1.Overview and scope
This Privacy Policy explains how [LEGAL ENTITY NAME], a [STATE OF FORMATION] [ENTITY TYPE] (“Sussmayr”, “we”, “us”), collects, uses, shares, and protects information when you use our websites at sussmayr.com and sussmayr.app, the Sussmayr songwriting application, and related services (the “Service”).
It applies to information we handle as a business — your account, your use of the Service, and the songs and files you store with us. It does not apply to third-party sites or services we link to, which have their own policies. Using the Service is also subject to our Terms of Service.
We are the controller of the information described here. Our contact details are in Section 18.
2.Information we collect
Information you give us
- Account information — your name or display name, email address, password (stored only as a salted hash), and, if you sign in with a third-party provider, the basic profile information that provider shares with us.
- Profile information — anything optional you add, such as an avatar, artist or band name, bio, or location.
- Billing information — your plan, billing email, billing address, and transaction history. Payment card details go directly to our payment processor; we never receive or store your full card number.
- Your song content — lyrics, chord charts, song sections, arrangements, notes, comments, album and track metadata, version history, and any files you upload such as audio demos, voice memos, stems, images, and artwork. See Section 3.
- Collaboration information — the email addresses you use to invite collaborators, workspace and team membership, roles and permissions, and comments or activity you share with others.
- AI prompts — the instructions and text you submit to AI features, and the results returned. See Section 5.
- Communications — messages you send us through support, the contact form, or email, including their contents and attachments.
Information we collect automatically
- Device and connection data — IP address, browser type and version, operating system, device identifiers, language, and time zone.
- Usage data — pages and features viewed, actions taken (for example, that a rhyming panel was opened or an export was generated), timestamps, referring pages, session duration, and approximate location inferred from IP address at a city or region level.
- Log and diagnostic data — server logs, crash reports, performance metrics, and error traces.
- Cookies and similar technologies — see Section 6.
We record that you used a feature, not what you wrote in it. Our analytics and logging are designed to capture the shape of usage, not the substance of your songs.
Information from third parties
- our payment processor (subscription status, payment outcomes, partial card details such as brand and last four digits, fraud signals);
- authentication providers, if you choose to sign in with one;
- a collaborator or team administrator who invites you, who may provide your email address; and
- analytics and infrastructure providers acting on our behalf.
3.Your songs: what we commit to
Your unreleased songs are among the most sensitive things you could store with an online service, so we want to be specific about how we treat them.
We do not use your lyrics, music, recordings, or uploads to train, fine-tune, or improve any AI or machine learning model of our own.
What a third-party AI provider may do with a prompt you send it depends on your plan. On paid plans we access providers on business or API terms under which your Input is not used to train their models and is retained only briefly for quality control and safety. On the free plan, some providers may retain your Input and use it to train their models. This applies only to material you choose to send to an AI feature — see Section 5. Songs you simply write and store in Sussmayr are never sent to an AI provider at all.
- We do not sell your content, and we do not share it for advertising or cross-context behavioral advertising.
- We do not publish it or make it public. Your songs are private to you and to the collaborators you choose to invite.
- We do not read it routinely. Access by our personnel is restricted, logged, and limited to specific circumstances: when you ask us for support and we need to look in order to help; to investigate a suspected violation of our Terms of Service or a security incident; to respond to a valid legal request; or where necessary to protect the rights or safety of someone.
- We may use de-identified, aggregated statistics about how the Service is used — for example, how many songs an average project contains, or aggregate feature adoption and error rates — to understand and improve the product. This information does not identify you and does not include or reveal the substance of your songs, and we do not attempt to re-identify it.
- Automated systems may process your content to provide the Service — search and indexing, spell checking, syllable counting, rhyme and chord suggestions, exports, malware scanning of uploads, and transmitting your Input to an AI provider when you use an AI feature.
Ownership of your songs is addressed in our Terms of Service: you keep every right in what you write.
4.How we use information
We use the information described above to:
- provide, operate, and maintain the Service, including storing and syncing your songs and delivering AI features you request;
- create and manage your account and authenticate you;
- process payments, manage subscriptions, and send billing notices;
- enable collaboration, invitations, sharing, and team management;
- provide customer support and respond to your messages;
- send service and transactional messages, such as security alerts, billing notices, and changes to our terms;
- send product updates and marketing, where permitted — you can unsubscribe at any time;
- monitor, troubleshoot, secure, and improve the Service, including debugging, capacity planning, and measuring feature usage;
- detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service;
- comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims; and
- with your consent, for any other purpose we describe at the time.
