Happy Songs

Cookies & SDK Policy

Controller: Happy Songs USA Corp. (merchant of record and data controller / responsable)
Version: 1.0 · Effective date: June 25, 2026 · Last updated: 2026-08-03
Applies to: the “Mi Música” mobile application (iOS and Android); the Happy Songs website, including the web sales panel and the web share surfaces for songs and referrals; and Happy Songs marketing pages at happysongs.ai (together, the “Services”).
Markets covered: United States and Mexico. Region-specific rules for the European Economic Area, the United Kingdom, Brazil, and other Latin American countries are addressed in separate localized instruments and are not part of this text (see Section 10).

This policy explains the cookies, software development kits (SDKs), and similar technologies that store or read information on the device you use to access the Services, why we use them, how they are controlled, and the choices available to you. It forms part of, and should be read together with, the Happy Songs Privacy Policy (Aviso de Privacidad). Where this policy and the Privacy Policy address the same subject, the Privacy Policy governs the underlying processing and this policy governs the device technologies used to carry it out.

1. Who we are and how to contact us

Happy Songs USA Corp. (“Happy Songs,” “we,” “us,” “our”) is the provider of the Services, the merchant of record, and the data controller / responsable for the personal information processed through the technologies described here.

Legal entityHappy Songs USA Corp. (Texas C-Corporation, United States)
Operating fromMexico
US registered address8350 Ashlane Way, Suite 103, The Woodlands, TX 77382, United States
Mexico operating addressCalle Tijuana 22-1, Col. Del Valle, C.P. 03100, Benito Juárez, Ciudad de México, México
Privacy contactprivacy@happysongs.ai
Supportsupport@happysongs.ai
Websitehappysongs.ai

Mexico. For data subjects in Mexico, the applicable authority is the Secretaría de Anticorrupción y Buen Gobierno, under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025). Requests concerning the technologies described here may be directed to privacy@happysongs.ai.

2. Scope and the account model this policy sits inside

The Services are contracted and operated by the Customer — an adult (at least 18 years old, or the age of majority in the Customer's place of residence) who opens the account, operates the Services, and is responsible for the device on which the Services run. The Services are not offered to, and are not intended to be operated by, children. Consent to, and control over, the non-essential technologies described in this policy is exercised by the Customer.

A Happy Songs song is created for a named person, who may be a child. Where the Customer provides information about a minor, the Customer represents that they are that minor's parent or legal guardian and consents, on the child's behalf, to the limited processing described in this policy and in the Privacy Policy.

The Services have no child-facing account or interface — the adult Customer operates every screen, and a child does not sign in, operate the Services, or provide data. Every surface is adult-operated: the mobile application, the marketing website, and the page used to share a song are each accessed and operated by an adult. Because a Happy Songs song is created for, and is likely to be played for and enjoyed by, a child, a child may be present as the beneficiary the song is for — but that incidental presence does not make any surface a “children's surface,” and it does not change who operates it. What protects the child is a rule about data and audience, not a gate on any surface: we never use a child's personal information (the child's first name, or any information about the child) for advertising, ad-targeting, audience-building, or profiling, we never direct advertising at a child, and we build no advertising profile of a child (Section 7).

Incidental, supervised listening does not make the Services child-directed. A child's incidental presence is not a concession that the Services are directed to children under COPPA or that we have a child's “actual knowledge” trigger. As with any general-audience app, an adult Customer may let a child hear a song on the adult's own device; that incidental, supervised listening is a child being present as the beneficiary the song is for, not a child using or accessing the Services as a user, and it does not convert an adult-operated Service into one directed to children. Three affirmative facts about how the product is built hold this line: (1) we build no profile of the child — we hold only the first name the Customer provides; (2) we direct no feature, screen, content, character, or message at a child — there is no child login, no child-facing mode, and nothing that invites a child to act, earn, or transact; and (3) we collect no data from the child — every input is provided by, and the account is operated by, the adult Customer. The honest boundary, which we keep and do not over-claim: a minor's first name is processed, with the Customer's parental consent, and even so we do not market to, advertise to, track, or profile a child. If a future feature were to speak to a child or be operated by a child, that would change this analysis and we would re-assess before it ships.

