Private by design

Privacy Policy

This policy explains what Hummingly handles, why it is needed, where it goes, how long it remains, and the choices available to you.

Version 2026-07-27 Effective July 27, 2026 Last updated July 27, 2026

The short version. Your words and songs are not public by default. Hummingly has no advertising SDK, does not build advertising profiles, and does not sell personal or consumer health data or share it for cross-context behavioral advertising. We process personal data to provide the account, AI creation, sync, backup, app-only playback, private sharing, safety, and support features you choose.

1. Scope, operator, and eligibility

This policy applies to the Hummingly iOS and Android apps, the public website at hummingly.app, related account and support services, Library Sync, Cloud Backup coordination, health export, and private song sharing. It does not replace the privacy terms of Apple, Google, an app store, a health store, a backup provider, or an external messaging app you choose.

The service operator is Hummingly, the developer/service operator identified in the applicable app-store listing (“Hummingly,” “we,” “us,” or “our”). Privacy questions and requests can be sent to hello@hummingly.app.

Hummingly is available only to adults age 18 and older. Before account creation, sign-in, or guest access, Hummingly uses a neutral age screen to determine eligibility and records the resulting adult-age attestation and versioned legal acceptance as described below.

2. Personal data we handle

What we handle depends on the features you use. “Collect” in this policy can include receiving, accessing, storing, transmitting, or otherwise processing data. Some data remains only on your device or in a provider account you choose and is not collected by Hummingly’s servers.

Account and authentication data

Words, lyrics, songs, and creative choices

These inputs can reveal beliefs, emotions, relationships, goals, or health-related concerns. Treat the words you enter as sensitive, and do not include another person’s private information without permission.

Local library data

Your working library—including locally available audio, lyrics, generation history, playlists, favorites, presets, playback state, and settings—is stored in an account-scoped area on your device. Local wellness history is also stored per account on the device, but is excluded from Library Sync and Google Drive/iCloud Backup.

Account-level Library Sync

For eligible saved accounts, Library Sync stores a private, access-controlled service copy of song metadata and audio so your devices signed in to the same Hummingly account can converge. After full-library Backup is explicitly enabled, its metadata layer also synchronizes lyric generation history, playlists, favorites, style presets, deletion state, continue-listening progress, and selected appearance/audio preferences. Shared inbox/grants, provider credentials, and local wellness history are not portable Library Sync content.

Synced audio is held in non-public Cloudflare R2 storage and transferred using authenticated, account-scoped requests and short-lived, object-specific authorization. It is encrypted in transit and protected by the provider’s encryption at rest. It is not end-to-end encrypted: Hummingly can process it as needed to verify, deliver, secure, support, and delete the file.

Optional Google Drive or iCloud Backup

If you enable Backup, Hummingly creates a versioned recovery mirror in Google Drive’s private Hummingly app-data area or, on supported Apple devices, Hummingly’s private iCloud container. The snapshot can include created songs and available primary/karaoke audio, lyrics and generation history, playlists and order, favorites, presets, playback and deletion state, selected preferences, and reconciliation state needed for a safe restore.

Passwords, Hummingly/provider authorization tokens, raw device identifiers, private-share grants, blocks/reports, and wellness-minute history are excluded. Backup data is held by Google or Apple under your provider account and its privacy, security, and retention terms. Turning Backup off stops future provider snapshots from that device; it does not erase an existing provider copy.

Usernames, profiles, and private sharing

A profile link identifies an account but grants no song access. A private invitation link is also not playback authorization: the matching recipient must be signed in and have a current grant. External messaging providers can see the generic link and any message you add, but Hummingly does not receive the contact you select in the system share sheet.

Playback, wellness, and health data

The app records audible playback intervals and calculates daily wellness totals on the device. Paused, loading, and buffering time is excluded. Those local totals are not sent to Hummingly servers, Library Sync, or provider Backup.

If you explicitly enable health export, Hummingly requests write-only permission to add Apple Health Mindful Minutes or Health Connect Mindfulness sessions. The app writes session start/end time, timezone-offset context, and a Hummingly session identifier used to avoid duplicate exports, categorized as music mindfulness. It does not write song titles, lyrics, prompts, audio, or account details, requests write-only health permission, and does not read your other health history. See the dedicated Consumer Health Data Privacy Notice.

