MyMelos Privacy Policy
Effective Date: October 9, 2026
1. Who We Are and How to Reach Us
BitDynamic (Shenzhen) Technology Co., Ltd. builds and operates MyMelos, an application that uses artificial intelligence to compose songs. This Policy describes the personal information we gather, why we gather it, how we handle it, who we may pass it to, how long we keep it, and the choices available to you.
It applies whenever you install the MyMelos app, sign in, visit our website, use the web console, take part in MyMelos Chat, generate or download a song, buy a subscription, or contact our support team. For the purposes of data protection law, BitDynamic (Shenzhen) Technology Co., Ltd. acts as the data controller of the information covered here.
How to reach us:
- Company: BitDynamic (Shenzhen) Technology Co., Ltd.
- Email (privacy, support, and business): service@bitdynamic.co
2. The Information We Handle
2.1 Details you give us directly
When you set up a profile or use the app's creative tools, you share information with us on purpose. This generally falls into these groups:
- Profile details — your display name, username, email, phone number, avatar, password or sign-in credentials, language, country, and app preferences.
- Creative material — the prompts, lyrics, song titles, project names, genre or mood choices, and any images, photos, audio, or video you add while working on a song.
- Your songs and history — the tracks MyMelos produces for you, along with saved projects, downloads, share links, and whether you chose to publish anything.
- Voice data (optional) — if you switch on voice cloning or build a personal voice, we handle the recordings you submit and the voice model we create from them. Depending on your location, law may treat this as sensitive information or biometric data, so we ask for your explicit agreement first.
- Guardian details — where a parent or guardian must consent, we may hold a contact address, a consent record, and verification status.
- Support and complaints — the contents of messages, refund requests, appeals, surveys, and feedback you send us.
- Web billing details — when you pay through our website, the payment is handled by a third-party processor such as Stripe or PayPal. We receive billing-related items like your name on the order, contact email, country, order number, invoice, subscription and refund status, and transaction-risk flags. Complete card numbers, PayPal logins, and full bank details never reach us.
- Copyright notices — if you file a takedown notice, counter-notice, or rights complaint (or one is filed about your content), we hold the details you submit, such as your name, contact information, ownership evidence, signature, and the material describing the disputed work.
2.2 Details we gather as you use the service
- Technical and log data — IP address, device and operating-system details, browser, app version, network type, language, time zone, device and advertising identifiers, install ID, crash reports, and access times.
- Activity data — which features you open, how many songs you generate, the settings you pick, time spent, saves, downloads, shares, subscription state, community activity, MyMelos Chat history, and the results of safety reviews.
- Security and anti-abuse data — device fingerprints, unusual request patterns, sign-in risk, payment risk, signs of automation, proxy or VPN indicators, and links between accounts.
- Web activity — pages viewed, referring links, click paths, session and consent status, checkout events, subscription-management actions, and browser error reports.
2.3 Cookies and similar tools
Our website and web console use cookies, local and session storage, pixel tags, SDKs, and device identifiers to remember you and to understand how the site is used. We group them as follows:
- Strictly necessary — keep you signed in, protect your account, prevent fraud, run checkout, manage subscriptions, balance traffic, and record your cookie choices. The site cannot work properly without them.
- Preference — remember your language, region, interface settings, and creative choices so you do not have to re-enter them.
- Analytics — help us count visitors, spot slow pages, trace errors, and see which features are used, so we can improve the product. Where we can, we rely on aggregated or de-identified figures.
- Marketing and attribution — where the law allows and subject to any consent or opt-out you are given, measure how campaigns perform, identify where visitors came from, and avoid showing the same ad twice.
- Third-party and payment tools — our payment, anti-fraud, analytics, support, and cloud partners may set or read their own cookies, SDKs, or similar tools while helping us run checkout, verify security, or deliver the service.
You can remove or block cookies in your browser, and manage non-essential ones through any preference tool we offer. Turning off strictly necessary or payment-related tools may stop sign-in, checkout, subscription management, or saved projects from working.
2.4 Details we receive from others
- Sign-in providers — if you use Apple, Google, WeChat, or another provider to log in, we receive the basic profile details and account identifiers you authorise them to share.
- Payment platforms — Apple, Google, Stripe, and PayPal tell us about order numbers, subscription and refund status, chargeback flags, billing email and country, transaction tokens, customer or subscription IDs, tax status, and anti-fraud results. They never pass us your full card number, PayPal credentials, or full bank details.
- Legal and safety sources — regulators, law enforcement, platform partners, or security providers may supply information when we handle unlawful content, fraud, or security incidents.
- Platform age signals (planned) — if we later enable age-assurance features and where the law and any user or guardian authorisation permit, we may read age bands, age categories, or guardian-approval status returned by tools such as Google's Play Age Signals and Apple's Declared Age Range. These signals do not include a full date of birth or identity documents.
