Privacy Policy
This policy explains what Hummingly handles, why it is needed, where it goes, how long it remains, and the choices available to you.
The short version. Your words and songs are not public by default. Hummingly has no advertising SDK, does not build advertising profiles, and does not sell personal or consumer health data or share it for cross-context behavioral advertising. We process personal data to provide the account, AI creation, sync, backup, app-only playback, private sharing, safety, and support features you choose.
1. Scope, operator, and eligibility
This policy applies to the Hummingly iOS and Android apps, the public website at hummingly.app, related account and support services, Library Sync, Cloud Backup coordination, health export, and private song sharing. It does not replace the privacy terms of Apple, Google, an app store, a health store, a backup provider, or an external messaging app you choose.
The service operator is Hummingly, the developer/service operator identified in the applicable app-store listing (“Hummingly,” “we,” “us,” or “our”). Privacy questions and requests can be sent to hello@hummingly.app.
Hummingly is available only to adults age 18 and older. Before account creation, sign-in, or guest access, Hummingly uses a neutral age screen to determine eligibility and records the resulting adult-age attestation and versioned legal acceptance as described below.
2. Personal data we handle
What we handle depends on the features you use. “Collect” in this policy can include receiving, accessing, storing, transmitting, or otherwise processing data. Some data remains only on your device or in a provider account you choose and is not collected by Hummingly’s servers.
Account and authentication data
- Email address, display name, password verifier for email accounts, provider sign-in identifier, account status, and sign-in/session records.
- Date of birth submitted to the age screen solely for an immediate eligibility calculation. Hummingly does not retain the date of birth after that calculation. For an eligible user, we retain the adult-age eligibility result, server-recorded confirmation time, and the versions of the age gate, Terms, and Privacy Policy accepted or acknowledged. After an ineligible result, the app can retain only a local “unavailable until” timestamp for up to 24 hours so the neutral screen cannot be repeatedly retried; it does not retain the entered date or the result on Hummingly’s server.
- Apple or Google sign-in data returned under the permissions you approve. Apple may provide a relay email when Hide My Email is used.
- Guest-account identifier and the information needed to convert a guest into a saved account.
- Subscription or entitlement status and store transaction references if paid products are offered in the future. Hummingly does not receive your full payment-card number from Apple or Google.
Words, lyrics, songs, and creative choices
- Your prompt, affirmations, gratitude, vision, free writing, or user-supplied lyrics.
- Generated lyric drafts and variants, your edits and selected take, final lyrics, title, genre, mood, voice preference, tempo, energy, duration, binaural choices, and reusable style presets.
- Generated song audio, previews, karaoke/instrumental renders, lyric timing and alignment data, file metadata, hashes, and generation status.
- Playlists, order, favorites, deletions, continue-listening song and position, and selected appearance/audio preferences.
These inputs can reveal beliefs, emotions, relationships, goals, or health-related concerns. Treat the words you enter as sensitive, and do not include another person’s private information without permission.
Local library data
Your working library—including locally available audio, lyrics, generation history, playlists, favorites, presets, playback state, and settings—is stored in an account-scoped area on your device. Local wellness history is also stored per account on the device, but is excluded from Library Sync and Google Drive/iCloud Backup.
Account-level Library Sync
For eligible saved accounts, Library Sync stores a private, access-controlled service copy of song metadata and audio so your devices signed in to the same Hummingly account can converge. After full-library Backup is explicitly enabled, its metadata layer also synchronizes lyric generation history, playlists, favorites, style presets, deletion state, continue-listening progress, and selected appearance/audio preferences. Shared inbox/grants, provider credentials, and local wellness history are not portable Library Sync content.
Synced audio is held in non-public Cloudflare R2 storage and transferred using authenticated, account-scoped requests and short-lived, object-specific authorization. It is encrypted in transit and protected by the provider’s encryption at rest. It is not end-to-end encrypted: Hummingly can process it as needed to verify, deliver, secure, support, and delete the file.
Optional Google Drive or iCloud Backup
If you enable Backup, Hummingly creates a versioned recovery mirror in Google Drive’s private Hummingly app-data area or, on supported Apple devices, Hummingly’s private iCloud container. The snapshot can include created songs and available primary/karaoke audio, lyrics and generation history, playlists and order, favorites, presets, playback and deletion state, selected preferences, and reconciliation state needed for a safe restore.
