Provider and controller: Happy Songs USA Corp., a Texas C-Corporation ("Happy Songs", "we", "us", "our"), provider of the Happy Songs application for iOS and Android (the "App" or "Service") and the data controller (in Mexico, responsable) for the personal information described here.
This Children's Privacy Notice explains how we handle personal information relating to children in connection with the Service, how we obtain verifiable parental consent, the safeguards we apply because the songs we create are made for and enjoyed by children, and the rights available to parents and legal guardians. It forms part of, and should be read together with, our Privacy Notice, our Terms of Service / EULA, our Subprocessor List, and our Acceptable Use Policy. Where this Notice and the Privacy Notice address the same matter, this Notice governs as to children's personal information.
Document control
| Field | Value |
|---|---|
| Document | Children's Privacy Notice |
| Version | 1.0 (in force) |
| Effective date | June 25, 2026 |
| Last updated | August 4, 2026 |
| Applies to | United States and Mexico |
| Language | English (master). The Spanish (Mexico) version governs for data subjects in Mexico. |
| Controller / responsable | Happy Songs USA Corp. |
| Privacy contact | privacy@happysongs.ai |
Jurisdiction-specific terms for the European Union, the United Kingdom, Brazil, and other Latin American markets are addressed in separate, market-specific notices and do not form part of this Notice.
1.Scope and who we are
1.1 Scope. This Notice applies to personal information relating to a child that we collect or process when an adult Customer creates a personalized song intended for or featuring that child, and to the child-protective practices we maintain across the Service. For the purposes of the U.S. Children's Online Privacy Protection Act ("COPPA"), a "child" is a person under 13 years of age; where a broader definition of "minor" applies under a specific law (for example, under California or Texas law, or under Mexican law), we apply the protections in this Notice to that broader class of minors as required.
1.2 The controller. Happy Songs USA Corp. is the merchant of record and the entity responsible for personal information processed through the Service.
| Field | Value |
|---|---|
| Entity | Happy Songs USA Corp. (Texas C-Corporation) |
| United States registered address | 8350 Ashlane Way, Suite 103, The Woodlands, TX 77382, United States |
| Mexico operating address | Calle Tijuana 22-1, Col. Del Valle, C.P. 03100, Benito Juárez, Ciudad de México, México |
| Privacy contact | privacy@happysongs.ai |
| Support contact | support@happysongs.ai |
| Website | happysongs.ai |
1.3 Relationship to our other terms. This Notice describes our children's-privacy practices and commitments. The Terms of Service / EULA govern the contract with the Customer; the Privacy Notice describes our processing generally; the Subprocessor List is the authoritative, current list of the third parties that process personal information for us; the Acceptable Use Policy sets the enforceable content rules; and our Data Retention Policy states our retention periods. Where the Terms of Service / EULA and this Notice appear to conflict as to the contract, the Terms of Service / EULA govern; this Notice governs our children's-privacy commitments.
2.Our operating model, and why children's protections apply
The account holder is the "Customer": an adult, at least 18 years of age or the age of majority where the Customer resides, who creates and operates the account, contracts with us, and pays for the Service. The Customer is the only person who operates the Service. A child does not create an account, does not operate the Service, and is not a party to any agreement with us.
Where the Customer provides information about a child — including where the Customer creates a song for or featuring a child — the Customer represents and warrants that they are that child's parent or legal guardian, and consents on the child's behalf to the processing described in this Notice. We use the terms "parent or legal guardian" only in this consent context; in all other respects the responsible adult is the Customer.
This adult-operated model is the lawful basis for processing a child's first name through a verified, consenting adult. It is not a reason to drop children's protections. Although a child does not operate the Service, the songs we create are made for and enjoyed by children, so we keep the information we hold about a child to a first name, apply age-appropriate defaults, and never market to, advertise to, track, or profile a child. The adult-operated posture is what makes these safeguards proportionate: because we collect a child's information from a consenting adult and never from a child, our protections center on data minimization and on not marketing to children, rather than on age-verifying or policing a child user who does not exist.
We do not knowingly permit a child to create an account or operate the Service. If we learn that a child has created an account or provided personal information without a parent's or legal guardian's involvement, we will delete that account and the associated information.
