# Privacy notice | Lyro

> What personal data Lyro collects, why, who receives it, how long we keep it, and how to export, delete or object. Written for UK GDPR and EU GDPR.

Source: https://lyromusic.com/legal/privacy

# Privacy notice

Last updated 21 September 2026

- RNIFY Limited, trading as Lyro, is responsible for your personal data.

- We collect what we need to run your account, make your music, take payment, keep the service secure and improve it. Stripe holds your card details. We do not.

- Your prompts, lyrics and audio go to the AI model providers that carry out your request. We do not sell data and we use no advertising trackers.

- Our analytics are first-party, and the "Analytics: on/off" switch in the footer turns them off. We do not join your browsing on our public pages to your account.

- Tips and offers inside the app are switched on by default, and Settings > Notifications switches them off. We send marketing email only if you opt in.

- Your library is deleted 30 days after your account stops being active, after reminders. Section 8 lists every retention period.

- You can export or delete your data from Settings, or contact us.

This summary is a guide and is not legally binding wording.

## 1. Who is responsible for your data

RNIFY Limited, trading as Lyro, is the controller of your personal data, which means we decide how and why it is used. We are a private limited company registered in England and Wales, company number 16749515, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. For any privacy question or request, contact us through [the contact form](https://lyromusic.com/contact) or [hello@lyromusic.com](mailto:hello@lyromusic.com).

This notice covers the website at https://lyromusic.com, the studio and share pages. We follow the UK GDPR and the Data Protection Act 2018. Where the EU GDPR applies to you, for example because you live in the European Economic Area, you have the same rights under it.

## 2. What we collect

We collect the data below. You give us most of it yourself, and the rest comes from your use of Lyro.

| Category | What it includes |
|---|---|
| Account | Email address, name if you give one, password (stored only as a salted hash), language, the version of the terms you accepted and when, whether you asked for product emails, and whether tips and offers inside the app are switched on. With Google sign-in: your name, email address and a Google account identifier, never your Google password. |
| Payment and billing | Plan, price, billing period, credit balance and credit history, plan changes, pauses and cancellations, with the reason for cancelling if you gave one, and Stripe customer and subscription identifiers. Stripe holds your card details and billing address. We never see your full card number. |
| Your content | Audio you upload or record, which can include your voice. Lyrics, prompts and titles. The tracks, stems and cover art you generate, your studio projects and your share links. |
| Usage analytics | On our public pages: pages and sections viewed, scroll depth, clicks on buttons, time on a page, referring site, campaign tags, browser language, device type, country, and a random identifier in the lyro_a cookie (section 4). Inside the signed-in studio: the screens you open and the steps you take, recorded under your account. |
| Technical data | IP address, browser type, and the security log and error log below. For each sign-in session, the browser and country, which you can review in Settings. |
| Security log | Sign-ups, log-ins, failed log-ins, lockouts, password resets and failed security checks. Each entry holds the time, the kind of event, the account it concerns if there is one, a keyed hash of the IP address (not the address itself), the country and the browser string. |
| Error log | When something breaks on a page or in a generation: the error message, the page path, and the account and the job it concerns if there is one. |
| Email log | For each email we send or try to send you: your email address, the kind of email, its subject line and whether it was sent. Not the body of the email. |
| Support conversations | What you and our team write, your email address and name, and the topic. When you write from Help inside the app, your plan, credit balance, language, browser string and last failed generation are attached automatically, so that you do not have to explain your account. If you rate the conversation, the rating. Messages from the contact form are handled in the same way, with your browser string attached. |
| In-app message records | For each tip, offer or notice shown to your account: how often it was shown, clicked and dismissed, when, and whether you did what it suggested within seven days. Also whether your account is in the small random group that gets no promotional messages (section 5). |
| Invite programme | Your invite code, who invited whom, whether the reward is waiting, given or refused, and a keyed hash of the IP address used when the invited account was created. We compare that hash with the inviter's entries in the security log to spot self-invites. |
| Other messages and feedback | Teams applications, reports about tracks, takedown notices, your thumbs up or down on tracks, and testimonials you submit. |
| Quiz answers | Your starting point, the genre, mood, voice, language and theme you chose, and how often you plan to make music. |

