Privacy Policy
Last updated: June 29, 2026
1. Introduction
Lyrio (“Lyrio”, “we”, “us”, “our”) respects your privacy and is committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR). This Privacy Policy explains what data we collect, how we use it, and the rights you have. It applies alongside our Terms of Service.
2. Data Controller
The data controller responsible for your personal data is Lyrio, established in the Czech Republic. For any privacy matter, contact us at support@thelyrio.com.
3. Information We Collect
We collect the following information:
- Song questionnaire data:the recipient’s name, the occasion, your personal story and details, and your chosen genre and mood.
- Third-party information:the personal story you provide may contain personal data about other people — in particular the person the song is for. See “Third-Party Personal Data” below.
- Buyer email address, collected at checkout and used to deliver your song.
- Payment information, processed by Stripe. We never receive or store your full card details.
We also collect automatically:
- your IP address, browser type, and device/technical information.
4. How We Use Your Data
We use your data to:
- generate your song using AI (lyrics and music);
- process your payment;
- deliver your song and send transactional emails;
- maintain security and prevent fraud and abuse;
- comply with our legal obligations.
5. Legal Basis for Processing
We process your data on the following legal bases under the GDPR:
- Consent — e.g., when you submit the questionnaire and unlock a song;
- Performance of a contract — delivering the song you purchased;
- Legitimate interest — security, fraud prevention, and improving the Service;
- Legal obligation — e.g., tax and accounting requirements.
6. AI Processing
To create your song, your questionnaire content is processed by third-party AI providers: Anthropic (Claude API) for the lyrics and fal.ai / MiniMax for the music. This data is processed under their commercial API terms and is not used to train their models. Under Anthropic’s commercial terms, API inputs and outputs are deleted within 30 days.
7. Data Sharing / Subprocessors
We share data only with the service providers (subprocessors) needed to run Lyrio. We do not sell your personal data.
- Supabase — Database and audio file storage (servers in the EU, Frankfurt).
- Stripe — Payment processing (we never store your card details).
- Resend — Transactional email delivery.
- Anthropic (Claude API) — AI lyrics generation.
- fal.ai / MiniMax — AI music generation.
8. Data Retention
We retain your questionnaire data and songs for a reasonable period (up to 2 years) so you can access your song and receive support. Payment records are kept for up to 7 years to comply with EU tax and accounting law. Email communications are retained as long as needed for support and record-keeping. We delete or anonymize data when it is no longer needed.
9. Your Rights Under GDPR
You have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”);
- restrict processing;
- data portability;
- object to processing;
- withdraw consent at any time;
- lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at support@thelyrio.com.
10. Third-Party Personal Data
The personal story you submit may describe another person — the song’s recipient. By submitting it, you confirm that you have the right to share that information for the purpose of creating the song.
If you are someone a song was made about and you want that data removed, contact us at support@thelyrio.com and we will handle your request, including erasing the relevant song and questionnaire data.
11. Cookies
We use only essential cookies required to operate the Service (such as security and basic functionality). We do not use analytics or advertising cookies.
12. Data Security
We protect your data using industry-standard measures: encrypted connections (HTTPS), PCI-compliant payment processing via Stripe, EU-hosted storage, and restricted internal access. No method of transmission or storage is completely secure, but we work hard to protect your data.
13. International Transfers
Our primary storage is hosted in the EU (Supabase, Frankfurt). However, some subprocessors — including Anthropic, Stripe, and fal.ai — operate in or transfer data to the United States. Where data is transferred outside the EU, it is protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs).
14. Children's Privacy
Lyrio is not intended for anyone under 16, and we do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact us at support@thelyrio.com and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Changes are reflected by updating the “Last updated” date above.
16. Contact
For privacy questions or to exercise your rights, contact us at support@thelyrio.com.