Privacy Policy
Controller and Contact
The controller responsible for processing your personal data within the meaning of the General Data Protection Regulation (GDPR) is:
Deep Blue Dodo LLC 30 N Gould St, Ste R Sheridan, WY 82801 USA
Contact for data-protection matters
- For company and legal matters: legal@deepbluedodo.com
- For support and to exercise your data-subject rights (access, rectification, erasure, and so on): support@canta.lol
No data protection officer is appointed; on assessed facts there is no statutory duty to appoint one (Article 37 GDPR; Section 38 of the German Federal Data Protection Act, BDSG).
Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right under Article 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work, or the place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR. A directory of supervisory authorities is published by the European Data Protection Board (edpb.europa.eu).
What we process and why
This section describes, per data category, what is processed, why, on which legal basis, for how long (retention), and to which recipients the data goes. The controller and contact route are set out in the imprint and the "Controller" section.
- What: Guest use generates a synthetic guest email. For account and purchase flows, your real email address is processed (confirmed via one-time code). Support and erasure correspondence runs through support@canta.lol.
- Why: Create and secure the account and deliver requested service messages; answer support, report and data-rights requests. No marketing without a separate, optional, unticked consent.
- Legal basis: Article 6(1)(b) GDPR (account and service communications); Article 6(1)(c) GDPR for records legally required to answer or evidence legal-rights requests.
- Retention: Account email for the account lifetime, then erasure or irreversible anonymisation after a verified deletion request, except for narrowly scoped records required by law. One-time codes and sign-in links are stored only as a cryptographic digest, expire after 10 minutes, and are permanently deleted no later than 24 hours after expiry. Support correspondence is deleted 24 months after the matter is closed (see the "Retention and your rights" section for detail).
- Recipients: Self-hosted Supabase stack on Hetzner (EU). Account emails (e.g. one-time codes, sign-in links and purchase confirmations) are sent via the delivery service Resend (Plus Five Five, Inc., USA); a data processing agreement with EU Standard Contractual Clauses applies, and the provider deletes send data after 30 days (details in the processor list).
Song text and message
- What: Message or lyrics text, an optional song title, the sender display name and, where supplied, the reason for a report/takedown.
- Why: Generate, store, deliver and share the requested song; secondarily investigate failures, moderation events, reports and takedowns.
- Legal basis: Article 6(1)(b) GDPR (requested generation, storage, playback, sharing); Article 6(1)(f) GDPR (security, abuse prevention, evidence-preserving takedown; a balancing test is required).
- Retention: Song text and generated assets while the song is active. When a single song is removed, public serving stops immediately; actual deletion or irreversible anonymisation follows a short, documented abuse/legal hold. Important: this single-song removal is initially a reversible suspension of public serving and is not presented as a completed hard erasure. When you delete your entire account, by contrast, a technical erasure process runs: audio files are removed from storage, song texts and titles are blanked, and sign-in and email data are deleted; pseudonymised purchase and credit records are retained only where statutory retention duties require it.
- Recipients: Self-hosted Supabase stack on Hetzner (EU); kie.ai (USA) as the gateway and, through it, Suno as the underlying model. According to kie.ai's published documentation, generated media files are automatically deleted there after around 14 days and text/metadata logs after around 2 months; however, kie.ai cannot produce a data processing agreement or binding data commitments. See the processor list for detail.
Voice
- What: The raw microphone recording during transcription and the resulting text, which becomes song text once you submit it.
- Why: Transcribe a voice message into editable text at your request. Excluded: biometric identification, speaker profiling, training, and stored voice archives.
- Legal basis: Article 6(1)(b) GDPR (requested transcription for song creation).
- Retention: CANTA does not store the raw recording; it exists only for the transcription request. Local transcription (faster-whisper) is preferred; Groq is a fallback. Zero Data Retention is enabled for CANTA's Groq account; under it, Groq does not store inputs or outputs. The transcript then follows song-text retention.
- Recipients: Local transcription on the Hetzner infrastructure (EU); on the fallback path the raw audio is sent to Groq (USA) under its DPA/Standard Contractual Clauses.