Passwords, Hummingly/provider authorization tokens, raw device identifiers, private-share grants, blocks/reports, and wellness-minute history are excluded. Backup data is held by Google or Apple under your provider account and its privacy, security, and retention terms. Turning Backup off stops future provider snapshots from that device; it does not erase an existing provider copy.
Usernames, profiles, and private sharing
- Public username, display name, profile link, QR representation, and account eligibility needed to let another signed-in user select the correct recipient.
- Authenticated directory searches by username or display-name prefix, or exact email-address match. Search is sent in the request body. Results never disclose the matched account’s email address.
- Current and retired username aliases. Older usernames remain reserved to the same account to reduce impersonation and can continue resolving to that account’s current public profile while it remains active.
- Sender and recipient account identifiers, song/share identifiers, invitation and acceptance state, expiration/revocation timestamps, blocked-account state, and security/audit events.
- A protected sharing copy of audio while a pending invitation or active recipient grant needs it.
A profile link identifies an account but grants no song access. A private invitation link is also not playback authorization: the matching recipient must be signed in and have a current grant. External messaging providers can see the generic link and any message you add, but Hummingly does not receive the contact you select in the system share sheet.
Playback, wellness, and health data
The app records audible playback intervals and calculates daily wellness totals on the device. Paused, loading, and buffering time is excluded. Those local totals are not sent to Hummingly servers, Library Sync, or provider Backup.
If you explicitly enable health export, Hummingly requests write-only permission to add Apple Health Mindful Minutes or Health Connect Mindfulness sessions. The app writes session start/end time, timezone-offset context, and a Hummingly session identifier used to avoid duplicate exports, categorized as music mindfulness. It does not write song titles, lyrics, prompts, audio, or account details, requests write-only health permission, and does not read your other health history. See the dedicated Consumer Health Data Privacy Notice.
Operational, device, network, and security data
- IP address, request time and path category, response status, user/account identifier when authenticated, and limited user-agent, platform, app version, and device-class information.
- A one-way hash of an app-install device identifier, sync timestamps, short-lived playback lease state, and integrity information such as expected file size, media type, and SHA-256 hash.
- Generation quota/count, job stage, provider status, retry and idempotency references, and service-health events.
- Security, moderation, blocked-account, report, crisis-category, and authorized administrator audit records. Crisis screening records a category/event rather than the user’s words where the feature is designed to do so.
General request logs are designed not to contain raw affirmation text, lyrics, full private invitation references, bearer leases, presigned storage URLs, raw storage keys, passwords, or provider tokens.
The age-eligibility endpoint is excluded from Hummingly’s durable request-log table. For abuse prevention, a one-way SHA-256 hash derived from the requesting network address can remain in a rate-limit store for about one hour. It does not contain the entered date, proof, account identity, or eligibility outcome.
For a previously verified account, the app can keep an encrypted, account-bound local identity snapshot for up to 24 hours. During that limited offline window, it can display only that account’s already-cached local library. Network calls, provider Backup, Library Sync, sharing, remote profile access, and pending deep-link handoff wait for a fresh server identity check. The snapshot contains no date of birth or eligibility proof and is cleared when it is invalid, expired, mismatched, signed out, or authoritatively rejected.
Support communications
If you contact support, we process your email address, message, attachments, device/app details, and follow-up history. Do not send passwords, authentication codes, access tokens, complete private sharing links, or sensitive lyrics/audio unless support specifically requests content and you choose to provide it.
Public website data
The public Hummingly website is static and does not set advertising or analytics cookies and does not run an analytics SDK. Normal web hosting necessarily receives network request data such as IP address, time, path, browser user agent, and security signals. Selecting an email link opens your chosen email service under its terms. Private song/profile fallback pages are generic, no-store, and noindex and do not send the opaque route to analytics or third parties.
3. Sources and purposes
Sources
- You: account details, words, lyrics, edits, choices, support messages, sharing selections, and permissions.
- Your device and app: playback state, local wellness intervals, app version, device-scoped security identifier, file integrity, and network requests.
- Service providers: authentication response, generated lyrics/audio/alignment, store entitlement status, backup confirmation, and health-store write confirmation.
- Other users: an invitation, block, or report involving your account.
Why we use data
- Create and authenticate accounts, keep sessions secure, and recover expected account state.
- Generate, align, deliver, play, organize, sync, back up, and restore songs and related data.
- Find intended recipients, deliver private invitations, authorize app-only streams, and enforce revocation and blocks.
