Legal
Privacy Policy
Last updated: 14 April 2026
LoveTune (“we”, “us”, or “our”) operates the LoveTune iOS application and the website at lovetune.app. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights under applicable data protection law including the UK GDPR, the EU GDPR, and the Data Protection Act 2018.
Data Controller
LoveTune is the data controller for the personal data described in this policy. You can reach our privacy contact by email at privacy@lovetune.app for any data-protection query, subject-access request, or complaint.
1. Data We Collect
Account information
When you create a LoveTune account we collect your email address, display name, and authentication identifiers. If you sign in with Apple or Google we receive only the identifiers those providers share with us — we do not receive your Apple or Google password.
Song creation data
To generate your personalised song we collect the story, occasion, music preferences, and names you provide in the creation wizard. This is the content used by our AI providers to produce your lyrics and audio. Generated lyrics and audio files are stored securely and linked to your account.
Payment information
All purchases are processed through Apple’s App Store via StoreKit 2. We receive transaction identifiers and purchase receipts from Apple to verify entitlements. We never see or store your card number or billing address — Apple handles all payment data.
Usage and device data
We collect anonymised usage events (such as which steps of the wizard you complete) through PostHog analytics. We also collect standard device information — device model, operating system version, and app version — to diagnose crashes via Sentry error tracking. IP addresses are processed transiently and are not stored in our database.
Shared content
When you share a song via a unique link or QR code, the landing page is publicly accessible to anyone with the link. No account is required to listen. We log basic access metadata (timestamp and country) to detect abuse.
2. How We Use Your Data
- Service delivery — to generate your personalised song, store it, and deliver it to you and your recipient.
- Account management — to authenticate you, manage your purchase history, and maintain your entitlements.
- Push notifications — to notify you when your song is ready. You can opt out in iOS Settings at any time.
- Service improvement — aggregated, anonymised usage data helps us understand how to make LoveTune better. We do not sell personal data.
- Legal compliance and fraud prevention — to meet our legal obligations, detect abuse, and protect our users.
Lawful basis for processing
Under Article 6 of the UK/EU GDPR, we rely on the following lawful bases:
- Contract (Art. 6(1)(b)) — to create your account, generate and deliver your song, process your purchase, and provide customer support.
- Legitimate interests (Art. 6(1)(f)) — for anonymised analytics, fraud prevention, abuse detection, and maintaining service security. You may object to processing carried out on this basis at any time.
- Legal obligation (Art. 6(1)(c)) — to retain financial records for tax and accounting purposes.
- Consent (Art. 6(1)(a)) — for optional marketing communications and non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
AI training and model improvement
We do not use your personal data, stories, lyrics, voice inputs, or generated songs to train, fine-tune, or improve any machine-learning or AI model — neither our own nor any third party’s. Our AI providers (Anthropic and ElevenLabs) process your inputs under zero-retention and no-training contractual terms. Your content is used solely to generate the song you requested.
3. Automated Decision-Making and AI
LoveTune uses automated systems, including large language models and music-generation models, to produce your lyrics and audio. Under Article 22 of the UK/EU GDPR you have the right to information about automated processing that significantly affects you.
- What is automated — lyric drafting, audio composition, quality scoring (profanity filter, sentiment check), and content-moderation decisions that block explicit or abusive inputs.
- Human oversight — our support team may listen to, review, and read the lyrics of songs you generate (including preview and full audio) for moderation, trust-and-safety, abuse investigation, and customer-support purposes. Reviewer access is restricted to authorised staff and logged in an internal audit trail. We handle any appeal you raise by email. We do not use automated decision-making for anything that produces legal or similarly significant effects on you.
- Your rights — you may request a regeneration, contest an outcome, or ask a human to review a moderation decision by emailing support@lovetune.app.
- AI limitations — generative AI can produce unexpected, inaccurate, or stylised output even when inputs are correct. You are responsible for the accuracy of the information you submit — see our Terms of Service for details.
4. Third-Party Services
We use the following third-party processors to deliver the service. Each is bound by a data processing agreement and subject to appropriate safeguards.
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Authentication & storage | Account info, song files |
| Anthropic | AI lyric generation | Story, occasion, names |
| ElevenLabs | AI music generation | Generated lyrics, style |
| Apple | Payments & distribution | Transaction receipts |
| Vercel | API hosting | Request metadata |
| PostHog | Analytics | Anonymised usage events |
| Sentry | Error monitoring | Crash reports, device info |
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.
6. Data Retention
- Active accounts — data is retained for as long as your account is active.
- Deleted accounts — we soft-delete your account on request. Personal data is permanently purged within 30 days. Song audio files are deleted from storage at the same time.
- Order records — purchase records are retained for 7 years to comply with UK financial and tax regulations. These records contain only transaction identifiers and amounts, not payment card details.
- Analytics data — anonymised analytics are retained indefinitely as they cannot be linked back to an individual.
7. Your Rights
Under UK and EU GDPR you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — request deletion of your account and personal data (“right to be forgotten”).
- Portability — receive your data in a structured, machine-readable format.
- Restriction — ask us to restrict processing while a dispute is resolved.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email us at support@lovetune.app. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.
8. Data Security
All data is encrypted in transit using TLS 1.2 or higher. Data stored in Supabase is encrypted at rest. Audio files are served via time-limited signed URLs — direct public access to storage is disabled. We follow industry-standard security practices and conduct regular reviews of our access controls.
9. International Transfers
LoveTune is operated from the United Kingdom. Some of our third-party providers process data in the United States. Where data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place — including Standard Contractual Clauses or the UK International Data Transfer Agreement — in line with ICO guidance.
10. Children's Privacy
LoveTune is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we become aware that we have inadvertently collected such data, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at support@lovetune.app.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, for material changes, notify you via the app or email. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions or concerns about this Privacy Policy or how we handle your data, please get in touch:
LoveTune
Privacy enquiries: privacy@lovetune.app
General support: support@lovetune.app
Website: lovetune.app
You also have the right to lodge a complaint with the UK Information Commissioner’s Office at ico.org.uk or with your local EU data-protection authority.
© 2026 LoveTune. All rights reserved.