Privacy Policy — BeMusic AI

Read BeMusic AI's privacy policy. Learn how we collect, use, and protect your data when using our AI music generation platform.
Feb 27, 2026(Updated: Sep 16, 2026)

At BeMusic AI, your privacy is a core value embedded in everything we build. This Privacy Policy explains what information we collect, how we use it, who we share it with, and how we protect it. We've written this in plain English so it's easy to understand, while still providing the legal details you need.

Effective Date: September 16, 2026

1. Information We Collect

We collect information to provide, improve, and protect our AI music generation services. Here's a detailed breakdown of what we collect and why.

1.1 Account Information

When you create an account, we collect:

Data TypePurposeRequired
Email addressAccount verification, communications, password recoveryYes
Full namePersonalization, identificationYes
PasswordAccount security (stored as secure hash)Yes
Profile pictureProfile personalizationNo

1.2 Content and Usage Data

When you use BeMusic AI tools, we collect:

Music Generation Data:

  • Text prompts and descriptions you enter
  • Genre, mood, and style preferences you select
  • Duration and format settings you choose
  • Generated audio files and their metadata
  • Lyrics you write or generate

Audio Processing Data:

  • Audio files you upload for processing
  • Vocal separation results
  • AI cover generation inputs and outputs
  • Voice samples submitted for permitted private voice-model training
  • Trained voice-model files and related processing metadata

Interaction Data:

  • Songs you like, save, or download
  • Features and tools you use most frequently
  • Time spent on different functions
  • Error reports and crash logs

1.3 Technical Information

We automatically collect technical data to ensure optimal service:

Device Information:

  • Device type (desktop, mobile, tablet)
  • Operating system and version
  • Browser type and version
  • Screen resolution

Network Information:

  • IP address
  • Geographic location (country/region level)

Session Information:

  • Pages and features visited
  • Time and duration of visits
  • Referring URLs (how you found us)

1.4 Payment and Billing Information

When you make purchases, we collect:

  • Payment method type (credit card, PayPal, etc.)
  • Billing name and address
  • Transaction amounts and dates
  • Subscription plan details

Important Security Note: We never store complete credit card numbers, CVV codes, or other sensitive payment credentials. Payments are processed by the third-party payment providers enabled at checkout. A provider that previously handled a subscription may continue to process renewals, cancellations, refunds, invoices, or account management for that subscription.

1.5 Communications Data

We collect information from your communications with us:

  • Support tickets and help requests
  • Email correspondence
  • Feedback and feature requests

1.6 Third-Party Data

We may receive information from third parties:

  • Social media profiles (if you sign in with Google, etc.)
  • Fraud prevention services
  • Analytics providers

2. How We Use Your Information

We use your information for specific, legitimate purposes:

2.1 Providing Our Services

  • Account Management: Create, authenticate, and manage your account
  • Music Generation: Process your prompts and generate AI music
  • Audio Processing: Perform vocal separation, AI covers, and audio enhancement
  • Content Storage: Safely store your generated music and projects
  • Feature Access: Enable premium features based on your subscription
  • Personalization: Remember your preferences and settings

2.2 Improving Our Technology

  • Service Analytics: Improve product reliability using aggregated operational and usage patterns
  • Quality Enhancement: Analyze generation quality to improve outputs
  • Bug Fixes: Identify and resolve technical issues
  • Performance Optimization: Optimize server response times and processing speed

AI Training Transparency: We do not use private prompts, uploads, voice samples, or generated content to train shared AI models unless you separately and explicitly opt in. Aggregated service metrics that do not contain your creative content may be used to improve reliability and product performance.

2.3 Communications

  • Transactional emails: Order confirmations, password resets, subscription updates
  • Service notifications: Feature updates, maintenance alerts, security notices
  • Marketing (with consent): New features, tips, promotional offers
  • Support: Respond to your questions and help requests

2.4 Safety and Security

  • Fraud prevention and abuse detection
  • Content moderation
  • Security monitoring
  • Legal compliance

For users in the European Economic Area (EEA), we process your data based on these legal grounds:

Legal BasisWhen It Applies
Contract PerformanceProviding our services, processing payments, account management
Legitimate InterestsService improvement, security, fraud prevention, aggregated operational analysis, and always-loaded measurement or service integrations where permitted
ConsentMarketing communications, Google analytics and advertising storage or personalization where required, AI training participation, and optional features
Legal ObligationTax records, responding to legal requests, compliance requirements

You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

4. Data Sharing and Disclosure

We do not sell personal information for money. Enabled analytics, advertising, attribution, and support integrations load on every visit and may receive limited identifiers, device information, online activity, referral data, support data, or conversion information. Google cookie storage, advertising user data, and personalization follow the Google privacy settings described below. Under some privacy laws, advertising disclosures may be considered a "sale," "sharing," or use for cross-context behavioral advertising even though no money is exchanged for the data.