Data minimization. About the person a song is created for, we store only a first name — no surname, no nickname, no age, no date of birth, no profile, and no precise location. Any age or life-stage information the Customer selects is used only in the moment to help browse and tailor a song and is not stored. We do not process any special-category information (such as health, biometric, or religious information) about any person of any age. The technologies described in this policy are configured consistently with these limits.

3. Definitions

  • Tracking technology / cookie: any technology that stores information on, or reads information from, the device you use — cookies, localStorage/sessionStorage, IndexedDB, mobile SDK local caches, device or software identifiers, pixels or beacons, and similar.
  • SDK (software development kit): third-party code embedded in the application or web surfaces that can store or read device data and transmit it to the vendor that supplies it. Happy Songs' non-essential SDKs are PostHog, OneSignal, and RevenueCat, together with the advertising/marketing SDKs used on the adult-operated Happy Songs website (including the page used to share a song) — for example Meta (Meta Pixel / Ads) and Google Ads (Section 5.1).
  • Strictly necessary / essential: technologies required to deliver a feature you have explicitly requested — authentication, session management, security, load management, and caching your song on the device for offline playback inside the application. These do not require prior opt-in consent and are not a “sale” or “sharing” of personal information.
  • Non-essential: analytics, push notifications, purchase-management, and advertising/marketing technologies. These are the technologies this policy gates. Every Happy Songs surface is adult-operated, and we use advertising and marketing technologies only to reach adults (marketing, acquisition, and retargeting), subject to the controls in Sections 8–10; we do not use a child's personal information for advertising, ad-targeting, audience-building, or profiling, and we never direct advertising at a child (Section 7).
  • “Sale” (US state law): disclosing personal information to a third party for monetary or other valuable consideration. We do not sell personal information for money; however, our website advertising disclosures to marketing partners may be treated as a “sale” under the broad definition some US state laws use (valuable consideration, even where no money changes hands), and we provide an opt-out for them (Section 8).
  • “Sharing” / “targeted advertising” (US state law): disclosing personal information for cross-context behavioral advertising. Our adult-directed website advertising (for example, retargeting through Meta and Google Ads) is such a disclosure, and disclosures to an analytics provider may be treated as “sharing” under some state laws even where no money changes hands; we therefore provide an opt-out (Section 8) and never apply this to a child.
  • Global Privacy Control (GPC): a browser or device signal communicating a user's opt-out of sale and sharing, recognized as a valid universal opt-out mechanism in California and a growing number of US states.

4. Our position, in brief

  • Happy Songs is adult-operated, and advertising directed at adults is a normal part of how we reach new Customers. On the Happy Songs website, and for adult-directed marketing, acquisition, and retargeting, we may use advertising and analytics partners — for example Meta (Meta Pixel / Ads) and Google Ads. This uses cookies and SDKs and involves sharing data with those partners for adult-directed advertising. It is controlled: where consent is required (the EEA, UK, and Switzerland cookie-consent regimes) it is obtained through the cookie banner under our localized instruments (Section 10); in the US you can opt out through the “Do Not Sell or Share My Personal Information” control and we honor Global Privacy Control (GPC) (Section 8); and in Mexico it is a secondary purpose you may refuse (Section 9). This adult-marketing tracking is never applied to a child (Sections 5.3 and 7).
  • In the “Mi Música” mobile application we do not track users across other companies' apps or websites: on iOS we truthfully declare no tracking and do not request the advertising identifier (IDFA) through App Tracking Transparency, and on Android we do not collect the Advertising ID (the AD_ID permission is removed). See Section 11. Cross-site retargeting occurs on the Happy Songs website surfaces described above — including the page used to share a song, whose visitor is an adult — never in the app, and never built from a child's data.
  • We do not profile, behaviorally track, retarget, or serve targeted advertising to children — this is prohibited, and it is enforced at the level of data and audience: we never use a child's personal information to build an advertising audience or profile, and we never direct advertising at a child (Section 7).
  • The non-essential technologies we do use (product analytics, push notifications, purchase management, and adult-directed advertising/marketing) are named, purpose-limited, and controlled as described below. Our analytics, push, and purchase-management providers are each engaged under a written data processing agreement that limits them to processing on our documented instructions; our advertising/marketing partners are engaged under their advertising and data-protection terms. None of them ever receives a child's personal information for advertising, and no advertising audience or profile is ever built from a child's data (Section 7).

