Privacy Policy

Privacy Policy for SongHQ
Jul 20, 2026

Effective date: July 20, 2026

This Privacy Policy explains what information SongHQ collects, how we use it, and the choices you have. We've written it to be readable — not just legally complete.

SongHQ is a production tool for sellers who fulfill custom-song orders (for example, on Etsy or Fiverr). Two kinds of people interact with SongHQ: sellers, who create an account and run their business through SongHQ, and their customers, who fill out intake forms, listen to review links, and view delivery pages without ever creating a SongHQ account. This policy covers both.

1. What We Collect

Seller Account Information

When you register as a seller, we collect your email address and any profile information you provide (such as your name). This is used to manage your account and contact you about the service.

Your Customers' Information

When a customer fills out one of your intake forms, submits a review response, or views a delivery page, we store what they enter (their answers, review feedback, and any name or contact details you asked for) so you can fulfill the order. This data belongs to your business relationship with your customer — you are responsible for having the right to collect it and for how you use it, and SongHQ processes it on your behalf as the tool you've chosen to run your fulfillment workflow.

Suno Credentials (BYO)

If you connect your own Suno account, we store the API key you provide in encrypted form (AES-256-GCM). It is never displayed back to you in full, and is only decrypted server-side at the moment it's needed to call the generation API on your behalf.

Generated Content

Lyrics, songs, cover art, and lyric cards produced through SongHQ are stored so you and your customers can access them — in the order workbench, on review links, and on delivery pages.

Usage Data

We collect information about how you use SongHQ — which features you use, how many orders and generations you run, and when you log in. This helps us understand how the product is being used and improve it. We also record certain actions (like admin operations) in an audit log for accountability.

Device and Browser Information

We collect basic technical information when you access our service: browser type, operating system, IP address, and referring URL. This is standard for any web service and is used for security and performance monitoring.

Cookies

We use cookies to keep you logged in and remember your preferences. We do not use cookies for advertising purposes. You can configure your browser to block cookies, but some parts of the service may not work correctly if you do.

Payment Information

Seller subscription payments are handled by Creem. We do not store your payment card details. We receive confirmation of payment and your subscription status from Creem, but not your full card number or CVV. SongHQ does not process payments between you and your customers — that happens on whatever marketplace or channel you use to sell.

2. How We Use Your Information

  • To provide the service: run your order workflow — intake, generation, review, and delivery
  • To manage your account: authentication, subscription and credit management
  • To communicate with you: service updates, billing notifications, support responses
  • To improve the product: understanding how people use SongHQ helps us make it better
  • To ensure security: detecting abuse, preventing fraud, and protecting accounts

We do not sell your personal information, or your customers' information, to anyone. We do not use it for advertising.

3. Your Customers' Data — Specifically

Because SongHQ sits between you and your customers:

  • Intake form submissions, review feedback, and delivery-page views are only accessible through unguessable, randomly generated links (or to you, as the seller who owns the order) — they are not publicly listed or indexed
  • We do not use your customers' submissions, or the songs generated from them, to train AI models
  • We do not contact your customers directly, market to them, or share their data with anyone outside the providers needed to run SongHQ (see the table below)
  • If a customer asks us directly to delete their data, we'll forward the request to you as the seller, since you control the underlying order

4. Third-Party Services

Running SongHQ requires a few third-party services. Here's what each receives:

ServicePurposeWhat They Receive
Cloud object storage (Cloudflare R2 / S3-compatible)Storage for generated audio, cover art, and lyric card assetsGenerated song files and images
AI generation provider (Suno API)Lyrics, song, and cover-art generationPrompt text derived from intake answers, and — if you've connected your own account — your API key at the moment of the call
CreemSeller subscription payment processingYour payment details and billing information
Better Auth and connected sign-in providersAuthenticationYour email address, login session data, and sign-in metadata
Hosting and application infrastructure providersApplication hosting, database, request logsRequest logs, account data, and operational metadata needed to run SongHQ

We limit sharing to service providers needed to run SongHQ. We do not share your data, or your customers' data, with unrelated third parties.

5. Data Retention

Data TypeHow Long We Keep It
Seller account informationUntil you delete your account
Customer intake/review/order dataWhile the related order or your account exists, or until you delete it
Suno API credentialsUntil you disconnect the connection
Generated assets (audio, cover art, lyric cards)While the related order or your account exists
Usage and audit logsRetained for security and accountability purposes
Payment recordsAs required by law (typically 7 years)

6. Your Rights

You can:

  • Access your data — request a copy of the personal information we hold about you
  • Delete your account — contact support and we'll remove your account and associated data
  • Correct your information — update your email or profile in your account settings
  • Export your data — ask us for an export of your account data

If you are a customer of a SongHQ seller and want to exercise these rights over data you submitted through an intake form, please contact the seller directly — they control that order. If they're unreachable, email us and we'll help.

To make any of these requests, email us at support@songhq.app.

7. Security

We use industry-standard practices to protect your data:

  • HTTPS for all connections
  • Encryption at rest for stored files and for BYO Suno API credentials (AES-256-GCM)
  • Access controls limiting which systems and personnel can access data
  • Server-side isolation of seller data — every query is scoped to the requesting seller's account

No system is completely secure. If you discover a security issue, please report it to support@songhq.app.

8. Children's Privacy

SongHQ is not intended for users under 13 years of age. We do not knowingly collect personal information from children as SongHQ account holders. If you believe a child has provided us with personal information, please contact us and we will delete it.

9. Changes to This Policy

We may update this policy from time to time. When we make significant changes, we'll notify you by email or by posting a notice in the app. The effective date at the top of this page reflects the most recent update.

10. Contact

Questions about your privacy or this policy? We're happy to help.

Operator: SongHQ Email: support@songhq.app Website: songhq.app