This Privacy Policy explains what personal information we process, why, with whom we share it, how long we keep it, and the choices and rights available to you. It is written to be read together with our Terms of Service and End User License Agreement, our AI Content and Disclosure Policy, and our Acceptable Use Policy. Where this Policy refers to a separately maintained document (for example, our Subprocessor List), that document is the current, authoritative source for the matter it covers.
Jurisdiction-specific requirements for the EEA, the United Kingdom, Brazil, Canada, Switzerland, and other regions beyond the United States and Mexico are addressed in separate materials and are summarized, for completeness, in Section 18.
1. Who we are and how to contact us
Happy Songs USA Corp. (“Happy Songs,” “we,” “us,” or “our”) is a C-Corporation organized under the laws of the State of Texas, United States (File No. 806668254), operating from Mexico. We are the data controller / responsable and the merchant of record for the Services.
| Legal entity | Happy Songs USA Corp. |
| Entity type / jurisdiction | C-Corporation, State of Texas, United States |
| Registered address (US) | 8350 Ashlane Way, Suite 103, The Woodlands, TX 77382, United States |
| Operating address (MX) | Calle Tijuana 22-1, Col. Del Valle, C.P. 03100, Benito Juárez, Ciudad de México, México |
| Privacy contact | privacy@happysongs.ai |
| Support | support@happysongs.ai |
| Website / domain | happysongs.ai |
For any question about this Policy or your personal information, or to exercise your rights, contact us at privacy@happysongs.ai. In Mexico, requests to exercise your ARCO rights and to revoke consent may be sent to the same address; see Section 15. If we serve the direct-web (merchant-of-record) rail to customers in Mexico, our Mexican legal representative and fiscal details will be identified here [Mexican legal representative / RFC / domicilio to be confirmed].
2. The account model behind this Policy
The Services are marketed to families, but the person we contract with and rely on is always an adult. To understand how the rights, consents, and disclosures in this Policy operate, read this section first.
- The Customer is an adult. The account holder — the person who registers, operates the Services, pays, and receives any Referral Program reward — is “the Customer,” an individual who is at least 18 years old, or the age of legal majority where they live, with full capacity to enter a contract. The Customer is the party whose consent we rely on and who exercises the rights described in this Policy. We take steps to confirm that the account holder is an adult; not asking for age is not, by itself, sufficient.
- The person a song is for is a beneficiary, not an operator. The Customer may create a song for a child or for any other person (an adult relative, a friend). That person does not create an account, does not operate the Services, does not pay, and is not a party to any agreement with us.
- Where the Customer provides a minor’s information, the Customer acts as that minor’s parent or legal guardian. When the person a song is for is a child, the Customer represents that they are that child’s parent or legal guardian and consents, on the child’s behalf, to the limited processing of the child’s information described in this Policy, including its disclosure to the AI providers named in Section 6.
- We do not use the adult-account model to avoid child-protection law. The Services are operated by adults; no child creates an account, operates the Services, or provides information to us. But a song is for and about a child, and a child will hear it — so we treat the first name of that child as children’s personal information and apply the child-safety and children’s-privacy safeguards in this Policy. We address the fact that children are likely to hear our Services the way child-protection law asks, proportionately to an adult-operated service: we do not market or advertise to children, we do not track or profile them, and we minimize the data to a first name the adult provides with consent. The adult-account model is a lawful basis for processing; it is not a child-protection exemption.
- Incidental, parent-supervised listening by a child does not make the Services child-directed. As with any general-audience app, the adult account holder may let a child hear a song on the adult’s device; that incidental, supervised listening is not a child “using” or “accessing” the Services as a user, and it does not turn an adult-operated Service into one directed to children. Three facts about how the product is built hold this line: (1) we build no profile of the child — we store only the first name the adult provides (Section 3.1); (2) we direct no feature, screen, content, character, or message at a child — there is no child login, no child-facing mode, and nothing that invites a child to act, earn, or transact (Sections 10 and 14.6); and (3) we collect no data from the child — every input is provided by, and the account is operated by, the adult Customer (Sections 3 and 4). We do not over-claim this: a minor’s first name is processed, with the consenting adult’s parental consent, and we still do not market to, advertise to, track, or profile a child. If a future feature were to speak to a child, or be operated by a child, that feature would change this analysis, and we would re-assess before it ships.
Throughout this Policy, “the Customer” and “you” refer to the adult account holder. We use “parent or legal guardian” only in the context of consent given on a child’s behalf.
A paid service currently offered with free promotional access. Happy Songs is a paid subscription service. It is currently offered with free promotional access: during the promotional period we do not collect a payment card and there is no automatic charge. How payments work when a plan applies is described in Section 8.
3. Personal information we collect
We practice data minimization. The single most important design choice in this product is what we do not collect about the person a song is for.
3.1 About the person a song is for — a first name only
About the individual a song is created for, we store only a first name. We do not store that person’s surname, nickname, age, date of birth, profile, or precise location. Where the Services ask about an age or stage — for example, to help you browse or tailor a song in the moment of creation — that age or stage is used only in that moment and is not stored on our systems. When the person a song is for is a child, this first name is children’s personal information and receives every protection described in Sections 6, 13, and 14.