Payment (buying credits)
- What: For each purchase, CANTA stores: your user ID, the chosen offer, amount and currency, the number of credits, the Stripe transaction identifiers (checkout session and payment intent), status, and timestamps; a Stripe customer ID is also linked to your account. CANTA never receives or stores your card details — the payment page is hosted entirely by Stripe, and your billing address is likewise stored by Stripe, not by CANTA. There are no subscriptions and no payment instruments on file with CANTA.
- Why: Sell credit packs and keep your balance accurate; secondarily refunds, fraud prevention, accounting, tax (including VAT records), and dispute evidence.
- Legal basis: Article 6(1)(b) GDPR (checkout, balance, refunds); Article 6(1)(c) GDPR (accounting/tax records); Article 6(1)(f) GDPR (fraud/dispute prevention, balancing test required).
- Retention: Purchase and balance data for the lifetime of the account. When your account is erased, the Stripe customer ID is removed from your user record; transaction and accounting evidence is kept beyond that only as long as tax and commercial law require (up to ten years for EU VAT records).
- Recipients: Stripe (USA/Ireland) as payment provider; details in the processor list. Your purchase confirmation with receipt (PDF) comes from CANTA by email. Where product analytics is enabled, the fact of a first purchase (transaction identifier, amount, currency, number of credits) is additionally passed to the analytics provider; card details are never passed to it at any point.
- No automated decisions: purchase and analytics data are not used to vary prices, offers or features for individual people, and not for automated decisions within the meaning of Article 22 GDPR.
Product analytics
- What: A pseudonymous identifier prefixed "anon_" — no name, no email address, no person profile — together with a fixed, closed list of eight events (visit, session start, first song, completed song, share, opening the checkout page, first purchase, explicit account departure), each with timestamp, platform, first-visit origin (the recognised
refandutmparameters) and limited event properties (song identifier, genre/style tags, estimated generation cost, surface, whether you are sender or recipient, a playback milestone). On the share and listen pages an identifier held only in memory is used, and it ends with the browser tab. Excluded: message and lyrics text, song titles, audio files and other free text; card details; automatic capture of every page view; session replays and heatmaps; advertising profiles; cross-product tracking. Your IP address is not evaluated to determine your location. - Why: Measure activation, successful generation, sharing, purchase and drop-off points; secondarily reliability and cost monitoring.
- Legal basis: Article 6(1)(f) GDPR (legitimate interest in strictly minimised, profile-free product measurement). The measurement stores nothing on your device and reads nothing from it, so Section 25(1) TDDDG is not triggered and no consent banner is required. The balancing assessment is documented; an objection under Article 21 GDPR stops collection.
- Retention: Raw events 12 months, then deleted at the provider; aggregate statistics that no longer identify anyone are retained beyond that.
- Recipients: PostHog, Inc. (USA) as processor, EU Cloud in Frankfurt. EU hosting does not mean data never leaves the EU — details and transfer bases are in the processor list. Details of the measurement, the objection route and deletion are in the "Product analytics" section of the cookie and browser-storage policy.
Cookies and browser storage
- What and why: A signed session cookie, an access-gate cookie during the invite phase, preferences stored in the browser (sender name, most recently created song), and Turnstile security signals when enabled. Details and durations are in the cookie and browser-storage policy.
- Legal basis: Section 25(2)(2) TDDDG (strictly necessary terminal storage) and Article 6(1)(b) and (f) GDPR. There are no advertising or tracking cookies and no analytics cookies; product measurement likewise stores nothing on your device and reads nothing from it. Hence there is no consent banner.
- Recipients: Self-hosted Supabase stack on Hetzner (EU); Cloudflare only when Turnstile is enabled.
The limits of our current deletion
Today, deleting content stops its public serving (a takedown). A complete, final erasure across all layers is not yet implemented as a workflow. Raw voice recordings are never stored.
Who receives your data, and transfers to third countries
This section explains, in narrative form, the categories of recipients to whom personal data is disclosed and how transfers to the USA are safeguarded. The itemised list of each provider, its location, role, and transfer basis is set out in the processor list.
Categories of recipients
- Infrastructure in the EU: CANTA's self-hosted Supabase stack runs on infrastructure of Hetzner Online GmbH (Germany) in the EU. This processing takes place in the EU; there is no third-country transfer.