2.5 Third-party AI models
Producing a song calls for specialised AI models, so MyMelos passes the necessary inputs to outside providers (“AI Providers”) for processing. At present these include Suno, Inc. for music generation, vocal synthesis, and arrangement; Anthropic PBC (Claude) for prompt handling, lyric help, and instruction generation; and OpenAI, LLC (ChatGPT) for prompt writing, multimodal understanding, and responses.
The inputs we send are limited to what a request needs, and may include:
- Audio, voice samples, and images you supply, where a music or vocal model must process them.
- Text such as prompts, keywords, lyrics, and genre or mood settings, where a language model must handle them.
We require each AI Provider to keep your data only as long as needed to complete the request and then clear it from their processing systems, except where a limited retention period is demanded for legal, regulatory, security, abuse-prevention, audit, or dispute reasons. Unless you separately and clearly agree, or the law permits it, we do not let AI Providers use your private prompts, private projects, original voice recordings, voiceprints, personal voice models, or any content from a minor's account to train their general models.
3. Why We Use Your Information
We rely on your information only where we have a lawful reason to do so. Each purpose below is paired with the reason that supports it.
- Running the service — creating accounts, verifying sign-ins, processing prompts and media, producing songs, saving projects, syncing devices, managing subscriptions, handling checkout and payments, issuing refunds and invoices, and answering support requests. Basis: performing our contract with you, or steps you ask us to take before a contract.
- Operating AI and voice features — completing the generation, editing, remix, or voice-cloning requests you start. Basis: performing our contract, and explicit consent where the data is sensitive or biometric.
- Safety and fraud prevention — detecting fake accounts, bots, payment fraud, chargeback risk, unusual requests, policy-breaking content, infringement risk, risks to minors, and attacks. Basis: our legitimate interests, our contract with you, and legal obligations.
- Age-appropriate use and minor protection — where we later adopt platform age signals, using age bands and guardian-consent status to adjust access to posting, social features, purchases, voice cloning, adult content, and external sharing. We will not use those signals for cross-context advertising or profiling unrelated to age-appropriate experiences and compliance. Basis: our contract with you, legitimate interests, legal obligations, and consent where required.
- Reviewing content — checking material that may breach our Terms or involve child-safety risks, non-consensual content, infringement, fraud, hate, violence, or other high-risk activity. Basis: our legitimate interests, legal obligations, and the protection of important public interests.
- Improving the product and our models — within the limits set out in Section 4, using public content, aggregated or anonymised data, feedback, and data you authorise us to use. Basis: our legitimate interests, consent, or another lawful ground.
- Notices, marketing, and web analytics — sending service and security messages, subscription reminders, policy updates, and, where allowed, promotions or surveys, and using cookies for analytics and attribution. You can opt out of marketing through your email settings, in-app controls, or cookie preferences. Basis: our contract, legitimate interests, consent, and, for some messages, your prior request.
- Rights protection and legal requests — handling appeals, law-enforcement requests, regulatory enquiries, disputes, claims, audits, and our own defence. Basis: legal obligations and legitimate interests.
- Copyright matters — receiving and assessing notices, counter-notices, and infringement disputes, deciding repeat-infringer questions, and keeping the records the law requires. Basis: legal obligations, legitimate interests, and the protection of rights holders and the platform.
4. Where AI Training Stands
We may learn from material that is already public — published songs, public remixes, public settings, general prompts, feedback, and aggregated or anonymised data — to test, evaluate, and improve our models and safety systems.
We will not feed the following into public or third-party foundation models unless you separately and clearly agree, or the law otherwise requires it:
- Private projects, uploads, prompts, audio, or images you have kept private;
- Original voice recordings, voiceprints, personal voice models, and other biometric data used for cloning;
- Material that plainly contains identity documents, financial or health information, children's data, intimate content, or other sensitive personal information;
- Anything from a minor's account; and
- Data we are barred from using by law, or which you have objected to, withdrawn consent for, or asked us to delete.
To keep data inside its permitted use, we apply access limits, classification, review rules, permission separation, logging, de-identification, aggregation, and retention controls.
5. Voice Cloning and Biometric Information
Voice cloning and personal voice models work by analysing recordings to build a model of how you sound. In some places, the resulting voiceprints count as sensitive or biometric information, so we treat them with extra care.
We only begin once you switch the feature on, complete the authorisation steps, and accept the notice shown at the time. We use the data solely to:
- Create, run, maintain, and improve the personal voice model in your account;
- Check sample quality, authorisation, and the risk of misuse;
- Spot cloning without consent, impersonation, infringement, and unlawful content; and
- Meet legal duties, handle complaints, and protect users and the platform.
Unless you separately and clearly agree, we do not sell, rent, trade, or otherwise profit separately from your voiceprint or biometric data, and we do not use your original recordings or personal voiceprints to train public foundation models. When you close your account, delete the voice model, or withdraw consent — or when the retention period required by law runs out — we remove or anonymise the data, subject to the limited retention described in Section 8.
7. Sending Data Across Borders
We are based in Shenzhen, China, and our service relies on cloud providers, vendors, and teams in other countries and regions. If you use MyMelos from outside China, your information may be transferred to, stored in, or processed in places other than where you live.