Incidental, parent-supervised listening does not make the Service child-directed. As with any general-audience app, an adult Customer may let a child hear a song on the adult's own device. That incidental, supervised listening is not a child "using" or "accessing" the Service as a user, and it does not convert an adult-operated Service into one directed to children. Three affirmative facts about how the Service is built hold this line: (1) we build no profile of the child — we hold only the first name the adult provides (§3); (2) we direct no feature, screen, content, character, or message at a child — there is no child login, no child-facing mode, and nothing that invites a child to act, earn, or transact (§§7–8); and (3) we collect no data from the child — every input is provided by, and the account is operated by, the adult Customer (§§2 and 4). We do not over-claim this boundary: a minor's first name is processed, with the consenting adult's parental consent, and we still do not market to, advertise to, track, or profile a child. If a future feature were to speak to a child, or be operated by a child, that feature would change this analysis, and we would re-assess our obligations before it ships.
3.Data minimization — what we collect about a child
Data minimization is central to how we protect children. About the person a song is for, we collect and store only a first name. We do not collect or store that person's surname, nickname, age, date of birth, photograph, likeness, voice, behavioral profile, or precise location.
- A child's age or stage may be selected momentarily, in the moment of creation, only to help the Customer browse and tailor a song. This selection is used transiently and is not stored and not associated with the child.
- We do not build any profile of a child.
- We do not collect a child's date of birth. We do not use an age gate that requires a child's birth date.
No special-category (sensitive) information, of any person, at any age. We do not collect or infer health, medical, biometric, genetic, racial or ethnic, religious, political, sexual-orientation, or precise-geolocation information about any person. The Service does not capture a child's voice or image.
"Get Well" / "Mejórate Pronto" occasion. Where a song is created for a well-wishing occasion, the Service captures only a generic sentiment of encouragement or good wishes. It never captures, infers, or stores a specific illness, diagnosis, symptom, or health condition. Accordingly, it is not health or consumer-health information.
4.What we collect from the Customer
From the adult Customer, and to operate the Service, we hold:
| Category | Detail |
|---|---|
| Phone number | The Customer's primary account identifier and login, verified by a one-time code sent through our telephony provider (see the Subprocessor List). |
| Email address | Optional; used for account, support, and consent-receipt communications if provided. |
| Device and technical data | Device identifiers, app version, operating system, diagnostics, and similar technical information necessary to deliver and secure the Service. |
| Usage and analytics | Product-analytics information, which is consent-gated, off by default, and not applied to a child's information (see §5.4 and §7). |
| Song-creation content | The first name of the person the song is for, the occasion or theme, dedications, and any free text the Customer enters to create a song. |
| Communications | Messages the Customer sends to support or safety, and our responses. |
| Transaction and subscription records | Subscription status and receipts, and tax records, as described in §12. We do not store payment-card numbers. |
5.Verifiable parental consent and the adult-verification gate
5.1Adult-verification gate
Before any account is created or any child information is collected, the Customer passes an adult-verification gate. The Customer must expressly affirm, in an unbundled statement, that they are at least 18 years of age (or the age of majority where they reside) and the parent or legal guardian of the person for whom songs will be made. A bare, unverifiable checkbox is not sufficient on its own; the affirmation is paired with verification of the Customer's phone number by one-time code, which establishes a real, reachable, unique adult contact and anchors the consent record.
5.2Verifiable parental consent (VPC)
We obtain verifiable parental consent before we collect a child's first name or generate a song, and before we disclose a child's information to the third parties described in §6. Because the Service discloses a child's first name and song-creation content to third-party providers (§6), we use a method drawn from the more reliable set recognized under the amended COPPA Rule, rather than an email-based method.
Our current VPC method combines: (a) verification of the Customer's phone number by one-time code; (b) the express, unbundled parental affirmation described in §5.1; and (c) [a signed consent form, or an equivalent method from the FTC-recognized set, applied at the point of third-party disclosure]. When the Service moves from free promotional access to paid subscription (§12), payment-based verification with account notification is available as an additional recognized method.
5.3Consent is granular and by purpose
Consent is requested at the moment it is needed, in plain language, with each purpose presented as its own affirmative choice. No choice is pre-selected. The purposes are:
- Creating the song (integral). Consent to send the child's first name and the Customer's song-creation content to the AI providers named in §6 in order to generate and deliver the song. This purpose is required to use the creation feature.
- Using the person's first name (integral). Consent to use the first name the Customer provides solely to create and deliver the personalized song within the App. This grant is narrow: it is limited to service delivery, is not a grant to use the person for our marketing, and is never a grant to feature or target a child in marketing.
