Gigapop — Privacy Policy
Last updated: 25 July 2026
This policy explains what happens to personal information when you use Gigapop (https://gigapop.app) — the service that writes and records a personalised song from a short brief.
It is written to be read, not skimmed past. If something here is unclear, write to hi@gigapop.app and we will explain it in plain words.
If you are reading this because a song was written about you and you did not order it, go straight to Section 5. That section is written for you and you do not need an account to use anything in it.
At a glance
| Who is responsible | Ivan Smetanin, an individual entrepreneur based in Kazakhstan |
| Where your data is stored | Servers in Finland (Hetzner), inside the EU/EEA |
| Where it is sent to be processed | Your brief, and your recording if you dictate, are sent to AI providers outside the EU — including the United States and other third countries — to write and perform the song. Storage in Finland does not change that. See Section 8 |
| The most sensitive thing we hold | The brief you write — because it is usually about someone else |
| Your brief is screened automatically | Before a song is written, software reads the brief to check for sexual content and for material we must refuse outright. This affects which AI provider sees it, and some orders are refused automatically. See Section 11 |
| Voice recordings | Transcribed to text and discarded. We never save the audio file |
| AI training | We do not use your brief, recording or song to train AI models ourselves. being finalised — what our providers may do is governed by contracts that are not yet in place; see Section 4 |
| Advertising | We do not sell your data, and we do not do behavioural advertising |
| Your rights | Access, correct, delete, restrict, object, port, complain — free of charge |
| Complaints | You can complain to the data protection authority in your own country |
1. Who we are, and who to contact
Controller. The person who decides why and how your personal data is processed is:
IVAN SMETANIN, individual entrepreneur (sole trader — not a company) Kazakhstan Email: hi@gigapop.app
Gigapop is operated by one person. When you write to hi@gigapop.app, he reads it.
being finalised A full postal address must be published here. EU consumer law separately requires a geographical address, not only an email.
EU representative (Article 27 GDPR). Because we are established outside the EU but offer our service to people in the EU, we are required to designate a representative inside the EU. You can contact the representative about anything in this policy, in the same way and with the same effect as contacting us directly, and supervisory authorities can address them too.
⛔ NOT YET APPOINTED — THIS MUST BE COMPLETED BEFORE THIS POLICY IS PUBLISHED. The representative's name, postal address and email will appear here. Designating a representative is a legal requirement for this service, not an option, and naming them in this notice is part of that requirement.
Data Protection Officer. We have not appointed one. We do not believe our processing meets the conditions in Article 37 GDPR that would require one. If that changes, we will say so here and publish the contact details.
2. Why EU law applies to us
We are based in Kazakhstan and our servers are in Finland. Neither of those facts decides the question.
EU data protection law (the GDPR) applies to us because of Article 3(2)(a): we offer a service to people who are in the EU. Our prices are in euros, our audience is Russian-speaking people living in the EU, and we market the service to them. That means we have the same obligations as a company established inside the EU, and you have the same rights against us. We are not going to pretend otherwise.
Renting servers in Finland does not give us an establishment in the EU, and it does not change any of the above. It does mean your data physically sits inside the EU/EEA, which is genuinely good for you — see Section 9.
3. What we collect
3.1 What you give us
Your email address. To create your account, to send you your song, and so the receipt reaches you.
Your Telegram ID and username — only if you choose to sign in with Telegram. This is optional.
The brief. This is the free-text description you write when you order a song: who the song is for, the occasion, and the facts, stories, habits and inside jokes you want in it. Plus the options you pick (genre, length, occasion, voice).
This is the part that matters most. A Gigapop brief is almost never about the person writing it. It is usually about somebody else — the person having the birthday, the couple getting married, the colleague leaving. It typically contains that person's name, their age, what they do for a living, who they are related to, what they are like, and things that happened to them. That is personal data about a third party, and we take it seriously. Section 5 is written for those people.
Voice recordings. If you dictate your contribution instead of typing it, your browser records audio and sends it to us. See Section 6 for exactly what happens to it.
Jam contributions. In jam mode, a host creates a jam and guests join by scanning a QR code on their phones. Each guest adds a fact and votes on a genre. We store the guest's contribution text (or dictated transcript), their genre vote, and a browser cookie identifier so the guest can edit their own contribution and so we do not count them twice. Guests do not need an account.
Anything you send us by email, when you contact support.
A review, if you choose to leave one. A rating, free text, and — only if you fill it in — a name to sign it with. If you ask us to publish it, the text and that signature go on a public page of the site where anyone can read them. Publication is optional, it is never automatic, and we do not publish your email address or your order.
An application, if you apply to host jams for us. Your name, a short bio in your own words, and a contact of your choosing.
3.2 What we record automatically
A session / guest cookie (gb_guest). A random identifier stored in your browser for
90 days. It is what makes "your songs are yours" work: it keeps you signed in and links a
song, or a jam contribution, back to you. Without it, the service does not function.
Basic visit statistics. The page path you visited, the referring website's host name, how long the visit lasted, and whether you were on a mobile device. If you are signed in, the record is linked to your account as well as to the cookie. This is our own first-party counter — there is no Google Analytics, no advertising pixel and no cross-site tracking anywhere on Gigapop.
