Privacy Policy

Privacy Policy

Effective date: March 7, 2026

1. Who We Are

Todd – AI Music Insight ("Todd", "we", "our", or "us") is a music intelligence application that helps users identify songs, explore lyrics with AI, and build a personal music story. This Privacy Policy explains how we collect, use, and protect your information when you use Todd.

2. Information We Collect

2.1 Information You Provide

  • Account information: When you sign in via Manus OAuth, we receive your name and a unique identifier. We do not receive or store your password.
  • User-generated content: Lyric annotations, mood tags, collection names, venue check-ins, and any text you submit through the app.
  • Preferences: Settings such as notification preferences, reminder times, and subscription tier.

2.2 Information Collected Automatically

  • Audio data: When you tap the mic to identify a song, a short audio sample (approximately 12 seconds) is captured and sent to our audio fingerprinting provider (AudD) for identification. We do not store raw audio recordings. AudD processes the audio and returns metadata; the audio sample is discarded immediately.
  • Usage data: Songs identified, pages visited, features used, and interaction timestamps — used to personalise your experience and improve the app.
  • Device information: Browser type, operating system, and approximate location (country/city level, derived from IP address) for analytics and concert map features.

2.3 Payment Information

If you subscribe to a paid plan, payment is processed by Stripe. We do not store your full card number, CVV, or billing address. We store only a Stripe Customer ID and Subscription ID to manage your account.

3. How We Use Your Information

  • To identify songs and deliver AI-generated insights, annotations, and lyric analysis.
  • To personalise your music story, mood themes, and recommendations.
  • To operate community features (annotations, reactions, leaderboards, concert map).
  • To send notifications you have explicitly opted into (weekly digest, challenge reminders).
  • To process payments and manage your subscription.
  • To improve the app through aggregated, anonymised analytics.
  • To comply with legal obligations.

4. Audio Data and Microphone Access

Todd requests microphone access solely to capture short audio samples for song identification. This access is only active while you are actively using the "Identify" feature. We do not record ambient audio passively, and we do not store audio recordings. The audio fingerprint is processed by AudD under their own privacy policy, available at audd.io/privacy.

5. Sharing Your Information

We do not sell your personal information. We share data only in the following circumstances:

  • Service providers: AudD (audio fingerprinting), OpenAI (AI-generated insights and annotations), Stripe (payments), and our hosting infrastructure. Each provider processes data only as necessary to deliver their service.
  • Community features: Annotations, reactions, and public profile information you create are visible to other Todd users.
  • Legal requirements: If required by law, court order, or to protect the rights and safety of users.

6. Data Retention

We retain your account data and music history for as long as your account is active. You may delete your account at any time from Settings, which will permanently delete your history, annotations, and profile data within 30 days. Aggregated, anonymised analytics data may be retained indefinitely.

7. Your Rights (GDPR / CCPA)

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your account and associated data.
  • Portability: Request your data in a machine-readable format.
  • Opt-out: Opt out of non-essential communications at any time from Settings.

To exercise any of these rights, contact us at [email protected].

8. Children's Privacy

Todd is not directed at children under the age of 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

9. Security

We use industry-standard security measures including HTTPS encryption, hashed session tokens, and access controls. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy in the app and updating the effective date above. Continued use of Todd after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or your data, please contact us at [email protected].

© 2026 Todd – AI Music Insight. All rights reserved.

Hear a Song? Todd Knows It.

Tap the mic, hold your phone up for a few seconds, and Todd identifies the song — anywhere music plays.

Works at concerts, restaurants, on the radio, in a store.