Vocal2Melody Privacy Policy
Effective date: July 20, 2026
1. Scope and information we process
- Controller and scope: 深圳市科米奈特信息技术有限责任公司 is the personal information handler for Vocal2Melody and, where applicable, the relevant data controller. Its registered address is 深圳市南山区桃源街道桃源社区北环大道方大广场(二期)1、2号研发楼1号楼908 (English translation for reference: Room 908, Building 1, R&D Buildings 1–2, Fangda Plaza Phase II, Beihuan Avenue, Taoyuan Community, Taoyuan Subdistrict, Nanshan District, Shenzhen, China). This Policy applies to users worldwide who access the service through vocal2melody.com.
- Account and contact information: email address, account identifier, display name, authentication status, and sign-in security records. If you choose Google sign-in, we receive the account identifier and basic profile information needed to complete authentication. If you contact support, we process the name, messages, and attachments you provide.
- User content and task information: audio you upload; filename, media type, size, duration, task title, processing mode, status, and error records; and separated vocal audio, melodies, notation, timelines, MIDI, result JSON, and related files generated by the service. Audio, tasks, and results are private to the relevant account by default.
- Subscription and transaction information: plan, credits, subscription status, order number, transaction amount, currency, payment status, and refund status. Full payment-card details are processed by Paddle and other payment providers and are not stored directly by us.
- Technical and analytics information: IP address, browser and device type, language, timestamps, request paths, necessary cookies or local-storage identifiers, feature use, experiment assignments, conversion events, and redacted diagnostic and security logs. Our analytics services receive privacy-masked link, button, and form interactions, dead or repeated-click signals, scroll and heatmap measurements, Core Web Vitals, page and session data, referrer domains, and UTM campaign data. We do not intentionally send request bodies, audio, filenames, task titles, email addresses, tokens, temporary signed links, element text, or element attributes to those services, and session recording remains disabled.
2. Purposes and legal bases
We process information needed to create and manage accounts, receive uploads, perform automated transcription, store and deliver results, manage subscriptions and credits, and provide support in order to perform our contract with you. We retain necessary records to comply with tax, accounting, consumer-protection, and other legal obligations. We process the minimum technical and redacted analytics information needed for legitimate interests such as account and system security, fraud prevention, troubleshooting, usage measurement, and product improvement. Where applicable law requires it, we obtain consent for non-essential cookies or local storage, marketing, particular international transfers, or other activities. Unless we separately explain the practice and obtain any required authorization, we do not use identifiable raw audio or transcription results to train general-purpose artificial-intelligence models and do not use user content to make automated decisions that produce legal or similarly significant effects for you.
3. Service providers, payments, and international processing
We use Supabase for authentication, databases, and private file storage; Upstash QStash to schedule asynchronous tasks; Modal for model inference; Netlify to host the website and server endpoints; and third-party analytics services for limited product analytics, feature flags, experiments, and redacted error reporting. Google processes authentication information if you choose Google sign-in. When paid features are enabled, Paddle independently processes checkout, payments, taxes, receipts, subscription management, and monetary refunds as Merchant of Record. These providers may process information outside your country or region and are also governed by their own privacy policies. We provide only the information needed for the relevant service and use data minimization, access controls, contractual measures, and other appropriate safeguards for international processing as required by applicable law.
4. Sharing, publication, and sale
Your audio, tasks, and results are private by default. We disclose only the minimum information needed to service providers, professional advisers, transaction parties, or competent authorities where necessary to provide the service, follow your instructions, complete a corporate reorganization, protect users or the platform, handle rights claims, or comply with law, courts, or regulators. We do not sell personal information, share it for cross-context behavioral advertising, or provide private audio or results to unrelated third parties. Once you download, export, or share a file, that copy is controlled by you and its recipient.
5. Cookies, local storage, and security
We use necessary cookies or browser storage to maintain sign-in sessions and remember language and interface settings. We use limited identifiers to measure service use and respect browser Do Not Track settings. You may limit or clear browser storage, but you may need to sign in again. Business tables use row-level access controls, file storage is private by default, upload and result links use time-limited authorization, internal callbacks use service authentication, and server-side secrets are not exposed to clients. We also use reasonable measures such as encryption in transit, separation of privileges, minimized logging, dependency updates, and exception monitoring. No internet transmission or storage system is absolutely secure. If a personal-data incident requires notification, we will notify affected users and authorities as required by applicable law.
6. Retention and deletion
We retain personal information only for as long as needed for the purposes described in this Policy. Specific periods depend on the data type, whether the account or service relationship continues, the processing purpose and risk, and legal requirements for tax, accounting, fraud prevention, and dispute handling. Account information is generally retained until account closure or the service relationship ends. User audio, tasks, and results are generally retained until you delete the relevant content, request account closure, or we no longer need them to provide the service. Technical, security, and analytics records are retained only as reasonably needed for troubleshooting, security, and improvement, while transaction records are retained as required by applicable law. Information in backups may remain for a limited rolling period and be used only for recovery. When retention is no longer needed, we delete or anonymize information unless it must be preserved for a pending dispute, fraud prevention, a security incident, legal hold, or another legal obligation.
7. Your rights and children
Subject to applicable law, you may request access to, a copy of, correction or supplementation of, deletion of, or restriction of personal information; withdraw consent-based processing; object to particular processing; close your account; obtain a portable copy; or appeal a processing decision. Submit requests using the contact email shown on this page. We may verify your identity and will respond within the period required by applicable law. Withdrawal does not affect processing that was lawful before withdrawal, and some information cannot be deleted immediately where needed for a legal obligation or rights claim. The service is not directed to children under 13. If local law sets a higher minimum age, that age applies. Users who cannot legally consent on their own must use the service with a parent or guardian's consent and supervision. If we learn that a child's information was processed without appropriate consent, we will promptly delete it or take other legally required measures.
8. Regional rights, updates, and contact
Users in different countries or regions may have additional rights under local data-protection law. Where mandatory law provides greater protection, that law applies, and you may complain to a competent data-protection or consumer-protection authority. We may update this Policy when features, service providers, or legal requirements change. Material adverse changes will be reasonably notified through the website, an in-product notice, or account email, and the effective date will be updated without retroactively reducing accrued rights. For questions about personal information, deletion, children's data, or this Policy, use the contact email shown on this page. Do not send passwords, full payment-card numbers, or access tokens in ordinary email.
Operations, terms, and privacy contact: support@vocal2melody.com; support phone: +86 136 2096 5109.

