Privacy policy
Last updated August 31, 2026
This explains what data FilmMySong handles, why, and what control you have. The philosophy is simple: we handle your data to make your videos, and for nothing else. We don't sell it, we don't run ad tracking, and we never train AI models on your music.
What we collect
- Account data: your email address and artist name. If you sign in with Google instead of an emailed link, we take your email address from your Google account and nothing else. Not your Google display name, not your profile picture. Your artist name is still the one you type here, because that is what goes on your videos.
- Your uploads: songs, cover art, photos you add for characters, and finished music videos you bring to cut clips from. Character photos are used for exactly one thing: rendering those people into your scenes, on your instruction. We never use them to identify anyone, and you must have the permission of anyone in them (the terms spell this out). A video you bring is used only to cut your clips, and its frames never go to any AI provider. We extract its soundtrack to time your words: that audio runs through the same lyric timing as an uploaded song — our own code, on our servers or on the GPUs we rent from Modal — and when you don't paste your lyrics, Google's Gemini listens once to write them down. It is deleted when you delete the project, like every upload. We also store a fingerprint of each song file you upload, which lets us recognise when you are uploading a song you already have and offer to add the new video to it. It is only ever matched against your own songs, it tells us nothing about the music itself, and it goes when the song goes.
- Generated content: lyrics we transcribe, the Song DNA, scenes, and finished videos.
- Chat with Finch messages: what you type when you chat with a video, and Finch's replies. They exist so the conversation keeps its thread, and they're used for nothing else. Each chat belongs to one video and is deleted with it.
- Feedback you send us: notes you write in the app's feedback box, kept with your account so we can act on them and follow up. They are used for nothing else and are deleted with your account.
- Usage and billing data: your credit movements, plan, and the technical logs any web service keeps (IP address, browser, timestamps) for security and debugging.
- Abuse-prevention records: when an account is created, we keep the network address (IP) it came from for up to 7 days, only to decide whether brand-new accounts from that address still receive free starting credits. This keeps bulk fake signups pointless without ever blocking a real person from signing up. After 7 days these records are deleted. We also keep a per-account daily tally of what your generations cost us to run, in dollars, used only for fraud protection (it pauses accounts that burn far past any honest day's use). The tally lives exactly as long as your account and is deleted with it.
- Support records: when one of us changes something on your account by hand (a plan we gave you, a credit grant, a spending limit), we keep a record of who did it, what changed and when. It names the account by email, is used only for accountability and fraud protection, and is kept after an account is deleted for as long as the billing records are.
- Sign-in security counters: a small tally of recent sign-in activity for an email address, and the network address it came from, so nobody can guess their way into your account or bury you in sign-in email. The email address is stored as a one-way hash rather than the address itself. These counters are deleted a day after the last attempt and are used for nothing else.
Cookies: only what sign-in needs (your session, which lasts 90 days and renews while you keep using the app). Strictly necessary, so no cookie banner. No third-party ad or analytics cookies.
Why we're allowed to (legal bases)
GDPR asks for a legal basis per purpose, so here they are. Your account data, uploads, and generated content are processed to perform our contract with you (Art. 6(1)(b)). Security logs and the abuse-prevention records run on our legitimate interest in keeping the service safe and un-defrauded (Art. 6(1)(f)). Billing records are kept because tax law obliges us to (Art. 6(1)(c)). We run no marketing tracking, so nothing here rests on consent; if that ever changes, we'll ask first, not tell you after.
One automated decision, disclosed: whether a brand-new account starts with free credits is decided automatically by the abuse check above. It never blocks an account and never touches anything paid. If you think it got you wrong, email us and a human looks at it.
Who processes it for us
Generation runs on infrastructure we don't own. When you use the service, the relevant pieces of your content are processed by:
- Google (Gemini API) — reads your song's audio, lyrics, cover art, and questionnaire answers to transcribe and write the Song DNA and scene plans. When you chat with a video, your messages and that video's details go there too, so Finch can answer.
- Google (sign-in) — only if you choose to sign in with Google. Google confirms who you are and hands us your email address. It learns that you have an account here, the way it does for every site you use it on. Sign in with an emailed link instead and Google is never involved in getting you in.
- Replicate — generates scene images and video clips from the scene descriptions and, when your scenes include people, the reference photos you added.
- Runware — a second provider for the same generation work (each scene goes to whichever serves it best); receives the same scene descriptions and reference photos as Replicate.
- Modal — rents us the GPUs that time your words. It receives your song's audio (or a brought video's soundtrack) and your lyrics, runs our own timing code on them for that one job, and we store no files there.
- Our hosting provider — runs the app and holds working copies of your files while videos are made (servers in the EU).
- Backblaze — stores your uploads and finished videos in its EU data center (Amsterdam), and stores our database backups. When you play or download your media, the bytes come from there.
- Cloudflare — sits in front of the site for speed and attack protection, so visitor traffic (including your IP address) passes through it; your media plays through the same shield.
- Resend — delivers sign-in links and the emails we send you, so it handles your email address and those messages. It sends from servers in the EU.
- Stripe — handles checkout, card details, and subscription billing. Stripe receives your email address, your name, and what you bought; card numbers never touch our servers. Stripe also tells us when a payment succeeded so your credits arrive.
These providers act on our instructions to deliver the service to you. We don't permit them to use your content to train their models.
Where it goes (international transfers)
Our own servers are in the EU, and your stored files live in Backblaze's EU data center. Generation crosses borders: Google and Replicate are US companies, and Runware is a UK company running infrastructure in the EU and the US. Modal, which rents us the GPUs that time your words, is a US company running its compute in the US. So content can leave the EEA while your video is being made. Backblaze is a US company too — the files sit in its EU region, and its US side is covered by the safeguards below. Resend, which delivers our email, is a US company; we use its EU sending region, so the mail itself goes out from EU servers. Payments run through Stripe Payments Europe (Ireland), with some processing by its US parent. Those transfers rest on the safeguards GDPR accepts: the EU's adequacy decision for the UK, the EU-US Data Privacy Framework where the provider is certified under it (Google, Stripe and Backblaze are), and data-processing agreements with Standard Contractual Clauses for the rest. Email us if you want the details for a specific provider.
How long we keep it
Your uploads and generated content stay until you delete them. Chat with Finch messages live exactly as long as the video they belong to. Deleting a project, or your whole account, permanently removes the database records and the files; backup copies, where they exist, expire within 30 days. Billing records are kept as long as tax law requires. If you request a sign-in link and never use it, no account is created, and the link, the code beside it and the address they went to all expire within minutes.
Under 16?
The service is for people 16 and up, and we don't knowingly process younger users' data. If you believe a child is using it, email us and we'll delete the account.
Your rights
You can access your data, correct it, get a copy in a portable format, and delete it. You can object to, or ask us to restrict, the processing we base on legitimate interest (the security and abuse records above), and if we ever process anything on consent you can withdraw it as easily as you gave it. Deleting a song and its videos is self-serve in the app; for deleting your whole account, and everything else, email us and we'll answer within a month, as GDPR requires. You also have the right to complain to a data protection authority: your own country's, or ours, the Bulgarian Commission for Personal Data Protection (cpdp.bg).
When this policy changes
If we change this policy in a way that matters, we'll tell you by email or in the app before it takes effect. This page always carries its last-updated date.
Contact
The data controller is More Than Streams LTD, a Bulgarian limited liability company. Data questions: [email protected].