We only share data in these limited circumstances:

4.1 Service Providers

We work with carefully selected companies that help us operate:

Provider TypePurposeData Shared
Cloud InfrastructureHosting, storage, computingAll service data (encrypted)
Payment ProcessorsTransaction handlingPayment and billing info
AI Model ProvidersMusic, image, video, and permitted voice processingPrompts, selected settings, and files needed for the requested generation
Email ServicesTransactional and marketing emailsEmail, name
Customer SupportSupport chat and help-request handlingContact details, chat content, and device information when the provider is enabled
AnalyticsUsage analysisDevice information, online activity, and usage data; Google storage follows your Google privacy settings
AdvertisingAdvertising measurement, attribution, frequency control, and personalized advertising where permittedCookie identifiers, device information, online activity, referral data, and conversion events; Google storage and personalization follow your Google privacy settings
CDN ProvidersContent deliveryGenerated audio files

All service providers are bound by strict data processing agreements and can only use your data to provide services to us.

We may disclose your information when required by law:

  • Valid court orders or subpoenas
  • Government agency requests with legal authority
  • To protect someone's life or safety
  • To protect BeMusic AI's legal rights

We will notify you of legal requests when legally permitted to do so.

4.3 Business Transfers

If BeMusic AI is involved in a merger, acquisition, or sale:

  • We will notify you before your data is transferred
  • This policy will continue to apply to your data
  • You will have the option to delete your data before transfer

4.4 Aggregated Data

We may share anonymized, aggregated statistics that cannot identify you.

5. Cookies and Tracking Technologies

5.1 Types of Cookies We Use

Strictly Necessary Cookies

  • Authentication and login status
  • Security tokens
  • Session management
  • Cannot be disabled (service won't work without them)

Always-Loaded Integrations

  • Enabled analytics, advertising, attribution, and support scripts load on every visit
  • Providers may include Google Analytics, Google Ads, Google AdSense, Microsoft Clarity, Plausible, OpenPanel, Vercel Analytics, affiliate providers, Crisp, or Tawk
  • Providers that are not enabled in our production configuration are not loaded

Google Analytics Storage

  • Controls whether Google Analytics may store or read analytics cookies and identifiers
  • When denied, Google tags still load and may send limited cookieless measurements under advanced Consent Mode

Google Advertising Storage and Personalization

  • Controls whether Google Ads may use advertising cookies, advertising user data, and personalization
  • When denied, Google advertising tags still load in limited mode and may send cookieless measurements
  • Other enabled advertising or affiliate integrations may continue to load

5.2 Managing Cookies

On your first visit, our privacy banner lets you accept Google analytics and advertising storage, use limited mode, or manage the two Google storage categories separately. These choices do not prevent enabled integrations from loading. Limited mode keeps Google storage and personalization denied while Google tags continue cookieless measurement. Other configured analytics, advertising, attribution, and support providers continue to load as described in our Cookie Policy.

You can reopen the preference center at any time using the Cookie Settings link in the website footer. Withdrawing a Google storage permission sends Google an updated denied signal and removes common first-party Google tracking cookies where technically possible; it does not unload the enabled integrations. Previously collected data may still be retained as described in this Policy or as required by law.

When we detect a browser Global Privacy Control signal, Google advertising storage, advertising user data, and personalization remain denied on that device. The signal does not prevent always-loaded integrations from loading or disable measurement that does not rely on Google advertising storage. Most browsers also let you block scripts, cookies, or site storage, although broad blocking may prevent account and service features from working.

For provider details, cookie categories, and preference durations, see our Cookie Policy.

6. Data Security

6.1 Technical Safeguards

Encryption:

  • TLS 1.2+ for all data in transit
  • AES-256 encryption for data at rest
  • Secure key management

Infrastructure Security:

  • Hosting on enterprise-grade cloud providers
  • DDoS protection and mitigation
  • Web Application Firewall (WAF)
  • Regular vulnerability scanning

Application Security:

  • Secure software development lifecycle
  • Code reviews and security testing
  • Input validation and sanitization

6.2 Your Role in Security

Help keep your account safe:

  • Use a strong, unique password (12+ characters recommended)
  • Don't share your login credentials
  • Log out on shared or public computers
  • Report suspicious activity immediately

6.3 Breach Notification

In the event of a data breach affecting your personal information:

  • We will notify relevant regulatory authorities within the time required by applicable law, including within 72 hours where that GDPR deadline applies
  • We will notify affected users without undue delay when the breach is likely to create a high risk to their rights and freedoms or when otherwise required by law
  • We will provide details about what data was affected
  • We will explain steps we're taking to address the breach

7. Data Retention

We retain your data only as long as necessary:

Data TypeRetention PeriodReason
Account InformationActive account + 30 days after deletion requestService provision, account recovery
Generated MusicUntil you delete it or close accountYour content ownership
Uploaded Audio, Images, and Other Processing FilesUp to 30 days after processing (or until you delete them earlier)Processing completion, retry support, and abuse prevention
Temporary Voice-Training ArchivesDeleted from BeMusic-controlled object storage after training succeeds or failsVoice-model training
Trained Voice ModelsUntil you delete the model or close your accountReuse of your private voice model
Payment Records7 years after transactionLegal and tax requirements
Support Conversations2 yearsQuality assurance, dispute handling, and legal protection
Analytics Data26 monthsService improvement
Server Logs90 daysSecurity and debugging

After retention periods, data is permanently deleted or anonymized.