An operational log. When something breaks, when an order is paid, or when a new account is created, we record it so we can run the service and fix faults. These entries can contain your email address, an order number and the details of what was being generated at the time. They are also pushed to the operator as an alert — see Section 8, because that alerting runs over Telegram.
Your IP address, processed at the web-server level in ordinary access logs, and used for rate limiting and abuse prevention.
being finalised In its current form the visit counter reuses the same gb_guest cookie as the
sign-in function and runs before any consent is collected. This has to change before
launch — see the separate Cookie Policy and Section 16.
3.3 What we create
The lyrics we write for you, the audio track, the cover art, the preview, and the karaoke video. These are derived from your brief, so they contain the same personal information your brief did — set to music.
3.4 What we do not collect
We do not require your own name to open an account, and we never ask for your address, your date of birth, or any government identifier. We never see your card number — payment happens on Dodo Payments' own checkout (see Section 8). We do not run behavioural advertising, we do not build advertising profiles, and we do not sell personal data to anyone.
To be exact rather than flattering about this: names do reach us, just not as an account field. The brief normally contains the name of the person the song is for. A review carries whatever signature you choose to give it. A host application carries the applicant's name. All three are things you type in, and none of them is required to buy a song.
4. What we do with it, and on what legal basis
Under Article 13(1)(c) GDPR we have to tell you the legal basis for each purpose separately, not as a general list. Here it is.
| # | What we do | Data used | Legal basis (Art. 6 GDPR) | How long we keep it |
|---|---|---|---|---|
| 1 | Create and run your account; keep you signed in; show you your songs | Email, Telegram ID (if used), session/guest cookie | 6(1)(b) — performance of our contract with you | Life of the account, then deleted — see §12 |
| 2 | Write and record the song you asked for: preview, full track, cover, karaoke video | Brief text, voice transcript, chosen options | 6(1)(b) — performance of the contract. Without the brief there is no song | See §12 |
| 3 | Run a jam and generate the collective song | Guest contributions, genre votes, guest cookie | 6(1)(b) — you asked to take part in the jam | See §12 |
| 4 | Take payment, unlock the full track, and get you a receipt | Email, order reference, payment status returned by Dodo Payments | 6(1)(b) — performance of the contract | See §12 |
| 5 | Handle the personal data about other people that appears in briefs | Names, ages, jobs, relationships, anecdotes and other facts about the person the song is about | 6(1)(f) — legitimate interests. See §5 for the full explanation, including what those interests are | See §12 |
| 5a | Screen the brief automatically before writing anything — check it for sexual content, decide which AI provider it goes to, and refuse outright the small number of briefs that describe things we will not set to music (see §11) | The whole brief text | 6(1)(b) — we cannot deliver a lawful song without it, and it is part of what you asked for — combined with 6(1)(f) as regards the person the song is about: our legitimate interest, and the wider public interest, in not generating sexual content about minors or about people described as not consenting | The class assigned is stored with the order — see §12 |
| 6 | Keep the service working and stop abuse: rate limits, blocking scripted abuse of paid AI capacity | IP address, guest cookie, request timestamps | 6(1)(f) — our legitimate interest in not having our paid AI capacity drained by automated abuse, and in keeping the service available for everyone else | Logs: 14 days — see §12 |
| 6a | Run and fix the service: an operational log of errors, sign-ups and payments, pushed to the operator as an alert so faults get noticed | Email address, order number, what was being generated, error details | 6(1)(f) — our legitimate interest in noticing and fixing faults quickly. The alerting runs over Telegram, which is a disclosure to a third country — §8 | 12 months |
| 7 | Understand which pages people use, so we can fix the ones that do not work | Page path, referrer host, visit duration, mobile/desktop, guest cookie | 6(1)(a) — your consent, collected through the cookie banner. This is not covered by "performance of the contract" | Raw records 6 months, then aggregate counts only |
| 8 | Answer your emails and support requests | Your email address and whatever you write to us | 6(1)(b) where it concerns your order; otherwise 6(1)(f) — our legitimate interest in answering people who contact us | 24 months |
| 9 | Keep records of transactions, to reconcile with our payment provider and to defend or bring legal claims | Order reference, amount, date, email | 6(1)(f) — our legitimate interest in having provable financial records, in reconciling against the merchant of record, and in defending claims. Kazakh accounting law also drives this, and we describe it honestly as an interest rather than dressing it up as an EU legal obligation | 5 years from the transaction |
| 10 | Comply with data protection law itself — for example, keeping a record that you asked us to delete something, so we do not restore it from a backup | Minimal request log | 6(1)(c) — a legal obligation under EU law (the GDPR) | 3 years |
| 11 | Send you occasional emails about Gigapop, if you asked for them | Email address | 6(1)(a) — your consent | Until you unsubscribe |
| 12 | Publish your review on the site, if you ask us to | The review text and the signature you chose | 6(1)(a) — your consent, given separately when you submit the review. You can withdraw it and we take the review down | Until you withdraw consent — see §12 |
| 13 | Assess an application to become a Gigapop host | Name, bio, contact | 6(1)(b) — steps taken at your request before entering a contract | 12 months from the decision |
What we do not do, and will not do quietly:
- We do not train AI models on your data. Your brief, your voice recording, your transcript and your finished song are not used by us to train or fine-tune any AI model, and we will not start without asking you first and getting your consent; "performance of the contract" would not cover it, and we are not going to pretend it does. being finalised — we will not claim more than we can currently deliver. Whether the AI providers in Section 8 may use your brief for their own training is a matter of the contracts we hold with them, and those contracts are not yet in place. We are not going to state a guarantee we cannot presently enforce. This line will say either "and our providers are contractually barred from doing so" or something more limited, once the agreements are signed — and it will be accurate either way.
