Privacy Policy
This page explains what Serenade collects when you use our website, why we collect it, and who we share it with. In short: we collect the information needed to create your song, take payment, deliver the result, and measure how well our ads are performing. We do not sell your personal information.
1. What we collect
When you use Serenade we may collect the following information:
- Quiz answers. The relationship, recipient name, musical style, voice, qualities, memories, and personal message you submit through the composer.
- Email address. Provided at checkout so we can deliver your order.
- Payment details. Card details are entered directly into Stripe’s secure checkout. Serenade never sees or stores your card number; we retain only the Stripe payment identifier and the amount charged for accounting purposes.
- Cookies. Two first-party cookies —
serenade_visitor_id(400-day lifetime) andserenade_session_id(30-minute rolling lifetime) — plus Meta’s_fbpand_fbccookies for ad attribution. - Attribution data. When you arrive from a Meta ad we may capture the click identifier (fbclid), UTM parameters, the referring URL, and the landing page URL.
- Request context. Your IP address and browser user-agent string, as sent by your browser on each request.
2. Why we collect it
We use this information to:
- Generate and deliver your song.
- Process your payment and send confirmation.
- Notify you by email when your delivery is ready.
- Provide customer support if something goes wrong.
- Measure the performance of our advertising on Meta so we can continue to operate.
- Detect and prevent abuse of the service.
3. Who we share it with
To run Serenade we share specific pieces of information with the following service providers. Each only receives what it needs to do its job:
- Stripe — payment processing. Receives card details, amount, email, and order ID.
- Google Firebase (Firestore and Cloud Storage) — order and song persistence; hosts the audio files on Google Cloud infrastructure.
- Replicate — runs the AI models. Receives the lyric prompt and the music prompt for each song.
- Anthropic — produces lyrics from your quiz answers via Replicate.
- MiniMax — produces audio from the lyrics and music prompt via Replicate.
- Resend — sends the delivery email. Receives your email address and order ID.
- Meta — receives Pixel and Conversions API events to measure advertising performance. Your email address and visitor identifier are SHA-256 hashed (a one-way transformation) before being sent.
We do not sell your personal information. We do not share it with any party outside the list above except where required by law.
4. Cookies and tracking
Serenade uses two first-party cookies to maintain your session and link your activity across visits. Both are marked httpOnly, sameSite=lax, and secure in production.
We also use the Meta Pixel, which sets the _fbp and _fbc cookies for ad attribution. You can opt out of personalised advertising through your browser’s tracking-protection controls or through Meta’s Ad Preferences at facebook.com/ads/preferences.
5. Data retention
We retain orders, songs, and the audio files in Firebase Storage indefinitely so that you can continue to access your delivery link and so we can support you if questions arise later. Cookies expire according to the lifetimes listed above. If you would like your personal data deleted, email support@serenade.media and we will remove it from our systems within a reasonable time, subject to any legal retention requirements (for example, tax records associated with your payment).
6. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Request deletion of your personal data.
- Receive a portable copy of your personal data.
- Object to or restrict certain processing activities.
To exercise any of these rights, email support@serenade.media from the address associated with your order.
7. Children
Serenade is intended for adults purchasing a gift. We do not knowingly collect information from anyone under 16 years of age, and the service is not designed for minors. If you believe a minor has used Serenade, contact us and we will delete the associated data.
8. International transfers
Serenade uses providers headquartered in the United States (Stripe, Google, Replicate, Anthropic, MiniMax, Resend, and Meta). Regardless of where you are located, your data will be processed on servers operated by these providers, which may be in the United States or elsewhere.
9. Security
All traffic between your browser and Serenade is encrypted in transit over HTTPS. Audio files are served from Firebase Storage via signed URLs. Our session and visitor cookies are marked httpOnly, sameSite=lax, and secure in production. No system is perfectly secure, but we take reasonable steps to protect the information you entrust to us.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. We encourage you to review the policy periodically.
11. Contact
Questions about this policy or about the data we hold about you? Email support@serenade.media.