Legal
Privacy Policy
Last updated 12 September 2026
This describes what the Lyrumi Android app collects, why, who else sees it, and how long it is kept. It is written against what the app and its server actually do, not against a template.
1. Who is responsible
The data controller is Nikita Zarubin, sole trader, registered in the Republic of Serbia. Contact: support@lyrumi.com.
2. What we collect
Your Google account
Signing in requires a Google account. Google gives us a signed token, and from it we store four things: your Google account identifier, your email address, the name on the account, and your language. The token also contains a link to your profile picture — we do not read it, do not store it, and never use it as your picture in Lyrumi.
The name on your account is private. It is not shown to other users: it is only what the app fills the stage-name field in with, so that you have something to accept or replace.
Your stage name and picture
Before you share or publish a song, or post a comment, the app asks you for a stage name and a picture. We store the name you chose and either the number of one of the sixteen pictures that ship with the app, or — if you uploaded one — the photo you chose, resized to a 512×512 square.
An uploaded photo is re-encoded on our server before it is stored, which removes everything the file carried besides the picture itself: the camera, the software, and the place the photo was taken. We never store that.
What you create
The text you write and everything made from it: the prompt or lyrics you submit, the song title, the lyrics the model produced, the musical settings (style, voice, tempo, language, key, tempo in BPM), the generated audio file and cover image, and any comments you post or reports you file.
Purchases
When you subscribe or buy a pack, we store the Google Play purchase token, the order identifier, the product identifier, your current plan, and a ledger of every credit added to or spent from your balance. We also store the notifications Google Play sends us about renewals, cancellations and refunds.
We never see your card details. Payment happens entirely inside Google Play. Nothing about your payment method reaches us.
Notifications
If you allow notifications, the app registers with Firebase Cloud Messaging and sends our server the installation identifier it receives, together with your app version. We store it against your account and use it only to tell you that a song is ready, that someone commented on or liked a song you published, and that your subscription renewed or ended. It is deleted when you sign out, when you delete your account, or after 60 days in which the app has not checked in. You can turn notifications off in the app’s settings or in Android’s.
Technical and diagnostic data
Our server records, for each request, the path, the response status, how long it took, your app version and platform, and a truncated user-agent string. Your account identifier is attached to those records. If sign-in or a purchase fails, the app also sends us the error together with your device model and Android version, so that the failure can be diagnosed.
What we do not collect
- No IP addresses are stored or logged. Your address is used in memory for a moment to rate-limit the diagnostics endpoint, and is never written anywhere.
- No advertising identifier, and no advertising of any kind.
- No analytics, attribution or crash-reporting SDK. The only Firebase component in the app is Cloud Messaging, used solely to deliver notifications — no Firebase Analytics, no Crashlytics, no third-party analytics library.
- No location, contacts, camera, microphone or phone-state access. The app requests three Android permissions: internet access; permission to show notifications, which it asks for and you can refuse or withdraw at any time; and — on Android 9 and older only — file write access, so that a downloaded song can be saved.
On your phone, the app stores your session token, encrypted with a key held in the Android Keystore, and — unencrypted — your language and theme choices, the song you are currently writing, and the notification installation identifier.
3. Why we use it, and on what legal basis
- To provide the service — your account, generating songs, your library, Explore, purchases. Legal basis: performance of our contract with you.
- To keep records we are required to keep — purchase and payment records. Legal basis: legal obligation, and our legitimate interest in being able to reconcile a disputed charge.
- To keep the service working and safe — diagnostics, abuse reports, rate limiting. Legal basis: legitimate interests.
We do not use your content to train AI models, and we do not sell or rent personal data to anyone.
4. Who else receives data
Lyrumi cannot work without these four. Each receives only what is listed.
- Verifies your sign-in token. Runs Play Billing and tells our server whether a purchase is valid — we send Google the app package name and the purchase token, and no identifier of you. Delivers notifications through Firebase Cloud Messaging: receives the installation identifier and the notification text — a song title, or a comment together with its author’s stage name. Google’s own handling of your account is governed by Google’s privacy policy.