- We do not use your data for behavioural advertising or lookalike targeting.
- We do not share your brief or your song with anyone except the recipients listed in Section 8. That section is the complete list, and it includes the ones that are unglamorous — our email sender, our hosting, and the messenger our fault alerts run over — not only the ones that make the music.
Where we rely on legitimate interests (rows 5, 5a, 6, 6a, 8 and 9 above), we have weighed our interest against your rights and interests. You can object to any of it — see Section 14. If you object, we stop unless we can show compelling grounds that override your interests, or we need the data to establish or defend legal claims. One honest caveat on row 5a: if you object to the automatic screening of a brief, we cannot simply switch it off and write the song anyway — we would stop processing the brief altogether, which means no song.
5. If a song was written about you
This section is for people who never used Gigapop but whose name came up in someone else's brief. It is Article 14 GDPR information, and it is deliberately on a public page so you can read it without an account, without signing in, and without asking anyone's permission.
What happened
Someone — usually a friend, partner, relative or colleague of yours — ordered a personalised song as a gift and, to make the song about you, wrote facts about you into the brief. That brief came to us.
We are a controller of that information, and everything in this section is owed to you by us. Where the person who wrote the brief did so in a purely personal or household capacity — a friend ordering a birthday song — data protection law does not impose duties on them personally, so in practice we are the only one you need to deal with. That is not automatic, though: if the order came from an employer, a professional host, or anyone acting in a business capacity, they carry duties to you too. Either way, you do not have to work out which case you are in before contacting us. Come to us and we will deal with it.
We did not find you in a public database, and we do not buy data. The only source is the person who ordered the song. We have not collected your data from any publicly accessible source.
What categories of information about you we may hold
Whatever the person chose to write, which in practice is usually some of:
- your first name or nickname, sometimes your surname
- your age or birthday, and the occasion being celebrated
- what you do for a living, where you study or work
- your relationships — who you are married to, related to, friends with
- your hobbies, habits, catchphrases, quirks
- stories and inside jokes about things that happened to you
- occasionally, if the person volunteered it, more sensitive things: your health, your beliefs, your relationship or personal life. We ask users not to write this and we do not want it — see Section 7.
And whatever we then produced from it: lyrics, an audio track, cover art and a karaoke video that mention you.
Why we process it, and our legal basis
Legal basis: Article 6(1)(f) — legitimate interests. We cannot use "performance of a contract", because we have no contract with you. And the person who ordered the song cannot consent on your behalf — only you can consent to the use of your own data. We are not going to claim otherwise.
The specific interests we are pursuing are:
- Delivering the gift our user asked for. A personalised song is only possible if the details of the person it is for can be used to write it.
- Our user's own interest in being able to make a personal gift for someone they care about — which is the ordinary, socially expected way people give gifts.
- Refusing to make some of them. Every brief is screened before a song is written, and some are rejected outright — see Section 11. That screening is done partly for the benefit of the person the song is about, which may well be you.
We have weighed this against your interests, and we will describe the result plainly rather than favourably.
What is in your favour. The processing is narrow and of a kind you would expect from a gift: someone who knows you well described you, warmly, in order to have a song made for you. We do not build a profile of you, we do not enrich the data from other sources, we do not use it for advertising, we do not sell it, and we do not use it to train AI models.
What is not, and you should know it.
- It is not brief. The brief about you is kept for 12 months, and the finished song — which contains your name and your story — is kept for as long as the buyer's account exists. See Section 12. We are not going to call that short-lived.
- It leaves the EU. To write and perform the song, the text about you is sent to AI providers outside the EU. See Sections 8 and 9.
- Software reads it. The brief is automatically screened, including for sexual content, before anything is generated. See Section 11.
- You did not choose any of this, and someone else did. That is exactly why the right to object below is unconditional in practice: we do not make you argue.
What we do to limit it. We do not create an account for you, we do not build a profile of you, we do not look you up anywhere, and we do not keep any identifier for you separate from the brief and the song themselves. We could hold less than we do — for example by deleting briefs the moment the song is finished — and we have set the periods in Section 12 to the shortest that still lets us regenerate a song a buyer paid for.
Your rights, without needing an account
You have the same rights as anyone else, and you can use them by emailing hi@gigapop.app — or the EU representative named in Section 1. No account, no sign-up, no fee.
