Privacy Notice
How Moonsong handles your personal data: what we collect, why, who receives it, how long we keep it, and your rights.
Who is responsible
Moonsong is an iPhone app and website published under the Sansavision brand. Sansa Group AB (Swedish organisation number 559111-9507) is the company behind Sansavision and the controller of the personal data described in this notice.
Sansa Group ABSoldathemsgatan 20
415 28 Göteborg
Sweden
For anything about your personal data, email support@sansavision.com. Please put "Moonsong privacy" in the subject line so we can route it quickly.
This notice covers the Moonsong iOS app, the Moonsong service behind it and the website at moonsong.my. It is written for the service as it actually works today. When that changes, we update this notice and its version number.
The short version
Moonsong does not ask for access to your contacts, photos, microphone or location, and it does not accept voice recordings.
What we collect and why
The table lists every category of personal data the Moonsong service stores. "Contract" means the processing is necessary to provide the service you asked for (GDPR Article 6(1)(b)). "Legitimate interests" means Article 6(1)(f); you can object to it (see Your rights). "Legal obligation" means Article 6(1)(c).
| Data | Source | Why we use it | Legal basis | How long |
|---|---|---|---|---|
| Email address | You, when you sign in | Create and sign in to your account; send sign-in codes and links; answer you | Contract | Until you delete your account |
| Account ID and optional display name | Created by us; display name from you | Run your account and show your name in the app | Contract | Until you delete your account |
| Your creative content: lyrics, song briefs (Song Blueprint), notes, project titles and lyric revision history | You | Store and show your projects; send the parts needed for a requested AI action to the providers listed below | Contract. AI processing also requires your in-app permission | Until you delete the project or your account |
| Generated audio (MP3) and cover images | Created at your request by AI providers | Playback, comparison of takes, export | Contract | 24 months from creation, or sooner if you delete them (see Retention) |
| Generation job records | Created when you run an AI action | Deliver results, restore credits after failures, reconcile provider costs, prevent abuse | Contract; legitimate interests (cost control and abuse prevention) | With the project or account; minimal cost and credit records as described under Retention |
| Credit wallet ledger and Apple transaction identifiers | Apple (signed transaction data) and your actions | Grant and track credits, restore purchases, handle refunds and disputes, prevent fraud, keep accounts | Contract; legal obligation (bookkeeping); legitimate interests (fraud prevention) | Account lifetime; a minimal finance and fraud ledger is kept as long as the law requires |
| Consent and eligibility records: AI-processing permission, 18+ confirmation, accepted Terms and Privacy versions | You | Show what you agreed to and when | Legal obligation (demonstrating consent); legitimate interests | Until you delete your account, except where needed as evidence |
| Session records: device and app/browser details (user agent), sign-in and last-seen times | Your device | Keep you signed in, let you review and revoke sessions, protect your account | Contract; legitimate interests (account security) | Sessions last about 30 days; deleted with your account |
| IP address | Your network connection | Rate limiting to stop abuse of sign-in and other routes | Legitimate interests (security and abuse prevention) | Used in the moment and stored only as a one-way hash in short-lived rate-limit records that expire automatically. Not stored in your session. |
| Free-introduction record: a one-way keyed hash (HMAC-SHA-256) of your email address, an internal account ID and the date the free introduction was claimed | Created by us when your account receives the free introduction | Give the free introduction only once per email address. The hash cannot be turned back into your email address and is used for nothing else | Legitimate interests (preventing abuse of a free offer) | 24 months from the claim, including after you delete your account, so the same address cannot claim the free introduction again |
| Operational and security logs | Our servers | Keep the service running, investigate errors and security events | Legitimate interests | Operational logs about 30 days; security logs about 90 days. They don't contain your lyrics or prompts. |
| Support messages | You, when you email us | Answer your request and keep a record of it | Contract; legitimate interests | As long as needed to resolve and follow up on your request |
Your creative writing is yours to choose. It can contain personal or sensitive details about you or other people, so please include only what you are comfortable sending to the AI providers listed below. We don't analyse your writing to profile you and we don't infer sensitive characteristics from it.
AI processing
Moonsong's AI features only run after you give explicit permission in the app. That permission is recorded with the version of the AI processing notice you saw (currently ai-processing-2026-09-24). You can withdraw it at any time in the app under Profile → Privacy & data. Withdrawing stops all AI features from then on; manual writing, templates, playback and export keep working.
When you start an AI action, we send the content needed for that action through OpenRouter to the provider that runs the model:
| Action | Model | Provider | What is sent |
|---|---|---|---|
| Full song and 30-second clip | Lyria 3 Pro (preview) and Lyria 3 Clip (preview) | Your approved lyrics and Song Blueprint (style, mood, vocals, instruments, exclusions, pronunciation hints) | |
| AI lyric draft or revision | GPT-6 Luna | OpenAI | Your idea or instruction and the lyric sections you asked it to work on (locked sections are excluded from changes) |
| Automated safety check | Jev 1.13 | Typesafe | The text of the request, to check it against our content rules and provider policies |
| AI cover | FLUX.2 Klein 4B | Black Forest Labs | An image description based on your project and Song Blueprint |
We don't send your email address to AI providers. We ask OpenRouter to use only provider routes that do not collect data for training (data_collection: deny). These providers are still independent companies with their own retention and safety-logging practices, and they may process content outside the EU/EEA, including in the United States. See Subprocessors and AI & music rights.