3.2 Information we hold from and about the Customer
| # | Category | Data elements | Source |
|---|---|---|---|
| A | Account and identifier | Mobile phone number (primary identifier / login), verification status, email address (optional), account settings | Provided by the Customer |
| B | Device and technical data | IP address, device type/OS, app version, non-advertising device identifiers, coarse diagnostics, crash logs | Collected automatically |
| C | Song-creation content | Occasion/theme selections, dedication and free-text context you enter, generated lyrics, generated cover art, generated audio; the first name of the person the song is for | Provided by the Customer, and AI-generated |
| D | Usage and analytics | Feature-usage events, session data, in-app progress (“Jacks”/levels, which are non-monetary) | Collected automatically, consent-gated; never used to track or profile a child (Section 10) |
| E | Communications | SMS/one-time-code (OTP) messages, push-notification tokens, support messages, email (if provided) | Provided or generated |
| F | Transaction and subscription records | Subscription status, purchase receipts and identifiers, in-app purchase/entitlement metadata — not card numbers (Section 8) | Provided by the app stores / payment processor |
| G | Referral, payout, and tax records | Referral status, reward balance, the recipient payout details required to send a Referral Program reward, and the tax identifier and tax-reporting records required by law | Provided by the Customer; generated by us and our payout provider |
3.3 The free-text context you enter
The dedication and free-text context field (Category C) travels to the AI providers that generate the song (Section 6) and may persist in those providers’ logs, including trust-and-safety logs. We guide you not to enter sensitive details, we minimize the input, and we treat any special-category content nonetheless entered with heightened care. Do not include information you would not want processed by a third-party AI provider.
3.4 Categories we do not collect
- No surname, nickname, age, date of birth, profile, or precise location of the person a song is for (Section 3.1).
- No precise geolocation of any person.
- No biometric identifiers or voiceprints. The Services do not capture any person’s voice or create a voiceprint. If a future version captures voice, a voiceprint would be treated as personal information — and, where it describes a child, as children’s personal information — and biometric-specific consent and retention rules would apply before any such feature ships (Section 14.4).
- No special-category / sensitive personal data of any person, of any age — no health, biometric, genetic, racial or ethnic, religious or philosophical, sexual-orientation, or similar data. The “Get Well / Mejórate Pronto” occasion is a generic well-wishing gesture only (comparable to a get-well card): we do not capture, ask for, infer, store, or generate any person’s specific illness, diagnosis, or symptom, and neither the prompt nor the lyrics reference a specific medical condition. See Section 14.5.
Financial-data carve-out. The one category of heightened-sensitivity data we do process is the financial and payout information of the adult Customer, and only as needed to run subscriptions, the Referral Program, and tax reporting: subscription and transaction records, the recipient payout details our payout provider requires to send a reward, and the tax identifier and records the law requires. This is financial data about the adult account holder. It is handled with heightened safeguards; it is never information about the person a song is for, and it is never health, biometric, or other special-category data. We do not store payment card numbers (Section 8).
4. Why we use your information and our legal bases
| Purpose | Categories used | Legal basis (core) |
|---|---|---|
| Create and operate the account; verify the Customer’s phone number | A, B, E | Performance of a contract with the Customer; the Customer’s consent |
| Generate and deliver the personalized song, lyrics, and cover art the Customer requests | C, and the first name in Section 3.1 | Performance of a contract with the Customer; where the song is for a child, the Customer’s consent on the child’s behalf, including consent to disclose inputs to the AI providers (Section 6) |
| Apply child-safety filters and content moderation to inputs and outputs | C | Legitimate interest in child safety and lawful content; legal obligation; performance of contract |
| Operate, secure, debug, and improve the Services | A, B, D | Legitimate interest in a secure, functioning service; legal obligation (security) |
| Product analytics and measurement | B, D | Consent (analytics are gated behind consent where required, and never used to track or profile a child — Section 10) |
| Send transactional messages (OTP, service notices) | A, E | Performance of contract; legal obligation |
| Send optional marketing or product messages | A, E | Consent (opt-in), with an easy opt-out |
| Adult-directed advertising, measurement, and retargeting across the Happy Songs surfaces (for example, Meta and Google Ads) — never directed at a child, never using a child’s data | B, D | Consent (cookie consent where required), with opt-out and Global Privacy Control (Sections 10 and 14.3) |
| Process payments, subscriptions, and refunds; keep tax and accounting records | F, G | Performance of contract; legal obligation (tax) |
| Operate the Referral Program and pay rewards to the adult Customer; report payments for tax | G | Performance of contract; legal obligation (tax); the Customer’s consent to enroll |
| Comply with law, respond to lawful requests, enforce our Terms, and establish, exercise, or defend legal claims | Any | Legal obligation; legitimate interest; establishment, exercise, or defense of legal claims |
For Mexico, processing rests primarily on the Customer’s consent and on the necessity of the processing to provide the service requested; see Section 15. Jurisdiction-specific legal bases for regions beyond the United States and Mexico are addressed separately (Section 18).
5. Automated decision-making
Our AI providers apply automated child-safety and content filters to what is generated. These filters can automatically reject a song, a set of lyrics, or a cover image — including a generation the Customer requested and, where applicable, paid for — without a human reviewing it first.
- What this means for you. If a generation is rejected, you will see a notice and may try again with different inputs.
- The logic, in general terms. The filters block content that is unsafe, unlawful, sexualized, hateful, or otherwise disallowed, and content that would imitate a real person’s voice, name, or likeness.
- Human review. You may request human review of a rejected generation, or dispute an outcome you believe was wrong, by contacting us at privacy@happysongs.ai or support@happysongs.ai. Where a generation is a paid feature, our refund-and-retry handling for rejected paid generations is described in our Terms.
- We do not use these automated decisions to produce legal or similarly significant effects about you or the person a song is for, and we do not use them to build a profile of any child.