In particular:
- You can object (Article 21). Because we rely on legitimate interests, you can object at any time on grounds relating to your situation. If you object, we will stop unless we can demonstrate compelling legitimate grounds that override your rights, or we need it for legal claims. In practice: if you tell us you do not want a song about you, we will take it down.
- You can ask us to delete it (Article 17).
- You can ask what we hold (Article 15), and get a copy.
- You can ask us to correct it (Article 16) if it is wrong.
- You can complain to your national data protection authority — see Section 15.
To help us find the right record quickly, it helps if you tell us roughly who ordered the song and when, or send us the link to the song. If you do not know, tell us your name and the occasion and we will search.
Why we did not write to you directly
Article 14 normally requires us to contact you within a month of receiving your data. We usually cannot, because we have no way to reach you: the brief gives us your first name and some facts, not your email or phone number. We rely on Article 14(5)(b) — the effort would be disproportionate, and that difficulty comes directly from the fact that we got the data from someone else rather than from you. We have carried out and documented a balancing exercise for this.
Because we rely on that exemption, we are required to take protective measures instead, and we do:
- We publish this notice openly, on a page that anyone can reach without an account. This is the measure the law says must always be taken.
- We minimise. We do not create accounts or persistent identifiers for people who are not users, we do not build profiles of them, and we do not enrich the data from other sources. What we do hold about you is whatever the brief says and whatever the song says — nothing we went and found.
- We limit retention — see Section 12.
- We require our users to confirm in the Terms that they have the right to use the information they submit. That is a promise between us and them; it does not reduce what we owe you, and we do not treat it as if it did.
If we ever do get a way to contact you — for example because a user asks us to send the song to your email — we will give you this information in or with that first message, as Article 14(3)(b) requires.
6. Voice recordings and speech-to-text
You can dictate your brief or your jam contribution instead of typing it. Here is exactly what happens.
What we do. Your browser records audio and sends it to our server in Finland. We hold it in memory, pass it to a speech-to-text provider, get back the text, and discard the audio. The recording is never written to disk on our servers, never stored in our database, and never attached to your account. We keep the transcript, because the transcript is your brief — it is the thing the song gets written from.
That asymmetry is deliberate and you should know about it: the audio is gone within seconds; the text survives for as long as your brief does (see Section 12).
Who processes the audio. The audio goes to our speech-to-text provider(s) — see Section 8. They receive the raw recording. being finalised Each provider's own retention and no-training terms must be confirmed and stated here before publication.
We do not analyse your voice — but the words are treated exactly like typed ones. Once your recording has become a transcript, that transcript is your brief, which means it goes through the same automatic screening as anything typed in. See Section 11. Dictating is not a way around it and we are not going to imply that it is.
We use speech recognition only to turn what you said into words. We do not:
- create a voiceprint or voice template
- try to identify or verify who is speaking
- match your voice against other recordings, or use it for sign-in or anti-abuse
- infer your age, gender, mood, health or origin from how you sound
Is this "biometric data"? No — and we want to explain why rather than just assert it. Under the GDPR, voice becomes special-category biometric data when it is processed by specific technical means for the purpose of uniquely identifying a person. Plain transcription does not do that: no template is extracted and the purpose is to capture words, not to work out who said them. So Article 9 does not apply to the transcription itself.
If that ever changes, this section changes with it. If we ever add voice sign-in, speaker enrolment, or voice matching, we would be processing special-category biometric data from the moment of collection, we would need your explicit consent, and we would say so here first. We have no plans to.
Other people's voices. If you dictate at a party, other people may be audible in the recording. They are not our users and have not agreed to anything. We do not analyse anyone's voice, and the audio is discarded — but please point the microphone at yourself.
You never have to dictate. Typing is always available and gives you exactly the same result.
7. Sensitive information
Please do not put sensitive personal information into a brief — yours or, especially, anybody else's. That means information about health or medical history, religious or philosophical beliefs, political opinions, trade union membership, racial or ethnic origin, sex life or sexual orientation, or criminal offences.
We know people sometimes will anyway: a song about someone's recovery, or their faith, or their partner, is a natural thing to want. So here is our position, including the part that does not flatter us:
- We do not look for health, beliefs, politics, union membership or ethnicity, and we do not use them. Nothing in Gigapop analyses a brief, a recording or a transcript to work out someone's medical history, religion, politics or origin. If those things are in a brief, they are simply words the lyric model reads along with everything else.
- There is one exception, and we would rather state it than have you discover it. Every brief is automatically screened for sexual content before a song is written — because we will not generate sexual material about children, or about people described as not consenting, and because briefs written in explicit terms are handled differently from briefs that are not. That screening necessarily forms a view about what the brief says regarding somebody's sex life, and that view is recorded against the order. Section 11 explains how it works and what it does. It is the only inference of this kind the service makes, we would rather not have to make it, and it exists to prevent a specific harm rather than to learn anything about you.
- We are on thin ice with third-party sensitive data, and we know it. The person ordering the song cannot give consent on somebody else's behalf, and consent is the route the law mostly expects for this category. Where such data appears in a brief anyway, we do not seek it, do not use it beyond writing the song you asked for, and delete it on request. That is a mitigation, not a licence — which is why the request at the top of this section is a real request and not boilerplate. Please leave it out.