8. Your Privacy Rights

8.1 Universal Rights

All users have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate or incomplete information
  • Deletion: Request deletion of your personal data
  • Portability: Receive your data in a machine-readable format
  • Opt-Out: Unsubscribe from marketing communications
  • Object: Object to certain processing activities

8.2 How to Exercise Your Rights

Contact Us:

  • Email: support@bemusic.ai
  • Subject line: "Privacy Request - [Your Request Type]"
  • Include your account email for verification

Response Time:

  • Simple requests: Within 7 days
  • Complex requests: Within 30 days where practicable; verified CCPA/CPRA requests may take up to 90 days when a permitted extension is needed, and we will notify you within the initial response period if the extension applies

9. International Data Transfers

9.1 Where We Process Data

BeMusic AI and its service providers may process data in the United States, European Union, and other regions in which those providers operate. The exact processing region depends on the feature and provider used.

9.2 Transfer Safeguards

Where required, international transfers rely on safeguards such as Standard Contractual Clauses, applicable adequacy decisions, and contractual security obligations with service providers.

10. Children's Privacy

  • BeMusic AI is designed for users 13 years and older
  • In the EU/EEA, users must be 16+ (or have parental consent)
  • We do not knowingly collect data from children under these ages
  • If you believe your child under 13 (or 16 in EU) has created an account, contact us immediately at support@bemusic.ai

11. California Residents (CCPA/CPRA)

If you're a California resident, you have specific rights:

  • Right to Know: What personal information we collect, use, and share
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Correct inaccurate personal information
  • Right to Opt-Out: Opt out of "sale" or "sharing" of personal information
  • Right to Non-Discrimination: Equal service regardless of exercising rights

We do not sell personal information for money. Enabled advertising and attribution integrations load on every visit and may receive limited identifiers, device information, online activity, referral information, and conversion events. Google advertising storage, advertising user data, and personalization remain denied unless permitted through Google privacy settings. California law may treat some advertising disclosures as "sharing" for cross-context behavioral advertising.

You may restrict Google advertising storage and personalization through Cookie Settings or a supported Global Privacy Control signal. These controls do not stop enabled scripts from loading or disable advertising and attribution measurement that does not rely on Google advertising storage. You may contact us with a California privacy request if you want to exercise a broader opt-out right.

To make requests, email support@bemusic.ai with subject "California Privacy Request."

12. European Residents (GDPR)

If you're in the European Economic Area (EEA), United Kingdom, or Switzerland:

Your GDPR Rights:

  • Access (Art. 15): Obtain confirmation of processing and access to your data
  • Rectification (Art. 16): Correct inaccurate personal data
  • Erasure (Art. 17): Request deletion ("right to be forgotten")
  • Restriction (Art. 18): Restrict processing in certain circumstances
  • Portability (Art. 20): Receive data in structured, machine-readable format
  • Object (Art. 21): Object to processing based on legitimate interests

Data Controller: CEDAR ORBIT TECHNOLOGY LIMITED, the operator of BeMusic AI, is the data controller for your personal data.

  • Business Registration Number (BRN): 81009546
  • Registered address: Room 617A, 6/F, Global Plaza, No. 1 Sha Tsui Road, Tsuen Wan, Hong Kong
  • Privacy contact: support@bemusic.ai

You have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first so we can resolve your concerns.

13. AI and Machine Learning

13.1 How We Use AI

BeMusic AI uses artificial intelligence for:

  • Music generation from text prompts
  • Vocal separation and isolation
  • AI cover generation
  • Permitted private voice-model training and voice conversion
  • Audio quality enhancement
  • Music extension

13.2 AI Training Practices

What We May Use:

  • Aggregated operational and usage patterns that do not contain private creative content
  • Data a user separately and explicitly opts in to provide for a stated purpose

What We Don't Do:

  • Train on identifiable user data without consent
  • Use private prompts, uploads, voice samples, or generated content to train shared models without explicit opt-in
  • Use your private content to create models for others
  • Sell models trained on user data

14. Changes to This Policy

  • We may update this policy periodically
  • Material changes will be announced via email
  • Non-material changes take effect upon posting
  • Continuing to use BeMusic AI after policy changes means you accept the updated policy

15. Contact Us

CEDAR ORBIT TECHNOLOGY LIMITED — BeMusic AI Privacy Team

  • Business Registration Number (BRN): 81009546
  • Registered address: Room 617A, 6/F, Global Plaza, No. 1 Sha Tsui Road, Tsuen Wan, Hong Kong
  • Email: support@bemusic.ai

Response Times:

  • General inquiries: 5-7 business days
  • Rights requests: Normally 30 days; verified CCPA/CPRA requests may take up to 90 days when a permitted extension applies, as described in Section 8.2
  • Security concerns: 24-48 hours

Your privacy matters to us. If you have any questions, concerns, or feedback about this Privacy Policy or our data practices, please don't hesitate to reach out. We're committed to protecting your information and being transparent about how we use it.

Thank you for trusting BeMusic AI with your data.