← Home

SongBox FUN Privacy Policy

Version of 30 September 2026

This Privacy Policy governs how information about the service's users is collected, used and protected. We collect Telegram account identifiers, answers given while creating a song, song lyrics, generated audio, payment records and interaction history. The data is used to run the service, to communicate with the user, for moderation and for analysis. Information is shared with third parties only in the cases listed below. We do not receive or store bank card data. Data is not sold and is not used for advertising. The user can ask for their data to be deleted at any time through support in Telegram.

1. General provisions

1.1. This Privacy Policy (the "Policy") governs how information that the User provides when using the SongBox FUN Telegram bot (@SongBox_AI_bot) and the Service's website (together, the "Service") is processed and protected. The operator of the Service is SongBox FUN Service Administration (the "Administration").

1.2. By using the Service, the User confirms that they agree to this Policy. If the User does not agree, they must stop using the Service.

1.3. Terms not defined in this Policy have the meaning given in the Terms of Service (/terms command).

2. What data we process

2.1. The Service processes the following data:

  • Telegram account data that Telegram passes to the bot: numeric ID, username, display name, the Telegram language code as sent (for example "ru" or "en-GB" — even if the interface is shown in another language), and the interface language chosen in the bot;
  • answers given while creating a song — who the song is for, the occasion, genre, style, mood, vocals, song language, and the names and story the User types in, as well as the User's own lyrics if they sent them;
  • song lyrics created by the Service and requests to change them;
  • generated audio (preview clips and full versions of songs);
  • moderation results — the automated check's decision, the violation category, the time, and the refusal counter used for the temporary restriction;
  • payment records passed on by the payment service or Telegram: payment number and status, the chosen pack, amount and currency, payment method, date;
  • history of interactions with the Service — songs created, the song (credit) balance and its movements, referral-programme invitations, notifications sent by the Service, support requests;
  • usage events (analytics) — which screens were opened and which buttons were pressed, steps completed, time per step, errors; events contain only identifiers and chosen options and contain no message text;
  • traffic source — the tag from the link through which the User first opened the bot (for example an ad campaign or a referral link);
  • technical logs — service records of how the Service runs (identifiers, time, errors) without the text of answers, stories or songs.

2.2. The Service does not receive or store bank card data. Payments are processed by the payment service or by Telegram; the Service receives only the payment result and its identifier.

2.3. The Service does not require the User to provide passport data, documents, photos, a phone number, an email address or any other personal information beyond the minimum needed for it to work.

2.4. The User decides what to write in the story for a song. We recommend not including phone numbers, addresses, document numbers, health information or other details the song does not need.

2.5. If the User provides the name or story of another person (for example, the person the song is for), they confirm that they are entitled to share this information for creating the song.

3. Purposes and legal bases

3.1. The Service uses data only to:

  • make the features work: create the lyrics and music, deliver the song, keep the song balance, accept payments;
  • choose the interface language and the song language;
  • communicate with the User (notifications that a song is ready and about payments, reminders about an unfinished order, support replies);
  • check requests against the Service's rules (moderation) and apply the temporary restriction under the Terms of Service;
  • prevent abuse and fraud (including repeatedly obtaining free songs and bonuses);
  • account for payments and handle disputed payments;
  • analyse and improve the Service, including understanding where users come from and which languages to add.

3.2. Legal bases: performance of the Terms of Service (creating and delivering songs, balance, payments, support); the Administration's legitimate interests (moderation, security, abuse prevention, analytics without message text, traffic source); compliance with legal obligations (payment accounting); the User's consent — where applicable law requires it.

3.3. The User can opt out of reminders (messages not related to their current order) by writing to support or by blocking the bot. Messages that an ordered song is ready and about payments are always sent.

3.4. Moderation is automated, including artificial-intelligence classifiers. If the User disagrees with a refusal or with a temporary restriction, they can write to support — a person will review the request.

4. Sharing information with third parties

4.1. The Administration does not share the data it receives with third parties, except:

  • where required by law;
  • where necessary to fulfil obligations to the User (for example, when working with payment systems);
  • where the User has consented to it.

4.2. To fulfil its obligations, the Service uses the following categories of service providers, which receive only the data needed for their part of the work and process it on the Administration's behalf:

  • Telegram — the platform the bot runs on; delivers messages and files and accepts payments in Telegram Stars;
  • a payment system (payment processing provider) — for Russian payment methods in roubles; it receives the amount, currency and order number;
  • AI text-model providers — writing the lyrics and moderation; they receive the answers, the story and the lyrics without the Telegram ID, username or payment data;
  • an AI music-generation provider — creating the audio; it receives the lyrics and the style description without the Telegram ID, username or payment data;
  • hosting providers — the servers the Service runs on and where data is stored, and the website hosting;
  • a website analytics service (Cloudflare Web Analytics, part of the website hosting, on the provider's worldwide network) — aggregated website visit statistics under 7.1; it receives no data about bot users.

