Last Updated: January 27, 2025

Privacy Policy

Privacy Policy

Last Updated: January 27, 2025

At VerseOS, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. Please read this policy carefully.

1. Information We Collect

1.1 Information You Provide to Us

We collect information that you voluntarily provide when you:

  • Create an account: Email address, password, and optional profile information
  • Use our services: Lyrics, audio files, project data, collaboration notes, and other content you create
  • Contact us: Information you provide when contacting our support team
  • Subscribe to services: Payment information (processed securely through Stripe, not stored by us)

1.2 Automatically Collected Information

We automatically collect certain information when you use VerseOS:

  • Usage data: Features you use, pages you visit, time spent on the platform
  • Device information: Browser type, operating system, device identifiers
  • Log data: IP address, access times, error logs
  • Cookies and tracking technologies: As described in our Cookie Policy

1.3 Third-Party Service Data

We receive information from third-party services integrated with VerseOS:

  • Supabase Authentication: Account information, authentication tokens
  • Stripe: Payment transaction data, subscription status
  • PostHog Analytics: User behavior and product analytics (privacy-preserving)

2. How We Use Your Information

We use the information we collect to:

  • Provide our services: Enable you to create, store, and manage your songwriting projects
  • Process payments: Handle subscription payments and manage your account
  • Improve our services: Analyze usage patterns to enhance features and user experience
  • Communicate with you: Send service-related notifications, respond to support requests
  • Ensure security: Detect and prevent fraud, abuse, and security threats
  • Comply with legal obligations: Meet legal requirements and respond to legal processes

3. Data Storage and Security

3.1 Where Your Data is Stored

  • Database: Stored securely in Supabase (PostgreSQL), hosted in the European Union
  • Files: Audio files and other media stored in Supabase Storage with encryption at rest
  • Backups: Regular encrypted backups are maintained for data recovery

3.2 Security Measures

We implement industry-standard security measures to protect your data:

  • Encryption: Data in transit (HTTPS/TLS) and at rest
  • Authentication: Secure authentication via Supabase Auth with JWT tokens
  • Access controls: Row-level security policies ensure users can only access their own data
  • Regular security audits: We regularly review and update our security practices

4. Third-Party Services

VerseOS uses the following third-party services that may process your data:

4.1 Supabase

  • Purpose: Authentication, database, and file storage
  • Data processed: Account information, application data, authentication tokens
  • Privacy: Supabase Privacy Policy
  • Location: European Union (GDPR compliant)

4.2 Stripe

  • Purpose: Payment processing and subscription management
  • Data processed: Payment information, billing details, transaction history
  • Privacy: Stripe Privacy Policy
  • Certification: PCI DSS Level 1 compliant

4.3 PostHog

  • Purpose: Product analytics and user behavior tracking
  • Data processed: Usage events, feature interactions (anonymized where possible)
  • Privacy: PostHog Privacy Policy
  • Data retention: Configurable, defaults to 7 years

4.4 OpenAI / Anthropic (AI Features)

  • Purpose: AI-powered rhyme suggestions and lyric assistance
  • Data processed: Text content sent to AI services for processing
  • Privacy: OpenAI Privacy Policy, Anthropic Privacy Policy
  • Note: We do not use your content to train AI models

4.5 Vercel

  • Purpose: Hosting and content delivery
  • Data processed: Application access logs, error logs
  • Privacy: Vercel Privacy Policy

5. Your Rights and Choices

5.1 Access and Control

You have the right to:

  • Access your data: View all personal information we hold about you
  • Update your information: Modify your profile and account settings at any time
  • Delete your account: Request account deletion, which will remove your personal data
  • Export your data: Download your projects and data in a portable format (GDPR right to data portability)

5.2 Cookies and Tracking

You can control cookies through your browser settings. See our Cookie Policy for more information.

5.3 Marketing Communications

You can opt out of marketing emails by:

  • Clicking the unsubscribe link in any marketing email
  • Adjusting your preferences in account settings
  • Contacting us directly

6. Data Retention

We retain your information for as long as necessary to:

  • Provide services to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain security and prevent abuse

Account deletion: When you delete your account, we will:

  • Delete your personal information within 30 days
  • Retain anonymized usage data for analytics purposes
  • Retain certain information as required by law (e.g., transaction records)

7. Children's Privacy

VerseOS is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.

8. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place:

  • EU users: Data primarily stored in EU (Supabase), GDPR compliant
  • Standard Contractual Clauses: Used for transfers outside the EU when necessary
  • Privacy Shield: For US-based services, we rely on appropriate legal frameworks

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will:

  • Post the updated policy on this page
  • Update the "Last Updated" date
  • Notify you of significant changes via email or in-app notification

10. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Email: privacy@verseos.studio

Address:
VerseOS
[Your Business Address]

Data Protection Officer: If you are an EU resident, you may also contact our Data Protection Officer at dpo@verseos.studio


11. GDPR-Specific Rights (EU Users)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to rectification: Correct inaccurate personal data
  • Right to erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to restrict processing: Limit how we use your data
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing of your data for certain purposes
  • Right to withdraw consent: Withdraw consent for data processing at any time

To exercise these rights, please contact us at privacy@verseos.studio. We will respond within one month.


Your privacy matters to us. Thank you for trusting VerseOS with your creative work.