6. AI generation and disclosure of your inputs to AI providers
Happy Songs generates songs using artificial intelligence. Our current AI providers are:
- Music / audio: Google Lyria, via Google Vertex AI (United States). Generated audio carries Google SynthID, a machine-readable watermark that identifies the audio as AI-generated.
- Lyrics / text: Anthropic and OpenAI (United States).
- Cover art: Nano Banana (Google’s Gemini image-generation model), a Google service, United States. [Engineering/counsel note: Nano Banana must be accessed via Vertex AI / a paid API tier, not the consumer Gemini Dev API (which bars under-18 services) — the same reason Lyria runs on Vertex.]
We may add or change our AI providers as the technology evolves. The current, authoritative list of AI providers and other subprocessors is maintained in our Subprocessor List, published at happysongs.ai/legal/subprocessors and summarized in Section 7. That list — not this paragraph — is the source of truth for who currently receives your inputs. We update it before a new provider goes live and give notice of material changes as described in Section 16.
6.1 What we send, to whom, minimized by design
To generate a song we disclose only the inputs each provider needs, and we minimize the most sensitive disclosure by design:
- Lyric providers (Anthropic, OpenAI) receive a placeholder, not the real name. By design, the real first name of the person a song is for is not sent to the lyric providers. We send a placeholder together with the occasion and your dedication/context text, and we insert the real first name locally, on our side, after the lyrics come back. This is a deliberate minimization measure.
- The music provider (Google Lyria / Vertex AI) receives the real first name. Because the song is sung with the name, the real first name is sent to the music provider together with the finalized lyrics. This is the single most sensitive disclosure in the product.
- The free-text context you enter travels to the providers as described above and, if it contains sensitive details, is handled per Section 3.3.
6.2 Explicit in-app consent, naming the providers
Before any of this disclosure happens, we ask the Customer for explicit in-app consent and we name the providers that will receive the data. A link to this Policy alone is not treated as sufficient consent for this disclosure. Where the person a song is for is a child, this is the point at which the parent or legal guardian consents, on the child’s behalf, to the disclosure.
6.3 A provider’s own use, and separate consent for children’s data
Sending a child’s input to a provider to generate the requested song is integral to the service and is covered by the single consent above. But where a provider would use a child’s data for its own purposes — for example, training its models on consumer-tier data, human review of content its systems flag, or abuse and safety logging — that is a disclosure to a third party for that party’s own use, which for children’s data requires a separate, additional parental consent. Our position is to contract for processor-only terms (no training, and zero or short retention) so the disclosure stays within the single consent. Where we cannot obtain those terms for a given provider, we will obtain a separate consent or not send the data.
6.4 A human at a provider may see the content
If a provider’s automated safety systems flag a generation, a provider’s human reviewer may read the flagged content — which can include the first name and the context you entered — as part of their trust-and-safety process. We disclose this plainly: content you submit is not guaranteed to be seen only by machines.
6.5 No-training commitment and flag-driven retention
We seek a contractual no-training commitment from each AI provider for the data we send, and zero or short retention. Even so, providers commonly retain flagged content longer for safety purposes. For example, a lyric provider may retain flagged trust-and-safety content for up to approximately 24 months, and the music provider may keep abuse/safety logs for approximately 90 days. These flag-driven retentions are exceptions to the zero/short-retention posture we ask for; they are provider-side periods that we disclose but do not control through our own deletion jobs, and each figure is confirmed against the provider’s executed data processing agreement.
6.6 Limits, watermarking, and risk allocation
- The song and lyrics are AI-generated content. Because a work generated entirely by AI is generally not registrable for copyright, you receive a personal, non-exclusive, revocable license to access and play the song inside the Happy Songs app — not ownership, not an exportable file, and not a unique or exclusive work. The full license terms, including the closed-ecosystem and anti-circumvention terms, are in our Terms. A summary relevant to your data appears in Section 12 (retention and deletion).
- We prohibit prompts that imitate the voice, name, or likeness of a real person or artist, and our filters seek to block them.
- Risk allocation. The music provider does not indemnify Happy Songs against third-party intellectual-property claims arising from the generated output; that is a content-rights matter addressed in our AI Content and Disclosure Policy and Terms, not a privacy matter. Separately, and relevant here: no AI provider indemnifies Happy Songs for a data breach of your or a child’s personal data. Happy Songs therefore carries that residual risk itself, mitigated by the security program described in Section 13 and by cyber/breach-response insurance that Happy Songs maintains or intends to maintain, rather than by a provider indemnity.
7. Who we share information with (subprocessors)
We share personal information with vendors (“subprocessors”) who process it on our behalf to run the Services. Our current subprocessors are located in the United States, except our cross-border payout provider (Wise), which operates internationally to deliver Referral Program rewards to the adult Customer. We contract with each subprocessor under a data processing agreement. Separately, across our public surfaces (all adult-operated, including the song-share page) we work with adult-directed advertising and analytics partners — for example Meta and Google Ads (Section 10). We do not exchange personal information for money, but sharing data with those partners for adult-directed advertising may qualify as a “sale” or “sharing” under some US state privacy laws; it is subject to consent and to the opt-out described in Sections 10 and 14.3. We never use a child’s personal data for advertising and never direct advertising at a child.