4.3. The Service does not sell Users' data and does not share it for advertising.

4.4. The servers of the Service and of the providers listed above may be located outside the User's country of residence. By using the Service, the User understands that their data may be processed in other countries. The Administration shares only the minimum data necessary with providers.

5. Storage and protection of data

5.1. Data is kept only as long as needed for the purposes of processing:

  • generated audio is kept on the Service's servers for no longer than 90 days from creation; after that the song remains available in Telegram (in the chat history with the bot and under "My songs", for as long as Telegram keeps the file);
  • exact requests to the AI text model (which include the answers and the story) — no longer than 30 days;
  • answers, song lyrics, interaction history, usage events and the traffic source — while the User's account exists in the Service or until a deletion request;
  • moderation results — no longer than 12 months (to protect against abuse), without the text of the request;
  • technical logs — no longer than 30 days;
  • payment records and balance movements — for the period required by law and payment-system rules for accounting and handling disputed payments, even after the rest of the data is deleted; after the account is deleted these records are de-identified (the link to the Telegram account is removed).

5.2. Database backups are not changed retroactively and are overwritten within 30 days; deleted data disappears from them for good once that period ends.

5.3. The Administration takes reasonable measures to protect data (restricted access, encrypted transport, separate environments, logs without message text and without secrets), but does not guarantee the absolute security of information transmitted over the internet.

6. User rights and data deletion

6.1. The User has the right to:

  • find out what data about them the Service keeps, and get a copy;
  • have inaccurate data corrected;
  • have their data deleted (answers, lyrics, audio, their account in the Service);
  • object to processing based on legitimate interests (for example, analytics) or have it restricted;
  • withdraw consent where processing is based on consent;
  • complain to a data-protection supervisory authority where applicable law provides for it.

6.2. Requests go to support in Telegram: @SongBox_AI_support (or the "🆘 Support" button in the bot). To confirm the request comes from the account holder, support replies only to the same Telegram account the data belongs to.

6.3. The Administration replies to a request within 30 days.

6.4. Deletion works like this: if a song is being created at that moment, deletion happens after it finishes; then the answers, lyrics, audio, requests to AI models, notifications, usage events and the account in the Service are deleted, while payment records and balance movements are de-identified and kept only for accounting (clause 5.1). Copies of songs already sent to the chat stay in Telegram until the User deletes the chat with the bot. On deletion the profile, lyrics and songs are erased, but de-identified records of serious safety violations and of bans are kept — with no request text and no name, only a one-way hash of the Telegram ID — to prevent abuse and ban evasion; they are kept for the moderation-results period stated in clause 5.1 (12 months).

6.5. After deletion, unused songs (credits) on the balance are forfeited — we recommend using up the balance first or requesting a refund under the Terms of Service.

7. Website, cookies and analytics

7.1. The Service's website does not use cookies or advertising scripts and does not collect data through forms. To understand how the website is used, we count page views with the cookieless web analytics built into the website hosting (Cloudflare Web Analytics). It stores nothing on the visitor's device (no cookies, no local storage), does not identify the visitor, does not "fingerprint" them by IP address or browser details and does not track them across other websites. It records the page viewed, the referring website, the approximate country, the device type, the browser and operating system, and how fast the page loaded; parameters in the link (including campaign tags) and presses of website buttons are not recorded. We see the reports only in aggregated form and for no more than the last 6 months.

7.2. The website works fully without the analytics script, so it can be blocked in the browser (for example, with a content blocker). Questions about this counting and objections to it can be sent to support in Telegram (@SongBox_AI_support).

7.3. The language, colour theme and price currency chosen on the website are stored only in the User's browser (local storage) and are not sent anywhere. The campaign tag of the link the visitor arrived by is kept in the browser until the tab is closed and is passed to the bot only inside the link to it, when the visitor presses the button to open Telegram; it contains no visitor identifier.

7.4. The website host may keep technical request logs (for example, IP address and time of the request) to run and secure the website.

8. Age

8.1. The Service is intended only for people aged 18 or over. We do not knowingly process data of people under 18; if such data is found, it is deleted.

9. Disclaimer

9.1. The User understands and agrees that transmitting information over the internet always carries risks.

9.2. The Administration is not liable for loss, theft or disclosure of data caused by third parties or by the User.

10. Changes to this Policy

10.1. The Administration may change this Policy. The current version, with its date, is always available in the bot via the /privacy command and on the Service's website. The Administration announces material changes in the bot or on the website before they take effect.

10.2. Continued use of the Service after changes means the User agrees to the new version of the Policy.

11. Contact

For questions about data processing: Telegram @SongBox_AI_support or the "🆘 Support" button in the bot.