and the author of a song can delete comments under it. Deleting your account deletes your Community profile, your likes and comments, your hide list, counters and badges; your @tag then stays reserved for 30 days, so that nobody can pass for you straight away, and is released after that. Search engines and other people may keep copies of public pages for some time after they are removed; we cannot delete those.
Website quiz and TikTok ads
The quiz on our website, quiz.melodo.app, loads the TikTok Pixel, an analytics and advertising tag from TikTok that sets the _ttp cookie in your browser. It reports the steps of the quiz to TikTok — starting the quiz, submitting your email address, starting checkout and completing a purchase (with its value and currency) — so that we can measure and improve our ads on TikTok. With the email and purchase events it sends a SHA-256 hash of your email address and of a random visitor identifier created by the quiz, not the address itself.
After a purchase, our server also reports it to TikTok through TikTok’s Events API: the hashed email address and visitor identifier, the TikTok click identifier (ttclid) if you arrived from a TikTok ad, the _ttp cookie, your IP address and browser user agent, and the order’s value, currency and product. We delete the IP address and user agent from our database once they have been sent. TikTok processes this data under its own privacy policy (https://www.tiktok.com/legal/privacy-policy) and may link it to your TikTok account if you have one.
You can limit this tracking by blocking or clearing cookies or using a tracker blocker in your browser, and in the ads and privacy settings of your TikTok account. The App itself does not contain TikTok’s code.
Data retention
Data stored on your device stays there until you delete it or remove the App. Data processed on servers is kept only as long as needed for the purpose described above, then deleted or anonymized; diagnostic and analytics data is retained according to the providers’ standard retention periods.
Children
The App is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
Your rights
Depending on where you live (for example, under the GDPR or CCPA), you may have the right to access, correct, delete or export your personal information, to object to or restrict its processing, and to withdraw consent. To exercise any of these rights, email us — we will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Security
We use industry-standard measures, including encryption in transit (HTTPS), to protect information. No method of transmission or storage is 100% secure, but we work to protect your data and limit access to it.
International transfers
Our service providers may process data in countries other than yours, including the United States. Where required, such transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
Changes to this policy
We may update this policy from time to time. The “Last updated” date above shows when it was last changed. Significant changes will be communicated in the App or on this page.
Contact
Questions about this policy or your data: support@melodo.app
Hanna Freitag