- Calculate local wellness totals and, only with permission, write session intervals to the selected health store.
- Apply feature limits or future entitlements, verify app-store transactions, and prevent fraud.
- Protect users and the service, moderate reports, investigate abuse, troubleshoot failures, and maintain auditability.
- Respond to support/privacy requests and comply with legal obligations or establish, exercise, and defend legal claims.
We do not use prompts, songs, wellness data, or account activity to target advertising. We do not sell personal data and do not share it for cross-context behavioral advertising.
4. AI, infrastructure, and platform providers
We disclose data only as needed for the selected feature, security, legal compliance, or with your direction. Current principal providers include:
| Provider | Purpose and data involved |
|---|---|
| Google Gemini | Generates lyric drafts from the words, mode, style context, and instructions you submit. Google processes that request and response under Hummingly’s applicable service arrangement. |
| ElevenLabs | Generates music from approved lyrics and style descriptors. For synced-lyrics repair/forced alignment, full song audio and lyrics may also be sent so timing can be calculated. |
| Cloudflare | Provides public-site delivery, edge security, private network routing, rate limiting, private R2 object storage, and the recipient-authorized media gateway. Cloudflare can process request/network data and encrypted-at-rest stored audio needed for sync or sharing. |
| Apple | As applicable: Sign in with Apple, App Store distribution and future purchase verification, iCloud Backup, Apple Health write-only Mindful Minutes, and device platform services. |
| As applicable: Google Sign-In, Google Play distribution and future purchase verification, Google Drive app-data Backup, Health Connect write-only Mindfulness sessions, and Android platform services. |
AI-provider retention and model use
Google Gemini and ElevenLabs receive content required to perform the generation or alignment request. Provider-side retention, abuse monitoring, and model-improvement treatment depend on Hummingly’s current commercial arrangement and the provider’s applicable service terms. We do not promise that a provider uses zero retention or never uses data for service improvement unless that is guaranteed by the applicable provider contract. Do not submit information that is unnecessary for creation. We evaluate provider settings and terms and update this policy when processing materially changes.
Internal karaoke processing
When you request Karaoke, Hummingly’s internal Demucs separation service processes the song audio to reduce vocals. Working files are placed on transient service disk for the separation job and are not intended as a separate permanent karaoke-processing archive. The finished render may then be stored locally and, if enabled, in Library Sync and your selected Backup snapshot.
Providers may process data in countries other than your own. See EEA/UK lawful bases and transfers.
6. Security
Controls include encrypted transport, provider encryption at rest, account-scoped authorization, non-public object storage, short-lived signed transfers and playback leases, media type/size/hash verification, secure token storage, request limits, device-binding hashes, durable deletion/revocation state, generic link previews, and administrative audit controls.
No service or storage method is perfectly secure. Hummingly’s sync, backup, and sharing designs are not end-to-end encrypted, and app-only streaming cannot prevent an authorized person using a compromised device or external recorder from capturing audio. Keep your account secure, select recipients carefully, and contact us if you suspect unauthorized use.
7. Retention and deletion
| Data | Typical retention approach |
|---|---|
| Account and account library | While the account is active and as needed to provide the service; deleted or de-identified after account deletion subject to exceptions below. |
| Age eligibility | The entered date of birth is used for the immediate calculation and is not retained. A local ineligible-result cooldown timestamp can remain for up to 24 hours. A successful one-time eligibility proof expires quickly, cannot be reused after consumption, and is removed through routine cleanup. A validated, account-bound local identity snapshot can remain for up to 24 hours to permit local-only offline access. The adult eligibility result, server-recorded confirmation time, and applicable document versions remain with the active account and are deleted or de-identified with it, subject to legal exceptions. |
| Authentication sessions | Short-lived access credentials expire quickly; refresh/session credentials normally expire within about 60 days and can be revoked sooner. Revocation records can remain briefly so logged-out credentials cannot be reused. |
| Fresh generation delivery audio | Held in a transient delivery buffer until downloaded/acknowledged or expiry; the default undelivered-object window is up to 24 hours. |
| Library Sync audio and metadata | While current for the account; replacement/deletion makes a revision unavailable and queues object deletion. |
| Deletion tombstones and sync devices | Metadata deletion tombstones are normally retained for about 90 days so an offline device cannot restore deleted content. Inactive hashed sync-device registrations are normally removed after about 180 days, subject to security or legal need. |
| Private share invitations and audio | While an invitation, pending acceptance, active grant, report, or required audit state needs it. Targeted invitations normally expire after 7 days; short-lived playback leases normally last no more than 5 minutes. Final revoked object deletion is queued after a short operational window (normally 24 hours), unless quarantined for review. |
| Provider Backup | Maintained in your Google/Apple provider account until removed through provider controls or retention. The app normally maintains up to the latest three verified account-scoped snapshot revisions there. |
| Request/security logs | Normally 30 days for general operational request logs, unless a shorter period applies or longer retention is reasonably necessary for security, support, law, or an active investigation. |
| Support, moderation, and legal records | For the request/report lifecycle and a limited period needed for safety, audit, dispute, fraud-prevention, accounting, or legal obligations. |
| Local wellness history | On the device for the account until app data/account-scoped local data is removed; separately written Apple Health/Health Connect sessions remain under provider controls. |
Deletion from private object storage is asynchronous and retryable. Encrypted infrastructure backups may retain deleted information until their protected rotation cycle ends, isolated from normal use.