5. Inventory of cookies, SDKs, and similar technologies

This is the authoritative inventory of technologies that store or read data on your device. It is kept consistent with the Happy Songs Subprocessor List, which is the single source of truth for the identity of the vendors we engage; where a vendor's identity or status differs between documents, the Subprocessor List controls. All of the vendors below are located in the United States.

5.1 Non-essential SDKs (the technologies this policy governs)

SDK / Vendor Surface Purpose Device data stored or read Category Default and audience rule Your control
PostHog App and web Product analytics and measurement IP address (configured for anonymization), device/session identifiers, an application user identifier, in-app usage events Analytics — non-essential; a disclosure that may be “sharing” under US state law Off unless and until consent is given where consent is required; opt-out honored (Do Not Sell/Share and GPC) in the US. Never used to profile a child or to build an advertising audience from a child's data Do Not Sell/Share link and GPC (Section 8); in-app privacy setting
OneSignal App Push notifications Device push token, application user identifier, device/OS data Communications — non-essential Off until you opt in to notifications (operating-system permission and in-app setting); tied to the adult Customer's account and never to a child Operating-system notification permission and in-app toggle; opt out at any time
RevenueCat App Subscription and purchase management (entitlement status) Application user identifier, device identifiers, purchase/receipt metadata Purchase management — functional; not advertising and not used for profiling Present to manage subscription status; used only for the adult Customer's account and purchases, never in relation to a child Governed by the store purchase flow
Meta (Meta Pixel / Ads) and Google Ads Website (adult-operated) — not in the app Adult-directed marketing, acquisition measurement, and retargeting Cookies and pixel/beacon data, advertising/click identifiers, IP address, page-visit and conversion events Advertising — non-essential; a disclosure that is or may be treated as a “sale”/“sharing” under US state law On for adults across the website surfaces, including the page used to share a song (its visitor is an adult), subject to opt-out (Do Not Sell/Share and GPC) in the US and to consent where required (EEA/UK/CH). Audiences are built only from the adult visitor's own signals; a child's data is never used and no advertising profile of a child is ever created Cookie banner where required (Section 10); Do Not Sell/Share link and GPC (Section 8); refusal in Mexico (Section 9)

RevenueCat manages the status of a subscription and the associated store receipts. It does not receive or store card numbers (see Section 5.2). Happy Songs is a paid subscription service currently offered with free promotional access that requires no card and triggers no automatic charge during the promotional period; RevenueCat records subscription and entitlement status regardless of whether a payment is being taken.

PostHog is configured with IP anonymization and is not used to profile, retarget, or build advertising profiles of any user, and is never used in relation to a child.

Meta and Google Ads technologies run on the Happy Songs website surfaces — all of which are adult-operated — to reach and re-engage adults, including retargeting on the page used to share a song, whose visitor is an adult. They are not deployed in the mobile application. Advertising audiences are built only from the adult visitor's own signals; we never use a child's personal information for advertising, and no advertising profile of a child is ever created (Section 7). Data shared with these partners for advertising may be a “sale” or “sharing” under US state law, and you can opt out (Section 8).

