Privacy Policy
Last updated: July 17, 2026.
The legal text below is available in English only.
This Privacy Policy explains how LrcSong ("we", "us", "our") collects, uses, stores and shares information when you use lrcsong.com("Service"). By using the Service you agree to this policy. If you do not agree, please do not use the Service.
Operator / data controller: LrcSong. Contact for privacy matters: support@lrcsong.com.
1. Information we collect
(a) Account data
- Email address (required to create an account).
- A salted
bcrypthash of your password. We never store or see the plaintext. - Optional display name and avatar URL.
- Credit balance, subscription plan, and lifetime credit usage.
- Email verification state and password-reset tokens.
(b) Usage data
- Records of AI jobs you run: job type, status, duration, error messages, credits consumed, and the generated lyrics/subtitle output. These are kept in your account history until you delete them. Closing your account does not delete them — see sections 6 and 7. (Large source uploads and media output files are removed sooner to save space — see below.)
- Records of AI requests made on your behalf: which provider and model handled the call, the module that issued it, token counts, and cost. These are retained after account deletion with your user ID removed.
- Webhook event receipts from Razorpay (for idempotency and audit).
- Server access logs (IP address, user-agent, request path, timestamp). Retained up to 30 days for abuse detection and debugging.
(c) Uploaded files
- Audio, video, image, and subtitle files you upload are written to a short-lived temporary directory for processing. For our instant tools (format conversion, tag and artwork editing, noise cleanup), your file is deleted as soon as the response is returned. For AI jobs, your original upload is kept after the job completes so you can replay it from your Job History; a scheduled cleanup then deletes it. That cleanup runs every six hours and removes uploads older than 24 hours — the default retention threshold, which an operator can change. Because it runs on a schedule rather than continuously, an upload's maximum lifetime is about 30 hours (24 hours of retention, plus up to 6 more until the next pass). Working copies derived from your upload are removed as soon as the job finishes.
- For in-browser tools (subtitle converters, viewers, validators, lyrics cleaner, CUE splitter), files never leave your browser — no server upload happens.
(d) Payment data
- We do not see or store card numbers. Payments are processed directly by Razorpay; we store only your Razorpay customer/subscription identifiers and subscription status.
2. Legal basis for processing (EU / UK users)
- Contract — to create your account, deliver the Service, process payments.
- Legitimate interests — to prevent fraud, debug failures, and secure the platform (rate limiting, abuse detection, access logs).
- Consent — for optional features (e.g., marketing emails, if ever introduced). Withdrawable at any time.
- Legal obligation — to retain invoices and tax records where law requires.
3. AI processing — where your audio and text go
Transcription and lyric generation. When you run an AI lyrics job, we try a chain of AI providers in order and use the first one that succeeds. By default that chain tries third-party cloud providers first — Azure OpenAI Whisper, MiniMax, and Google Gemini — before falling back to speech-recognition models running on our own servers. Your audio (or the YouTube URL you paste), and any lyrics text you supply, are sent to whichever provider handles the job. A provider with no API key configured is skipped, so which of them actually receives your data depends on our current configuration. We cannot promise that your audio stays on our infrastructure.
The LrcSong AI Assistant (text chat and the voice agent) also uses more than one provider, and not only as a fallback. If your message plainly names a tool, it is routed without an AI provider at all. Otherwise — the normal case for a free-form question — your message, plus up to the last four turns of the conversation, goes first to an intent classifier that by default tries Azure OpenAI, then Google Gemini, and only then the model on our own servers. The reply itself is drafted by a separate chain that does try our self-hosted model first, with Gemini behind it. As above, a provider with no key configured is skipped. We cannot promise that your prompts stay with us.
The in-browser tools listed in section 1(c) involve no AI provider at all — nothing is uploaded anywhere.
4. Third-party processors
- Razorpay (payments) — processes your card / UPI / netbanking details, email, and billing address. See Razorpay's privacy policy.
- AI providers (transcription, lyric generation, and the assistant) — Microsoft Azure OpenAI, MiniMax, and Google Gemini. Depending on which is configured and which handles your job, these receive the audio you upload, the YouTube URL you paste, lyrics text you supply, and assistant prompts. They do not receive your account email. See section 3 for the order in which they are tried, and each provider's own privacy policy for how they handle what they receive.
