Hummingly

Version 2026-08-22 · Effective August 22, 2026

Privacy Policy

This Policy explains how Hummingly, the developer/service operator identified in the applicable app-store listing (“Hummingly,” “we,” “us,” or “our”), collects, uses, discloses, protects, and deletes information in the Hummingly apps, website, and related services.

At a glance

1. Information we collect

Eligibility and legal records

Before login, you enter a date of birth and separately confirm that you are at least 18, that the date is accurate, and that you reviewed and agreed to the Terms and acknowledged this Policy. The raw birth date is transmitted securely for one eligibility request, evaluated in memory, and discarded. We store a one-way proof record, eligible/not-eligible outcome controls, acceptance timestamp, and the age-gate, Terms, and Privacy version identifiers. We do not retain the date of birth or calculated age.

Account and profile

Depending on sign-in method, we process an account identifier, email address, display name, username, password hash, Google or Apple sign-in identifiers, guest status, subscription status, preferences, notification tokens, and account-security records. Passwords are hashed; we do not store the plaintext password.

Creative and library data

We process affirmations, prompts, user-provided and generated lyrics, titles, styles, presets, generated audio, karaoke timing, favorites, playlists, lyric and generation history, sharing records, playback state, and library metadata. Song audio is delivered through a short-lived private buffer; durable service copies exist only where needed for an enabled Library Sync or private sharing feature. Device/provider backups follow your selected backup settings.

Private sharing

We process sender and recipient account identifiers, usernames used for lookup, invitation references, encrypted/tokenized access records, delivery state, acceptance, revocation, blocks, reports, and a protected song copy needed for recipients to stream in Hummingly. Links do not embed playable audio. Access is checked against the signed-in recipient.

Wellness and health data

With permission, we process eligible playback duration and wellness-minute records and may read or write limited mindful-session data through Apple Health or Android Health Connect. We do not use consumer health data for advertising or unrelated profiling. See the Consumer Health Data Privacy Notice.

Backup, sync, support, and operations

We process your backup choice, provider status, last backup/sync time, sync cursors, conflict metadata, encrypted/provider file identifiers, support messages, diagnostics you choose to send, IP address, device/app version, security events, request timing, provider cost, rate-limit counters, crash data, and coarse operational logs. We design logs not to contain birth dates, raw creative text, access tokens, or song audio.

2. How we use information

We use information to validate adult eligibility and document consent; create, moderate, align, deliver, play, sync, back up, and privately share songs; manage accounts and subscriptions; calculate wellness minutes; prevent fraud, prompt injection, abuse, offensive content, and unauthorized access; provide support; maintain reliability; comply with law; and improve features using aggregate or appropriately de-identified operational information.

3. AI generation and safety processing

Inputs are normalized and structurally isolated from model instructions. Hummingly checks for prompt manipulation and clearly inappropriate content before generation. In production, contextual safety classification and Gemini’s strict safety settings are used in addition to deterministic controls. Generated lyrics are checked before reaching Lyria; Lyria’s returned text metadata and a temporary private transcript of the sung audio are checked before delivery. The transcript is used only for safety and alignment during that request and is not retained as a separate profile field. Requests may be rejected. Crisis signals are handled separately and can produce support resources instead of a song.

Automated safety systems can make mistakes. Do not include passwords, financial credentials, government identifiers, health records, or unnecessary sensitive information in creative text.

4. Service providers and disclosures

ServicePurpose and information
Google GeminiLyrics generation/refinement and contextual safety classification; receives the creative text and limited requested style needed for the call.
Google Lyria 3Music generation; receives approved lyrics, duration, and style descriptors. Generated audio includes SynthID.
CloudflareNetwork protection, public website, private object storage, transient delivery, sync/sharing storage, and related infrastructure.
Apple / GoogleApp distribution, purchases, sign-in where selected, push delivery, iCloud or Google Drive backup where enabled, and Apple Health or Health Connect where authorized.
Email/support providersAccount or support communications and delivery metadata.
Hummingly private audio processorInternal Demucs vocal separation and Whisper lyric alignment. Audio and lyrics are processed in temporary server storage and deleted after the request.

AI-provider retention and model use

Google Gemini and Google Lyria receive only content required to perform requested generation and safety functions. Provider handling is governed by the applicable Google Gemini API terms and data-use commitments. Because terms and preview products can change, we do not promise provider-level zero retention unless a binding provider commitment specifically applies to our account and request.

We may disclose information to comply with law, protect people and the Service, investigate fraud or abuse, respond to valid legal process, complete a corporate transaction subject to appropriate safeguards, or with your direction. We do not sell personal information or share it for cross-context behavioral advertising.

5. Storage, security, and retention

We use transport encryption, access controls, recipient-scoped authorization, short-lived tokens, secret separation, rate limits, prompt isolation, content checks, database constraints, transient delivery, deletion queues, and monitored backups. No system is perfectly secure.

6. Your choices and rights

You can edit profile information, disable notifications, Library Sync, backup, and health permissions; revoke private shares; remove songs; sign out; and request account deletion. Depending on location, you may request access, correction, deletion, portability, restriction, objection, or an appeal. We may verify your identity and may deny or limit a request where law permits. Contact hello@hummingly.app. You may also complain to your privacy regulator.

7. International processing

Information may be processed in the United States and other places where we or providers operate. Where required for EEA, UK, and Swiss information, we rely on performance of the contract, consent for optional health/provider features, legitimate interests in security and operations, and legal obligations, with appropriate transfer safeguards.

8. California notice at collection

We collect identifiers, account/commercial information, internet or device activity, user content, and—only with permission—wellness information. We use and retain these categories for the purposes and periods described above. We do not sell or share personal information for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics beyond providing requested features, security, and legal compliance.

9. Consumer Health Data Privacy Notice

Categories of consumer health data

Depending on your choices, Hummingly may process mindful/wellness minutes, timestamps and duration of eligible playback, selected wellness intent or binaural setting, and authorization/status metadata for Apple Health or Health Connect. We do not diagnose conditions or intentionally collect clinical records.

Sources

Sources are you, your in-app playback activity, the settings you select, and Apple Health or Health Connect when you authorize access.

Purposes

We use this data to show wellness-minute views by day, week, month, year, or all time; write or reconcile authorized mindful sessions; prevent duplicates; troubleshoot sync; and protect feature integrity.

Sharing and third parties

We disclose only what is necessary to Apple Health, Android Health Connect, hosting/security providers, or authorities where legally required. Hummingly does not sell consumer health data and does not use it for advertising, data-broker activity, or unrelated profiling.

Your rights

You may withdraw Health permission in device settings, disable the integration, delete sessions where the platform permits, and request access, correction, or deletion by emailing us. If we deny a request, reply “Privacy Appeal.” Washington residents may contact the Washington State Attorney General; residents elsewhere may contact their regulator.

10. Children and adult eligibility

The Service is not offered to people under 18. The birthday check occurs before login and the raw date is not retained. If you believe an ineligible person used the Service or submitted personal information, contact us so we can investigate and delete information as appropriate.

11. Changes and contact

We may update this Policy. Material changes may require a new in-app acknowledgement tied to an immutable version. Prior accepted versions remain available at their versioned URLs.

Privacy requests and questions: hello@hummingly.app. Support: Help & Support.