- Criminal offence data is worse still. There is no consent route available to a private operator like us. Do not include it.
- If you tell us there is sensitive information in a song about you, we will delete it. Email hi@gigapop.app. You do not need to explain yourself and we will not ask you to justify it.
8. Who else receives your data
We use a small number of providers to run the service. Below is each one, what it actually receives, its role, where it is, and the basis on which data reaches it.
"Processor" means they act only on our instructions. "Independent controller" means they decide things for themselves and have their own privacy policy that also applies to you.
| Recipient | What it receives | Role | Where | Adequacy? | Transfer basis |
|---|---|---|---|---|---|
| Hetzner Online GmbH | Everything — this is where Gigapop runs and stores data | Processor | Finland (EU/EEA) | Not needed | No transfer — data stays in the EEA |
| Dodo Payments — merchant of record | Your email and billing details, order reference, payment status | Independent controller for the sale, and seller of record. It — not us — is the party you buy from, it collects and remits EU VAT and issues your invoice | Outside the EEA — being finalised exact entity and country to be confirmed from the merchant agreement | No | Most billing data you enter directly on Dodo's own checkout, so it is collected by Dodo from you, not exported by us. For the limited data we pass (order reference, email): controller-to-controller Standard Contractual Clauses under Dodo's DPA — being finalised to be confirmed and executed |
| Resend — email delivery | Your email address, and the contents of every email we send you: your sign-in code, the link to your finished song, the song's title | Processor | United States | being finalised to be verified | Standard Contractual Clauses — being finalised to be executed |
| APIYI — AI request aggregator. This is the single biggest recipient of your brief. It is a reseller: we send it the request, and it passes it on to whichever AI model is configured | Your brief text — including the information about the person the song is for. Your voice recording, when it handles speech-to-text | Processor | Third country — being finalised entity and country to be confirmed. The service is reached at api.apiyi.com and its upstream errors come back in Chinese, so please assume the answer is not a country with an adequacy decision until it is verified |
No | ⚠️ being finalised — no data processing agreement and no transfer mechanism is currently in place with this provider. This must be resolved, or this provider must be switched off for the EU service, before launch |
| The AI models reached through APIYI — currently DeepSeek (the default lyric writer), Anthropic's Claude (short utility calls, brief screening, and lyrics when the premium tier is on), and xAI's Grok (only for briefs the screening classifies as sexually explicit — see §11) | Your brief text | Sub-processors, reached through APIYI rather than contracted by us directly | Various, all outside the EEA — being finalised | No | Whatever APIYI's own terms provide. We do not currently hold a direct agreement with any of them, which is part of why the APIYI position above must be fixed |
| KIE.ai / Suno — music generation, karaoke and jam video | The finished lyrics and the style prompt | Processor | Outside the EEA — being finalised entity and country to be confirmed. being finalised the code contains both a KIE.ai route and a direct Suno route; confirm which is live for the EU service, because they may be two separate relationships | No | Art. 46(2)(c) Standard Contractual Clauses (controller-to-processor), plus a transfer impact assessment — being finalised to be executed |
| Groq — speech-to-text (primary) | Your voice recording | Processor | United States | being finalised | Standard Contractual Clauses — being finalised to be executed. This provider was identified from the running code and its terms have not yet been reviewed |
| Cloudflare — cover art generation (primary) | A short image prompt derived from the song's theme | Processor | United States | being finalised | Standard Contractual Clauses — being finalised to be executed. When Cloudflare is unavailable the same prompt goes to APIYI instead |
| Google LLC — web fonts | Your IP address and browser user-agent, on nearly every page, because the fonts are loaded from Google's servers rather than ours. No cookie is set and nothing about your song is involved | Independent controller | United States | being finalised | being finalised — we intend to host these fonts ourselves, which removes this disclosure entirely. Until we do, see the Cookie Policy |
| Telegram | Two separate things. (1) If you choose Telegram sign-in: your Telegram ID and username, plus message content if you use a Gigapop bot. (2) Whether or not you use Telegram at all: our fault and operational alerts are delivered to the operator over Telegram, and those alerts can contain your email address, your order number, and — when a song fails to generate — the name of the person the song is for, the occasion and the genre | Independent controller for its own platform | United Arab Emirates | No | For (1), you choose to connect Telegram and its own privacy policy governs what it does; it is optional and you never have to use it. For (2) you have no choice, and we are not going to describe it as optional. being finalised — this alerting should be moved off Telegram, or a transfer mechanism found for it, before launch |
We may also disclose data where we are legally required to, or to establish, exercise or defend legal claims. We do not routinely give data to anyone else.
A note about demands from authorities outside the EU. If an authority in Kazakhstan or any other non-EU country demands your data, EU law (Article 48 GDPR) says a judgment or decision from a third-country authority is not by itself a basis for us to hand data over — that has to come through an international agreement such as a mutual legal assistance treaty.