5.2 Strictly-necessary / essential technologies (no opt-in required; listed for transparency)

Technology / Vendor Purpose Device data Why essential
Supabase (authentication / session) Keep the Customer signed in; authenticate requests Authentication/session token in secure local storage The account cannot function without it
First-party session, state, and security Security (including CSRF protection), load and screen state, and remembering your privacy choices localStorage/sessionStorage; secure cookies on the web Security and delivery of the screen you requested
In-app song cache (on device) Stores your song on the device so it can be played offline inside the application Audio held in application-managed storage This is the feature you asked for. The cache is application-managed; the song is not a downloadable or exportable file, and the cache is purged on account deletion or when access ends
Twilio (server-side) SMS one-time-password verification of the account Phone number and one-time code (processed server-side, not through a device SDK) Verification of the account you requested
Vercel (web hosting) Serve the website and web surfaces IP address and standard request logs Required to deliver the web pages you requested
Apple App Store / Google Play (in-app purchases) Process subscription charges through the app stores' in-app-purchase systems Payment handled by the app store; Happy Songs receives only subscription status and receipts (relayed via RevenueCat), not the card number Required to complete a subscription purchase you initiate; there is no separate web/card payment processor

Essential technologies are not “sale” or “sharing” and are listed here only for transparency. Subscription charges are processed by the app stores through their in-app-purchase systems (Apple App Store / Google Play): Apple and Google process the card and we receive only subscription status and receipts (relayed via RevenueCat). There is no separate web/card payment processor. Happy Songs does not store card numbers.

5.3 Advertising — where it runs, and the rule that protects children

Advertising and marketing technologies (for example Meta Pixel / Ads and Google Ads) run on the Happy Songs website surfaces — all of which are adult-operated, including the page used to share a song — to reach and re-engage adults, and only subject to the controls in Sections 8–10. Beyond that, the following hold:

  • In the mobile application: no advertising or ad-attribution SDK — no advertising-network SDK, and no mobile measurement partner for ad attribution.
  • No IDFA and no App Tracking Transparency prompt in the app — we declare no cross-app tracking there.
  • No Android Advertising ID — the AD_ID permission is removed.
  • No advertising, ad-attribution, cross-context behavioral advertising, retargeting, or profiling directed at a child — ever, on any surface. Advertising audiences are built only from the adult visitor's or Customer's own signals; a child's personal information is never used to build an advertising audience or profile, and no advertising profile of a child is ever created (Section 7).

5.4 Server-side AI providers are not device SDKs governed by this policy

To create a song, some content is processed server-side by artificial-intelligence providers. These providers are not the on-device SDKs this policy gates; they are subprocessors governed by our Privacy Policy and by the Subprocessor List (the source of truth). We name them here only for transparency:

  • Music: Google Lyria via Google Vertex AI (United States). Generated audio carries a Google SynthID provenance watermark.
  • Lyrics and text: Anthropic and OpenAI (United States).
  • Cover art: Nano Banana (Google's Gemini image-generation model) — a Google service (United States).

To limit exposure, we minimize what these providers receive: the real first name is sent only to the music provider (because it is sung), while the lyric/text providers receive a placeholder name, with the real name inserted locally after generation. Before any personal information is sent to these providers, we obtain the Customer's explicit in-app consent that names them.

6. How the essential-versus-non-essential test is applied

  1. Is the technology required to deliver something you explicitly requested (sign-in, security, caching your song for offline in-app playback, completing a purchase you started)? If yes, it is essential and runs without a gate.
  2. Otherwise (analytics, push notifications, adult-directed advertising/marketing, purchase-attribution) it is non-essential and is subject to:
    • the child data-and-audience rule (Section 7) — always, everywhere: no child's personal information is used for advertising, ad-targeting, audience-building, or profiling, and no advertising is directed at a child;
    • the US-state opt-out controls (Section 8);
    • the Mexico disclosure and refusal mechanism (Section 9).

Ambiguous cases are resolved toward “non-essential” and are gated.