| Subprocessor | Location | What they process for us |
|---|---|---|
| Google Cloud — Vertex AI / Lyria | US | AI music generation — receives the real first name (it is sung) and the finalized lyrics; may keep an abuse/safety log (~90 days) |
| Anthropic | US | AI lyric generation — receives a placeholder and your context text; not the real first name |
| OpenAI | US | AI lyric generation — receives a placeholder and your context text; not the real first name |
| Nano Banana (Google Gemini image model) | US | AI cover-art generation from song inputs; accessed via Vertex AI / paid API tier (not the consumer Gemini Dev API, which bars under-18 services) |
| Supabase | US | Database, authentication, and object/file storage (system of record) |
| Vercel | US | App and web hosting and edge delivery |
| Twilio | US | SMS / one-time-code phone verification and messaging |
| OneSignal | US | Push notifications |
| PostHog | US | Product analytics (consent-gated; never used to track or profile a child) |
| Meta (Meta Pixel / Meta Ads) | US | Advertising partner — adult-directed. Measurement and retargeting for adult marketing and acquisition across the Happy Songs surfaces, including the song-share page (its visitor is an adult); sets cookies/SDKs and shares surface data for advertising (may be “sale”/“sharing” under some state laws); consent-gated and opt-out honored (Sections 10, 14.3); never uses a child’s data and never directs advertising at a child |
| Google Ads | US | Advertising partner — adult-directed. Measurement and retargeting for adult marketing and acquisition across the Happy Songs surfaces, including the song-share page (its visitor is an adult); sets cookies/SDKs and shares surface data for advertising (may be “sale”/“sharing” under some state laws); consent-gated and opt-out honored (Sections 10, 14.3); never uses a child’s data and never directs advertising at a child |
| RevenueCat | US | Subscription status and receipt management (we receive subscription status/receipts, not card numbers — Section 8) |
| Apple App Store / Google Play (in-app purchases) | US | Process subscription charges via in-app purchase and handle the payment card; we receive transaction status and receipts (via RevenueCat), not card numbers (Section 8) |
| Wise | Cross-border payout provider | Sends Referral Program rewards to the adult Customer; runs its own identity verification (KYC); availability is limited to the countries and banks Wise supports (Section 9) |
We also disclose information (a) to comply with law or lawful government or court requests; (b) to protect the safety of a child or any person, including reporting apparent child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC); (c) to enforce our Terms; and (d) in connection with a corporate transaction, subject to this Policy.
Breach risk is not transferred to our subprocessors. The data processing agreements we sign with the subprocessors above generally do not indemnify Happy Songs for a data breach of your or a child’s personal data; provider agreements typically cap liability and exclude that indemnity. Happy Songs carries that residual breach risk itself, mitigated by the security program in Section 13 and by cyber/breach-response insurance it maintains or intends to maintain, not by a provider indemnity.
Disclosures of a child’s data that are not integral to the song require separate consent. For any disclosure of a child’s personal information to a third party that is not integral to delivering the requested song — for example, analytics (PostHog) or push (OneSignal) — we obtain a separate parental consent and do not condition the song service on it; absent that consent, no child’s personal data is disclosed to them. The same rule governs any AI provider’s own use of a child’s data (Section 6.3).
8. Payments and subscriptions
Happy Songs is a paid subscription service, currently offered with free promotional access. During the promotional period we do not collect a payment card and there is no automatic charge.
- We do not store card numbers. When a plan or paid feature applies, payment is processed by the applicable app store — Apple In-App Purchase or Google Play Billing — which handle the card. We receive only your subscription status and receipts, through RevenueCat. There is no separate web/card payment processor; subscription charges are processed by the app stores’ in-app purchase systems.
- What we keep. We keep transaction and subscription records (Category F) and the tax and accounting records the law requires (Category G). We do not keep the primary account number of any payment card.
- How your data is used for payments. We use these records to provide and manage your subscription, process refunds, prevent fraud and abuse, and comply with tax and accounting law.
Retention of transaction and tax records is described in Section 12.
9. Referral Program
Happy Songs operates a Referral Program (presented in the app as “Familia Emprendedora”). This section explains how it processes personal information and how rewards are paid.
- Single-tier; a reward, not a commission. The Referral Program is single-tier: a Customer refers another person, and a reward may be paid to that Customer. It is not a multi-level, pyramid, or chain-marketing scheme, and the reward is a reward / cashback, not a sales commission.
- The payee is always the adult Customer. The child is never paid. The Referral Program is operated by, and any reward is paid only to, the adult Customer. A child is never a participant, is never a payee, and is never paid. Any financial-literacy framing in the app is a motivational and educational narrative only; it does not make a child a participant, an operator, or a recipient of money. There is no payment to minors.
- How a reward is earned and paid. A reward is credited when the referred person pays and the referring Customer has reached their goal. There is a two-month window to claim a credited reward. If a referred payment is later refunded or charged back, the corresponding reward is clawed back — deducted from a later payout.
- Payout rail. Rewards are paid through Wise, a regulated cross-border payments provider. Availability is limited to the countries and banks that Wise supports. Wise runs its own identity verification (KYC). To send a reward, we share with Wise the recipient payout details Wise requires; Wise processes that information under its own terms and privacy policy.
- Data we process for the Referral Program. Referral linkage (who referred whom), reward status and balance, the payout details required to pay you, and the tax identifier and records required to report the payment (Category G).
- Tax. Payments to the adult payee are reported as the law requires — for example, CFDI issuance and any applicable withholding in Mexico, and Form 1099 reporting in the United States. This is an ordinary payment to an adult; it is not a minor-payment arrangement.
- Financial-incentive notice. To the extent the Referral Program constitutes a “financial incentive” under a law that requires a specific notice (for example, the California Consumer Privacy Act), that notice is provided in Section 14.3.
10. Cookies, SDKs, and analytics
The app and web surfaces use software development kits (SDKs) and similar technologies:
- Strictly necessary technologies (security, authentication, delivery) run to operate the Services.