To open an account you must give an email address and a password, or use Google sign-in, and to buy a plan you must give payment details. Everything else is optional. A voice recording is personal data, and we do not use voices to identify anyone. Our analytics store the country that our host derives from your IP address, not the address itself. We do not ask for your friends' contact details for the invite programme, and we do not message them: you share your link yourself.

## 3. Why we use it and our lawful bases

We use your data only for the purposes below. Each has a lawful basis under data protection law.

| Purpose | Data | Lawful basis |
|---|---|---|
| Run your account, sign you in and keep it secure | Account, technical data | Contract. Legitimate interests in security. |
| Protect sign-up and sign-in: the security log, the short lock after repeated wrong passwords, the refusal of throwaway email addresses, rate limits and, when it is switched on, the Turnstile check | Security log, technical data, email address | Legitimate interests in preventing fraud and abuse and in keeping accounts safe. |
| Make, store and play your music, which includes sending prompts, lyrics and audio to the model providers and serving share links you switch on | Your content | Contract. |
| Keep your library for as long as the terms say, remind you before it is deleted, and then delete it | Your content, account, email address | Contract. |
| Take payment, manage your plan and credits, including changes, pauses and cancellations, and send receipts and other emails about your account | Payment and billing, email address, email log | Contract. Legal obligation for tax and accounting records. |
| Turn your quiz answers into a song plan and a suggested plan | Quiz answers | Steps before a contract, at your request. Legitimate interests. |
| Answer support conversations, contact form messages and Teams applications | Support conversations, other messages and feedback | Contract, where you are a customer. Legitimate interests in replying. Steps before a contract for Teams. |
| Show messages about your own account inside the app, such as a failed payment or a reminder that your library will be deleted | Account, payment and billing, in-app message records | Contract. |
| Show tips, product news and offers inside the app, limit how often you see them, and measure whether they help | Account, payment and billing, how you have used Lyro (for example how many tracks you have made), in-app message records | Legitimate interests in helping you get more out of Lyro and in promoting our own service. You can object at any time with the switch in Settings > Notifications (section 5). |
| Run the invite programme: give the rewards and spot self-invites | Invite programme, security log | Contract, to give the reward. Legitimate interests in preventing abuse of the programme. |
| Understand how the site, the studio and the models perform, so that we can improve them | Usage analytics, feedback on tracks | Legitimate interests. You can object at any time (section 4). |
| Find and fix faults | Error log | Legitimate interests in a service that works. |
| Keep a record of the emails we sent, so that we can answer when you ask whether we emailed you | Email log | Legitimate interests. |
| Back up the database every night, so that a failure does not lose your account or your credits | Everything in our database | Legitimate interests in a reliable service. Legal obligation to keep personal data secure. |
| Prevent abuse and fraud, enforce our terms, handle reports and takedown notices | Technical data, security log, your content, support conversations, other messages and feedback | Legitimate interests in a safe and lawful service. Legal obligation where the law requires action. |
| Send tips, product news and offers by email, or publish a testimonial you wrote | Email address, quote and display name | Consent, which you can withdraw at any time. Every such email has a one-click unsubscribe link. |
| Bring or defend legal claims and answer regulators | Whatever is relevant | Legitimate interests. Legal obligation. |

## 4. Our analytics and your right to object

We run our own analytics, and you can turn them off at any time. There are no advertising trackers and no third-party analytics scripts. The data stays in our own database and is used only to improve the site and the studio.

The analytics cookie is set under the statistical-purposes exception in the UK Privacy and Electronic Communications Regulations, in force since 5 February 2026. It allows improvement statistics without consent if we explain them clearly and give you a simple, free way to object. Our lawful basis for the processing is legitimate interests.