7. Protecting children — a data-and-audience rule, not a surface gate

This is the cross-cutting rule and applies independently of geography:

  • Every Happy Songs surface is adult-operated — the mobile application, the marketing website, and the page used to share a song. A child may be present as the beneficiary a song is for (for example, listening to a song an adult plays), but that incidental presence does not make any surface a “children's surface.” What protects the child is a rule about data and audience, not a gate on any surface: we never use a child's personal information (the child's first name, or any information about the child) for advertising, ad-targeting, audience-building, or profiling, we never direct advertising at a child, and no advertising profile of a child is ever created. Advertising and analytics audiences are built only from the adult visitor's or Customer's own signals.
  • No behavioral profiling, no cross-context tracking, and no targeted advertising to a child — ever.
  • Analytics and advertising run on the adult-operated Happy Songs surfaces — the application, the website, and the page used to share a song (whose visitor is an adult) — subject to the consent and opt-out controls in Sections 8–10, and always subject to the child data-and-audience rule above. We declare the Services as general-audience / adult-operated, not child-directed, and do not place them in an app-store Kids category.
  • Push notifications are tied to the Customer's account, never to a child, and only after the Customer opts in.
  • The “Mejórate Pronto” (Get Well) occasion captures only a generic well-wishing sentiment. A child's specific illness, diagnosis, or symptom is never captured, inferred, or stored, and no non-essential technology attaches to that flow.

Legal anchors: COPPA and the amended COPPA Rule (2025) (no behavioral tracking of children, and no non-integral third-party disclosure such as analytics or push tied to a child — which we satisfy by never tying those technologies to a child and never using a child's data for advertising, audience-building, or profiling, not by collecting a child's data under a verifiable-parental-consent apparatus); the Apple and Google child-directed and Kids-category rules (we declare the Services as general-audience / adult-operated, not child-directed); and the reinforced minors' protections under US state law (Section 8). This is a lawful-processing model operated by the adult Customer: the child does not hold an account or provide data beyond the first name the Customer supplies as the child's parent or guardian. It does not remove children from these protections, and we do not treat the adult-operated model as a reason to relax them.

8. United States — Do Not Sell/Share, Global Privacy Control, and minors

Under the California Consumer Privacy Act as amended (CCPA/CPRA), the Texas Data Privacy and Security Act (TDPSA — our home state; no small-business threshold), and the comparable comprehensive privacy laws of other states, the following apply. This is an opt-out regime; it does not require a European-style “accept cookies” opt-in banner.

8.1 “Do Not Sell or Share My Personal Information”

  • We publish a “Do Not Sell or Share My Personal Information” control at [Do Not Sell/Share link], in the website footer and in the app's privacy settings.
  • Activating it opts you out of any disclosure that could be treated as a “sale” or “sharing” — including the advertising disclosures to our website marketing partners (for example, Meta and Google Ads) and the analytics disclosure to PostHog. We do not sell personal information for money, but some of these disclosures may be a “sale” or “sharing” under US state law even where no money changes hands; this control covers all of them. It never involves a child's information, because we never use a child's personal data for advertising or audience-building and never create an advertising profile of a child (Section 7).
  • Where a state requires it, we also provide a “Limit the Use of My Sensitive Personal Information” control.

8.2 Global Privacy Control (GPC)

  • We detect and honor GPC and other recognized universal opt-out signals as a valid opt-out of sale and sharing, at the browser or device level, without requiring you to also click the link. Where you are signed in, we apply the opt-out to the known account as well.
  • Honoring a universal opt-out signal is mandatory in a growing number of states; we treat it as required across our US footprint.

8.3 Minors

  • We do not sell or share the personal information of any consumer we know to be under 16. In our model a child is not a user or consumer who interacts with the Services: the only information about a minor is the first name the adult Customer provides as the child's parent or legal guardian. The CCPA/CPRA affirmative-opt-in-for-minors requirement is satisfied because no such sale or sharing occurs — in practice, we do not sell or share a child's information at all.
  • We do not knowingly serve targeted advertising to minors. The state-by-state minors' rules we honor (including the stronger protections in Texas, Oregon, New Jersey, Maryland, and other states) are maintained in the Privacy Policy; this policy's data-and-audience rule (Section 7) implements them — a child's personal information is never used to build an advertising audience or profile, and no advertising is directed at a child.