- Analytics (PostHog) and push (OneSignal) are not strictly necessary. Where consent is legally required, they are gated behind the Customer’s opt-in, and — because every event comes from the adult Customer (Section 2) — they are never used to track or profile a child.
- Advertising and analytics partners — adult-directed. Across the Happy Songs surfaces (all of which are adult-operated — the mobile app, the marketing website, and the song-share page at /r/), for adult-directed marketing, acquisition, and retargeting, we may use advertising and analytics partners — for example Meta (Meta Pixel / Meta Ads) and Google Ads. This includes retargeting on the song-share page, whose visitor is an adult. These set cookies/SDKs and involve sharing surface data with those partners for adult-directed advertising, which may be a “sale” or “sharing” under some US state privacy laws (Section 14.3). Where consent is required (for example, EEA/UK/CH cookie consent), we obtain it through the cookie banner; you can opt out through the “Do Not Sell or Share My Personal Information” control, we honor the Global Privacy Control (GPC), and in Mexico you may refuse this use (Section 15).
- Advertising serves adults, never children — as a data-and-audience rule, not a surface rule. We never use a child’s personal data (the child’s first name, or any information about the child) for advertising, ad-targeting, audience-building, or profiling, and we never direct advertising at a child. Advertising audiences are built from the adult visitor’s or Customer’s own signals, never from a child’s data, and no advertising profile of a child is ever created.
For US state “sale”/“sharing” controls and the Global Privacy Control, see Section 14.3. A full EEA/UK cookie-consent (CMP) section is addressed separately (Section 18).
11. International data transfers
Happy Songs operates from Mexico, and its subprocessors are located in the United States.
- For data subjects in Mexico: your personal data is transferred to and processed in the United States by us and by the subprocessors in Section 7, including the AI providers that generate the song. We rely on your consent and on the necessity of the transfer to provide the service you requested, and we bind subprocessors by contract. See Section 15 for how this is disclosed under Mexican law.
- For data subjects in the United States: data is processed within the United States.
- Referral Program payouts are made through Wise, a cross-border payments provider, and are limited to the countries and banks Wise supports (Section 9).
Transfer mechanisms for regions beyond the United States and Mexico are addressed separately (Section 18).
12. How long we keep information
We keep personal information only as long as needed for the purposes described above, then delete or de-identify it. We do not retain personal information indefinitely, and we do not keep children’s personal information beyond what is reasonably necessary for the purpose for which it was collected. Every period below is enforced by an automated purge process.
| Category | Retention period | Deletion trigger |
|---|---|---|
| Account and identifier (A) | Life of the account, then purged within 30 days of deletion | Account deletion |
| First name of the person a song is for (children’s data where that person is a minor) | Kept only while needed to deliver the song(s); priority-purged within 30 days on account deletion or on the Customer’s request; auto-deleted after 24 months of account inactivity | Account/subject deletion; Customer request; 24-month inactivity |
| Device and technical logs (B) | Application and security logs 12 months; edge/access logs (Vercel) 30 days | Rolling window |
| Song content — server copy (C) | Life of the account; served only by in-app access. The on-device offline cache is app-managed and is purged on account deletion or end of access | Account deletion or end of access |
| Free-text creation context (part of C) | Free-text refinement content purged 90 days after song completion (finalized lyrics persist as part of the song) | 90-day post-completion job; account deletion |
| Usage and analytics events (D) | 14 months, de-identified where feasible | Rolling window; opt-out |
| Communications / OTP metadata (E) | 12 months | Rolling window |
| Push tokens (E) | Life of the push subscription; unused tokens purged after 12 months | Opt-out; deletion; bounce |
| Consent / parental-consent records | Life of the account, then a minimized proof kept 3 years after deletion, to evidence lawful consent | Age-out |
| Transaction and tax records (F, G) | As required by tax and accounting law (approximately 7 years) | Statutory period |
Deleted data may persist briefly in encrypted, access-controlled backups until they age out on a 35-day rotation; a suppression record ensures that a restore never returns deleted data to production. Provider-side flag-driven retention is described in Section 6.5. The standalone Data Retention Schedule is the authoritative source for every period; the values above mirror it. This published schedule, together with the security program in Section 13, satisfies the amended COPPA Rule’s requirements for children’s data.
Because songs are only ever accessible inside the app and are never delivered to you as a separate file, when your account is deleted or your access ends, we remove our server-side copy and the app purges the copy cached on your device — no exported copy remains outside the app.
13. How we protect information and data breaches
- We maintain a written information-security program appropriate to the sensitivity of the data, including encryption in transit and at rest, access controls, logging, and least-privilege access. Because we process children’s data, we apply heightened safeguards and review the program at least annually.
- We contractually require subprocessors to maintain appropriate security.
- Residual breach risk. As noted in Sections 6.6 and 7, our subprocessors’ agreements generally do not indemnify us for a breach of your or a child’s data. We carry that risk directly and mitigate it with this security program and with cyber/breach-response insurance we maintain or intend to maintain, rather than relying on a provider indemnity.
- Data breaches. If a breach affecting personal information occurs, we will notify affected individuals and the competent authorities as required by, and within the timelines of, applicable law — including the deadlines set by US state breach-notification laws and, for Mexico, the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025). We will describe the nature of the incident, the data involved, the likely consequences, and the measures taken. [Final breach-notification timelines and authority contacts per market to be confirmed.]
14. United States — specific disclosures
14.1 Notice at collection
At or before the point at which we collect your information — in the app, on the web Sales Panel, and in store listings — we provide a short notice at collection that links to this Policy and states the categories we collect and why. This Policy is the full notice.