- Song generation: The lyric or message text you enter is transferred to kie.ai (USA) for generation and, through kie.ai, to Suno's underlying music model. This is necessary to create the song you request.
- Voice transcription (fallback): Transcription is performed locally on the EU infrastructure as the preferred path. Only when local processing is unavailable is the raw recording sent to Groq (USA); CANTA does not store it.
- Security (only when enabled): When Turnstile security signals are enabled, Cloudflare (USA/global network) receives the signals needed for bot and abuse protection.
- Payments: When you buy credits, Stripe handles the payment; the payment page is hosted by Stripe, and card details and billing address are held exclusively by Stripe. CANTA passes your account email and the transaction data of the purchase to Stripe.
- Email delivery: Account emails (e.g. one-time codes, sign-in links and purchase confirmations) are sent via the delivery service Resend (Plus Five Five, Inc., USA). A data processing agreement with EU Standard Contractual Clauses applies; the provider deletes send data after 30 days. Details in the processor list.
- Product analytics: PostHog, Inc. (USA) acts as processor; processing runs on the EU Cloud in Frankfurt, and its EU sub-processors (Amazon Web Services, Wiz, PlanetScale, Modal Labs) are routed through Germany. EU hosting is not a promise that data never leaves the EU: Cloudflare sits on the provider's global edge regardless of the region chosen, and PostHog, Inc. is a US company with no EU establishment, so access from the USA (for example in support) is possible. The measurement stores nothing on your device and reads nothing from it; details are in the "Product analytics" section.
Transfers to the USA
Where recipients are located in the USA, those transfers rely, where available, on each provider's European Commission Standard Contractual Clauses (SCC), supplemented by further safeguards where applicable. For Groq and Resend, data processing agreements with EU Standard Contractual Clauses are in place. For PostHog, the provider's agreement provides for EU, UK and Swiss Standard Contractual Clauses, and the provider additionally declares certification under the EU-US Data Privacy Framework. For Stripe, the contracting party is Stripe, LLC (USA); its automatically incorporated data processing agreement applies, and transfers from the EU rely, under its Data Transfers Addendum, primarily on the EU-US Data Privacy Framework (certification declared by Stripe), with EU Standard Contractual Clauses as fallback.
Honest limitation regarding kie.ai: For kie.ai, no publicly verifiable contractual or data-processing terms and no DPA can be found. CANTA therefore cannot represent any transfer mechanism or any provider-side commitment for kie.ai. We tell you openly which data CANTA sends to kie.ai, but we cannot evidence any kie.ai commitment as to handling, retention, or non-use for training.
No further sharing
Beyond the service providers named and the planned services above, your personal data is not shared with third parties. No personal data is sold, and there is no sharing for advertising or cross-product tracking. Disclosure to authorities occurs only where required by law.
Retention and your rights
This section describes how long data is kept and which rights you have as a data subject under the GDPR. Contact for exercising your rights: support@canta.lol.
Your rights as a data subject
- Access (Article 15 GDPR): You may obtain confirmation of whether data concerning you is processed, information about that data, and a copy.
- Rectification (Article 16 GDPR): You may request the correction of inaccurate data and the completion of incomplete data.
- Erasure (Article 17 GDPR): You may request erasure of your data where a statutory ground applies and no retention obligation stands in the way. Account deletion: When you delete your account (confirmed by one-time code), a technical erasure process runs: audio files are removed from storage, song texts and titles are blanked, sign-in and email data are deleted, and the Stripe customer reference is removed from your user record. Pseudonymised purchase and credit records are retained only where tax and commercial law require it. Product analytics (where enabled): we instruct the analytics provider to delete the events stored against your identifier, and the link between identifier and account is removed at CANTA. The memory-only identifiers used on the share and listen pages are never stored anywhere and therefore cannot be traced or deleted afterwards by anyone — including us. Individual items: Removing a single song initially stops its public serving immediately (a takedown); the actual deletion or irreversible anonymisation follows a short, documented abuse/legal hold and is not presented as a completed hard erasure.
- Restriction of processing (Article 18 GDPR): You may request restriction of processing where the statutory conditions are met.
