BeatGramCreate a song

Privacy Policy

Last updated: 6 August 2026

1. Introduction

BeatGram (“we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and personalised song creation service (“the Service”). It also tells you about your privacy rights and how the law protects you.

BeatGram is the data controller responsible for your personal data. We are registered in the United Kingdom. Our contact details are available on request.

This Privacy Policy is provided in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), the Data (Use and Access) Act 2025, and, where applicable, the EU General Data Protection Regulation (EU GDPR).

2. The Data We Collect About You

Personal data means any information about an individual from which that person can be identified. We collect, use, store, and transfer different kinds of personal data about you, which we have grouped as follows:

Identity Data
Your name (collected at checkout) and any name you provide for the song recipient.
Contact Data
Your email address, collected at checkout or when you request a login code.
Order Data
Details about songs you create, including the occasion, genre, relationship to the recipient, story details, personalisation preferences, vibe notes, and package tier selected.
Generated Content
The AI-generated lyrics, audio, and album art created from your inputs.
Transaction Data
Payment amounts, currency, and payment status. We do not store your full payment card details — these are processed securely by Stripe, our payment provider.
Technical Data
Internet protocol (IP) address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Service.
Usage Data
Information about how you use our website, including page views, navigation paths, and feature interactions (collected via Google Analytics only where you have consented).
Communication Data
Any correspondence you send to us, including customer support enquiries and feedback.

3. How We Collect Your Data

We collect data through the following methods:

  • Direct interactions: You provide Identity, Contact, and Order Data when you fill in our song creation form, place an order, request a login code, or contact us.
  • Automated technologies: As you interact with our website, we automatically collect Technical Data and (with your consent) Usage Data through cookies and similar technologies.
  • Third parties: We receive Transaction Data from Stripe when you complete a payment. We may receive Technical Data from analytics providers (with your consent) and hosting providers.

4. How We Use Your Personal Data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

Service delivery

We process your Order Data, Identity Data, and Contact Data to create your personalised song. This includes sending your Inputs to our AI service providers for lyric and music generation.

Lawful basis: Performance of a contract with you (Article 6(1)(b) UK GDPR).

Payment processing

We share your Identity Data, Contact Data, and order details with Stripe to process your payment.

Lawful basis: Performance of a contract with you (Article 6(1)(b) UK GDPR).

Account and order management

We use your Contact Data to verify your identity, provide order tracking, and deliver your completed song via email.

Lawful basis: Performance of a contract with you (Article 6(1)(b) UK GDPR).

Customer support

We use your Contact and Order Data to respond to your enquiries and support requests.

Lawful basis: Performance of a contract and our legitimate interest in providing effective customer service (Article 6(1)(f) UK GDPR).

Service improvement and analytics

We analyse Usage Data and Technical Data (with your consent) to understand how visitors use our website, identify issues, and improve the Service.

Lawful basis: Your consent (Article 6(1)(a) UK GDPR) for analytics. Our legitimate interest in maintaining service quality for basic Technical Data (Article 6(1)(f) UK GDPR).

Fraud prevention and security

We monitor Technical Data and transaction patterns to detect and prevent fraudulent activity and protect the security of our Service.

Lawful basis: Our legitimate interest in protecting our business and customers from fraud (Article 6(1)(f) UK GDPR).

Legal compliance

We may process and retain your data as necessary to comply with our legal obligations, including tax and regulatory requirements.

Lawful basis: Compliance with a legal obligation (Article 6(1)(c) UK GDPR).

Note: We do not use your personal data for marketing purposes unless you have given your explicit consent. We will never sell your personal data to third parties.

5. AI Processing and Automated Decision-Making

To create your song, we use artificial intelligence services to generate lyrics and music from your Inputs. This constitutes automated processing, including profiling of your Inputs to produce personalised creative output.

Under Article 22 of the UK GDPR, you have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you. However, the automated processing involved in creating your song is necessary for the performance of our contract with you, and you provide your explicit consent to this processing when you place your order.

If you have concerns about the AI-generated output of your song, you may request a human review by contacting us. We will assess your concerns and, where appropriate, arrange for a human to review and, if necessary, adjust or regenerate the content.

6. Sharing Your Personal Data

We share your personal data with the following categories of recipients:

Stripe, Inc. (USA)

Data: Identity, Contact, and Transaction Data

Purpose: Payment processing

Stripe is certified under the EU-US Data Privacy Framework and maintains UK International Data Transfer Agreement (IDTA) safeguards.

AI service providers (lyrics and music generation)

Data: Order Data (story details, occasion, genre, preferences)

Purpose: Generating your song lyrics and audio

Data is transmitted securely over encrypted connections and processed solely for the purpose of generating your song.

Resend, Inc. (USA)

Data: Contact Data, order details

Purpose: Sending transactional emails (order confirmation, delivery notification, login codes)

Data is transmitted securely and used only for delivering our emails to you.