Account deletion does not automatically erase: files already on a device; Google Drive/iCloud provider snapshots; Apple Health/Health Connect sessions; local wellness data/preferences on a device; permanently reserved username aliases used to prevent impersonation; de-identified or aggregated records; or narrow billing, security, moderation, block, report, fraud-prevention, and legal records that must or may lawfully be retained.
Consumer Health Data Privacy Notice
This section supplements the rest of this policy for “consumer health data” under laws such as Washington’s My Health My Data Act. It applies when Hummingly handles information that identifies or can reasonably be linked to a consumer and identifies past, present, or future physical or mental health status. It is not a statement that Hummingly is a health-care provider or that every item below is legally health data in every region.
Categories of consumer health data
- Local wellness listening intervals and daily totals derived from audible Hummingly playback.
- Start/end times exported, with permission, as Apple Health Mindful Minutes or Health Connect music Mindfulness sessions.
- User-entered words, lyrics, support messages, or generated content that reveal or permit an inference about emotions, mental health, physical health, treatment, disability, symptoms, or wellbeing.
- Feature selections or interaction data that could reveal a health-related interest, such as requesting relaxation-oriented content.
Sources
We receive consumer health data directly from you, derive local listening time from app playback on your device, and receive only the provider confirmation needed to know whether an authorized health-store write succeeded. Hummingly does not read your Apple Health or Health Connect history.
Purposes
- Provide the song, lyric, wellness-counter, and support features you request.
- Write mindfulness session intervals to your selected health store when you explicitly enable that feature.
- Operate private sync/backup if you separately choose those features; local wellness-minute history itself is excluded.
- Protect users, respond to crisis signals without retaining the raw words in general logs, comply with law, and resolve support/security issues.
Sharing and third parties
Consumer health data may be processed by Google Gemini for requested lyric creation, ElevenLabs for requested music generation or audio-and-lyrics alignment, Cloudflare for secure infrastructure/storage, and Apple or Google when you direct Hummingly to use authentication, provider Backup, or write-only health export. Hummingly’s internal Demucs service transiently processes audio for Karaoke. A private song is disclosed to the specific recipient you authorize after the recipient accepts and remains eligible.
Hummingly does not sell consumer health data. We do not use it for targeted or cross-context behavioral advertising and do not permit a geofence around health-care facilities for identification or advertising. Hummingly writes authorized sessions to Apple Health or Health Connect; it does not ingest your wider health record.
Your consumer health data rights
Subject to verification and applicable exceptions, you may ask to confirm whether we collect/share consumer health data, access it, obtain a list of third parties/affiliates with whom it was shared, withdraw consent, or delete Hummingly-held consumer health data. Email hello@hummingly.app with “Consumer Health Data Request.” We will not discriminate for exercising a right.
Withdrawing permission stops future health-store exports but does not automatically delete sessions already held by Apple or Google. Delete those through Apple Health or Health Connect. Provider Backup and local device copies also require the provider/device controls described above. When required, we will notify processors and other recipients of an approved deletion request, subject to legal exceptions.
If we deny a request, reply with “Privacy Appeal” and explain why you believe the decision should change. We will review the appeal and provide any regulator contact available under applicable law. Washington residents may also contact the Washington State Attorney General.