- RunPod
- Generates the music. Receives your lyrics and the style you wrote, together with the musical settings. It receives no account identifier, no email and no device data.
- Cloudflare
- Runs two AI models for us. When you ask the app to write lyrics, a language model receives your idea for the song and the style you wrote — and, when you ask for another take, the lyrics it wrote before. To draw the cover image, an image model receives a fixed style instruction plus the song’s title, used as a mood hint. Neither receives an account identifier, an email or device data.
- Railway
- Hosts the server, the database and the file storage that holds your audio, your cover images and your uploaded picture. Everything Lyrumi stores lives there.
We may also disclose data where the law requires it, or to establish or defend a legal claim.
5. Where data is stored
The database, the servers and the file storage are in the European Union — the Netherlands for compute, Amsterdam for stored files. Audio, cover images and uploaded pictures are kept in private storage and are only reachable through short-lived links that expire after fifteen minutes.
RunPod and Cloudflare may process the text you submit outside the European Economic Area. Where that happens, it is covered by the Standard Contractual Clauses in our agreements with them.
6. What becomes visible to other people
Your songs are private by default. Nothing you make is visible to anyone else unless you publish it, and publishing is a deliberate action you can reverse at any time.
While a song is published to Explore, other signed-in users of the app can see its title, its full lyrics, its cover, its audio, and your stage name and picture. The same name and picture appear next to any comment you post, and on the page anybody who has the link to one of your songs can open — that page is public, and it needs no account to read.
The name on your Google account is never shown to other users, and neither is your Google profile picture. What other people see is the stage name you chose and the picture you picked or uploaded, and you can change either at any time under Account.
Your email address is never shown to other users. There is no public web page for any song: everything in Explore requires being signed in.
7. How long we keep things
- Your account and your songs: until you delete them.
- Sign-in sessions: 30 days, then you sign in again.
- Server diagnostic logs: 30 days, then deleted automatically.
- Purchase and ledger records: kept for as long as we may need them for accounting and dispute resolution.
8. Deleting your account
You can delete your account yourself, in the app, under Account. It takes effect immediately and cannot be undone. When you do:
- your Google account is unlinked, so the account can no longer be signed into;
- your email address is overwritten, and your account name, your stage name and your uploaded picture are deleted;
- every song you made is removed from Explore and from your library.
What deletion does not currently remove. For accounting and dispute resolution, the prompts and lyrics you submitted, your song records, the text of comments you wrote, and your purchase and credit ledger are retained in our database rather than erased. The audio files and cover images stay in storage. Comments you left on other people’s songs remain visible, no longer attached to a name.
We would rather say this plainly than promise an erasure the system does not perform. If you want that data actually erased, write to support@lyrumi.com and we will do it manually — see your rights below.
9. Your rights
Under Serbian data protection law and, where it applies to you, the GDPR, you can ask us to give you a copy of your data, correct it, erase it, restrict or object to how we use it, or hand it over in a portable format.
There is no self-service export in the app yet. Write to support@lyrumi.com from the address on your account and we will respond within 30 days.
If you think we have handled your data badly, you can complain to your national data protection authority — in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection.
10. Children
Lyrumi is not directed to children. You must be at least 13, or at least 16 in the European Economic Area and the United Kingdom, to use it. We do not knowingly collect data from anyone younger, and the app performs no independent age check beyond requiring a Google account. If you believe a child has an account, write to us and we will delete it.
11. Security
All traffic between the app and our server is encrypted in transit. Your session token is stored encrypted on your device. Audio and cover files are held in private storage and served only through links that expire. Access to the production database is restricted to the operator over a private network.
No system is perfect. If a breach affects your data, we will notify you and the relevant authority as the law requires.
12. Changes
When this policy changes, the date at the top changes with it. If a change is significant, we will tell you in the app before it takes effect.
13. Contact
Privacy questions and requests: support@lyrumi.com.