Legal bases (EEA, UK, and Switzerland)
- Performance of a contract — providing the Service, your account, collaboration features, AI features you invoke, and billing.
- Legitimate interests — securing and improving the Service, preventing fraud and abuse, aggregate analytics, and direct marketing to existing customers, balanced against your rights.
- Consent — non-essential cookies and analytics where consent is required, and marketing email where required. You may withdraw consent at any time.
- Legal obligation — tax, accounting, and responding to lawful requests.
5.AI features and what is sent to AI providers
Some features use third-party AI models to generate lyrics, suggestions, or music. Those features run only when you invoke them. If you never use an AI feature, your song content is not sent to an AI provider.
What is sent
When you use an AI feature, we transmit your prompt together with the context needed to answer it — for example, the section of lyrics you asked about, a style description, or relevant parts of the song you are working in (your “Input”). We send the minimum context the feature needs. We do not send your account password or your payment details. Requests are associated with a pseudonymous account or request identifier for rate limiting and abuse prevention rather than your name.
Who receives it
Depending on the feature and on routing, availability, and cost, your Input may be processed by:
- Anthropic (Claude models) — text and lyric generation;
- Google (Gemini models and the Lyria family of music generation models) — text and music generation;
- OpenAI — text generation;
- OpenRouter — a routing service that forwards requests to models operated by the above and other model providers. Where a request is routed through OpenRouter, the practices of the underlying model provider apply and can vary by model and route.
We may add, remove, or change providers and models over time. Each provider processes your Input under its own terms and privacy policy, which we do not control and which may change.
How providers handle it
- Training — paid plans. For paid plans we access these providers on business, enterprise, or paid API terms under which submitted content is not used to train their models. We do not opt in to any model-improvement program on your behalf.
- Training — free plan. Free AI capacity is served in part by models and providers offered on free, trial, community, or consumer tiers. Some of those providers may retain your Input and Output indefinitely and may use them to train, fine-tune, or otherwise improve their models, and their staff or contractors may review that material. We cannot limit this by contract on those tiers. Free routes through OpenRouter in particular may permit training on prompts. If you do not want your prompts used for model training, use a paid plan or do not use the AI features.
- Retention. On paid plans, providers may retain Input and Output for a limited period — commonly up to 30 days, and longer where a legal or safety hold applies — for quality control, abuse monitoring, security, and legal compliance. Retention periods are set by each provider. On the free plan, retention may be indefinite as described above.
- Safety systems. Providers may run automated classifiers over Input and Output to enforce their usage policies, which can result in a request being blocked.
- Watermarking. Generated audio may carry provenance signals such as Google's SynthID identifying it as AI-generated.
- Location. Providers may process data in the United States and other countries. See Section 14.
To review the providers' own practices, see the privacy policies published by Anthropic, Google, OpenAI, and OpenRouter. If you would rather not have any content processed by an AI provider, simply do not use the AI features; the rest of the Service works without them.
Legal and creative limits on AI output — including that output may not be unique and may not be protectable by copyright — are covered in our Terms of Service.
8.How long we keep information
We keep information for as long as your account is active and as needed to provide the Service. After that:
- Your content is retained until you delete it or close your account. On account closure we make your content available for export for at least 30 days, then delete it from active systems.
- Backups containing deleted content are overwritten on our normal backup rotation, typically within 90 days.
- Content shared with collaborators may remain in their workspaces or copies, which we cannot delete on your behalf.
- Billing and tax records are kept as long as required by law, typically seven years.
- Security, abuse, and audit logs are kept for a limited period, typically up to 12 months.
- Support communications are kept for as long as needed to resolve issues and maintain a record.
- Aggregated and de-identified data may be kept indefinitely.
We may retain information longer where necessary to comply with a legal obligation, resolve a dispute, or enforce our agreements.
9.Security
We use technical and organizational measures appropriate to the risk, including encryption in transit (TLS), encryption of data at rest, hashed passwords, access controls and least-privilege administrative access, logging, network protections, and regular updates to our dependencies and infrastructure.
No service can guarantee absolute security. You are responsible for using a strong, unique password, enabling any additional security features we offer, keeping your credentials confidential, and being careful about who you invite to your work. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law.
10.Your choices and how to exercise your rights
Regardless of where you live, you can:
- Access and correct your account information in your account settings;
- Export your songs and content from the Service;
- Delete individual content or your entire account;
- Opt out of marketing email using the unsubscribe link in any marketing message — you will still receive transactional messages about your account and billing; and
- Control cookies through your browser.