8. California and other U.S. state privacy rights
Depending on your state and subject to legal exceptions, you may have rights to know/confirm processing; access and obtain a portable copy; correct; delete; opt out of sale, targeted advertising, or certain profiling; limit certain sensitive-data use; obtain a list of third parties; appeal a denial; and receive equal service without retaliation.
California notice at collection
During the preceding 12 months, Hummingly may have collected these CCPA categories: identifiers; customer-record/account information; commercial and entitlement information; internet/electronic activity; audio and creative content; approximate location inferred from IP (not precise geolocation); age eligibility and a temporarily processed date of birth; inferences from content/choices; and sensitive personal information such as account credentials, private communications/content, and health-related information a user chooses to submit. Sources, purposes, recipients, and retention are described above.
Hummingly has not sold these categories and has not shared them for cross-context behavioral advertising. We do not use/disclose sensitive personal information to infer characteristics for advertising or outside purposes reasonably necessary to provide, secure, and legally operate the service. Therefore there is currently no separate sale/share or sensitive-use opt-out needed. If that changes, we will provide required notice and controls. Global Privacy Control signals are treated as legally required, though the current service has no sale or targeted-ad sharing to opt out of.
Make a request or appeal
Email hello@hummingly.app and describe the right and account involved. We will verify requests in a proportionate way, usually through the account email or active session. An authorized agent may submit a request where law permits; we may ask for signed authority and direct identity confirmation. If denied, reply with “Privacy Appeal.”
A portable server-data export can include available account and song records, synced asset inventory, synchronized metadata, subscription or entitlement records, and current/retired username aliases. It does not necessarily include binary audio, local device files, local wellness history, provider-held backups or health records, private-sharing/security records, credentials, privileged material, or audit data whose disclosure would create risk or violate another person’s rights.
9. EEA, UK, and Swiss information
Lawful bases
- Contract: account access, generation, delivery, Library Sync, organization, private sharing, support, and any future purchased entitlement you request.
- Consent: optional health export, provider authorization, and other processing where the interface or law requests consent. Consent can be withdrawn without affecting earlier lawful processing.
- Legitimate interests: service reliability, security, fraud/abuse prevention, limited operational diagnostics, moderation, protecting rights, and improving feature performance without advertising profiling, balanced against user rights.
- Legal obligation and claims: tax/accounting, regulator/law-enforcement compliance, rights requests, and establishing, exercising, or defending legal claims.
- Vital interests: limited safety action where genuinely necessary to protect a person and another basis is unavailable.
Your rights
You may have rights to access, correct, erase, restrict, object, portability, withdraw consent, and complain to your local supervisory authority. You can object to legitimate-interest processing by explaining your circumstances. Hummingly does not make decisions producing legal or similarly significant effects solely through automated processing.
International transfers
Hummingly and its providers may process data outside your country, including in the United States. Where required, transfers rely on an adequacy decision, approved contractual safeguards such as Standard Contractual Clauses and the UK Addendum/IDTA, a valid provider transfer mechanism, or a legal exception. Contact us for information about applicable safeguards.
10. Your controls
- Edit profile and username in You; the service may retain old aliases to prevent impersonation.
- Favorite/unfavorite, remove shared items, or delete owned songs from app controls.
- Accept, decline, revoke, block, or report through Private sharing.
- Turn provider Backup off; separately manage existing provider copies through Google or Apple.
- Disable health export; separately view/delete prior sessions and manage permission in Apple Health or Health Connect.
- Delete your Hummingly account in You → Delete account or follow the account deletion guide.
11. Children
Hummingly is not directed to or available to anyone under 18, and we do not knowingly offer accounts or guest access to children. The age screen occurs before account creation, sign-in, or guest access. The service temporarily receives the entered date of birth to calculate eligibility, does not retain that date, and does not create an eligibility proof for an ineligible user.
If we learn that a person under 18 has provided personal data or is using Hummingly, we may suspend access and will investigate and delete, restrict, or otherwise handle the account and data as required by law. To report a concern, contact hello@hummingly.app.
12. Changes to this policy
We may update this policy as features, providers, or laws change. We will change the “Last updated” date and provide additional in-app or other notice when required for a material change. If consent is legally required for new processing, continued use alone will not replace that consent.
13. Contact and requests
Email hello@hummingly.app for privacy questions, requests, or appeals. Include the email or username associated with the account and the right you want to exercise, but never include your password, provider token, sign-in code, or private invitation credential.
For product help, visit Help & Support. To understand every feature, see the User Manual.
Back to top ↑