Privacy Policy
Last updated: September 15, 2026
1. Introduction
This Privacy Policy applies to AIJingleMaker.com, the AI Jingle Maker mobile apps for iOS and Android, and the related tools we publish on this domain (together, "AI Jingle Maker" or "the Service"). It explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you sign in with a Google or GitHub account, section 4 explains exactly what we receive from that account and what we do with it.
2. Data Controller
AI Jingle Maker is operated by adsyme Ltd (trading as Call Me Fred), 86-90 Paul Street, London EC2A 4NE, United Kingdom. adsyme Ltd is the Data Controller for the personal data described in this policy. You can contact us at:
Email: [email protected]
Address: adsyme Ltd, 86-90 Paul Street, London EC2A 4NE, UK
3. Information We Collect
Depending on how you use the Service, we collect the following categories of personal data:
- Account data: your email address, a hashed password (if you register with email), your credit balance, purchase history, and account settings.
- Sign-in data from Google or GitHub: described in full in section 4 below.
- Content you create: the text scripts and prompts you type, the audio files you upload (including voice recordings you provide for voice cloning), the voices and music you select, and the jingles, voiceovers and other audio the Service generates for you.
- Payment data: when you buy credits, our payment providers collect your payment details. We never see or store your full card number or mobile-money credentials. We receive and keep a record of the transaction (amount, currency, date, product, country and a provider transaction ID) together with the email address on the order.
- Support and communication data: messages you send us through the help form or chat, and any account deletion or data requests you make.
- Technical data: IP address, browser type, device and operating system, language, referring page, and cookie or local-storage identifiers.
- Usage data: which pages and features you use, the actions you take in the Service, and errors that occur, collected through our analytics tools.
Voice recordings you upload for voice cloning are used only to create the voice you asked for. We do not use them to identify you or anyone else, and we do not process any other special category data (such as health, racial, political or religious data).
4. Signing In With Google or GitHub
You can create an account or sign in using a Google account or a GitHub account instead of a password. This section explains how we handle the data we receive from those providers.
4.1 What Google user data we access
When you choose "Continue with Google", we request the Google email and profile permissions (OAuth scopes). Through those permissions we receive from Google:
- your Google account email address and whether Google has verified it;
- your name as shown on your Google account.
We do not request access to, and never read, your Gmail, Google Drive, Google Contacts, Google Calendar, Google Photos or any other Google service or content.
4.2 How we use Google user data
- Email address: used to find the AI Jingle Maker account that matches it, or to create a new account if none exists, and to sign you in. Because Google has already verified the address, we mark your account as email-verified. Your email address is then used in the same way as any other account email address (see section 5).
- Name: read during the sign-in step only. We do not store it.
- Google access tokens: used once, at the moment you sign in, to retrieve the two items above. We do not store Google access tokens or refresh tokens, and we do not access your Google account again after sign-in.
We use Google user data solely to provide and improve the sign-in and account features of the Service. We do not use it for advertising, we do not sell it, we do not use it to build profiles of you, and no human at adsyme Ltd reads it except to provide support you have asked for, to investigate abuse or security incidents, or where the law requires it.
AI Jingle Maker's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4.3 GitHub sign-in
When you choose "Continue with GitHub", we request the GitHub user:email permission and receive your primary verified email address and your GitHub display name. We handle them exactly as described for Google above: the email address becomes your account email address, the name is not stored, and the GitHub token is not stored.
4.4 Revoking access
You can withdraw AI Jingle Maker's access to your Google account at any time from your Google account permissions page, and to your GitHub account from your GitHub authorized applications page. Revoking access does not delete your AI Jingle Maker account; to delete the account and the data we hold, follow section 8.
5. How We Use Your Information
We use the personal data described above for the following purposes, and no others:
- Providing the Service: creating and managing your account, generating the audio you request, storing your creations so you can download them again, and processing your purchases.
- Transactional communication: email verification, password resets, purchase receipts, notifications that your audio is ready, and replies to support requests.
- Product news and offers: when you create an account we add your email address to our mailing list so we can send you onboarding tips, product updates and occasional offers. Every such email contains an unsubscribe link, and you can opt out at any time without affecting your account.
- Analytics and improvement: understanding how the Service is used so we can fix problems and improve it.
- Advertising measurement: measuring whether our own advertising campaigns lead to sign-ups and purchases. We do not sell or share your data with advertisers for their own advertising.
- Security, fraud prevention and legal compliance: detecting abuse, protecting accounts, keeping financial records, and responding to lawful requests.
We will never sell, rent or trade your personal data.
6. Legal Basis for Processing
Under the UK GDPR we rely on the following legal bases:
- Contract (Article 6(1)(b)): to provide the Service you signed up for, including sign-in with Google or GitHub, audio generation, storage of your creations and purchases.
- Legitimate interests (Article 6(1)(f)): analytics, advertising measurement, security, fraud prevention, and sending product news to existing customers. You can object to any of these at any time (section 9).
- Consent (Article 6(1)(a)): where we ask for it, for example when you upload a voice recording for cloning.
- Legal obligation (Article 6(1)(c)): keeping tax and accounting records of purchases.