- Optional analytics and notifications (non-integral). A separate, off-by-default opt-in for limited, non-profiling product analytics and push notifications about the account. See §5.4.
5.4Separate consent for non-integral disclosures; no conditioning
We do not condition the Customer's ability to create a song, or the delivery of the Service, on any consent that is not integral to the Service. Product analytics and push notifications are not integral. They require a separate, express opt-in that is off by default, and declining or withdrawing that opt-in has no effect on the ability to create songs. Analytics are not applied to a child's information, operate at the account or device level, are never used to profile a child, and are never used for targeted advertising (§7).
5.5Consent record
For each consent event we keep a timestamped record that ties the consent to the exact text and provider list shown, the purpose, the state (granted, denied, or revoked), the verification method, and the account. We retain this record for the period necessary to evidence compliance, and can produce it on request from the Customer or a competent authority.
5.6Re-consent
We prompt for consent again — we do not silently continue — when a new provider or a materially new recipient or purpose is introduced, when the consent text or purposes change materially, or when the Customer adds a new child.
6.Third-party providers, disclosures, and international transfers
To generate a song we disclose a limited set of information to the third-party artificial-intelligence providers below. We obtain the Customer's express, in-App consent, which names these providers, before any of the child's information leaves the device. A link to a policy is not treated as sufficient; the providers are named on-screen at the point of consent. The Subprocessor List is the authoritative, current source of the providers we use; because providers may change, we maintain that list and re-prompt for consent when a provider materially changes (§5.6).
| Purpose | Provider(s) | Location |
|---|---|---|
| Music generation | Google (via Google Vertex AI, Lyria) | United States |
| Lyrics and text generation | Anthropic and OpenAI | United States |
| Cover art | Nano Banana (Google's Gemini image-generation model) | United States |
Minimization of what each provider receives. We limit the child's information disclosed to each provider to what that provider needs:
- The child's real first name is transmitted only to the music-generation provider, because the name is sung in the audio.
- The lyric and text providers receive a placeholder in place of the child's name; the real first name is inserted locally on the Customer's device. These providers do not receive the child's real first name.
Watermarking. Audio generated by the music provider carries a Google SynthID watermark identifying it as AI-generated.
International transfer. For Customers in Mexico, disclosing a child's first name and song-creation content to these United States providers is an international transfer of personal information. This transfer is disclosed and consented to in-App and is legitimated as described in our Privacy Notice.
Non-integral recipients. Our product-analytics and push-notification providers (identified in the Subprocessor List) are engaged only under the separate, non-conditioning opt-in described in §5.4, are not applied to a child's information, and are never used to profile a child.
No sale or sharing. We do not sell, and do not "share" for cross-context behavioral advertising, the personal information of any child, and we do not do so for any person under 16 without the opt-in that the law requires.
Allocation of risk with providers. No provider indemnifies Happy Songs against a data breach, and the music provider does not indemnify Happy Songs for intellectual-property infringement in generated output. Happy Songs therefore carries the residual risk, which we mitigate through our written information-security program and the cyber and breach-response insurance we maintain or intend to maintain (§13). We do not represent that any of these risks has been transferred away from us.
7.No profiling, no targeted advertising, no dark patterns
Regardless of any consent given, and across the Service:
- We do not build behavioral, advertising, or interest profiles of a child, and we do not use a child's information to shape what the child sees.
- We do not serve behavioral or targeted advertising to a child. The Service carries no advertising to children, and does not condition content on advertising.
- We do not collect or infer a child's precise geolocation, and no feature depends on it.
- We do not operate third-party tracking or profiling in connection with a child; any analytics are non-profiling, consent-gated, off by default, and operate at the account or device level (§5.4).
- We do not use manipulative design, false urgency, confirm-shaming, guilt or loss framing directed at a child, artificial scarcity, or engagement-maximizing mechanics that exploit a child's age-based vulnerability. Consent controls are presented without pre-ticked boxes, and withdrawing consent is as easy as granting it (§11).
- We do not operate public social features for children — no public profiles, no public feeds, no public leaderboards, and no messaging with strangers. Any progress or ranking indicators are private to the account.