To object, use the "Analytics: on/off" switch in the footer of any page, or choose "Turn off" in the analytics notice. The cookie is deleted and the tracker stops at once. After that the only thing our server counts about a visit is each page request, in a daily total, with no cookie and no identifier. The [cookies and analytics page](https://lyromusic.com/legal/cookies) has the details.

We do not join your browsing on our public pages to your account. A visit is recorded under the random identifier in the cookie, with no account identifier. What you do inside the signed-in studio is recorded under your account, without the cookie identifier.

One link exists, and it is narrow. When you sign up, start a checkout or pay, our server records that step under your account, together with the random identifier of the visit it happened in, and marks the visit as one that led to a sign-up or a purchase. We do this to see which pages help people get started. The mark is a yes or a no, and the visit record never holds your account identifier. Turning analytics off stops this, because there is then no visit identifier.

Account steps such as signing up, paying, changing a plan or cancelling are recorded under your account whether analytics is on or off, because they are part of running your account.

## 5. Messages inside the app, and how we measure them

Tips, product news and offers inside the app are switched on by default, and the [terms](https://lyromusic.com/legal/terms#messages-inside-the-app) say so. You can switch them off at any time in Settings > Notifications. That switch is also how you object to this use of your data, and it works at once. Messages about your own account, such as a failed payment or a reminder that your library will be deleted, are always shown.

To decide which message fits, the app looks at facts about your account: your plan, your credit balance, how many tracks you have made, which tools you have used and how long you have been with us. Nothing is sent to anyone else for this, and no advertising network is involved.

For each message we record, under your account, how often it was shown, clicked and dismissed, when, and whether you did what it suggested within seven days. We use these records for two things: to keep to the frequency limits in the terms, and to measure which messages help.

A small share of accounts, picked at random when the account is created, never gets promotional messages. Comparing the two groups is how we measure the effect. If your account is in that group, the only difference is that you do not see tips and offers.

Our lawful basis is legitimate interests. These messages are not emails, texts or push notifications: they exist only inside the app, while you are using it.

## 6. Who we share data with

We share data with the providers that run Lyro for us, and with nobody for advertising. Each provider acts on our instructions under a contract, except where we say otherwise.

| Provider | What it does | Where |
|---|---|---|
| Cloudflare | Hosting, database, file storage, the nightly database backups, security and rate limiting, the Turnstile check at sign-up when it is switched on, and a fallback language model for the writing assistant. | USA and its global network |
| fal.ai | Runs the AI models for music, stem separation and cover art. Receives your prompt and lyrics and, for audio tasks, a short-lived signed link to the audio file. | USA |
| Google | Provides the Lyria 3 Pro model through fal.ai. Receives the prompt and lyrics for songs made with it. | USA |
| OpenRouter | Routes writing assistant requests to a language model provider, through fal.ai. Receives the text you give the prompt generator or lyric writer. | USA |
| Stripe | Payments, invoices, the billing portal and fraud prevention. Also a controller in its own right for part of this, under its privacy policy. | USA and the countries where Stripe operates |
| Resend | Emails about your account: email confirmation, password reset, receipts, failed payments, cancellation and pause confirmations, library deletion reminders, support replies and invite rewards. Also tips and offers by email, if you opted in. Receives your email address and the content of the email. Used only while email sending is switched on. | USA |
| Have I Been Pwned | Password breach check. Our server sends only the first 5 characters of a SHA-1 hash of a new password, never the password, your email address or your IP address. | No personal data is sent |

Requests to the model providers carry the content of your request. They do not include your name, email address or account identifier.

When the Turnstile check is switched on, the sign-up page loads a small program from Cloudflare that tells people from automated programs. Cloudflare receives your IP address, technical details of your browser and connection, and the address of our site. Our server then sends Cloudflare your IP address with the result, so that Cloudflare can confirm it. Cloudflare runs the check on our instructions. It also uses the same signals to improve its bot detection, as a controller in its own right, under its [Turnstile privacy addendum](https://www.cloudflare.com/turnstile-privacy-policy/).