14.2 Children’s privacy — COPPA and the amended COPPA Rule (2025)
We treat information about a child as children’s personal information subject to COPPA and the amended COPPA Rule.
- Parental consent, obtained from the adult account holder. We collect a child’s information from the adult Customer, not from a child using the Services. Before we collect a child’s first name and before we disclose any child input to the AI providers named in Section 6, the Customer represents in-app that they are the child’s parent or legal guardian and consents, in context, on the child’s behalf. Because the information comes from the adult account holder — and not from a child operating the app — this in-context parental consent, together with the adult-verification gate below, is how we obtain and confirm consent; we do not run a service that collects personal information directly from children, so no separate age-verification apparatus is imposed on a child.
- The Services are not “directed to children,” and we apply COPPA to the child’s first name regardless. A child does not operate the Services, and incidental, parent-supervised listening on the adult’s device is not a child “using” or “accessing” them as a user (Section 2). We build no profile of the child, direct no feature, screen, content, character, or message at a child, and collect no data from a child — every input comes from the adult Customer. We nonetheless treat the first name of the child a song is for as children’s personal information and apply the protections in this Section to it, and we do not market to, advertise to, track, or profile a child. Were a future feature to speak to or be operated by a child, we would re-assess this determination before it ships.
- Adult-verification gate. We take steps to confirm the account holder giving consent is an adult; not asking for age is not, by itself, sufficient.
- Separate consent for non-integral third-party disclosure, including AI-provider own use. We obtain a separate parental consent before disclosing a child’s data to a third party where that disclosure is not integral to delivering the song (for example, analytics or push), and we do not condition the service on it (Sections 6.3 and 7).
- No behavioral profiling or targeted advertising to children. We do not profile, behaviorally track, or serve targeted advertising to children.
- Data minimization. About the child, we store only a first name — no surname, nickname, age, date of birth, or precise location.
- Published retention and no indefinite retention. See Section 12.
- Written security program with annual review. See Section 13.
- Voiceprints. The Services do not capture a child’s voice. If a future version does, the resulting voiceprint would be children’s personal information and would receive all protections above, plus the biometric rules in Section 14.4.
- Parental rights. The parent or legal guardian may review the child’s information, request its deletion, and refuse further collection or use, by contacting us at privacy@happysongs.ai or through the in-app controls (Section 17).
- Age-appropriate design. No child operates the Services, so there is no child-facing interface to design; because children nonetheless hear the songs, we apply age-appropriate defaults proportionately — not marketing to children, minimizing data, and keeping protective settings on by default (Section 14.6).
14.3 State comprehensive privacy laws (CCPA/CPRA, Texas TDPSA, and others)
Depending on your state of residence, you may have rights under a state comprehensive privacy law, including the California Consumer Privacy Act, as amended by the CPRA, and the Texas Data Privacy and Security Act (TDPSA) — Texas is our home state and its law has no small-business threshold.
- Categories collected and disclosed. The categories in Section 3, disclosed to the subprocessors in Section 7 for the business purposes in Section 4.
- “Sale” / “Sharing.” We do not exchange personal information for money. However, our surfaces (all adult-operated, including the song-share page) use adult-directed advertising and analytics partners — for example Meta and Google Ads (Section 10) — and some analytics- and advertising-related disclosures may be considered a “sale” or “sharing” under some state laws. You can opt out via the “Do Not Sell or Share My Personal Information” control in app settings and at happysongs.ai, and we honor the Global Privacy Control (see below). This advertising is adult-directed: we never use the personal information of the person a song is for to build or target advertising, we do not sell or share that person’s data, and we do not serve targeted advertising to minors (see “Minors” below).
- Global Privacy Control. We honor the Global Privacy Control and other recognized universal opt-out signals as an opt-out of sale/sharing, where required.
- Sensitive data. We process the limited sensitive personal information described in this Policy — namely the adult Customer’s financial and payout information (Section 3.4) — only as needed to provide the Services, and we honor limitation rights where required. We do not process special-category data of the person a song is for.
- Minors. We apply reinforced protections to minors’ data. We do not sell the personal information of a consumer we know to be under 16, and we do not knowingly serve targeted advertising to minors; we apply the stricter state-specific rules (for example, opt-in and sale prohibitions for younger minors) where they apply.
- Financial-incentive notice (Referral Program). Our Referral Program (Section 9) may involve a financial incentive. To the extent a financial-incentive notice is required: the program offers a reward/cashback to the adult Customer for a successful referral (Section 9); the material terms are those in Section 9; participation is voluntary and requires enrollment; and you may withdraw at any time by contacting us at privacy@happysongs.ai. Any value associated with the program relates to the referral, and, to the extent any value must be ascribed to personal information, it is reasonably related to the value the data provides to our business. The child is never a participant or payee.
- Your rights. To know/access, correct, delete, obtain a portable copy, and opt out of sale/sharing and certain profiling. We will not discriminate against you for exercising these rights.
- How to exercise. See Section 17. We verify requests and respond within the timelines the applicable law requires.
14.4 Biometric information (reserved)
We do not collect biometric identifiers, biometric information, or voiceprints. If a future version does, biometric-specific laws (Illinois BIPA, Texas CUBI, Washington) require prior written consent, a published retention and destruction schedule, and a prohibition on selling the biometric data. We would publish that consent and schedule before any such feature ships.