8.Age-appropriate design
Because the Service is operated by adults and has no child-facing interface for a child to navigate, we meet age-appropriate-design expectations through the defaults below — high privacy, data minimization, and no marketing to children — rather than through the design of a child-user experience. These are defaults, not options a Customer must find and enable:
| Commitment | What it means in the App |
|---|---|
| High privacy by default | A child's first name and the songs made for that child are private to the account by default; there is nothing for the Customer to lock down. |
| Data minimization by default | We collect only a child's first name, and use a child's age or stage only in the moment and without storing it (§3). |
| No profiling and no targeted advertising | We do not profile a child or advertise to a child (§7). |
| Clear and honest interface | AI-generated content is labeled as AI-generated; controls to report, delete, and manage consent are easy to find; choices are not hidden behind confusing design. |
| Adult-gated actions | Account creation, consent, disclosure choices, and any purchase sit behind the adult-verification gate (§5). |
| Best interests of the child | In design, moderation, and product decisions that affect children, we treat the best interests of the child as a primary consideration, favoring safety and well-being over engagement. |
9.Content safety, moderation, and child sexual abuse material
Because the Service creates content with AI for an audience that includes children, content moderation is central to protecting children. We moderate at two points and maintain a human remediation path behind both.
9.1 Input moderation. Before anything is generated, the information the Customer enters to shape a song — the first name, the occasion or theme, dedications, and free text — is screened against our child-safety and content rules. Inputs that are sexual or that sexualize a minor, violent, hateful, harassing, self-harm-related, dangerous, or that seek to imitate a real, identifiable person are blocked. See the Acceptable Use Policy.
9.2 Output moderation. Generated lyrics, audio, and cover art are screened — through the providers' own safety filters and our own moderation layer — before content is delivered to the Customer. Output that is inappropriate for a child is blocked or regenerated.
9.3 Honest limits. AI systems and safety filters are probabilistic. We do not guarantee that every request produces a finished song, or that filtering catches all unwanted content in every case. A blocked request is expected and normal behavior, not an error. We do not rely on an "as-is" disclaimer to discharge our responsibility to filter content for an audience that includes children; we also provide a working reporting and remediation channel (§16), and we maintain human oversight of our safety systems.
9.4 Child sexual abuse material (CSAM) — zero tolerance and mandatory reporting. Any attempt to use the Service to create, request, or obtain child sexual abuse material, or content that sexualizes a minor, is strictly prohibited. Where we become aware of apparent CSAM, we report it to the U.S. National Center for Missing & Exploited Children (NCMEC) through its CyberTipline as required by U.S. federal law (18 U.S.C. § 2258A), and we preserve the relevant evidence in accordance with law and our internal procedures. We may immediately block, remove, suspend, or terminate any account involved, and we cooperate with lawful requests from competent authorities. We handle suspected CSAM only through a restricted, documented procedure and do not act in any way that would impede a lawful investigation.
10.Data retention
We publish our retention practices and do not retain a child's personal information indefinitely.
- The child's first name and the associated song-creation content are retained only while the Customer maintains the account and the associated in-App access license, and are deleted and purged from the Customer's device cache when the Customer deletes the child or the account, when consent that entails deletion is withdrawn, or when access ends.
- Consent records are retained for the period necessary to evidence compliance (§5.5).
- Records we are legally required to keep — such as transaction and tax records (which do not contain a child's information) and evidence subject to a legal-preservation obligation (§9.4) — are retained only for the period the applicable law requires.
- Retention periods and the destruction process are set out in our Data Retention Policy.
11.Parental rights and how to exercise them
The Customer, as the child's parent or legal guardian, may at any time:
- Review the personal information we hold about the child;
- Refuse to permit further collection or use of the child's information;
- Delete the child's information and the songs made for the child; and
- Withdraw consent, in whole or by purpose. Withdrawing is as easy as granting. Withdrawing consent to create songs stops any further generation for that child. Because a first name that has already been used is part of a finished song, the Customer is given an explicit choice at the moment of withdrawal — to keep the already-made songs available in the App under the existing access license, or to remove and purge them — rather than a silent default. Full account deletion always ends access and purges the cache. These flows are described in our Account Deletion / DSAR process.
Depending on where the Customer resides, additional statutory rights may apply and may be exercised through the same contacts:
- United States (COPPA): the review, refusal, and deletion rights above.
- California (CCPA/CPRA): rights to know, delete, correct, and to limit; we do not sell or share a child's information, and we honor the heightened opt-in the law requires for consumers under 16.