When you write to support, a copy of your message is emailed to our team's mailbox through the email provider above, so that a person sees it quickly.

Two services receive data straight from your browser, as controllers in their own right. Our pages load the Instrument Sans typeface from Google Fonts, so Google receives your IP address and browser details when the font files load. If you choose Google sign-in, Google handles it under its own privacy policy.

We also share data when the law requires it, to bring or defend legal claims, with a rights holder where a takedown process requires it, and with a buyer if the business is sold, under the same protections. We do not sell personal data.

## 7. International transfers

We are in the UK and most of our providers are in the United States, so your data leaves the UK and the European Economic Area, with safeguards.

Where a US provider is certified under the UK Extension to the EU-US Data Privacy Framework, known as the UK-US data bridge, we rely on that. For data covered by the EU GDPR, we rely on the EU-US Data Privacy Framework in the same way. Where a provider is not certified, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and on the Standard Contractual Clauses themselves for data covered by the EU GDPR. Contact us for a copy of the safeguard that applies to a provider.

## 8. How long we keep data

We keep data only as long as we need it for the purposes above. The periods are:

| Data | How long |
|---|---|
| Your library: tracks, stems, uploads, recordings, cover art and studio projects | While your account is active, which means while it has a plan or unused top-up credits. When it stops being active we keep the library for 30 more days, remind you by email and in the app 30, 7 and 1 days before the deletion date, and then delete it. The account itself stays, and starting a plan again before the date keeps everything. You can also delete a track, or your account, yourself at any time. |
| Deleted files | A deleted track leaves your library at once. A nightly clean-up erases the file from storage once it has been deleted for 24 hours, so in practice within about one to two days. |
| Account record and quiz answers | Until you delete your account. The account record is then anonymised at once. Quiz answers that were never linked to an account carry no name or email address. |
| Billing records: plans, invoices and the credit history | 6 years, as tax and accounting law requires |
| Analytics events | 120 days |
| Visit summaries, one row for each browsing session | 400 days |
| Security log | 90 days |
| Email log | 90 days |
| Error log | 30 days |
| Sign-in sessions and one-time links | Sessions last 30 days or until you sign out, email confirmation links 3 days and password reset links 1 hour. Expired records are deleted every night. |
| Support conversations and contact form messages | Until you delete your account, or 24 months after the conversation is solved, whichever comes first |
| In-app message records | Until you delete your account. We need them for that long so that a message you have dismissed for good stays away. |
| Notices in your in-app inbox | Up to 30 days |
| Invite programme records | While your account is open. If you delete your account, the record of the invite stays with the credit history, because it explains why credits were given, but it then points to an anonymised account record. The hash of the IP address in it is only ever compared with security log entries, which last 90 days. |
| Teams applications, reports about tracks and takedown notices | While we deal with the matter, and then for as long as a legal claim could arise from it |
| Server request logs at our host | A short time, for debugging and security, and then deleted automatically |

**Backups.** A copy of the database is made every night and stored in Cloudflare R2, inside our own Cloudflare account. We keep the three most recent copies, so data that you delete disappears from the backups within about three days. Cloudflare also keeps a point-in-time recovery history of the database for up to 30 days. We would use either only to recover from a failure. Audio files are not part of these backups.

We may in future set a storage period for individual tracks. We have not done this. If we do, the terms say how you will be told: in the app, with at least 7 days' notice before any track is deleted, and by email before the change takes effect.

## 9. Your rights and how to use them

You have the right to:

- get a copy of your data, in a portable format;

- have wrong data corrected;

- have your data erased;

- object to processing based on legitimate interests, including our analytics, and ask us to restrict processing;

- object to direct marketing at any time. For tips and offers inside the app, use the switch in Settings > Notifications. For marketing email, use the unsubscribe link in any such email or the switch in Settings. We always act on this objection;

- withdraw consent at any time, where we rely on consent;

- not be subject to a decision based only on automated processing that has a legal or similarly significant effect.