14.5 Washington consumer health data
Washington’s My Health My Data Act and comparable laws apply to consumer health data that identifies or infers a specific health condition. The “Get Well / Mejórate Pronto” occasion is designed not to reach that threshold: under the guardrail in Section 3.4, we do not capture, infer, store, or generate any person’s specific illness, diagnosis, or symptom — only a generic well-wishing sentiment. Because no specific health condition is captured or inferred, this occasion is not consumer health data, and a separate consumer-health-data policy does not apply. This assessment holds only while the guardrail holds.
14.6 Age-appropriate design commitments
No child operates the Services or holds an account, so there is no child-facing interface for us to design. Because a child nonetheless hears the songs, we address age-appropriate-design expectations proportionately, through the following defaults:
- High privacy by default — the most protective settings apply without the user having to enable them.
- Data minimization — a first name only about the person a song is for; no precise geolocation; a placeholder name to the lyric providers (Section 6); no voiceprint or biometric data.
- No behavioral advertising to, or profiling of, children; we never use a child’s data for advertising, and analytics and push are consent-gated and never used to track or profile a child.
- No dark patterns — we do not use manipulative design or engagement traps directed at children; any gamification (for example, “Jacks”/levels, which are non-monetary) is reviewed for age-appropriateness.
15. México — Aviso de Privacidad
Conforme a la Ley Federal de Protección de Datos Personales en Posesión de los Particulares (publicada en el DOF el 20 de marzo de 2025, en vigor a partir del 21 de marzo de 2025), que abrogó la ley de 2010, el presente Aviso de Privacidad dirigido a los titulares en México se pone a disposición en español. La autoridad competente es la Secretaría de Anticorrupción y Buen Gobierno (habiéndose extinguido el INAI). Esta Sección 15 es el texto que rige para los titulares en México; el resto de esta Política sirve como referencia.
15.1 Aviso de Privacidad Integral
1. Identidad y domicilio del responsable. Happy Songs USA Corp., sociedad constituida en el Estado de Texas, Estados Unidos, que opera desde México, con domicilio operativo en Calle Tijuana 22-1, Col. Del Valle, C.P. 03100, Benito Juárez, Ciudad de México, México, y correo de contacto privacy@happysongs.ai, es el responsable del tratamiento de sus datos personales. [Representante legal en México / RFC / domicilio fiscal por confirmar en caso de operar el canal web directo en México.]
2. Datos personales que tratamos. Del Cliente (adulto titular de la cuenta): número de teléfono (identificador principal), correo electrónico (opcional), datos técnicos y del dispositivo, datos de uso, comunicaciones, contenido para crear la canción, y —para la suscripción y el Programa de Referidos— registros de transacción, datos de pago del reembolso y datos fiscales del propio Cliente adulto. De la persona para quien se crea la canción: únicamente su nombre de pila. No recabamos apellido, apodo, edad, fecha de nacimiento, perfil ni ubicación precisa de dicha persona. La edad o etapa, cuando se utiliza para adaptar la canción, se usa solo en ese momento y no se almacena.
3. Datos de menores y datos sensibles. Podemos tratar datos personales de menores, proporcionados por el padre, madre o tutor, quien consiente en nombre del menor. No tratamos datos personales sensibles de ninguna persona (no recabamos condición de salud específica, ni datos biométricos, ni religiosos). La ocasión “Mejórate Pronto” se ofrece bajo una salvaguarda que capta únicamente un mensaje genérico de buenos deseos y nunca una enfermedad, diagnóstico o síntoma específico. La única categoría de datos de mayor sensibilidad que tratamos es la información financiera y de pago del Cliente adulto, necesaria para la suscripción, el Programa de Referidos y las obligaciones fiscales. No almacenamos números de tarjeta.
4. Finalidades del tratamiento.
- Primarias (necesarias para el servicio): crear la cuenta y verificar el teléfono del Cliente; generar y entregar la canción personalizada, la letra y la portada solicitadas; aplicar filtros de seguridad infantil; operar, asegurar y dar soporte al servicio; procesar pagos y cumplir obligaciones fiscales; operar el Programa de Referidos y pagar la recompensa al Cliente adulto; y cumplir la ley.
- Secundarias (requieren su consentimiento y puede negarlas): analítica del producto y comunicaciones de marketing. Puede negarlas o revocar su consentimiento en cualquier momento (punto 8) sin afectar el servicio primario.
5. Transferencias. Para prestar el servicio transferimos sus datos a Estados Unidos, donde se ubican nuestros proveedores (Sección 7), incluidos los proveedores de inteligencia artificial (Google/Lyria para la música; Anthropic y OpenAI para la letra; y Nano Banana —el modelo de generación de imágenes Gemini de Google— para la portada). Estas transferencias son necesarias para prestar el servicio que usted solicitó y se realizan al amparo de contratos. Las recompensas del Programa de Referidos se pagan mediante Wise, proveedor transfronterizo regulado que realiza su propia verificación de identidad. No transferimos sus datos a terceros para finalidades que requieran su consentimiento sin obtenerlo.
6. Fundamento del tratamiento. Nos basamos en su consentimiento y en la necesidad del tratamiento para prestar el servicio solicitado. Cuando usted proporciona datos de un menor, lo hace como padre, madre o tutor que consiente en nombre del menor.