Operational, device, network, and security data

General request logs are designed not to contain raw affirmation text, lyrics, full private invitation references, bearer leases, presigned storage URLs, raw storage keys, passwords, or provider tokens.

The age-eligibility endpoint is excluded from Hummingly’s durable request-log table. For abuse prevention, a one-way SHA-256 hash derived from the requesting network address can remain in a rate-limit store for about one hour. It does not contain the entered date, proof, account identity, or eligibility outcome.

For a previously verified account, the app can keep an encrypted, account-bound local identity snapshot for up to 24 hours. During that limited offline window, it can display only that account’s already-cached local library. Network calls, provider Backup, Library Sync, sharing, remote profile access, and pending deep-link handoff wait for a fresh server identity check. The snapshot contains no date of birth or eligibility proof and is cleared when it is invalid, expired, mismatched, signed out, or authoritatively rejected.

Support communications

If you contact support, we process your email address, message, attachments, device/app details, and follow-up history. Do not send passwords, authentication codes, access tokens, complete private sharing links, or sensitive lyrics/audio unless support specifically requests content and you choose to provide it.

Public website data

The public Hummingly website is static and does not set advertising or analytics cookies and does not run an analytics SDK. Normal web hosting necessarily receives network request data such as IP address, time, path, browser user agent, and security signals. Selecting an email link opens your chosen email service under its terms. Private song/profile fallback pages are generic, no-store, and noindex and do not send the opaque route to analytics or third parties.

3. Sources and purposes

Sources

Why we use data

We do not use prompts, songs, wellness data, or account activity to target advertising. We do not sell personal data and do not share it for cross-context behavioral advertising.

4. AI, infrastructure, and platform providers

We disclose data only as needed for the selected feature, security, legal compliance, or with your direction. Current principal providers include:

ProviderPurpose and data involved
Google Gemini Generates lyric drafts from the words, mode, style context, and instructions you submit. Google processes that request and response under Hummingly’s applicable service arrangement.
ElevenLabs Generates music from approved lyrics and style descriptors. For synced-lyrics repair/forced alignment, full song audio and lyrics may also be sent so timing can be calculated.
Cloudflare Provides public-site delivery, edge security, private network routing, rate limiting, private R2 object storage, and the recipient-authorized media gateway. Cloudflare can process request/network data and encrypted-at-rest stored audio needed for sync or sharing.
Apple As applicable: Sign in with Apple, App Store distribution and future purchase verification, iCloud Backup, Apple Health write-only Mindful Minutes, and device platform services.
Google As applicable: Google Sign-In, Google Play distribution and future purchase verification, Google Drive app-data Backup, Health Connect write-only Mindfulness sessions, and Android platform services.

AI-provider retention and model use

Google Gemini and ElevenLabs receive content required to perform the generation or alignment request. Provider-side retention, abuse monitoring, and model-improvement treatment depend on Hummingly’s current commercial arrangement and the provider’s applicable service terms. We do not promise that a provider uses zero retention or never uses data for service improvement unless that is guaranteed by the applicable provider contract. Do not submit information that is unnecessary for creation. We evaluate provider settings and terms and update this policy when processing materially changes.

Internal karaoke processing

When you request Karaoke, Hummingly’s internal Demucs separation service processes the song audio to reduce vocals. Working files are placed on transient service disk for the separation job and are not intended as a separate permanent karaoke-processing archive. The finished render may then be stored locally and, if enabled, in Library Sync and your selected Backup snapshot.

Providers may process data in countries other than your own. See EEA/UK lawful bases and transfers.

5. When personal data is disclosed

We may disclose data:

We do not publish your private library, operate a public song feed, or provide a browser player for a private share. Messaging apps used to send an invitation process the generic link and your message independently.

6. Security

Controls include encrypted transport, provider encryption at rest, account-scoped authorization, non-public object storage, short-lived signed transfers and playback leases, media type/size/hash verification, secure token storage, request limits, device-binding hashes, durable deletion/revocation state, generic link previews, and administrative audit controls.