We don't write raw lyrics or prompts to our operational logs, and we don't use your content to train AI models.
Automated safety checks
Before an AI action runs, the text is checked automatically against our content rules. If the check blocks a request, you see a message in the app, no credits are spent for the blocked action, and nothing is generated. A blocked request has no legal or similarly significant effect on you, but you can always ask a person to review it: email us with the project name and roughly when it happened. See Appeals.
Sign-in and security
Moonsong uses passwordless sign-in. You enter your email address and receive either a 6-digit code or a sign-in link. These emails are sent from auth@moonsong.my through Cloudflare's email service. There are no passwords and no social log-ins.
A signed-in session lasts about 30 days. We store it with your device and app details so you can see where you are signed in. We do not store your IP address or any IP-based location in your session, and Moonsong never uses your iPhone's location.
To stop abuse, sign-in and other requests are rate limited. The limiter uses your IP address in the moment and keeps only a one-way hash of it in short-lived records that expire automatically.
We will never ask you for your sign-in code or link by email or phone.
Purchases and credits
Subscriptions and credit packs are sold by Apple through the App Store. Apple handles payment and your payment details; we never see your card. We receive signed transaction information from Apple (such as product, transaction identifiers, dates and renewal status) to grant your credits and keep your wallet accurate. We keep a ledger of credit grants, reservations, spending, restorations and refunds.
Apple processes your purchase as an independent controller under its own privacy policy.
Who receives your data
We don't sell personal data and we don't share it for advertising. We use these service providers:
- Cloudflare hosts the service, database and private file storage, protects the network and delivers sign-in emails.
- OpenRouter routes AI requests to the model providers.
- Google, OpenAI, Typesafe and Black Forest Labs run the AI models for the actions you request.
- Apple sells and manages App Store purchases and subscriptions.
The full list, with purposes and locations, is on the Subprocessors page. We may also disclose data where the law requires it, to protect people's safety or our legal rights, or as part of a business transfer, in which case this notice would continue to protect it.
International transfers
Sansa Group AB is based in Sweden. Some providers above are based in, or process data in, countries outside the EU/EEA, including the United States. Where personal data is transferred outside the EU/EEA, we rely on an adequacy decision (such as the EU–US Data Privacy Framework for certified recipients) or the European Commission's Standard Contractual Clauses, together with any additional safeguards needed. You can ask us for more information about the safeguards for a specific provider.
Retention
- Generated songs, clips and covers are stored for 24 months from creation, unless you delete them sooner. Before routine deletion we remind you in the app 90, 30 and 7 days ahead so you can export. Files you have exported to your device are yours and are not affected.
- Lyrics, briefs, notes and projects are kept until you delete the project or your account. A deleted project's files are removed within 7 days.
- Account deletion removes your data from our active systems within 7 days and from backups within 30 days.
- Finance and fraud records: a minimal ledger of purchases, credit grants and refunds is kept separately for as long as accounting and tax law requires (in Sweden, generally seven years), and is not used for anything else.
- Free-introduction records (a one-way hash of your email address) are kept for 24 months from the claim, including after account deletion, and are then deleted automatically.
- Sessions expire after about 30 days. Rate-limit records are short-lived and expire automatically.
- Logs: operational logs about 30 days, security logs about 90 days.
AI providers keep data according to their own policies, which we cannot shorten for you. Paid credits do not expire when an old song reaches its retention date.
Your rights
You have the right to access your data, correct it, delete it, restrict its use, receive a portable copy, and object to processing based on our legitimate interests. Where we rely on your permission, you can withdraw it at any time; this doesn't affect what happened before.
- Delete your account: in the app under Profile → Privacy & data. See Delete your account.
- Withdraw AI permission: in the app under Profile → Privacy & data.
- Everything else: email support@sansavision.com from the address you use with Moonsong.
We answer within one month. If a request is complex we may extend that by up to two further months, and we will tell you why within the first month. Requests are free unless they are clearly unfounded or excessive. We may need to confirm that a request comes from the account owner; we will never ask for your sign-in code or link.
You can complain to a data protection authority, in particular where you live or work. In Sweden this is:
Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection
Box 8114, 104 20 Stockholm, Sweden
www.imy.se
More detail: Your GDPR rights · California privacy.
Children
Moonsong is only for adults aged 18 and over. We ask you to confirm your age when you start. If we learn that an account belongs to someone under 18, we will close it and delete its data. If you believe a child has used Moonsong, email us.
Security
Data is sent over encrypted connections (HTTPS). Your projects and files are stored in private storage that is not publicly accessible; media is delivered only through short-lived signed links after we check that you own it. Your session is kept in the iPhone's secure storage. Access to production data is limited to people who need it to run the service. No system is perfectly secure, so please keep your email account secure, because it is how you sign in.
Cookies
This website sets no cookies and uses no analytics. The app uses one essential session cookie to keep you signed in. See Cookies.
Changes to this notice
We update this notice when the service or the law changes. Each version has an identifier and date at the top of this page. If a change materially affects how we use data you have already given us, we will tell you in the app before it takes effect and, where required, ask for your permission again.
Contact
Email support@sansavision.com or write to:
Sansa Group ABSoldathemsgatan 20
415 28 Göteborg
Sweden