Legal

PRIVACY POLICY

Last updated: March 2026. This policy explains how AI MUSIC PROMPT ARCHITECT collects, uses, and protects your personal data.

1. Controller

The data controller is Armando Brecciaroli, operating under the artist/brand name Obiriec, based in Rome, Italy. For privacy-related enquiries: privacy@obiriec.com

2. Data We Collect

Account data: Email address, name, hashed password (bcrypt). We do not store plaintext passwords.

Billing data: Subscription plan and billing status. Payment details are processed exclusively by Stripe and are never stored on our servers.

Usage data: Anonymized generation counts, active tab, session timestamps. We do not store the content of your prompts, lyrics, or generated output.

Images: Images uploaded to Image Analysis are converted to base64 and sent directly to the Anthropic API. They are not stored on our servers.

Cookies: Session cookies for authentication. See our Cookie Policy.

3. How We Use Your Data

To provide and improve the service · To process subscription payments via Stripe · To send essential service communications · To analyze aggregate anonymized usage patterns · We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Third-Party Services

Anthropic API: All AI generation calls are sent to Anthropic's API. Your prompts may be processed by Anthropic subject to their Privacy Policy.

Stripe: Payment processing. Subject to Stripe's Privacy Policy.

Render.com: Hosting provider. Infrastructure-level data processing subject to Render's privacy terms.

5. Data Retention

Account data is retained for the duration of your subscription plus 30 days after cancellation, after which it is permanently deleted. You may request immediate deletion at any time by contacting us.

6. Your Rights (GDPR)

As an EU resident you have the right to: access your data · request correction or deletion · object to processing · request portability · withdraw consent at any time. Contact privacy@obiriec.com to exercise any of these rights.

7. Security

Passwords are hashed with bcrypt. All data transmission uses HTTPS/TLS. API keys are stored as environment variables and never exposed in client-side code or logs.

8. Contact

For any privacy questions or data requests: privacy@obiriec.com