Ritzma Ritzma
Features How it works Pricing FAQ
EN UA RU
Download
← Back to home

Privacy Policy

Effective August 3, 2026

This document explains what data the Ritzma app ("we", "the app", "the service") collects, how we use it and how you can control it. We deliberately designed Ritzma to collect as little as possible: you do not need an email address, a name or a phone number to use the app.

1. Who is responsible for your data

The data controller is the developer and operator of the Ritzma app. For privacy questions, requests or complaints, contact [email protected].

2. What data we collect

  • Anonymous user and account identifiers. The app creates an opaque user ID, authentication token and store account token. They identify an app account, not your real-world identity.
  • Device identifier. On iOS, the app reads the device vendor identifier (IDFV); on Android it reads Android ID. The backend converts this device seed into a hashed, device-bound user ID so the anonymous account can be restored on the same device. This identifier is not used for advertising.
  • Prompts, photos, lyrics and generated content. We process track descriptions, titles, selected genre, vocal and mood, lyrics you submit or ask AI to write, and the resulting audio track and cover image. When you explicitly choose Photo mode, the selected photo is processed to create a music prompt. If you then generate a track from that photo, a downscaled copy is stored as that track's cover image and is kept for as long as the track stays in your library; deleting the track or your account deletes it. If you never generate a track, the photo is discarded within a few hours.
  • Purchase history. We receive product IDs, transaction or original transaction IDs, purchase tokens/receipts, subscription status, renewal status and expiration date from Apple or Google to verify purchases and grant notes. We never receive or store your payment card or full billing details.
  • Firebase push tokens. If you enable notifications, we receive a Firebase Cloud Messaging (FCM) device token and platform so we can notify you when a generation finishes. You can disable notifications in the app.
  • First-party product analytics. Our backend records the session-linked events app_opened, onboarding_completed, audio_generated and paywall_opened. A raw event contains a timestamp and pseudonymous account and session identifiers and may include platform, app version and language. An audio-generation event may also include generation mode, genre, note cost and duration; a paywall event may include its source and reason and the note balance and cost shown at that point. These analytics events do not contain prompts, lyrics, track titles or audio URLs. We use them to understand the product funnel, diagnose where users encounter problems and improve onboarding, generation and subscription presentation.
  • Basic Firebase analytics. Separately, we use Firebase Analytics for a limited set of basic events, such as first app open and the start of checkout for a specific subscription, to verify that those flows work. Neither our first-party analytics nor Firebase Analytics is used for third-party advertising.
  • Technical and support data. We process app version, platform, selected language, last activity and limited server/security logs. If you email support, we also receive your email address, message, attachments and any user ID, device model or store order number you choose to provide.

No name, email or phone number is required to create an account. We do not access your contacts or precise location, and we do not show third-party ads.

3. Why we use the data

  • to create and maintain your anonymous account and provide the core function of the service — generating, storing and delivering music and lyrics from your prompts;
  • to credit and deduct notes and to verify purchases and subscriptions;
  • to send push notifications when a track is ready (you can turn them off in Settings);
  • to measure and improve the product funnel from app open through onboarding, audio generation and paywall display, diagnose product problems, and separately verify basic first-open and checkout-start signals in Firebase;
  • to respond to support requests;
  • to protect the service from fraud and abuse and to comply with legal obligations.

Legal bases for processing (for users in the EEA/UK) are performance of a contract (account, generations and purchases), legitimate interests (first-party product analytics, service improvement, security, diagnostics, support and abuse prevention), consent (push notifications where required) and compliance with legal obligations. We balance our analytics and improvement interests against your rights; you may object to processing based on legitimate interests as described in Section 6.

4. Who we share data with

We share only the data needed for the following services:

  • Suno or another configured AI music provider. Only after you explicitly tap to create a track, we send the prompt, lyrics and generation settings needed to create the audio and cover. The provider returns generated content to us.
  • OpenAI or another configured OpenAI-compatible provider. Only after you explicitly ask the AI lyric writer to generate lyrics, we send that lyrics prompt. When you choose a photo and request a music idea, we send a reduced copy of that photo solely to create the music prompt. The photo is not sent until you choose it, and the provider is not asked to retain it. If the lyrics provider is unavailable, the lyrics request may be processed by Suno's lyrics service.
  • Apple App Store and Google Play. They process payments and subscriptions under their own privacy terms. We exchange opaque account tokens, transaction data and purchase confirmations, not card details.
  • Google Firebase Cloud Messaging. If notifications are enabled, Google processes the FCM token and notification delivery data.
  • Google Firebase Analytics. Google separately processes the limited basic app analytics events described above, including first app open and subscription checkout starts.
  • Hosting and infrastructure providers. They store the application database, our first-party product analytics events, generated audio and cover files, backups and security logs on our behalf.

AI providers may retain and use prompts, lyrics and generated output under their own terms and privacy notices, including for safety, service improvement or model development. Do not submit confidential, sensitive or third-party personal information in a prompt or lyrics. We require service providers to protect data appropriately, but their independent retention obligations may differ from ours.

We do not sell personal data, share it with data brokers, use it for third-party advertising, or track you across other companies' apps or websites. We do not use Apple's advertising identifier.

5. Storage and retention

We keep the anonymous account, note ledger, generation records, prompts, lyrics and generated audio while your account exists so your library remains available. Raw first-party product analytics events are kept for no more than 365 days from the event date, then deleted or converted into aggregated, de-identified statistics that can no longer be linked to an account or session. An FCM token is kept until you disable notifications, the token becomes invalid or you delete the account. Purchase and subscription history is kept while the account exists and may be retained longer only where tax, accounting, fraud-prevention or other law requires it. Routine server/security logs are normally retained for up to 30 days.

When you confirm account deletion, account records, note balance, generation history, purchase records, active push tokens and first-party product analytics events linked to the account are deleted from the active application database. Generated audio, cover files, transient logs and other residual active-system copies are permanently purged within 30 days; encrypted backups, which may temporarily still contain those records but are not used for product analytics, age out within 90 days. A narrowly limited record may be retained longer if law requires it. AI providers process deletion under their own policies; contact us and we will forward or support an applicable provider deletion request where reasonably possible.

6. Your rights

  • Access, notification choice and deletion. You can see your identifier, balance and history in the app, disable push notifications in Settings, and initiate full account deletion under Settings → Danger zone → Delete account. See the Account Deletion page.
  • GDPR rights. If you are in the EEA or the UK, you have the rights of access, rectification, erasure, restriction of processing, data portability and objection, and the right to lodge a complaint with a supervisory authority. To exercise these rights, write to [email protected].

Because accounts are anonymous, we may need the user identifier shown in Settings to locate the account. Deleting an account does not cancel an App Store or Google Play subscription, because the store controls billing; cancellation instructions are on the Account Deletion page.

7. Children

The service is not directed to children under 13, and we do not knowingly collect their data. If you believe a child is using the service, let us know and we will delete the relevant data.

8. Changes to this policy

We may update this policy. We will announce material changes in the app or on this page and update the effective date. Continuing to use the service after an update means you accept the new version.

Ritzma

Music from your words. Create songs with AI right from your phone.

Questions or ideas? Write to: [email protected]

Product

Features How it works Pricing FAQ

Legal

Privacy Terms of Service Refund Policy Support Account Deletion

Language

EN UA RU

© 2026 Ritzma. All rights reserved.