Version 2026-09-14 · Effective September 14, 2026

Privacy Policy

This Policy explains how Epicalin, LLC, the owner and operator of Hummingly and controller of the personal information described here (“Hummingly,” “we,” “us,” or “our”), collects, uses, discloses, protects, and deletes information in its apps, website, and related services.

Epicalin, LLC, owner and operator of Hummingly. CEO: Catalin Calin. Business mailing address: 1810 N Burning Bush Ln, Mount Prospect, IL 60056, United States. Email: hello@hummingly.app.

At a glance

1. Information we collect

Eligibility and legal records

Before login, you enter a date of birth and separately confirm adult eligibility, accuracy, agreement to the Terms, and acknowledgement of this Policy. The raw date is securely transmitted for one request, evaluated in memory, and discarded. We store a one way, short lived proof while the flow completes and retain the eligibility result, acceptance timestamp, and policy version identifiers. We do not retain the birth date or calculated age.

Account and profile

We may process an account identifier, email, display name, username, password hash, Apple or Google sign in identifier, guest status, preferences, notification tokens, device/app details, and account security records. Passwords are hashed, not stored in plaintext. For Sign in with Apple, we exchange your temporary authorization code and encrypt the resulting authorization credential so we can revoke it when you delete your account. We store your AI permission choice, disclosure version and the times you grant or withdraw it.

Membership and purchase records

For App Store and Google Play subscriptions, we process the store platform, product and base plan identifier, original and current transaction or purchase token identifiers, start and expiration dates, environment, renewal or lifecycle status, acknowledgement state, an account binding token or one way account hash, and verification time. We store creation allowance counters by account and period. Administrators may record a selected complimentary plan, optional expiration, and internal support reason. Apple and Google process payment credentials and billing details under their policies; Hummingly does not receive your complete payment card number.

Creative, library, and sharing data

We process affirmations, prompts, provided and generated lyrics, titles, styles, presets, generated audio, karaoke timing, favorites, playlists, history, playback state, and library metadata. For private sharing, we process sender and recipient identifiers, usernames used for lookup, invitations, tokenized access records, delivery state, acceptance, revocation, blocks, reports, and the protected copy needed for in app streaming. Links do not embed playable audio.

If you flag generated lyrics or music, we process your account identifier, the content category, reason, optional song reference, optional details you choose to provide, review status, and an internal resolution note. The report record does not create another copy of the lyrics or audio. Do not place passwords, private links, or unnecessary sensitive information in report details.

Authorized Hummingly content moderators can access this limited report record through a role restricted console. A moderator can see the reporting profile’s display name or username, song name and generation provider when attached, the category, your optional details, and the disposition history. AI report email alerts contain only a report identifier, content type, category, and a link to the protected queue, not account information, lyrics, prompts, song audio, or report details. Moderator actions and notes are audited.

Sensitive creative content

Creative text and support reports may reveal sensitive health information if you choose to enter it. Hummingly does not collect clinical records, track listening minutes, or connect to device health services. See the consumer health notice below for information you voluntarily include in creative fields.

Backup, sync, support, and operations

We process backup choice, provider status, last backup or sync time, cursors, conflict metadata, protected provider identifiers, support messages, diagnostics you choose to send, IP address, device/app version, security events, request timing, provider cost, rate limit counters, crash data, and coarse logs. Logs are designed not to contain birth dates, raw creative text, authentication tokens, or song audio.

2. How we use information

We use information to validate eligibility and document acceptance; create, moderate, align, deliver, play, sync, back up, and privately share songs; verify purchases, provide entitlements, restore memberships, apply monthly allowances, prevent receipt reuse and fraud, and respond to refunds or expiration; protect against prompt injection, abuse, offensive content, and unauthorized access; provide support; operate reliably; comply with law; and improve features with aggregate or appropriately de identified operational information.

3. AI generation, safety, and provenance

Your separate permission. Before AI creation, Hummingly asks whether you allow creative content to be sent to Google. This includes affirmations, provided or generated lyrics, title, requested style, language, voice preference and duration, as needed for the request. Google Gemini processes text for generation, refinement and safety checks. Google Lyria processes approved lyrics and music instructions. The permission applies to future requests for that account until withdrawn in Settings. Declining leaves creation unavailable. Withdrawing stops new requests and cancels unfinished jobs where possible; it cannot recall data already transmitted or stop processing a provider has already begun. Existing library playback and account controls remain available. We do not send your password, payment card details to these AI services.

Inputs are normalized and isolated from model instructions. Hummingly checks for manipulation and inappropriate content before generation, uses strict provider safety settings, checks generated lyrics before Lyria, and checks returned text metadata and a temporary private transcript before delivery. The transcript is used for safety and alignment during the request and is not retained as a separate profile field. Requests may be rejected. Crisis signals may produce support resources instead of a song. Generated audio retains SynthID or other provider provenance.