To make a request you cannot complete in the app, email privacy@sussmayr.com. We will verify your request, usually by confirming control of the email address on the account, and may ask for additional information for sensitive requests. We respond within the timeframe required by applicable law — generally 45 days in the United States (extendable by another 45 with notice) and one month in the EEA and UK (extendable by two months for complex requests). We will not discriminate against you for exercising your rights.
If you received an invitation from a collaborator and want your information removed, contact the person who invited you, or email us and we will help.
11.California privacy rights (CCPA/CPRA)
If you are a California resident, you have the rights described here.
What we collect and why
In the past 12 months we have collected the following categories of personal information, for the business purposes described in Section 4, from the sources described in Section 2, and disclosed each to the service providers described in Section 7:
- Identifiers — name, email address, account ID, IP address.
- Customer records — billing name and address, payment status.
- Commercial information — plan, subscription and transaction history.
- Internet or network activity — usage, feature interactions, device and log data.
- Geolocation — approximate location inferred from IP address (city or region level).
- Audio, electronic, and visual information — the song content and files you create or upload.
- Professional information — artist, band, or organization details you choose to provide.
- Inferences — limited preferences derived from usage to operate the Service.
We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding 12 months. We do not sell or share the personal information of anyone we know to be under 16. We do not use or disclose sensitive personal information for purposes beyond those permitted under CCPA section 7027(m), and we therefore do not offer a “limit the use of my sensitive personal information” option.
Your rights
- Know the categories and specific pieces of personal information we collected, the sources, our purposes, and the categories of third parties to whom we disclosed it;
- Delete personal information we collected from you, subject to legal exceptions;
- Correct inaccurate personal information;
- Opt out of sale or sharing — not applicable, as we do not sell or share; and
- Non-discrimination for exercising your rights.
Submit a request at privacy@sussmayr.com. You may use an authorized agent, who must provide written permission signed by you and whose authority we may verify directly with you. California residents may also request information about disclosures for third-party direct marketing under California's “Shine the Light” law — we make no such disclosures.
12.EEA, UK, and Swiss privacy rights (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we are the controller of your personal data and the legal bases in Section 4 apply.
Your rights
- Access a copy of the personal data we hold about you;
- Rectification of inaccurate or incomplete data;
- Erasure of your data in the circumstances the law provides;
- Restriction of processing in certain circumstances;
- Portability — receive data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- Object to processing based on our legitimate interests, including profiling, and to direct marketing at any time;
- Withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal; and
- Complain to your local supervisory authority or, in the UK, the Information Commissioner's Office. We would appreciate the chance to address your concern first.
Automated decision-making. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. AI features generate creative suggestions at your request and do not make decisions about you.
To exercise these rights, email privacy@sussmayr.com.
13.Other US state privacy rights
If you are a resident of Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Montana, or another state with a comprehensive consumer privacy law, you have the right to confirm whether we process your personal data and to access it, to correct inaccuracies, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not sell personal data, engage in targeted advertising, or conduct such profiling, so those opt-outs do not apply to our processing.
We obtain consent before processing sensitive data where the law requires it. Submit a request at privacy@sussmayr.com. If we decline your request, you may appeal by replying to our decision with the word “Appeal”; we will respond within 45 days (or 60 days where the applicable state law allows) and, if we deny the appeal, tell you how to contact your state attorney general.
14.International data transfers
We are based in the United States and our infrastructure and service providers, including our AI providers, may process information in the United States and other countries whose data protection laws differ from those where you live.
Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with additional technical and organizational measures where needed. You may request a copy of the relevant safeguards by emailing privacy@sussmayr.com.
15.Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. Users between 13 and 17 may use the Service only with the involvement of a parent or guardian as described in our Terms of Service.
If you believe a child under 13 has provided us personal information, contact privacy@sussmayr.com and we will delete it and close the account.
16.Do Not Track and Global Privacy Control
There is no common industry standard for responding to browser “Do Not Track” signals, and we do not respond to them. We do not track you across third-party websites for advertising.
Where required by law, we treat a Global Privacy Control (GPC) signal from your browser as a valid opt-out of the sale or sharing of personal information for the browser sending it — though, as noted above, we do not sell or share personal information.
17.Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice by email or in the app before the change takes effect. Where required by law, we will obtain your consent.
We encourage you to review this page periodically. Continuing to use the Service after an update takes effect means you accept the updated Policy.
18.Contact us
Questions, requests, or concerns about privacy? Email privacy@sussmayr.com, or write to us:
[LEGAL ENTITY NAME]
Attn: Privacy
[STREET ADDRESS, CITY, STATE ZIP, USA]
If you are in the EEA or UK and are not satisfied with our response, you may lodge a complaint with your local supervisory authority.
