Version operator-approved-v4-2026-08-28

Privacy notice

Last updated: 29 August 2026.

Controller

The controller is Stéphane François Xavier Lavergé, a self-employed person in Spain operating MusicForYou, NIE Z3520169R, Carrer d'Amàlia Soler, 16, 2, 08720 Vilafranca del Penedès, Barcelona, Spain. Privacy contact: stef-cloud@proton.me.

Data processed

MusicForYou processes the contact details provided (last name, first name, email and optional telephone), language, exchanges with Melira, questionnaire answers, memories, recipient, musical preferences, actions in the journey (help, progression, modification, creation or abandonment), technical indicators of model calls, lyrics, modification requests, produced files, orders, consents and elements necessary for support. Detailed payment data is handled by Stripe; MusicForYou keeps only necessary references, status and amounts.

When someone agrees to provide a testimonial, MusicForYou may also process the testimonial text, a minimised display name, an optional rating out of 5, an optional audio excerpt and the internal reference used to prove authorisation.

Data may come directly from the person, from a Meta lead form or from someone preparing a gift. You are asked not to provide unnecessary sensitive or intimate information about another person.

Purposes and legal bases

  • preparing the preview and creating, invoicing and delivering the song: pre-contractual steps and performance of the contract;
  • managing payment, invoices, accounting and legal obligations: contract and legal obligation;
  • link security, abuse prevention, incident handling and legal claims: legitimate interest in protecting the service;
  • support and data-rights requests: contract and legal obligation;
  • detecting misunderstandings, errors and abandonment in order to improve Melira and the journey: legitimate interest in improving the service, with human review and pseudonymised samples for automated analysis;
  • marketing messages: consent, withdrawable at any time;
  • publishing a written or audio testimonial and any optional rating: explicit consent, withdrawable at any time;
  • minimised performance measurement and advertising-spend synchronisation: legitimate interest, with browser DNT/GPC respected;
  • advertising conversions using hashed identifiers: only when enabled and supported by a documented legal basis.

Only on public presentation pages, MusicForYou uses Umami for strictly necessary anonymous audience measurement: page paths without query strings or fragments, referring site, browser, operating system, device type, screen size, language, country or approximate area, and visit duration. The server uses the IP address transiently to create an anonymous session identifier that changes every month, but does not store the IP address. Umami uses no cookies, advertising profiles, cross-site tracking, session recordings or heatmaps. Do Not Track and Global Privacy Control signals disable this measurement.

Separate Meta advertising measurement is offered only after explicit permission in the dedicated window. The Meta Pixel may then set _fbp and _fbc. MusicForYou sends Meta only ViewContent, Contact, InitiateCheckout and Purchase, with a shared browser/server event identifier, source URL, purchase order identifier, browser identifiers, user agent and hashed normalised contact details when available. The IP address can be sent only when a separate setting records specific legal approval; that setting is off by default. Memories, recipient details, questionnaire answers, detailed preferences and lyrics are never sent to Meta. Refusal does not restrict use or purchase of the service. Permission can be changed at any time through “Manage advertising measurement”; withdrawal deletes Meta identifiers held by MusicForYou and blocks later events. Encrypted Meta signals are retained for no more than 90 days; proof of the decision follows the retention period applicable to consent evidence.

Information required to create and deliver the song is mandatory. MusicForYou does not make solely automated decisions producing legal effects for the customer.

Recipients and providers

Access is limited to authorised people and necessary providers, depending on enabled functions: OVHcloud (hosting), OpenRouter and selected model providers (lyrics), APIFrame (music-generation gateway to Suno), Brevo (email and consented marketing), Stripe (payments) and Meta (advertising, leads and measurement). To produce the two interpretations, APIFrame and Suno receive the final lyrics checked by MusicForYou, title and necessary music directions, without customer contact details. Only data necessary for each task is disclosed.

APIFrame states that request logs and hosted results may be retained for up to 90 days. MusicForYou immediately downloads validated files to its private storage and never delivers a temporary provider URL to the customer.

Umami is open-source software self-hosted by MusicForYou on OVHcloud infrastructure. Audience data is not sent to Umami's publisher or reused for any other purpose.

Some providers or sub-processors may handle data outside the EEA. MusicForYou relies on the transfer safeguards announced by those providers, such as adequacy decisions or standard contractual clauses, and minimises transferred data.

Retention

  • raw technical measurement events: 72 hours;
  • anonymous Umami audience data: no more than 13 months;
  • verification links: 24 hours; privacy-request links: 72 hours;
  • detailed Melira conversation logs: 180 days after the last activity, after which message content is erased and only anonymous metrics may remain;
  • projects without purchase, contacts and pre-contractual exchanges: no more than 3 years after the last activity, unless requested earlier;
  • song, lyrics and gift page of an order: for the period needed for provision and support, no more than 3 years after the last activity, unless the customer asks for retention or earlier erasure;
  • contracts, consent evidence, invoices and payment records: the applicable statutory period, which may be up to 6 years;
  • marketing data: until consent is withdrawn or, without interaction, no more than 3 years;
  • backups: limited rotation followed by secure overwriting under the operating cycle.

Security and confidentiality

Conversations, stories, lyrics and change requests are stored in readable form in the database so that authorised people can process and analyse them. Access to them is restricted. Access secrets remain protected according to their use. Links are random, private and revocable. Technical logs must not contain stories or lyrics in plain text. Viewing a conversation in the administration area is restricted to authorised roles and is itself logged. Administrative access is named, restricted and protected.

Rights

Data subjects may request access, rectification, erasure, restriction, objection and portability, and withdraw consent without retroactive effect. A verified email workflow supports export and erasure. Requests may also be sent to stef-cloud@proton.me.

A complaint may be lodged with the Spanish Data Protection Agency at aepd.es or the competent authority in the country of residence.

Minors and third parties

The service is not intended for minors acting alone. When a story concerns a third party, the customer must limit the information to what is reasonably necessary and respect that person's rights.

Changes

The applicable version is the one accepted at the time of the order; its fingerprint is kept with the proof of consent. Important changes are indicated when the law requires it.

Status of this document

This version was updated on 29 August 2026 by the MusicForYou operator for the pilot launch after reviewing the information published by APIFrame and Suno. It had not been reviewed by a legal professional as of that date and may be updated later without retroactively changing retained consent records.