Privacy Policy

Effective September 9, 2026

This Privacy Policy describes what information LyricMyLife, operated by Michelle Alexander, collects when you use the Service, and how it is used, shared, and retained. It describes actual current behavior of the Service, not aspirational commitments.

1. Information You Provide

  • Account information: if you create an account, your email address and any name/profile information you provide, handled by our authentication provider (Neon Auth) — see Section 4.
  • Stories and song details: the recipient name, occasion, story/memory text, and style choices (tone, genre, voice style) you submit to generate a song.
  • Generated lyrics and edits: the lyrics generated from your submission, and any edits you make to them. Editing overwrites the previously stored lyrics for that song; we do not keep a separate copy of the pre-edit version.
  • Generated audio: when you generate a song’s audio, the resulting audio file is stored in our object storage so it can be played back and shared.

2. Information Collected Automatically

  • Rate-limiting data: to prevent abuse of song generation, we compute a one-way cryptographic hash of your IP address (keyed by a server-side secret) and store that hash, together with a request timestamp/count, for a short rolling window. We do not store your raw IP address.
  • Anonymous-claim cookie: if you create a song before signing in, we set an HttpOnly cookie containing a random token, and store a one-way hash of that token with the story. This lets you (and only you, via that browser) later edit that song or link it to your account when you sign in — the raw token itself is not readable by our client-side code and is never stored anywhere in reversible form.
  • Session cookie: if you sign in, an HttpOnly, signed session cookie set by our authentication provider identifies your session to the Service.
  • Server logs: our infrastructure and hosting providers generate standard operational logs (e.g. request errors) in the course of running the Service. We do not log full story text, generated lyrics, or moderation scores.

We do not currently use third-party analytics or advertising cookies.

3. Content Moderation

Story submissions and generated lyrics are checked against OpenAI’s content-moderation system before and after generation. We store only the outcome of that check (approved/blocked, and a short category label such as “hate or slur” when blocked) — not the detailed classifier scores returned by the moderation service.

4. Third-Party Service Providers

Operating LyricMyLife requires sending parts of your submission to the following categories of third-party providers, each under their own terms and privacy practices:

  • Authentication: Neon Auth, to manage sign-in/sign-up and sessions.
  • Lyric generation & moderation: OpenAI, to generate lyrics from your story and to run content moderation.
  • Music/audio generation: one of our supported AI music providers (which may include Google’s Lyria or ElevenLabs Music, depending on configuration), to turn your lyrics into an audio track.
  • Database & object storage: Neon, to store your account’s stories, lyrics, and generated audio files.

Third-party providers process information under their own terms and privacy practices, which we do not control. Where a provider’s own retention or model-training practices for submitted content are not something we can verify or guarantee from our side, we do not make claims about them here — consult that provider’s own privacy documentation if that matters to you.

5. How We Use Information

We use the information described above to:

  • generate, store, and let you play back and edit your lyrics and songs;
  • operate sign-in, session management, and account-song ownership (including linking a song you created anonymously to your account once you sign in);
  • prevent abuse of song generation (rate limiting);
  • maintain, secure, and troubleshoot the Service; and
  • record and enforce your acceptance of our Terms of Service and this Privacy Policy (see Section 8).

6. Public Sharing

A song is only made available at a public share link if and when you choose to share it. Anyone with that link can view it. We do not otherwise make your stories, lyrics, or songs visible to other users of the Service.

7. Data Retention & Deletion

We retain your stories, lyrics, and generated audio indefinitely, whether or not you have an account, so you can continue to access, edit, and share what you’ve created. If you created a song before signing in, we set an HttpOnly cookie holding a random claim token on your browser, and store only a one-way hash and expiration date of that token — never the raw token — to let that specific browser later edit the song or link it to an account. When that token expires, that browser can no longer use it to edit or claim the song, but expiration does not delete anything: the story, lyrics, and any generated audio remain stored the same as any other content on the Service. The Service does not currently provide a self-serve account-deletion or bulk-data-export flow; if you want your account or content removed, contact us at legal@lyricmylife.com.

8. Legal Acceptance Records

If you have an account, we keep a record of which version of the Terms of Service and Privacy Policy you accepted and when, for as long as your account exists. This history is not overwritten when a newer version becomes required — we retain the record of what you accepted previously alongside your current acceptance.

9. Children

LyricMyLife is intended for a general audience and is not directed to children. We do not knowingly collect personal information from children under the age required by applicable law for independent use of online services without parental consent.

10. Your Choices

You can review and edit the lyrics associated with your songs at any time before generating audio. If you no longer want a song publicly shared, use the Service’s unshare/sharing controls where available; note the limits on what unsharing can guarantee, described in our Terms of Service.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date above and treat the update as a new required version, subject to the same versioned acceptance described in Section 8.

12. Contact

Questions about this Privacy Policy can be sent to legal@lyricmylife.com or to [business mailing address — TODO: set LEGAL_MAILING_ADDRESS].