7. Tecnologías de rastreo (cookies/SDKs). Véase la Sección 10. La analítica y las notificaciones push están sujetas a su consentimiento cuando la ley lo exige y nunca se usan para rastrear ni perfilar a un menor (todos los eventos provienen del Cliente adulto). En las superficies de Happy Songs —todas operadas por adultos: la app, el sitio web y la página para compartir la canción (/r/)—, para marketing dirigido a personas adultas, podemos usar socios de publicidad y analítica —por ejemplo, Meta y Google Ads—, lo que implica cookies/SDKs y compartir datos de esas superficies con dichos socios con fines publicitarios; esto incluye el retargeting en la página para compartir la canción, cuyo visitante es un adulto. Cuando se requiere consentimiento, se obtiene mediante el banner de cookies, y usted puede oponerse mediante el control correspondiente o negar este uso. Esta publicidad se dirige únicamente a personas adultas: nunca usamos los datos personales de un menor para publicidad, segmentación o perfilado, las audiencias se construyen a partir de las señales del propio adulto, y nunca dirigimos publicidad a un menor.
8. Medios para ejercer derechos ARCO y revocar el consentimiento. Usted (como Cliente, incluso en nombre del menor) puede ejercer sus derechos de Acceso, Rectificación, Cancelación y Oposición (ARCO), revocar su consentimiento y limitar el uso o divulgación de sus datos enviando una solicitud a privacy@happysongs.ai o a través de los controles de privacidad en la app. Su solicitud debe identificarle, describir los datos y el derecho que desea ejercer, y señalar un medio de contacto. Responderemos en los plazos que fije la Ley Federal de 2025 y su reglamento. [Plazos de respuesta por confirmar conforme al reglamento de la ley de 2025.]
9. Opciones para limitar el uso o divulgación. Puede limitar usos no esenciales (analítica, marketing) mediante los ajustes de la app y el canal ARCO anterior, y cancelar las comunicaciones en cualquier momento.
10. Cambios al Aviso. Podemos actualizar este Aviso; publicaremos los cambios en happysongs.ai/privacy y, para cambios materiales, se lo notificaremos según la Sección 16.
11. Autoridad. Si considera que sus derechos no han sido atendidos, puede acudir a la autoridad competente, la Secretaría de Anticorrupción y Buen Gobierno. [Datos de contacto y procedimiento por confirmar una vez publicado el reglamento.]
15.2 Puesta a disposición
El aviso integral se pone a disposición en happysongs.ai/privacy y dentro de la app; un aviso simplificado se muestra en el punto de recolección (onboarding de la app y Panel de Ventas) con un enlace a este aviso integral.
15.3 Aviso de Privacidad Simplificado
Happy Songs USA Corp., como responsable, tratará los datos personales del Cliente (adulto) —número de teléfono, correo opcional, datos del dispositivo y de uso, contenido para crear la canción y, para la suscripción y el Programa de Referidos, datos de transacción, pago y fiscales del propio Cliente— y únicamente el nombre de pila de la persona para quien se crea la canción, con la finalidad primaria de crear y entregar la canción personalizada que usted solicita, verificar su cuenta, operar y dar soporte al servicio, procesar pagos y operar el Programa de Referidos. Como finalidades secundarias (que puede negar) realizamos analítica del producto y comunicaciones de marketing. Para prestar el servicio, transferimos sus datos a Estados Unidos, donde se ubican nuestros proveedores, incluidos los de inteligencia artificial (Google/Lyria, Anthropic, OpenAI). Usted, como padre, madre o tutor, consiente el tratamiento de los datos del menor. Puede conocer el Aviso de Privacidad Integral y ejercer sus derechos ARCO o revocar su consentimiento en happysongs.ai/privacy o escribiendo a privacy@happysongs.ai.
16. Changes to this Policy, and to plans, features, and the Referral Program
We may update this Policy. We will post the updated version at happysongs.ai/privacy with a new “Last updated” date, and for material changes we will provide additional notice (in-app or by message) and, where the law requires it, obtain fresh consent before the change takes effect.
Our plans, features, pricing, and the Referral Program may also change, be added, or be discontinued over time. Any such change is prospective only: it does not retroactively alter what you have already paid for or the terms on which content you have already created is made available to you. Where the law requires notice of a change — in particular, notice of a subscription price increase before it takes effect on a renewal — we will provide it, and you may cancel. This Policy does not grant us a right to make retroactive or unfair changes; your non-waivable consumer rights are preserved.
17. Your rights and how to exercise them
Depending on where you live, you (as the Customer, including on behalf of a child) may have rights to:
- Access / know what personal information we hold;
- Correct / rectify inaccurate information;
- Delete / cancel your information and your account;
- Object / opt out of certain processing (including sale/sharing and non-essential analytics or marketing);
- Withdraw consent at any time, without affecting prior lawful processing;
- Portability — obtain a copy in a usable format.
How to exercise. Use the in-app account-deletion and privacy controls, or contact us at privacy@happysongs.ai. We verify requests, respond free of charge within the timelines applicable law requires, and — for a child’s data — process requests made by the parent or legal guardian.
Account and data deletion. You can start account deletion from within the app. Deleting your account, or the end of your access, removes your data from our servers and purges the songs cached in the app on your device. Because songs are only ever accessible inside the app and are never delivered to you as a separate file, no exported copy remains outside the app.
18. Regions beyond the United States and Mexico
This Policy governs our processing for the United States and Mexico, which are our launch markets. Jurisdiction-specific requirements for other regions — including the EEA and GDPR, the United Kingdom, Brazil (LGPD), Canada (including Quebec), and Switzerland — are addressed in separate materials and applied before we serve those markets. These include, as applicable, additional legal-basis and transfer disclosures, local representatives, supervisory-authority contacts, cookie-consent management, and children’s-code and consumer-protection requirements.
Happy Songs USA Corp. — Privacy Policy & Aviso de Privacidad, version 1.0. This document is the operative privacy notice for the Services in the United States and Mexico.