Our commitment, stated at the level we can actually keep it: we will not disclose EU users' data to a third-country authority voluntarily; we will require the request to be put through a lawful route; we will challenge it where there are grounds; and we will tell you unless we are legally barred from doing so. What we will not do is promise you an absolute refusal in every case. The operator is an individual in Kazakhstan and is subject to Kazakh law in person, and a promise that ignores that would be worth nothing to you at the moment you needed it.
Changes to this list. If we add or replace a provider that handles your brief, your recording or your song, we will update this section before the change takes effect.
9. International transfers
We are going to be precise about this, because it is easy to get wrong in both directions.
You sending us your data is not an "international transfer". When you type a brief into Gigapop, you are giving your data directly to us. There is no EU-based exporter passing it on. Under the EDPB's criteria, Chapter V of the GDPR simply does not apply to that step, and you should be suspicious of any policy that claims Standard Contractual Clauses cover it. What matters instead is that we are directly bound by the GDPR for that processing — which we are, and which is why this policy exists.
Where your data physically lives is the EU. Gigapop runs on servers in Finland. Your account, your brief, your song and your files are stored inside the EU/EEA.
We do administer those servers from Kazakhstan. That means the operator can access data held in Finland from outside the EU. That is not a disclosure to a different organisation, so it is not a Chapter V transfer — but you should know it happens.
Our onward disclosures to providers outside the EEA are transfers, and they need a legal mechanism. Being based outside the EU ourselves does not exempt us: what counts is where the recipient sits.
Kazakhstan has no adequacy decision, and neither do several of our providers' countries. An "adequacy decision" is the European Commission's finding that a country protects personal data well enough for it to flow there freely. The Commission keeps the authoritative, current list itself, and we would rather send you to it than reprint a snapshot here that quietly goes out of date: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en
The one entry that matters for us is the United States, and only partially: transfers there are covered by adequacy only where the receiving organisation is certified under the EU–US Data Privacy Framework. Certification is per-company and can be withdrawn, so it has to be checked for each provider rather than assumed — see the table in Section 8, where it is still marked open.
So for each non-EEA recipient we rely on either an adequacy decision where one genuinely applies, or Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), backed by an assessment of whether the destination country's laws actually let those clauses work. The per-recipient position is in the table in Section 8.
We do not rely on the Article 49 exceptions for our provider arrangements. Those exceptions are for genuinely occasional transfers, and our provider relationships are regular and structural. Using them here would be a misuse of the law.
You can get a copy of the safeguards. Email hi@gigapop.app and we will send you a copy of the relevant Standard Contractual Clauses, with commercial terms redacted.
10. Do you have to give us this data?
Article 13(2)(e) requires us to say so plainly:
| Data | Required? | What happens if you do not give it |
|---|---|---|
| Email address | Yes — a contractual requirement | We cannot create your account, deliver your song, or get you a receipt. There is no way to buy a song without it |
| The brief | Yes — a contractual requirement | There is no song without a brief. A blank brief means nothing to write about |
| Payment details | Yes, to buy — but you give these to Dodo Payments, not to us | Without payment you can still generate and listen to a free preview; you just cannot unlock the full track or the karaoke video |
| Voice recording | No — entirely optional | Nothing. Type instead; the result is identical |
| Telegram sign-in | No — optional | Nothing. Use email sign-in instead |
| Analytics cookie | No — optional | Nothing at all. The service works exactly the same if you refuse |
| A review, and a name to sign it with | No — optional, and publishing it is a separate choice again | Nothing. You keep everything you bought |
There is no statutory requirement anywhere in this list. Nobody is obliging you to use Gigapop.
One thing that is not on the list because it is not a choice: the brief you submit is screened automatically before a song is written, and a small number of briefs are refused on that basis. You cannot opt out of the screening and still get a song. See Section 11.
11. Automated decisions and AI
Gigapop is built on AI, and that is the point — an AI model writes the lyrics from your brief and another one performs them. That is automated processing, and it is what you asked us to do.
We do not score you, profile you, price differently for different people, or automatically decide anything about your rights. We do not believe anything below reaches the threshold in Article 22 GDPR of a decision producing legal effects concerning you or similarly significantly affecting you. But we are not going to hide behind that assessment, so here is everything automated that happens, described plainly.
Screening of the brief — read this one
Before any song is written, software reads your brief. It happens on every order, automatically, with no person involved. It does two things:
- It classifies how explicit the brief is. Briefs written in frank sexual terms are sent to a different AI model from everything else, because models differ in how they handle that. The classification is recorded against your order.
- It refuses some orders outright. Where the screening finds sexual content involving children, or involving someone described as not consenting, or incest or bestiality, the order is rejected before anything is generated. This is deliberately cautious: it is set to refuse when in doubt, which means it will occasionally refuse something innocent.
Two consequences you are entitled to know about. First, this necessarily means software forms a view about what your brief says regarding somebody's sex life — see Section 7. Second, it means which company outside the EU receives your brief depends on that view — see Section 8.
If your order is refused and you think that is wrong, email hi@gigapop.app. A person will look at it, you can explain, and the decision can be changed. You are not stuck with what the software decided. being finalised — the refusal message shown in the product must tell people this, and must say what happens to any payment; it does not yet.