No service or storage method is perfectly secure. Hummingly’s sync, backup, and sharing designs are not end-to-end encrypted, and app-only streaming cannot prevent an authorized person using a compromised device or external recorder from capturing audio. Keep your account secure, select recipients carefully, and contact us if you suspect unauthorized use.

7. Retention and deletion

DataTypical retention approach
Account and account libraryWhile the account is active and as needed to provide the service; deleted or de-identified after account deletion subject to exceptions below.
Age eligibilityThe entered date of birth is used for the immediate calculation and is not retained. A local ineligible-result cooldown timestamp can remain for up to 24 hours. A successful one-time eligibility proof expires quickly, cannot be reused after consumption, and is removed through routine cleanup. A validated, account-bound local identity snapshot can remain for up to 24 hours to permit local-only offline access. The adult eligibility result, server-recorded confirmation time, and applicable document versions remain with the active account and are deleted or de-identified with it, subject to legal exceptions.
Authentication sessionsShort-lived access credentials expire quickly; refresh/session credentials normally expire within about 60 days and can be revoked sooner. Revocation records can remain briefly so logged-out credentials cannot be reused.
Fresh generation delivery audioHeld in a transient delivery buffer until downloaded/acknowledged or expiry; the default undelivered-object window is up to 24 hours.
Library Sync audio and metadataWhile current for the account; replacement/deletion makes a revision unavailable and queues object deletion.
Deletion tombstones and sync devicesMetadata deletion tombstones are normally retained for about 90 days so an offline device cannot restore deleted content. Inactive hashed sync-device registrations are normally removed after about 180 days, subject to security or legal need.
Private share invitations and audioWhile an invitation, pending acceptance, active grant, report, or required audit state needs it. Targeted invitations normally expire after 7 days; short-lived playback leases normally last no more than 5 minutes. Final revoked object deletion is queued after a short operational window (normally 24 hours), unless quarantined for review.
Provider BackupMaintained in your Google/Apple provider account until removed through provider controls or retention. The app normally maintains up to the latest three verified account-scoped snapshot revisions there.
Request/security logsNormally 30 days for general operational request logs, unless a shorter period applies or longer retention is reasonably necessary for security, support, law, or an active investigation.
Support, moderation, and legal recordsFor the request/report lifecycle and a limited period needed for safety, audit, dispute, fraud-prevention, accounting, or legal obligations.
Local wellness historyOn the device for the account until app data/account-scoped local data is removed; separately written Apple Health/Health Connect sessions remain under provider controls.

Deletion from private object storage is asynchronous and retryable. Encrypted infrastructure backups may retain deleted information until their protected rotation cycle ends, isolated from normal use.

Account deletion does not automatically erase: files already on a device; Google Drive/iCloud provider snapshots; Apple Health/Health Connect sessions; local wellness data/preferences on a device; permanently reserved username aliases used to prevent impersonation; de-identified or aggregated records; or narrow billing, security, moderation, block, report, fraud-prevention, and legal records that must or may lawfully be retained.

Washington-style notice

Consumer Health Data Privacy Notice

This section supplements the rest of this policy for “consumer health data” under laws such as Washington’s My Health My Data Act. It applies when Hummingly handles information that identifies or can reasonably be linked to a consumer and identifies past, present, or future physical or mental health status. It is not a statement that Hummingly is a health-care provider or that every item below is legally health data in every region.

Categories of consumer health data

Sources

We receive consumer health data directly from you, derive local listening time from app playback on your device, and receive only the provider confirmation needed to know whether an authorized health-store write succeeded. Hummingly does not read your Apple Health or Health Connect history.

Purposes

Sharing and third parties

Consumer health data may be processed by Google Gemini for requested lyric creation, ElevenLabs for requested music generation or audio-and-lyrics alignment, Cloudflare for secure infrastructure/storage, and Apple or Google when you direct Hummingly to use authentication, provider Backup, or write-only health export. Hummingly’s internal Demucs service transiently processes audio for Karaoke. A private song is disclosed to the specific recipient you authorize after the recipient accepts and remains eligible.

Hummingly does not sell consumer health data. We do not use it for targeted or cross-context behavioral advertising and do not permit a geofence around health-care facilities for identification or advertising. Hummingly writes authorized sessions to Apple Health or Health Connect; it does not ingest your wider health record.