- Data portability (Article 20 GDPR): You may receive the data concerning you that you have provided, in a structured, commonly used, machine-readable format, where processing is based on consent or a contract and is carried out by automated means.
- Objection (Article 21 GDPR): Where processing is based on a legitimate interest (Article 6(1)(f) GDPR), you may object on grounds relating to your particular situation. A separate objection route exists for the product analytics that stops collection rather than merely hiding it: an informal message to support@canta.lol is enough. No recognisable identifier is created on the share and listen pages, so no objection route is needed there.
- Withdrawal of consent: Where processing is based on your consent, you may withdraw it at any time with effect for the future.
- Right to complain: You may lodge a complaint with a supervisory authority (Article 77 GDPR); details are in the "Controller and Contact" section.
Retention periods
- Account and service email: for the account lifetime, then erasure or irreversible anonymisation after a verified deletion request, except for narrowly scoped records required by law. Support correspondence is deleted 24 months after the matter is closed, unless a statutory duty or an ongoing dispute requires longer retention.
- Song text and generated assets: while the song is active; when a single song is removed, public serving stops immediately, and actual deletion follows the short hold noted above; on account deletion, audio files and song texts are removed in the erasure process itself.
- Raw voice recording: not stored by CANTA; it exists only for the transcription request.
- Payment and accounting records: Purchase and credit data are stored for the account lifetime; on account deletion, pseudonymised records are retained only to the extent required by law (see the "Payment" section for detail). Retention follows the applicable statutory periods: EU VAT under the OSS scheme 10 years from the end of the relevant year, once EU B2C sales occur; US IRS tax records generally 3 to 7 years (longer for non-filing or fraud). German retention periods under Section 147 AO / Section 257 HGB (10/8/6 years) apply only where applicable — as a US LLC without a German establishment there is no direct binding today; they become relevant if a German tax presence arises.
- Product analytics: raw events are kept for 12 months and are then deleted at the provider. Aggregate statistics that no longer make an individual identifiable are retained beyond that.
Cookies and Browser Storage
CANTA uses strictly necessary cookies only, together with necessary browser storage. There are no advertising or cross-site tracking cookies and no analytics cookies. Product measurement, where it is used, likewise stores nothing on your device and reads nothing from it. For that reason there is no consent banner.
The legal ground for storing data on your device is Section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG, formerly TTDSG): storage that is strictly necessary to provide a service you have expressly requested. The subsequent processing of the data relies on Article 6(1)(b) GDPR (providing the requested service) and, for access control and abuse protection, on Article 6(1)(f) GDPR (legitimate interest in security).
Items used
| Item | Type | Purpose | Storage duration |
|---|---|---|---|
canta_session (signed) | Cookie | Maintains the requested session and the ownership of credits | One year |
canta_gate | Cookie | Access control during the invite/testing phase | One year; becomes inert when the invite phase ends |
| Sender name | Browser storage (localStorage) | Remembers the sender name you entered for your next composition; stays on your device | Until you clear browser storage or the app offers a reset |
| Last song | Browser storage (localStorage) | Remembers your most recently created song (identifier and title) so you can reopen it; stays on your device | Until you clear browser storage or sign out |
| Volume | Browser storage (localStorage) | Remembers the playback volume you set; stays on your device and is not transmitted | Until you clear browser storage |
The sender name is not repurposed as a tracking identifier. Where Turnstile security signals are used, the provider Cloudflare acts as a processor for site protection and as a separate controller for product improvement; see the processor list for detail.
Product analytics
CANTA measures whether the product works: how many people arrive, how many create a first song, how many complete one, share it, or buy credits, and where people stop. PostHog is used for this.
What is measured
- Identifier: a pseudonymous identifier prefixed "anon_". PostHog receives no name, no email address and no person profile. On the share and listen pages, an identifier held only in memory is used; it disappears for good when the browser tab is closed.
- Events: a fixed, closed list of eight events — visit, session start, first song, completed song, share, opening the checkout page, first successful purchase, and an explicit account departure. There is no automatic capture of every page view or click.