The quickest route is the Privacy tab in Settings. "Export my data" downloads one file with your account details, track list, generation history, credit history, activity and quiz answers, and "Delete my account" erases your account. The file does not include support conversations, in-app message records, invite records or security log entries. Contact us for those. You can also reach us through [the contact form](https://lyromusic.com/contact) or [hello@lyromusic.com](mailto:hello@lyromusic.com). Using your rights is free. We reply within one month and may need to check that the request comes from you.

Deleting your account ends any paid plan at the same moment, so that you are never charged again. If we cannot end the plan, for example because the payment provider does not answer, nothing is deleted and we ask you to try again. Deleting then erases your tracks, projects, support conversations, in-app message records, email log entries, analytics events and quiz answers, signs you out everywhere, and strips the account record of your email address, name, password hash and Google identifier. Billing records stay for the period in section 8. Security log entries age out after 90 days and error log entries after 30 days. Backups catch up within about three days, and Cloudflare's recovery history within 30 days.

## 10. Complaints

If you are unhappy with how we handle your data, please tell us first, through [the contact form](https://lyromusic.com/contact) or [hello@lyromusic.com](mailto:hello@lyromusic.com). We will acknowledge your complaint within 30 days and tell you the outcome without undue delay.

You can also complain to the UK regulator, the Information Commissioner's Office (ICO), at [ico.org.uk/make-a-complaint](https://ico.org.uk/make-a-complaint/). If you live in the European Economic Area, you can complain to the data protection authority in your country.

## 11. Children

Lyro is for adults. You must be 18 or over to have an account, and we do not knowingly collect data from anyone under 18. If you believe a child has opened an account, contact us and we will close it and delete the data.

## 12. How we protect your data

We use measures that fit the size of the service and the kind of data we hold:

- Passwords are stored only as salted hashes, and new passwords are checked against known breaches without leaving our server.

- The sign-in cookie is HttpOnly, so scripts in the page cannot read it, and we store only a hash of the session token.

- All traffic to Lyro is encrypted in transit.

- Your files are private: served only to you, through a share link you switched on, or to a model provider through a signed link that expires.

- Card details go straight to Stripe and never touch our servers.

- Repeated wrong passwords are refused for 15 minutes: first for the address they come from (after 8), and for the whole account only if they arrive from many addresses at once. You can add two-step sign-in with an authenticator app in Settings, Security.

- We refuse sign-ups from throwaway email services, we limit how fast sign-up and sign-in can be tried, and we may show a Cloudflare Turnstile check at sign-up.

- We keep a security log of sign-ups, log-ins, failed log-ins and lockouts. It holds a keyed hash of the IP address, which lets us see that the same address came back without storing the address itself.

- The database is backed up every night to storage inside our own Cloudflare account, and we keep the three most recent copies.

No service can promise perfect security. If a breach is likely to put you at risk, we will tell you and the regulator as the law requires.

## 13. Automated decisions

We make no automated decisions about you that have a legal or similarly significant effect. Some things are automated without such an effect: Lyro picks the AI model for a request from the language and the task, the quiz suggests a plan that you are free to ignore, and rate limits slow down unusually frequent requests.

Other steps are automatic too. Sign-in to an account is locked for a short time after repeated wrong passwords. Sign-ups from throwaway email services are refused. An invite reward is withheld when the two accounts appear to share a household or network. In-app messages are chosen by rules about your account, and a random share of accounts gets no promotional messages. None of these has a legal or similarly significant effect. If you think one of them got it wrong, contact us and a person will look at it.

## 14. Changes to this notice

We update this notice when what we do changes, for example when we add a provider. The date at the top shows the latest version. If a change is significant, we will tell you by email or in the studio before it takes effect.