Your consumer health data rights

Subject to verification and applicable exceptions, you may ask to confirm whether we collect/share consumer health data, access it, obtain a list of third parties/affiliates with whom it was shared, withdraw consent, or delete Hummingly-held consumer health data. Email hello@hummingly.app with “Consumer Health Data Request.” We will not discriminate for exercising a right.

Withdrawing permission stops future health-store exports but does not automatically delete sessions already held by Apple or Google. Delete those through Apple Health or Health Connect. Provider Backup and local device copies also require the provider/device controls described above. When required, we will notify processors and other recipients of an approved deletion request, subject to legal exceptions.

If we deny a request, reply with “Privacy Appeal” and explain why you believe the decision should change. We will review the appeal and provide any regulator contact available under applicable law. Washington residents may also contact the Washington State Attorney General.

8. California and other U.S. state privacy rights

Depending on your state and subject to legal exceptions, you may have rights to know/confirm processing; access and obtain a portable copy; correct; delete; opt out of sale, targeted advertising, or certain profiling; limit certain sensitive-data use; obtain a list of third parties; appeal a denial; and receive equal service without retaliation.

California notice at collection

During the preceding 12 months, Hummingly may have collected these CCPA categories: identifiers; customer-record/account information; commercial and entitlement information; internet/electronic activity; audio and creative content; approximate location inferred from IP (not precise geolocation); age eligibility and a temporarily processed date of birth; inferences from content/choices; and sensitive personal information such as account credentials, private communications/content, and health-related information a user chooses to submit. Sources, purposes, recipients, and retention are described above.

Hummingly has not sold these categories and has not shared them for cross-context behavioral advertising. We do not use/disclose sensitive personal information to infer characteristics for advertising or outside purposes reasonably necessary to provide, secure, and legally operate the service. Therefore there is currently no separate sale/share or sensitive-use opt-out needed. If that changes, we will provide required notice and controls. Global Privacy Control signals are treated as legally required, though the current service has no sale or targeted-ad sharing to opt out of.

Make a request or appeal

Email hello@hummingly.app and describe the right and account involved. We will verify requests in a proportionate way, usually through the account email or active session. An authorized agent may submit a request where law permits; we may ask for signed authority and direct identity confirmation. If denied, reply with “Privacy Appeal.”

A portable server-data export can include available account and song records, synced asset inventory, synchronized metadata, subscription or entitlement records, and current/retired username aliases. It does not necessarily include binary audio, local device files, local wellness history, provider-held backups or health records, private-sharing/security records, credentials, privileged material, or audit data whose disclosure would create risk or violate another person’s rights.

9. EEA, UK, and Swiss information

Lawful bases

Your rights

You may have rights to access, correct, erase, restrict, object, portability, withdraw consent, and complain to your local supervisory authority. You can object to legitimate-interest processing by explaining your circumstances. Hummingly does not make decisions producing legal or similarly significant effects solely through automated processing.

International transfers

Hummingly and its providers may process data outside your country, including in the United States. Where required, transfers rely on an adequacy decision, approved contractual safeguards such as Standard Contractual Clauses and the UK Addendum/IDTA, a valid provider transfer mechanism, or a legal exception. Contact us for information about applicable safeguards.

10. Your controls

11. Children

Hummingly is not directed to or available to anyone under 18, and we do not knowingly offer accounts or guest access to children. The age screen occurs before account creation, sign-in, or guest access. The service temporarily receives the entered date of birth to calculate eligibility, does not retain that date, and does not create an eligibility proof for an ineligible user.

If we learn that a person under 18 has provided personal data or is using Hummingly, we may suspend access and will investigate and delete, restrict, or otherwise handle the account and data as required by law. To report a concern, contact hello@hummingly.app.

12. Changes to this policy

We may update this policy as features, providers, or laws change. We will change the “Last updated” date and provide additional in-app or other notice when required for a material change. If consent is legally required for new processing, continued use alone will not replace that consent.

13. Contact and requests

Email hello@hummingly.app for privacy questions, requests, or appeals. Include the email or username associated with the account and the right you want to exercise, but never include your password, provider token, sign-in code, or private invitation credential.

For product help, visit Help & Support. To understand every feature, see the User Manual.

Back to top ↑