Skip to main content
Policies & Legal
11 min read

Privacy Policy

How we collect, use, and protect your data

Last updated: May 27, 2026

Effective: May 27, 2026

DailyWorship is operated by Intelligent Singularity Inc. ("we", "us", "our"), Suite C, 16644 - 71 St, Edmonton, AB T5Z 0N5, Canada. We are the controller of your personal information. This policy explains what we collect, why, how we share it, how long we keep it, and the rights you have. It is written to meet Canada's PIPEDA and Quebec's Law 25, and includes specific sections for the EU/UK (GDPR) and California (CCPA/CPRA).

For privacy questions or to exercise your rights, contact privacy@dailyworship.net or Contact Support. See also Your Data Rights and Data Retention.

Information We Collect#

Information you provide#

  • Account information: email, name, password (stored hashed, never in plain text).
  • Profile data: display name, profile picture.
  • Content: prompts, lyrics, settings, generated tracks, playlists.
  • Communications: support messages, feedback, survey responses.

Information collected automatically#

  • Usage data: features used, pages visited, actions taken.
  • Device data: browser type, operating system, device type.
  • Log data: IP address, access times, error and security logs.
  • Cookies and similar technologies (see "Cookies" below).

Information from third parties#

  • Authentication providers: if you sign in with Google, Apple, or GitHub, we receive basic profile and email data.
  • Payment processor (Stripe): transaction confirmations and limited billing details — we never receive your full card number.

We use your information to provide and secure the Service, process generations, send service communications, provide support, analyze and improve features, prevent fraud and abuse, and comply with law. For users in the EU/UK, our GDPR Article 6 legal bases are:

  • Performance of a contract — to provide the Service you signed up for.
  • Legitimate interests — to secure, analyze, and improve the Service (balanced against your rights).
  • Consent — for optional cookies, marketing, and any opt-in model-improvement program (you can withdraw consent at any time).
  • Legal obligation — to meet tax, accounting, and other legal requirements.

AI, Audio, and Voice Data#

Your prompts, lyrics, and generated audio are processed to produce and deliver Output and to operate moderation and similarity checks. Consistent with our Terms of Service:

  • We use aggregated, de-identified data to improve the Service.
  • We do not sell personal data.
  • We do not use your private Content to train foundation models without your consent.
  • Content you choose to make public may be shown in discovery feeds.

Automated Decision-Making#

Our content moderation and similarity detection are automated. They may block prompts, flag, regenerate, or quarantine Output. These checks do not produce legal or similarly significant effects about you as an individual; where you believe a decision was wrong, you may appeal — see Content Guidelines.

How We Share Information#

We do not sell your personal data. We share it only with:

  • Service providers (processors) acting on our instructions — for example, cloud hosting, payment processing (Stripe), email delivery, analytics, error monitoring (Sentry), search (Meilisearch), and AI compute. See Subprocessors & Service Providers for the current list and what each one processes.
  • Legal and safety — to comply with law or valid legal process, enforce our Terms, or protect the rights, safety, and property of users and the public.
  • With your consent or at your direction.
  • Business transfers — in a merger, acquisition, or sale of assets, subject to this policy.

International Data Transfers#

We may process data in countries other than yours, including Canada and the United States. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision (Canada holds a partial EU adequacy decision for commercial activity covered by PIPEDA).

Cookies#

We use strictly necessary cookies for authentication and security, and (with your consent where required) preference and analytics cookies. In the EU/UK you can accept or reject non-essential cookies via our cookie controls, and you can manage cookies in your browser. We honor Global Privacy Control (GPC) signals where applicable.

Data Security#

We protect your data with encryption in transit and at rest, secure authentication, access controls, monitoring, and regular security review. No system is perfectly secure, but we work to protect your information and will notify you and regulators of a personal-data breach where the law requires.

Data Retention#

We keep personal data only as long as needed to provide the Service, meet legal obligations, and resolve disputes. After account deletion, personal data is deleted within 30 days and purged from backups within 90 days; some anonymized/aggregated data may be retained. Full schedules are in Data Retention.

Children's Privacy#

The Service is not directed to children under 13, and we do not knowingly collect their data (consistent with COPPA). Users between 13 and the age of majority must have parental/guardian involvement. If you believe a child under 13 has provided us data, contact privacy@dailyworship.net and we will delete it.

Your Rights#

Your rights depend on where you live. To exercise any right, contact privacy@dailyworship.net; we verify identity before responding and aim to respond within the timelines below. See Your Data Rights for step-by-step instructions.

EU / UK (GDPR)#

You have rights to access, rectify, erase, restrict, port, and object to processing, and to withdraw consent. You may lodge a complaint with your local Data Protection Authority (in the UK, the ICO). We respond within one month.

Canada (PIPEDA / Quebec Law 25)#

You may access and correct your personal information, withdraw consent (subject to legal/contractual limits), and (under Quebec Law 25) request data portability and information about automated processing. You may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information.

California (CCPA/CPRA)#

You may know, access, correct, and delete your personal information, opt out of "sale"/"sharing" (we do not sell or share as defined), limit use of sensitive personal information, and not be discriminated against for exercising your rights. We respond within 45 days.

Changes to This Policy#

We may update this policy and will notify you of material changes. The "Effective" date above shows the latest version.

Contact#

Related Articles:

privacy
data
security
personal information
GDPR
PIPEDA

Was this article helpful?

Your feedback helps us improve our documentation.