8.4 Financial-incentive notice

Where a law such as the CCPA requires a notice of financial incentive, we provide it in connection with the Happy Songs Referral Program (presented in the app as “Familia Emprendedora”). The Referral Program is operated by, and its rewards are paid only to, the adult Customer; participation does not require, and does not involve, the sale of personal information for money.

8.5 Non-discrimination and response

We do not discriminate against you for exercising a choice under this section. Opt-out requests take effect promptly and are honored on a going-forward basis; verification and timelines follow the applicable state law, with mechanics described in the Privacy Policy and the account-deletion / rights-request flow.

9. Mexico — how these technologies are disclosed

Mexico does not have a prior-opt-in cookie regime of the European type. Tracking technologies are disclosed and consented through the Aviso de Privacidad under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025). For the Mexican market, the SDK inventory in Section 5 and the child data-and-audience rule (Section 7) are disclosed in the Spanish-language Aviso de Privacidad. Analytics and marketing technologies are secondary purposes that the Customer may refuse without affecting the core Services. The Customer may exercise limitation or refusal, and the ARCO rights (access, rectification, cancellation, and opposition) preserved under the 2025 law, through the mechanism described in the Aviso de Privacidad and by writing to privacy@happysongs.ai. The US “Do Not Sell or Share” control is not a Mexican legal construct; if globally visible it does no harm, but Mexican data subjects exercise their choices through the Aviso and the ARCO channel.

10. European Economic Area, United Kingdom, and other regions

The Services launch in the United States and Mexico. The European Economic Area, the United Kingdom, Brazil, and other Latin American jurisdictions impose different rules — including, for the EEA and the UK, a prior opt-in consent requirement (through a consent-management platform) before any non-essential storage or reading on the device, and age-appropriate-design obligations for children's data. Those requirements are addressed in separate localized instruments and are not offered to, or shown to, users in those regions through this text. We will not serve those markets until the corresponding localized controls are in place.

11. App-store and platform alignment

The inventory in Section 5 is kept consistent with what we declare to the app stores; a mismatch is a rejection and enforcement risk.

  • Apple App Privacy labels and Google Play Data Safety disclose exactly the data each SDK in Section 5.1 collects and the purpose for which it is collected, including RevenueCat's role in subscription management.
  • iOS App Tracking Transparency: we declare “Data Not Used to Track You” and do not present the ATT prompt or request the IDFA.
  • Android: the AD_ID permission is removed; we declare no advertising identifier.
  • Audience classification: our honest audience declaration and the age-rating questionnaires reflect that the Services are general-audience / adult-operated, not child-directed; we do not place them in an app-store Kids category. Regardless of classification, we never use a child's personal information for advertising, audience-building, or profiling, and never direct advertising at a child (Section 7).

12. Changes to this policy and to the Services

We may add, change, or discontinue plans, features, pricing, technologies, and programs (including the Referral Program) over time. Any such change applies prospectively only — it does not retroactively affect a benefit you have already paid for. Where the law requires notice of a change (for example, an increase in a subscription price), we give that notice, and you may cancel. When we make a material change to this policy, we update the version and “last updated” date above and, where required, provide additional notice. Your continued use of the Services after a change takes effect is subject to the updated policy.

13. How to exercise your choices

  • In the app: privacy settings (analytics on/off; notification permissions) and the “Do Not Sell or Share My Personal Information” control.
  • On the web: the “Do Not Sell or Share My Personal Information” control in the footer; your browser or device GPC signal, which we honor automatically.
  • By email: privacy@happysongs.ai for any request or question about the technologies described here, including access, rectification, cancellation, opposition, or limitation of use.

14. Related documents

  • Privacy Policy / Aviso de Privacidad — the underlying processing, data-subject rights, and the full subprocessor disclosure.
  • Subprocessor List — the single source of truth for the identity and status of the vendors named here.
  • Account-deletion and rights-request flow — the mechanics and timelines for exercising your choices.
  • App-store compliance materials — the privacy labels, Data Safety declarations, and age-rating basis referenced in Section 11.