Do not enter passwords, payment credentials, government identifiers, health records, or unnecessary sensitive information in creative fields.

4. Service providers and disclosures

ServicePurpose and information
Google GeminiLyrics generation, refinement, and safety classification; receives creative text and limited requested style.
Google LyriaMusic generation; receives approved lyrics, target duration, and style. Output includes SynthID.
CloudflareNetwork protection, website, protected storage, transient delivery, sync/sharing storage, and infrastructure.
Apple and GoogleApp distribution, purchases and lifecycle notices, sign in when selected, push delivery, iCloud or Drive backup when enabled.
Email/support providersAccount or support communications and delivery metadata.
Private audio processorTemporary Demucs vocal separation and Whisper lyric alignment; request data is deleted after processing.

Hummingly requires Google AI processing through a project with an active billing account. Under the Gemini API paid service terms, Google does not use these prompts and responses to improve its products. Google may retain them for a limited period for safety, abuse prevention and legal obligations. This is not a promise of zero retention. Google processes operational and billing information under its own applicable privacy terms. Epicalin, LLC does not use your private creative content to train a general AI model.

We may disclose information at your direction, to comply with law, protect people or the Service, investigate fraud or abuse, respond to valid process, or complete a corporate transaction with appropriate safeguards. We do not sell personal information or share it for cross context behavioral advertising.

5. Storage, security, and retention

Controls include transport encryption, account and recipient authorization, short lived tokens, secret separation, signed store receipt validation, store lifecycle notifications, rate limits, prompt isolation, content checks, database constraints, transient delivery, and deletion queues. No system is perfectly secure.

6. Your choices and rights

You can decline or withdraw AI processing permission; edit profile information; manage or restore subscriptions; disable notifications, Library Sync, and backup; revoke shares; remove songs; sign out; and request account deletion. Deleting a Hummingly account does not cancel a store subscription. Depending on location, you may request access, correction, deletion, portability, restriction, objection, or an appeal. We may verify identity and limit a request where law permits. To ask about an AI report disposition, email us with the report identifier if available; never email a password or private invitation link. Contact hello@hummingly.app or your regulator.

7. International processing and U.S. notices

Information may be processed in the United States and other provider locations. For EEA, UK and Swiss users, processing bases include contract performance for requested account and subscription services, consent for optional AI disclosures, legitimate interests in preventing fraud and maintaining security, and legal obligations. You may withdraw consent without affecting prior lawful processing. Where required, international transfers must use an applicable adequacy decision or contractual safeguards such as the relevant standard contractual clauses. You may request details or a copy of applicable safeguards, access, correction, erasure, portability, restriction or objection, and complain to your local data protection authority. We do not make decisions with legal or similarly significant effects solely by automated processing; safety filters can reject a creative request and you may contact support for review.

For California notice at collection purposes, categories include identifiers, account/commercial information, internet or device activity, user content, and sensitive information you choose to include in creative content. We use and retain them as described. We do not sell or share personal information for cross context behavioral advertising or use sensitive information to infer unrelated characteristics.

8. Consumer Health Data Privacy Notice

Categories and sources. Sources are the creative content, style choices, binaural settings, and optional support details you provide, together with generated content. Creative inputs or reports may reveal or imply physical or mental health conditions if you include them. We do not diagnose conditions or request clinical records.

Purposes and sharing. We use relevant information to create, check, play, organize and share requested content, answer support requests, and protect service integrity. When you consent to AI processing, health related information you put in creative fields may be sent to Google Gemini and Lyria and processed by our private audio processor. Hosting and security providers handle the service data they need. Private recipients receive content only when you choose to share it. We may disclose information when law requires. We do not sell consumer health data or use it for advertising, data broker activity, or unrelated profiling.

Your rights. Withdraw AI permission in Settings. This stops new AI requests but cannot recall prior provider processing. Contact us to confirm processing, obtain access or a copy, correct or delete information, or appeal a refusal without discrimination. We verify requests using information reasonably necessary to protect your account, and accept an authorized agent where required by law. If denied, reply “Privacy Appeal.” Washington residents may contact the Washington State Attorney General; others may contact their regulator.

9. Adults only

The Service is not offered to people under 18 because the Google AI API services used by Hummingly require an adult directed client. The birthday check occurs before login and the raw date is not retained. If you believe an ineligible person used the Service or submitted information, contact us to investigate and delete as appropriate.

10. Changes and contact

Material updates may require a new acknowledgement tied to an immutable version. Prior accepted versions remain available at their versioned URLs.

Epicalin, LLC, owner and operator of Hummingly. CEO: Catalin Calin. Business mailing address: 1810 N Burning Bush Ln, Mount Prospect, IL 60056, United States. Email: hello@hummingly.app. For a privacy request, use the subject “Privacy Request.” For an appeal, use “Privacy Appeal.” Support: Help & Support.