7. Who We Share Data With
We share personal data only with the service providers below, only to the extent needed to run the Service, and under contracts that require them to protect it. We do not transfer, sell or disclose Google user data, or any other personal data, to third parties for any other purpose.
- Hosting and storage: Railway (application and database hosting), Amazon Web Services (S3 storage for your uploaded and generated audio files) and Cloudflare (content delivery, security, and R2 file storage).
- Audio generation: ElevenLabs and Hume AI receive the text you ask us to voice and, for voice cloning, the recordings you upload. Stability AI receives text prompts when you ask us to generate cover artwork or images. These providers receive your content, not your account details.
- Payments: Paddle (our merchant of record for card and wallet payments worldwide) and Startbutton (mobile-money and local payments in African markets) receive your email address and payment details when you buy credits.
- Email: Brevo sends our transactional emails and Flodesk sends our onboarding and marketing emails. Both receive your email address.
- Analytics and advertising measurement: PostHog (product analytics) and Google Ads conversion tracking (advertising measurement). They receive technical and usage data as described in section 11.
- Sign-in providers: Google and GitHub, when you choose to sign in with them (section 4).
We may also disclose personal data if required by law, to protect the rights or safety of our users or the public, or as part of a merger or acquisition of adsyme Ltd, in which case this policy will continue to apply to your data.
8. Data Retention and Deletion
We keep personal data only for as long as needed for the purposes above:
- Account data (including the email address received from Google or GitHub): kept for as long as your account exists, and deleted when your account is deleted.
- Your creations (scripts, uploads, generated audio, cloned voices): kept for as long as your account exists so you can access them, and deleted with your account.
- Purchase records: kept for 7 years after the transaction, as required by UK tax law, even if the account is deleted. These records contain the email address and transaction details only.
- Support messages: kept for up to 24 months after the request is closed.
- Analytics and usage data: kept for up to 24 months, then deleted or anonymised.
- Server logs: kept for up to 90 days for security and debugging.
Deleting your account. You can request deletion of your account and all associated data at any time from the Account page in the Service, or by emailing [email protected] from the address on the account. We complete deletion within 30 days and confirm by email. Deletion removes your account, your creations, your uploaded and cloned voices, and your email address from our mailing lists. Only the purchase records described above are retained. We also instruct our processors to delete the data they hold for you, in line with their own retention schedules.
9. Your Rights
Under the UK GDPR you have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate or incomplete data.
- Erase your data (section 8).
- Restrict or object to processing based on legitimate interests, including analytics and marketing.
- Data portability: receive your data in a structured, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email [email protected]. We respond within one month. You also have the right to complain to the Information Commissioner's Office (details in section 15).
10. How We Protect Your Data
We apply technical and organisational measures appropriate to the sensitivity of the data, including:
- Encryption in transit: all traffic between you and the Service, and between the Service and our providers, uses TLS.
- Encryption at rest: our database and file storage are encrypted at rest by our hosting providers.
- Credential handling: passwords are stored only as salted hashes. Google and GitHub tokens are used once at sign-in and never stored. Payment details are handled entirely by our payment providers and never touch our servers.
- Access controls: production data is accessible only to authorised personnel over authenticated connections, and administrative actions are logged.
- Data minimisation: we collect only what the features you use require, and we store nothing from your Google account beyond your email address.
- Security monitoring and incident response: a documented process for assessing and containing incidents, including notifying the ICO within 72 hours and affected users without undue delay where required.
11. Cookies and Similar Technologies
We use cookies and browser local storage for the following purposes:
- Essential: keeping you signed in, protecting forms against forgery, remembering your language, and remembering a draft you started before signing up. These are required for the Service to work.
- Analytics: PostHog sets an identifier so we can understand how the Service is used and fix problems. This runs by default under our legitimate interest in improving the Service.
- Advertising measurement: the Google Ads tag lets us measure whether our own advertising leads to sign-ups and purchases. It does not serve you ads on our site.
Your choices. You can block or delete cookies in your browser settings; the Service will still work, but you may need to sign in again. You can opt out of Google's advertising measurement at adssettings.google.com, and you can ask us to exclude you from analytics by emailing [email protected].
12. International Transfers
adsyme Ltd is based in the United Kingdom. Some of the providers listed in section 7 process data in the United States or the European Union. Where data leaves the UK we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, on the UK's adequacy regulations for the EU, or on the provider's certification under the UK Extension to the EU-US Data Privacy Framework.
13. Children
The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
14. Changes to This Policy
We may update this policy when the Service, the law, or our providers change. The "Last updated" date at the top always shows the current version. If we change how we access, use, store or share Google user data, or make any other change that materially affects you, we will notify you by email to the address on your account and by a notice in the Service before the change takes effect. Earlier versions are available on request.
15. Contact and Complaints
For any question, request or complaint about this policy or your data:
Email: [email protected]
Address: adsyme Ltd, 86-90 Paul Street, London EC2A 4NE, UK
Website: AIJingleMaker.com
If you are not satisfied with our response, you can complain to the UK supervisory authority, the Information Commissioner's Office (ICO):
Website: https://ico.org.uk/
Phone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF