Audiogrant
Studio

Audiogrant

Privacy Policy

How personal information is handled on Audiogrant’s website, in Studio and through connected assistants and integrations.

Last updated October 4, 2026

On this page

  1. At a glance
  2. 1. Scope and contact
  3. 2. Information used by the service
  4. 3. Why information is processed
  5. 4. AI processing and service providers
  6. 5. Connected assistants, plugins and API access
  7. 6. Cookies and browser storage
  8. 7. Retention and security
  9. 8. Your choices and rights
  10. 9. Changes to this policy

At a glance

Audiogrant uses account information to run your workspace and the creative material you submit to carry out your requests. Some features send relevant material to external AI services.

You can manage your preferences and exercise privacy rights under applicable law. The sections below explain service providers, retention criteria and how to request access or erasure.

1. Scope and contact

This policy covers the Audiogrant public website, Audiogrant Studio and its plugins, connected assistants and API integrations, including MCP. Studio is our workspace for creating and managing AI Artists and their music, images and videos.

Audiogrant is a product of Cirtadev GmbH, Zugerstrasse 32, 6340 Baar, Canton Zug, Switzerland (UID CHE-468.012.449). Cirtadev GmbH operates the service and is responsible for account and service administration. Contact us at [email protected] or +41 77 456 69 64. If you use Studio for an organization and process other people’s personal information there, contact us to clarify the data-protection roles and any data-processing agreement that apply to that use.

  • [email protected]
  • +41 77 456 69 64

2. Information used by the service

Account information includes your name, email address, language, account status and authentication records. Security features use session information, IP addresses, browser information and, when enabled, multi-factor authentication or passkey records.

Studio processes the prompts, lyrics, Artist profiles, photographs, voice recordings, transcripts, music, videos and other material you submit, together with generated results, project history and usage records. Those materials can contain personal information about you or other people.

Technical records include usage, requests, errors and security events. Support messages and service notifications involve contact details and message content. If you connect Telegram notifications, the service also uses the linked destination and your notification preferences.

When billing is enabled, Audiogrant records the selected offer, billing period, credit allowance, payment and invoice references, subscription status, credit expiry and any payment review. Stripe collects payment-method and billing details through its hosted pages; Audiogrant does not collect full card details through the Studio billing form.

Information comes from you, people submitting material about you, your use of the website and Studio, and service providers reporting payment, delivery or security events. A payment status or billing reference received from Stripe is distinct from the full payment credentials entered on its hosted pages.

3. Why information is processed

Information is used to create and secure accounts, provide the creative tools you request, store and retrieve your projects, track usage, administer subscriptions and payments, maintain invoices and credit records, handle refunds and disputes, send service messages and investigate technical, security, rights or service complaints.

Where the GDPR applies, processing necessary to manage your account, provide your requested features and administer your purchases relies on performing our contract with you or taking steps you request before a contract. Necessary accounting and other legally required records rely on the relevant legal obligation. Protecting accounts, preventing fraud, resolving technical problems and investigating complaints rely on our legitimate interests in operating a secure service and resolving claims, except where your rights or interests override them. Where consent is required for an optional use, we request it separately and you may withdraw it.

A contract with you does not by itself authorize processing another person’s information or replace additional conditions for sensitive information. Any use for marketing or general-purpose model training requires its own clear purpose, lawful basis and disclosure, with consent where required. This notice and acceptance of the Terms do not provide that consent.

4. AI processing and service providers

Depending on the feature and its configured provider, a request sends relevant prompts, reference files and project context to an AI service. Voice processing can include a recording and transcript; image processing can include reference photographs. Only submit material you are entitled to share for that task.

Configured AI services can include OpenAI for text and images, and Modal for running ACE-Step music generation and Qwen voice processing. OpenAI receives the relevant text or image inputs; Modal processes the inputs and results of the generation tasks it runs. These are different services with different data practices; an open-source model license does not determine the hosting provider’s privacy practices.

Infrastructure providers can include Scaleway for hosting and transactional email, and OVHcloud for file storage. They process the account, technical, message or stored project data needed for those services. Cloudflare Turnstile may process browser and network information for anti-bot checks when enabled. Password security includes a compromised-password check.

Stripe provides Checkout, the Customer Portal, payment processing and invoicing, receiving the billing, transaction and payment details needed for those services. If you enable Telegram notifications, Telegram receives the linked destination and the messages delivered through it. You can manage optional notifications in your settings.

Audiogrant’s permission to process your private content for requested features does not authorize advertising or general-purpose model training. OpenAI states that API data is not used for training by default unless the customer opts in. Retention for abuse monitoring, service operation or legal obligations is separate from training: a no-training setting does not mean that no data is stored. Connected assistant services follow their own policies and account settings.

OpenAI’s API policies describe abuse-monitoring retention of up to 30 days, with exceptions for legal requirements and protection against harm; feature-specific storage can differ. Modal describes temporary function inputs and outputs, plan-dependent logs and persistent storage until deletion. See https://developers.openai.com/api/docs/guides/your-data and https://modal.com/docs/guide/security for provider details. These policies do not establish Audiogrant’s own deletion deadlines or a zero-retention configuration.

Processing may take place outside Switzerland and the EEA, including in the United States. Modal documents US storage for some logs and task data even when compute runs elsewhere; see https://modal.com/docs/guide/data-residency. Each provider applies its own storage locations and retention. Audiogrant does not promise EU-only processing or zero retention by these providers. For the recipients, destination countries and transfer safeguards that apply to a feature, contact [email protected].

5. Connected assistants, plugins and API access

Installing a plugin alone does not grant access to your Audiogrant account. For a new assistant connection, you sign in to Audiogrant and approve the access shown on its authorization screen. This connection covers supported library reading and editing, credit information, generation and generation settings. API keys have the permissions you select separately. Only connect applications you trust.

Audiogrant processes the connected application’s identifier, name and return address, its permissions and authorization records, and credential, expiry and revocation records to provide and secure that access. A connection can stay signed in until its authorization expires or you revoke it; closing the chat or signing out of Studio does not replace revocation.

An assistant sends Audiogrant the inputs for the actions it requests, such as prompts, lyrics, project references, files and generation settings. Within the connection’s permissions, it can receive library information, lyrics, creation results and status, credit balances and costs, and access to requested media. Audiogrant receives the information supplied with those requests, not automatic access to the assistant’s entire conversation history.

Private media can be returned through authenticated access or temporary download links. Anyone holding a signed download link can use it while it remains valid, so treat it as private. The assistant service can download and retain a copy; link expiry does not delete an already downloaded copy.

The assistant service you choose also processes your messages, files and tool results under its own terms, privacy notice and account settings. Check its retention, model-training and processing-location practices before connecting or sharing sensitive material. Authorizing access is not a separate consent for Audiogrant to advertise with your private content or train a general-purpose model on it, and does not remove Audiogrant’s own data-protection duties.

Revoke a connected application or API key in Studio Settings → Integrations to block subsequent authenticated requests through it. Already accepted work may still finish and incur the agreed credit charges; previously issued signed download links may remain usable until expiry. Disconnecting does not delete your Audiogrant projects or copies, chat history or files already held by the assistant service. Request deletion from the service holding the information; Audiogrant privacy requests follow the procedure below.

  • Assistant permissions and credit approvals
  • Privacy requests

6. Cookies and browser storage

The public website sets a cookie only when you choose a language, to remember that choice. Studio uses cookies for sign-in and security and to remember language and layout preferences. Browser storage also remembers preferences such as the interface theme and temporary identifiers used to resume uploads or remember a checkout attempt.

You can manage cookies and site storage in your browser. Clearing browser storage does not cancel a subscription or payment, or erase records held by the service. Removing authentication cookies signs you out, and blocking required storage can prevent parts of Studio from working. Any additional analytics or advertising technologies need their own disclosures and, where required, consent before activation.

7. Retention and security

We retain account and saved project information, including Artists, Voices and songs, for the provision of your workspace and the purposes described in this policy. Cancelling a subscription or blocking an account does not erase those records. You can request erasure by email; the request is assessed separately under applicable law.

When you delete a song or album in Studio, it moves to Recently deleted and can be restored for the period shown before confirmation. An album deletion includes songs that belong only to that album; songs also used by another album or compilation stay available there. After the restore deadline, deleted media and active records are scheduled for purge. A restricted generation and deletion audit record is retained until the audit deadline set when you delete the content, then purged. Existing deadlines do not change if the policy changes later. Purge jobs may need retries if storage is unavailable; restoration is unavailable after the restore deadline.

You may schedule deletion of your own Studio account in Settings. Access ends immediately and signing in during the restore period shown before confirmation offers only account restore and sign-out choices. Restoring within that period returns the workspace, but does not restart a cancelled subscription. After the restore deadline, creative media and active workspace data are scheduled for purge. A restricted generation and deletion audit remains until the audit deadline set when you request deletion, then is purged; financial records and legally required records may follow longer retention rules. A privacy erasure request is assessed separately under applicable law and is not automatically delayed until that audit deadline.

Retention is limited by the purpose of each category. Technical records support troubleshooting; security records support abuse prevention and incident investigation; support correspondence supports resolving your request and any related claim. Only records needed for an ongoing incident, legal obligation or claim are retained for that reason, and unrelated personal information is not kept indefinitely. Error reports about failed Studio actions in your account are deleted after 90 days, and Studio notifications after 180 days.

Accounting books and supporting accounting records subject to Swiss law must generally be retained for ten years from the end of the relevant financial year. This obligation does not require retaining all creative files, voice recordings or project content for ten years.

Deleting active data and removing backup or provider copies are separate operations. Backup rotation, provider retention, legal holds and the scope of a request affect removal. Removal from backups and provider systems can therefore take longer than deleting active data; your applicable statutory rights and response deadlines remain in force. Where information must be retained, we explain the relevant categories, reason and period or criteria.

Authentication and access controls help protect Studio and its content. Please protect your credentials and avoid uploading sensitive personal information that your project does not need. No online service can guarantee absolute security.

8. Your choices and rights

Depending on the law that applies to you, you may have rights to access, correct, erase or receive a copy of your personal information, restrict or object to certain processing, and withdraw consent for processing based on consent. Withdrawal applies to future consent-based processing and does not undo processing that was lawful before withdrawal. These rights can have legal exceptions; withdrawing consent and cancelling a subscription are separate actions.

Send privacy requests or concerns to [email protected]. You do not need an account or a signed-in session to contact us. You may also raise a concern with the competent data protection authority.

State the right you want to exercise and the account or material concerned. We may ask for information to confirm your identity, limited to what is proportionate. We handle access, correction, erasure, objection and other requests within the applicable legal deadlines and exceptions.

An account block is not erasure. If particular information must be retained, our response explains the categories, reason and applicable period or criteria, and we handle the remainder of the request.

9. Changes to this policy

The date above identifies this policy’s latest revision. We will notify you of material changes by email or a notice in the service before new processing starts, and obtain consent where required. The notice will state when the change takes effect. Publishing a revised policy does not itself authorize a new use of your information or replace required consent.

Privacy Policy Terms and Conditions