- Texas (TDPSA and applicable minors' laws): rights of access, correction, deletion, portability, and to opt out of targeted advertising and profiling; we do not conduct targeted advertising or profiling of children.
- Mexico (LFPDPPP): the ARCO rights — access, rectification, cancellation, and opposition — and the right to withdraw consent, exercised through the responsable using the contacts in §16 and the mechanism set out in the Spanish-language Aviso de Privacidad.
To exercise any right, contact privacy@happysongs.ai. We verify that the requester is the account's Customer before acting, and we respond within the timeframes the applicable law requires.
12.Children are never commercial participants
Happy Songs is a paid subscription service, currently offered with free promotional access — no payment card is collected and no charge occurs during the promotional period. We do not store payment-card numbers: Apple and Google in-app purchase process the card and provide us only subscription status and receipts (through RevenueCat). We retain subscription and tax records only.
Our Referral Program (presented in the App as "Familia Emprendedora") is operated only by the adult Customer, who is the sole participant and the sole payee of any reward. A child is never a participant, is never a payee, and is never paid. Any "young entrepreneur" narrative is motivational and educational only; it does not enroll a child, and it does not create any payment to a minor. We do not use a child's personal information for the Referral Program. Reward payouts are made to the adult Customer, and payment reporting (such as tax reporting) is made to the adult payee, as an ordinary adult payment. Where a law requires a financial-incentive notice in connection with referrals, it is provided in our Privacy Notice.
13.Security and residual-risk posture
We maintain a written information-security program with an annual review, applied with heightened sensitivity to information about children, and an incident-response and breach-notification process. Details are set out in our Security Program.
No safeguard is perfect, and no provider indemnifies us against a data breach (§6). Happy Songs carries this residual risk and mitigates it through its security program and the cyber and breach-response insurance it maintains or intends to maintain. The Service is provided on an "as-is" basis and the limitations and allocations of liability in the Terms of Service / EULA apply; the Customer is responsible for the content the Customer submits. Nothing in this Notice transfers to the Customer the risk associated with AI-generated output.
14.Applicable law
United States. We operate the Service in compliance with COPPA (15 U.S.C. §§ 6501–6506) and the FTC's COPPA Rule (16 C.F.R. Part 312, as amended in 2025), including verifiable parental consent, direct and online notice, the parental rights in §11, data minimization, a published retention policy, separate consent for non-integral third-party disclosures, the prohibition on conditioning participation, the prohibition on profiling and targeted advertising to children, and a written information-security program. We also comply with the Texas Data Privacy and Security Act (which applies without a small-business threshold) and applicable Texas minors' provisions, the California Consumer Privacy Act as amended (CCPA/CPRA), and other applicable U.S. state privacy and minors' laws. The federal CSAM-reporting obligation in §9.4 is in force.
Mexico. We process personal information as responsable under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025), including the duty to provide an Aviso de Privacidad, to obtain consent (given, for a minor, by the parent or legal guardian), to disclose international transfers, and to honor ARCO rights. The competent authority is the Secretaría de Anticorrupción y Buen Gobierno. The Spanish-language Aviso de Privacidad is the operative version for data subjects in Mexico.
15.Changes to this Notice
We may update this Notice, and may change, add, or discontinue plans, features, providers, or the Referral Program, as our product and legal obligations evolve. Any change applies prospectively only — it does not reduce rights in, or retroactively alter, what the Customer has already paid for or the songs already lawfully created. We provide notice of material changes through the App or by another reasonable means, and where a law requires advance notice or renewed consent (for example, for a subscription price increase or a materially new use or recipient of a child's information), we obtain it before the change takes effect. The Customer may cancel at any time. The "Last updated" date above reflects the current version.
16.Contact, reporting, and complaints
- Privacy and parental rights: privacy@happysongs.ai — Happy Songs USA Corp., Calle Tijuana 22-1, Col. Del Valle, C.P. 03100, Benito Juárez, Ciudad de México, México.
- Support: support@happysongs.ai.
- Report a safety concern: use the in-App report control on any creation, or email privacy@happysongs.ai. We acknowledge and review reports, act on content that violates this Notice or the Acceptable Use Policy, and prioritize suspected child-safety matters. We do not penalize good-faith reports.
- Suspected child sexual exploitation (United States): you may also report directly to NCMEC at CyberTipline.org, or to your local authority.
- Mexico: a data subject may also contact the Secretaría de Anticorrupción y Buen Gobierno regarding the processing of personal information.