Privacy Policy
Last updated: 24 May 2026
1. Who We Are
SongCrafted (“we”, “us”, “our”) operates the website songcrafted.org. We are a UK-based service that creates bespoke, musician-guided songs from personal stories. This policy explains how we collect, use, store, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
For data protection queries, contact us at: [email protected]
2. Data We Collect
We collect the following categories of personal data:
- Account information: name, email address, and hashed password when you create an account.
- Song creation data: recipient names, personal stories, memories, phrases, and other details you provide during the song creation process. This may include sensitive personal information about relationships and life events.
- Audio recordings: optional melody recordings you choose to upload.
- Payment information: processed securely by Stripe. We do not store card numbers, CVVs, or full payment details on our servers. We retain order records (amount, date, order number) for accounting purposes.
- Technical data: IP address, browser type, device information, and usage patterns collected automatically when you visit our site.
- Communication data: any emails or messages you send us.
3. How We Use Your Data
We use your personal data for the following purposes:
- Song creation: to generate personalised lyrics and music based on your stories and preferences. Your stories are processed through our proprietary behavioural engines and, where necessary, large language models to craft your song.
- Order fulfilment: to process payments, deliver your completed song, and provide customer support.
- Account management: to maintain your account, save drafts, and allow you to access your order history.
- Service improvement: to understand how our service is used and improve the quality of our output.
- Communication: to send you your completed song, order confirmations, and respond to queries. We do not send marketing emails unless you explicitly opt in.
Our lawful bases for processing under UK GDPR are:
- Contract: processing necessary to fulfil your song order.
- Legitimate interests: service improvement and fraud prevention.
- Consent: where you voluntarily provide sensitive personal stories for song creation.
4. AI and Automated Processing
Your personal stories and details are processed by our proprietary behavioural engine software and, during lyric generation, by third-party large language model APIs. This processing is essential to deliver the service you have requested.
We do not use your personal data to train AI models. Your stories are processed only to generate your specific song and are not shared with or sold to third parties for model training purposes.
5. Data Sharing
We share your data only with the following categories of recipients:
- Payment processor: Stripe processes your payment securely. See Stripe’s Privacy Policy.
- Cloud hosting: our application and database are hosted on secure cloud infrastructure.
- AI processing: anonymised or pseudonymised portions of your input may be sent to language model APIs for lyric generation. No personally identifiable information beyond what is necessary for song creation is transmitted.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
6. Data Retention
- Account data: retained for as long as your account is active. You may request deletion at any time.
- Song data and drafts: retained to allow you to access your songs and order history. Incomplete drafts may be automatically purged after 90 days of inactivity.
- Payment records: retained for 7 years as required by UK tax and accounting regulations.
- Audio recordings: retained alongside the associated order. You may request deletion at any time.
7. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate data.
- Erasure: request deletion of your personal data (“right to be forgotten”).
- Restriction: request that we limit how we process your data.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encrypted connections (HTTPS/TLS) for all data in transit.
- Passwords stored using bcrypt one-way hashing — we cannot see your password.
- Payment processing handled entirely by PCI-DSS compliant Stripe infrastructure.
- Access controls limiting who within our team can view customer data.
- Regular security reviews of our application and infrastructure.
9. Cookies and Tracking
We use essential cookies required for the site to function (authentication session cookies). We do not use advertising cookies or third-party tracking cookies. If we introduce analytics in the future, we will update this policy and provide appropriate consent mechanisms.
10. Children’s Privacy
SongCrafted is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. International Transfers
Your data may be processed on servers located outside the UK. Where this occurs, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses or adequacy decisions) to protect your data in accordance with UK GDPR requirements.
12. Complaints
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last updated” date. We encourage you to review this policy periodically.
Contact Us
For any questions about this Privacy Policy or how we handle your data:
Email: [email protected]
Website: songcrafted.org