Where the law requires it, we put safeguards in place for these transfers — such as data processing agreements, standard contractual clauses, transfer risk assessments, limited access rights, and technical security measures.
8. How Long We Keep Data
We keep personal data only as long as it is needed for the purposes in this Policy, or longer where the law, a dispute, security, anti-fraud, accounting, audit, minor-protection, or rights-protection need requires it. In general:
- Account details stay while your account is open and are usually deleted or anonymised from live systems within 30 business days of closure, unless a legal or safety reason requires limited retention.
- Prompts, uploads, and songs stay while your account is open or while you keep the project. Once you delete a song or close your account, they are usually removed or anonymised within 30 business days. Content already posted publicly, shared, remixed, or saved by others may not be fully retrievable.
- Voice data and personal voice models stay while the feature is on and your account is open, and are usually removed or anonymised within 30 business days of deleting the model, withdrawing consent, or closing the account, unless a legal, complaint, dispute, safety, or audit reason requires limited retention.
- Payment and accounting records stay for as long as tax, accounting, anti-fraud, app-store, Stripe, and PayPal rules require.
- Cookies and web logs stay as long as needed for sign-in, security, checkout, or preferences, with retention for non-essential cookies described in our cookie tool, your browser, or the relevant third-party notices.
- Security and anti-fraud records stay as long as needed to keep the platform secure and investigate misuse.
- Support, complaint, and legal records stay as long as needed to handle requests, disputes, defences, and legal duties.
- Backups are cleared, overwritten, or anonymised during the normal rotation cycle.
- Inputs sent to AI Providers are kept by them only as long as their processing needs, then cleared, unless a legal, regulatory, security, abuse-prevention, audit, or dispute reason requires limited retention.
You can delete some content inside the app, or write to service@bitdynamic.co to close your account, erase personal data, or withdraw consent. Once we confirm who you are, we handle the request as the law requires.
9. Your Choices and Rights
Depending on where you live, you may be able to:
- Ask what personal data we hold about you;
- Have incorrect or incomplete data corrected;
- Have personal data erased;
- Restrict or object to particular uses;
- Receive a copy of your data in a common, machine-readable format;
- Withdraw consent you previously gave;
- Opt out of sale, sharing, targeted advertising, profiling, or non-essential cookies where the law grants that choice;
- Appeal a decision we make about an automated process or a privacy request; and
- Complain to a data protection authority.
Send requests to service@bitdynamic.co. We may ask you to confirm your identity to protect your account, and if someone else is writing on your behalf, we may ask for proof that they are authorised.
9.1 If you are in the EEA, the UK, or Switzerland
You may exercise rights of access, correction, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority under applicable data protection law. Our legal grounds for processing are contract performance, your consent, our legitimate interests, legal obligations, and, in narrow cases, the protection of vital or public interests.
9.2 If you are in the United States
Residents of California, Texas, and other states with privacy laws may have rights to know, access, correct, delete, obtain portability, opt out of sale or sharing, opt out of targeted advertising, limit the use of sensitive personal information, and appeal, and to be free from discrimination for exercising those rights. We do not treat you unfairly for using them.
10. Children
MyMelos is not meant for children under 13, or under the higher minimum age set by local law, and we do not knowingly collect their personal data. If we find out, or are reliably told, that a child below the applicable age created an account or submitted personal data without proper consent, we take reasonable steps to delete the data and close the account.
Parents and guardians who believe a child used MyMelos without authorisation, or uploaded a photo, a recording, contact details, school information, or an identity document, can reach us at service@bitdynamic.co.
Accounts held by minors may be limited in public posting, direct messaging, social features, purchases, voice cloning, adult content, and external sharing, and we may require guardian consent or another reasonable check.
If we later adopt platform age signals, we may use the age bands, age categories, guardian consent, revoked approvals, or significant-update acknowledgements that Google, Apple, or other platforms return to trigger age-appropriate limits or consent steps. If those signals are unavailable or not enough, we may ask you or your guardian for another reasonable form of age or consent verification.
11. Keeping Data Secure
We use reasonable technical and organisational safeguards for personal data, including access controls, protected transmission and storage, separated permissions, log auditing, vulnerability fixes, anti-fraud checks, content-safety reviews, and vendor oversight. That said, no online service, cloud platform, or storage system can be guaranteed completely secure. Please keep your sign-in details safe and let us know promptly if you notice anything unusual.
12. Changes to This Policy
We may revise this Policy from time to time. If a change materially affects the kinds of data we handle, the reasons we use it, cookies, third-party payments, AI Providers, how AI models are trained, voice cloning, biometric data, protections for minors, platform age signals, cross-border transfers, or your rights, we will tell you through an in-app message, a notice, an email, an app-store update note, or another reasonable and lawful method.
13. Contacting Us
For questions about this Policy or about how we handle personal data, cookies, third-party payments, voice cloning, biometric data, protections for minors, AI training, or account deletion, write to:
- Email (privacy, support, and business): service@bitdynamic.co
© 2026 BitDynamic (Shenzhen) Technology Co., Ltd. All rights reserved.