The other two
- Rate limiting and abuse protection. If a very large number of requests comes from one address in a short window, our system will temporarily refuse further requests. It looks at request counts, not at who you are. If you think you have been blocked unfairly, email hi@gigapop.app and a human will look at it.
- Automatic safety fallbacks. If a provider is failing, features such as dictation can switch themselves off for everyone until it recovers. This is not a decision about you.
The lyrics are machine-written. They are generated from what you wrote, and an AI can get things wrong, misread a fact, or produce something that does not land. You always hear a free preview before you pay. Separate EU rules on labelling AI-generated content apply to the tracks themselves; we cover those in our Terms.
12. How long we keep things
We set actual time limits rather than saying "as long as necessary".
| What | How long | Why |
|---|---|---|
| Account data (email, Telegram ID) | For as long as your account exists, then 30 days after you close it or ask us to delete it | Short grace period in case the request was a mistake |
| Brief text (including facts about other people) | 12 months from when the song is generated, then deleted — the song itself stays | The brief is only needed to write and, if necessary, re-generate the song. Keeping it longer serves nobody |
| Brief and preview for songs that were never paid for | 90 days | If the preview was not bought, there is no reason to hold the material |
| Voice recordings (audio) | Not stored. Held in memory during transcription and discarded immediately | We only need the words |
| Transcripts of dictated contributions | Same as the brief they became part of | The transcript is the brief |
| Generated lyrics, audio track, cover art, karaoke video (paid songs) | For as long as your account exists, then 30 days | You bought it; you should be able to get it again |
| Jam guest contributions, votes and guest identifiers | 90 days after the jam ends | Long enough for the host to share the song; not longer |
| The screening class recorded against an order (see §11) | Deleted with the brief — 12 months | It is only meaningful alongside the brief it describes |
| Order records (reference, amount, date, email) | 5 years from the transaction | Financial records, reconciliation with the merchant of record, and legal claims |
| Operational log entries and fault alerts (email, order number, error details, and for failed songs the name/occasion/genre) | 12 months | Long enough to investigate a recurring fault, not longer. Copies already delivered as Telegram alerts are outside our control once sent — see §8 |
| A published review, and the signature on it | Until you withdraw consent or ask us to take it down, and then removed from the site straight away | It is published because you asked us to publish it |
| Host applications that were not accepted | 12 months from the decision | So we can explain a decision if you ask, and recognise a repeat application |
| Web-server access logs, including IP addresses | 14 days | Security and troubleshooting only |
| Raw visit records (page, referrer, duration) | 6 months, then reduced to aggregate counts with no identifiers | We only need trends, not individuals |
| Support emails | 24 months | So we have context if you write again |
| Marketing consent and unsubscribes | Until you unsubscribe; we keep a minimal record of the unsubscribe indefinitely | So we do not email you again by accident |
| Record that you exercised a data protection right | 3 years | To show we complied, and to stop a backup restore undoing your deletion |
Backups. We keep encrypted backups on a rolling cycle. When something is deleted from the live service it is gone from the live service straight away, and it is purged from backups within 30 days as the backup cycle rotates. We do not restore deleted data from a backup.
being finalised These periods are what we intend to commit to. They must be implemented in the product — with an actual deletion job — before this policy goes live, and the backup encryption and rotation described here must be verified.
13. How we protect it
We are a small operation and we would rather describe our security honestly than list impressive words.
- Everything travels over HTTPS/TLS. Nothing is sent in the clear.
- Data is stored in the EU/EEA, on servers in Finland.
- Access is limited to the operator. There is no support team browsing your briefs.
- We never store voice recordings, so there is no archive of audio to leak.
- We never see or store card data. It goes to Dodo Payments directly.
- Rate limiting and abuse protection guard the service against automated attack.
- Secrets and API keys are kept out of the codebase and out of version control.
- Data minimisation by design — we do not ask for a name, an address or an ID document, because we do not need them.
- Backups are kept encrypted and are rotated. being finalised to be verified.
Two things we will not dress up: the operator receives fault alerts containing user data over a third-party messenger (see Section 8), and there is one person with access to everything, which is a concentration of both trust and risk.
No system is perfectly secure. If a breach happens that is likely to result in a risk to your rights, we will notify the supervisory authorities within 72 hours as Article 33 requires — plural, because we have no EU establishment and therefore no single "lead" authority, so a breach affecting users in several countries is notified to each concerned authority rather than to one on everyone's behalf (see Section 15). We will tell you directly if the risk to you is high.
14. Your rights
These rights are yours under the GDPR. Using them is free, and you do not need a reason for most of them. Email hi@gigapop.app — or the EU representative in Section 1, whichever you prefer.
- Access (Article 15) — ask what we hold about you and get a copy.
- Rectification (Article 16) — have anything inaccurate corrected or completed.
- Erasure (Article 17) — "the right to be forgotten". Ask us to delete your data. We will, unless we still need it for a specific reason we will explain to you.
- Restriction (Article 18) — have us pause processing while something is being checked, for example while we look into whether data is accurate.