- Properties: timestamp, platform, first-visit origin (only the recognised
refandutmparameters — the full address of the page you opened and the referring address are read and immediately discarded, not stored), song identifier and metadata (genre and mood as fixed preset values, never free text; estimated generation cost, surface, whether you are the sender or the recipient, a playback milestone). On the purchase events, the fact of the purchase is added: transaction and offer identifiers, amount, currency, and number of credits. - Expressly not measured: message and lyrics text, song titles, audio files, prompts and any other free text; card details (these are held exclusively by Stripe); session replays and heatmaps; advertising profiles; cross-product tracking. No data is sold.
No consent banner — and why
The analytics stores nothing on your device and reads nothing from it: no analytics cookies, no browser local storage, no recognition based on device characteristics. The consent requirement in Section 25(1) TDDDG is therefore not triggered; the necessary storage CANTA does use is described in the cookie and browser-storage policy.
Your IP address is not evaluated to determine your location (geolocation is switched off at the provider).
Legal basis and objection
The legal basis is Article 6(1)(f) GDPR (legitimate interest in strictly minimised, profile-free product measurement). The balancing assessment is documented and is re-run if any of the safeguards above changes.
You may object to the analytics at any time (Article 21 GDPR). An objection stops collection; it does not merely hide it. Send an informal message to support@canta.lol; we will stop collection for you and delete the events already stored against your identifier. No objection route is needed on the share and listen pages, because no recognisable identifier is created there.
No automated decisions: analytics data is not used to vary prices, offers or features for individual people, and not for automated decisions within the meaning of Article 22 GDPR.
Retention
Raw events are kept for 12 months and are then deleted at the provider. Aggregate statistics that no longer make an individual identifiable are retained beyond that.
Recipients and transfers
The processor is PostHog, Inc. (San Francisco, USA); processing runs on the EU Cloud in Frankfurt. Its EU sub-processors (Amazon Web Services, Wiz, PlanetScale, Modal Labs) are routed through Germany.
Honest characterisation: EU hosting is not a promise that data never leaves the EU. Cloudflare sits on the provider's global edge regardless of the region chosen, and PostHog, Inc. is a US company with no EU establishment, so access from the USA (for example in support) is possible. Those transfers are safeguarded by the data processing agreement with EU Standard Contractual Clauses; certification under the EU-US Data Privacy Framework is declared by the provider.
Deletion
If you request erasure, we instruct the analytics provider to delete the events stored against your identifier, and the link between identifier and account is removed at CANTA. The memory-only identifiers used on the share and listen pages cannot, by their nature, be traced or deleted afterwards by anyone — including us — because they are never stored anywhere.
AI Content Disclosure
CANTA is made with AI.
CANTA lets people turn a written or spoken message into a song. Every song produced through CANTA is generated entirely by artificial intelligence. Songs are not performed or sung by human artists.
How the content is created
- Song generation: The music is produced by a generative music model from the provider Suno, which CANTA reaches through the kie.ai gateway. As things stand today, CANTA does not call Suno directly — only through kie.ai.
- Voice transcription: When lyrics are entered by voice, the recording is converted to text. This conversion runs first on CANTA's own infrastructure (local-first); the Groq service is used only as a fallback. CANTA does not store the raw recording (see the privacy notice for detail).
Provider roles (stated honestly)
- Suno is the underlying music model. Today CANTA reaches Suno only indirectly, via kie.ai.
- kie.ai is the gateway through which generation is triggered. kie.ai's contractual terms for handling the content sent to it are not publicly verifiable, so CANTA cannot represent any kie.ai commitment about storage, retention, or non-use for training.
- Groq is used only as a fallback for voice transcription.
Labelling
CANTA signals its use of AI prominently: through the line "CANTA is made with AI." in the footer of the landing page and on the legal pages. Individual shared songs carry no additional label.
This reflects Regulation (EU) 2024/1689 (the AI Act), Article 50:
- The machine-readable marking of artificially generated audio under Article 50(2) falls, on our reading, on the provider of the generating system (here the model/gateway side), not on the downstream service CANTA.
- The visible-disclosure duty under Article 50(4) concerns "deepfakes"; for artistic works an exception limits that disclosure to a manner that does not hamper the display or enjoyment of the work.
This assessment is reviewed and updated when the legal situation or the provider chain changes.
Last updated: 2026-07-27