- SMTP relay (e.g., Gmail, Postmark — operator-configurable) — delivers transactional emails (verification, password reset).
- YouTube — if you paste a YouTube URL,
yt-dlpfetches the public video from YouTube on our behalf. YouTube receives our server's IP address; it does not receive your account email. - Let's Encrypt — issues the TLS certificate for the site.
- Google Fonts — loads the Inter web font. Google receives your IP address when the font is fetched. No cookies are set.
We do not use analytics, advertising pixels, or tracking cookies. No data is sold.
5. Cookies & similar technologies
We set one cookie:
lrcsong_refresh— HTTP-only, Secure, SameSite=Lax, scoped to/auth. Holds the signed refresh token that keeps you logged in between visits. Expires in 30 days or when you log out.
We also use browser localStorage to cache your current access token and user profile so the UI doesn't refetch on every page reload. Clearing site data signs you out.
6. Data retention
- Account records (email, password hash, credits, subscription) — kept while your account is active. Hard-deleted on account deletion via
ON DELETE CASCADE. The same cascade covers your API keys, favourites, saved projects, setlists, notifications, login events, and voice models. - Job records & generated lyrics — kept in your history until you delete them. We do not auto-expire them on a timer. Closing your account does not delete them; the rows are kept with your user ID removed (see section 7).
- Uploaded source files — for our instant tools, deleted as soon as the response is returned. For AI jobs, kept so you can replay them from Job History, then deleted by a scheduled cleanup: a maximum lifetime of about 30 hours by default (see section 1(c)). The job record and its lyrics text remain after the file is gone.
- AI request logs — we keep a record of every AI request (which provider, what it cost, whether it succeeded) indefinitely, because it backs our cost accounting. The prompt and response text in that record is different: a truncated copy is kept for 30 days and then deleted. You can read your own log at Account → AI activity until then, after which entries show the size of what you sent but not the text.
- Razorpay webhook receipts — kept indefinitely by default for reconciliation and audit. These are payment events from Razorpay; they hold no lyrics or audio.
- Server logs — rotated daily, 14 days of history.
- Invoices & tax records — retained for the period required by applicable law (typically 7 years).
7. Your rights
You have the following rights over your personal data, subject to applicable law (GDPR / UK GDPR / CCPA and equivalents):
- Access — request a copy of the data we hold about you.
- Rectification — correct inaccurate data (edit your profile directly, or email us).
- Erasure — delete your account at any time from Account → Delete Account, or email us. This removes your account record and the data listed as cascading in section 6. It does not delete your job records: those rows, including the lyrics and subtitle text they hold, are kept with the link to your user ID removed. The same applies to AI request logs, audit logs, and any community lyrics or annotations you posted. If you want these deleted outright rather than unlinked, email us and we will remove them manually.
- Portability — export your job history as JSON (from the Job History page) or on request.
- Restriction / Objection — ask us to stop specific processing where you have grounds.
- Withdraw consent — for any consent-based processing, at any time.
- Complaint — you may lodge a complaint with your local data-protection authority.
To exercise any of these rights email support@lrcsong.com. We respond within 30 days.
8. Security
The Service is served over TLS 1.2+ (via Let's Encrypt) with HSTS enabled. Passwords are hashed with bcrypt. Access tokens are short-lived (15 min) and the refresh cookie is HTTP-only + Secure + SameSite=Lax. Admin endpoints require an is_admin flag. Rate limits protect login, registration, and password reset from brute-force abuse. We still recommend you use a strong, unique password and a password manager. No system is perfectly secure; if you believe you've found a vulnerability, email support@lrcsong.com.
9. Children
The Service is not directed to children under 13 (or the age of digital consent in your jurisdiction, whichever is higher). We do not knowingly collect personal data from children. If you believe a child has registered, email us and we will delete the account.
10. International transfers
Our servers are hosted on enterprise-grade cloud infrastructure. Depending on your location, your data may be processed outside your country of residence. Where we use sub-processors (Razorpay, SMTP providers, and the AI providers named in section 4), data transfers rely on standard contractual clauses or other lawful mechanisms published by those providers.
11. Changes to this policy
If we change this policy in any material way we will post the updated version here and update the "Last updated" date above. Continued use of the Service after a change constitutes acceptance.
12. Contact
Questions, requests, or complaints — email support@lrcsong.com.