- Portability (Article 20) — where processing is based on your consent or on our contract with you and is automated, get the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another provider where technically feasible. For Gigapop this covers your account details, your briefs and your transcripts.
- Objection (Article 21) — object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (rows 5, 5a, 6, 6a, 8 and 9 in Section 4). If we ever send you direct marketing, your right to object to that is absolute — say the word and we stop, with no balancing and no questions.
- Withdraw consent (Article 7(3)) — where we rely on your consent (analytics cookies, marketing emails, and publishing a review you submitted), you can withdraw it at any time, and withdrawing must be as easy as giving it. Withdrawing does not make what we did before unlawful; it just stops us going forward. For a published review, withdrawal means we take it off the site.
- Automated decisions (Article 22) — we do not make decisions of that kind about you (see Section 11), but if that ever changed you would have the right to human intervention, to express your view, and to contest the decision.
- Notification (Article 19) — if you have data corrected, deleted or restricted, we will tell each provider we shared it with, unless that proves impossible or involves disproportionate effort. We will tell you who they were if you ask.
How fast we respond. Without undue delay, and in any event within one month of your request. If the request is genuinely complex, or you have made several, we can extend by up to two further months — and if we do, we will tell you within the first month and explain why. If we decide not to act on your request, we will tell you within one month, say why, and tell you that you can complain to a supervisory authority and go to court.
No charge. We do not charge for any of this. The only exception the law allows is a request that is manifestly unfounded or excessive — and if we ever claimed that, the burden of proving it would be on us.
Identity. We may need to check you are who you say you are before handing over personal data — but we will not use that as a way to demand more information from you than we need.
If you are not one of our users, all of these rights are still yours — see Section 5.
15. Complaints and legal remedies
Come to us first if you can. Email hi@gigapop.app. We would much rather fix it.
But you never have to. You have the right under Article 77 GDPR to lodge a complaint with a supervisory authority — in particular in the Member State where you habitually live, where you work, or where you think the infringement happened. You do not need our permission and you do not need to contact us first.
We are not going to nominate an authority for you, because it is your choice and because a controller with no EU establishment has no "lead authority" and no one-stop-shop — any concerned authority can act. You can find your national authority through the European Data Protection Board's list of members: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
You also have the right under Article 79 to an effective judicial remedy against us, including before the courts of the Member State where you habitually live.
16. Cookies and similar technologies
Gigapop uses a small amount of browser storage. Full detail is in our separate Cookie Policy; in summary:
- Strictly necessary — the
gb_guestsession/guest cookie and the sign-in session. These are what keep you signed in and make your songs and jam contributions yours. They do not need consent, because the service literally cannot work without them. - Analytics — our own first-party visit counter. This needs your consent and is off until you give it. It is not a tracker: it is first-party only, it does not follow you across other sites, and it is not shared with any advertising network.
There is no advertising, no retargeting pixel and no third-party tracker anywhere on Gigapop.
Two pieces of third-party content are loaded by our pages, and although neither is a tracker and neither sets a cookie, both mean your browser contacts someone else's server and therefore discloses your IP address to them. We would rather list them than let "no third-party tracker" do work it should not do:
- Web fonts from Google, on nearly every page. We intend to host these ourselves, which removes the disclosure completely.
- Telegram's mini-app script, on the
/play/mini-game page only, so the game works when it is opened inside Telegram.
The Cookie Policy covers both in more detail.
You can change your mind at any time through the cookie settings control on the site, and refusing costs you nothing — the service works identically.
being finalised The consent banner in production today is notice-only, and the analytics counter runs before any choice is made. This must be corrected before this policy is accurate.
17. Children
Gigapop is not intended for children. You must be at least 16 to create an account and buy a song.
Two different rules sit behind that, and we would rather set them out than blur them:
- Buying is a contract. Whether a person under 18 can enter one, and on what terms, is decided by the national law of the country they live in, not by us. Our own rule is a flat 16.
- Where we rely on your consent — analytics cookies, marketing emails, publishing a review — data protection law sets a separate age for a child to consent by themselves, which each EU country fixes somewhere between 13 and 16. Below that age a parent or guardian has to authorise it. Our 16 rule is at the top of that range, so meeting it means the consent question does not arise.
Jams happen at parties, and children may be present and may join by QR code. We do not knowingly collect personal data from a child without the consent of a parent or guardian. If you believe a child's data has reached us, email hi@gigapop.app and we will delete it.
being finalised No age check exists in the product today.
18. Changes to this policy
If we change how we handle your data, we will update this page and change the "Last updated" date. If the change is significant — a new category of data, a new purpose, a new provider handling your brief — we will tell you directly before it takes effect, by email where we have one.
19. Contact
| hi@gigapop.app | |
| Controller | IVAN SMETANIN, individual entrepreneur, Kazakhstan |
| EU representative | ⛔ To be appointed — see Section 1 |
| Payments | Dodo Payments is the merchant of record and the seller for your purchase. For invoices, VAT and payment disputes, see our Terms |
If you write to us about a data protection matter, say so in the subject line and we will treat it as a formal request.