Hosting and infrastructure providers

Data: Technical Data, all stored personal data

Purpose: Hosting our website and storing your data

Data is stored on servers within the European Economic Area or the UK, or in countries with adequate data protection standards, with appropriate safeguards in place.

Google LLC (USA)

Data: Usage Data, Technical Data

Purpose: Website analytics (only where you have given your consent)

Google is certified under the EU-US Data Privacy Framework. Data is anonymised where possible.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

7. International Transfers

Some of our third-party service providers are based outside the United Kingdom. Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by implementing at least one of the following safeguards:

  • Transferring your data to countries that have been deemed to provide an adequate level of protection for personal data by the UK Government.
  • Using specific contracts approved for use in the UK (the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses).
  • Where providers are certified under an approved certification mechanism (such as the EU-US Data Privacy Framework, recognised via the UK-US Data Bridge).

8. Data Retention

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including satisfying any legal, accounting, or reporting requirements. Our retention periods are:

Order Data and Generated Content: 12 months from order delivery (or longer if you maintain an active account)
Account Data (email, name): Until account deletion, plus 30 days (after which data is permanently deleted)
Transaction Data: 6 years from the end of the financial year in which the transaction occurred (per HMRC requirements)
Analytics Data: 26 months from collection
Customer support correspondence: 2 years from last contact

In some circumstances, we may anonymise your personal data so that it can no longer be associated with you, in which case we may use such information without further notice to you.

9. Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions and are subject to a duty of confidentiality.

We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

10. Your Legal Rights

Under data protection law, you have rights including:

  • Right of access:You can ask for copies of your personal data (commonly known as a “data subject access request”).
  • Right to rectification: You can ask us to correct personal data you think is inaccurate or complete data you think is incomplete.
  • Right to erasure:You can ask us to delete your personal data in certain circumstances (also known as the “right to be forgotten”).
  • Right to restrict processing: You can ask us to limit the processing of your personal data in certain circumstances.
  • Right to data portability: You can ask that we transfer the personal data you gave us to another organisation, or to you, in certain circumstances.
  • Right to object: You can object to the processing of your personal data in certain circumstances, including where we rely on legitimate interests.
  • Right to withdraw consent: Where we rely on your consent to process your personal data, you can withdraw that consent at any time. This will not affect the lawfulness of any processing carried out before you withdraw your consent.
  • Rights relating to automated decision-making: You have the right not to be subject to a decision based solely on automated processing. See Section 5 above for how this applies to our AI song generation.

To exercise any of these rights, please contact us. We will respond within one month (which may be extended by a further two months for complex or numerous requests). You will not normally have to pay a fee to exercise your rights, though we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.

11. Complaints

If you have any concerns about how we handle your personal data, we encourage you to contact us first so we can try to resolve the matter directly. We will acknowledge your complaint within 5 working days and aim to resolve it within 28 days.

You also have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues. You can contact the ICO at ico.org.uk/make-a-complaint or by calling 0303 123 1113. We would, however, appreciate the chance to deal with your concerns before you approach the ICO.

12. Cookies

Our website uses cookies and similar tracking technologies. Cookies are small text files placed on your device when you visit a website. We use the following types of cookies:

  • Necessary cookies: Required for the website to function properly. These include authentication and session management cookies. These cannot be disabled as the Service would not work without them.
  • Analytics cookies: We use Google Analytics to understand how visitors use BeatGram. These cookies are only set if you consent to them via our cookie preferences banner. You can withdraw your consent at any time by clicking the cookie settings link available on every page.

We do not use advertising, tracking, or social media cookies. For more information about the specific cookies we use, you can view the cookie details in our cookie settings panel, available by clicking “Cookie settings” at the bottom of any page.

13. Children’s Privacy

Our Service is not directed to children under the age of 18, and we do not knowingly collect personal data from children. If we become aware that a child under 18 has provided us with personal data without parental consent, we will take steps to delete such information. If you are a parent or guardian and believe your child has provided us with personal data, please contact us.

14. Links to Third-Party Websites

Our website may contain links to third-party websites (such as Stripe's payment page). This Privacy Policy does not apply to those websites. We encourage you to read the privacy policies of any third-party websites you visit.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and, where appropriate, by email. We encourage you to review this Privacy Policy periodically for any changes.

16. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or want to make a complaint, please contact us at our registered UK address or via email. Contact details are available on our website.

Legal Notice

This document is a template and has not been reviewed by a qualified solicitor. Before deploying to production, you must have this Privacy Policy reviewed by a UK-qualified data protection lawyer. Specific details that require legal review include: the lawful bases for processing, international transfer mechanisms, retention periods, the description of AI automated decision-making, and the children's privacy provisions. You must also register with the ICO (ico.org.uk/fee) and pay the annual data protection fee before collecting personal data.