Privacy Policy

Last Updated: November 15, 2025

1. Introduction

Welcome to Plonkify ("we," "our," or "us"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at plonkify.com (the "Service").

2. Data Controller

Plonkify
Fuutu UG (haftungsbeschränkt)
Jaegersstr. 15
41462 Neuss
Germany
Email: privacy@plonkify.com
Phone: +49 1556 3300477

3. Information We Collect

3.1 Personal Information

  • Account Information: Name, email address, username, password (encrypted)
  • Profile Information: Profile picture, bio, preferences
  • Payment Information: Processed securely through our payment provider (we do not store full credit card details)
  • Usage Data: IP address, browser type, device information, pages visited, time spent

3.2 AI-Generated Content

  • Track Generation Data: Prompts, lyrics, style descriptions you provide
  • Generated Tracks: Audio files, metadata, cover images
  • User Uploads: Tracks you upload (if applicable)

3.3 Automatically Collected Information

  • Cookies and similar tracking technologies
  • Log data (IP addresses, access times, browser type)
  • Device information (operating system, device identifiers)

4. How We Use Your Information

We use your personal data for the following purposes:

4.1 Service Provision

  • Create and manage your account
  • Generate AI music tracks based on your inputs
  • Process payments and manage subscriptions
  • Provide customer support

4.2 Service Improvement

  • Analyze usage patterns to improve our AI models
  • Develop new features and functionality
  • Conduct research and analytics

4.3 Communication

  • Send service-related notifications
  • Respond to your inquiries
  • Send marketing communications (with your consent)

4.4 Legal Compliance

  • Comply with legal obligations
  • Enforce our Terms of Service
  • Protect against fraud and abuse

5. Legal Basis for Processing (GDPR)

We process your personal data based on:

  • Contract Performance: To provide our services
  • Legitimate Interests: To improve our services and prevent fraud
  • Consent: For marketing communications and non-essential cookies
  • Legal Obligations: To comply with applicable laws

6. Data Sharing and Disclosure

We may share your information with:

6.1 Service Providers

  • AI Music Generation: Third-party AI providers (currently MiniMax Music 2.0) for track and lyrics generation. Plonkify acts as an intermediary platform and does not develop or control these AI services.
  • Payment Processing: Stripe, PayPal, or other payment processors
  • Cloud Hosting: Vercel, AWS, or similar providers
  • Email Services: For transactional and marketing emails
  • Analytics: Google Analytics, Plausible, or similar services

6.2 Legal Requirements

  • When required by law or legal process
  • To protect our rights, property, or safety
  • In connection with a merger, acquisition, or sale of assets

6.3 Public Content

  • Tracks you mark as "Public" will be visible to other users
  • Your username and profile information may be visible on public tracks

7. Data Retention

  • Account Data: Retained while your account is active and for 30 days after deletion
  • Generated Tracks: Retained as long as you keep them or until account deletion
  • Payment Records: Retained for 7 years for tax and accounting purposes
  • Usage Logs: Retained for 90 days

8. Your Rights (GDPR & Privacy Laws)

You have the right to:

8.1 Access and Portability

  • Request a copy of your personal data
  • Export your data in a machine-readable format

8.2 Rectification

  • Correct inaccurate or incomplete data

8.3 Erasure ("Right to be Forgotten")

  • Request deletion of your personal data
  • Note: Some data may be retained for legal compliance

8.4 Restriction and Objection

  • Restrict processing of your data
  • Object to processing based on legitimate interests

8.5 Withdraw Consent

  • Withdraw consent for marketing communications at any time

8.6 Lodge a Complaint

  • File a complaint with your local data protection authority

To exercise these rights, contact us at privacy@plonkify.com

9. Data Security

We implement appropriate technical and organizational measures:

  • Encryption: Data encrypted in transit (TLS/SSL) and at rest
  • Access Controls: Limited access to personal data
  • Regular Audits: Security assessments and updates
  • Secure Authentication: Password hashing and optional 2FA

10. International Data Transfers

Your data may be transferred to and processed in countries outside your residence. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Other appropriate safeguards

11. Cookies and Tracking

We use cookies for:

11.1 Essential Cookies

  • Authentication and session management
  • Security features

11.2 Analytics Cookies

  • Usage statistics and performance monitoring

11.3 Marketing Cookies (with consent)

  • Personalized advertising

You can manage cookie preferences in your browser settings.

12. Children's Privacy

Our Service is not intended for users under 16 years of age. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately.

13. AI and Automated Decision-Making

13.1 Third-Party AI Services

  • AI Music Generation: We provide access to third-party AI services (currently MiniMax Music 2.0) for music generation
  • Platform Role: Plonkify acts as an intermediary platform and does not develop, train, or control the AI models
  • Data Processing: Your prompts and inputs are processed by third-party AI providers according to their privacy policies

13.2 Automated Processing

  • No Profiling: We do not use automated decision-making that significantly affects you
  • Human Oversight: Content moderation includes human review

14. Third-Party Links

Our Service may contain links to third-party websites. We are not responsible for their privacy practices. Please review their privacy policies.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via:

  • Email notification
  • Prominent notice on our website
  • In-app notification

Continued use of the Service after changes constitutes acceptance.

16. Contact Us

For privacy-related questions or to exercise your rights:

Email: privacy@plonkify.com
Address: Fuutu UG (haftungsbeschränkt), Jaegersstr. 15, 41462 Neuss, Germany

17. Specific Regional Information

17.1 European Economic Area (EEA)

  • We comply with GDPR requirements
  • You have all rights listed in Section 8
  • Supervisory Authority: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)

17.2 California (CCPA/CPRA)

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of sale (we do not sell personal information)
  • Right to non-discrimination

17.3 United Kingdom

  • We comply with UK GDPR and Data Protection Act 2018
  • ICO is the supervisory authority

Effective Date: November 15, 2025

By using Plonkify, you acknowledge that you have read and understood this Privacy Policy.