Privacy Policy

Who controls your data at MigosAI, what we collect, why, who processes it, how long we keep it, how we handle children’s data, and how to exercise your rights.

Last updated: 2026-09-30

This policy covers migosai.io and everything you do while signed in. It is written to be read, not filed. If something here is unclear, write to privacy@migosai.io and we will explain it.

Who is responsible

MigosAI is the data controller for the personal data described here. MigosAI is operated by its founder as a sole trader, not as a company. Privacy contact: privacy@migosai.io.

What we collect

Account data. Your email address, and the display name and profile picture you choose. If you sign in with Google, Google sends us your email address, name and profile picture — we never receive your Google password. If you sign up with an email and password, we store a one-way hash of the password, never the password itself.

What you type into the tools. The lyrics topic and notes you write, the settings you choose (quality, length, format, layout), and the prompt the system builds from them. Prompts are stored with the result they produced.

What you generate. The booth photo previews and generated videos. Your photos, previews and videos are private to your account; we never publish them.

Photos of the performers. The two photos you upload are photos of real people, so we handle them strictly. Each photo is checked by an automated NSFW classifier before it is stored; a rejected photo is never kept. Accepted photos are stored in a private storage bucket that has no public address, are shown back to you only through short-lived signed links, and are deleted 24 hours after upload. They are sent to the AI model providers listed below only to generate the booth photo and video you asked for. We do not publish them and do not use them to train any model. By uploading a photo you confirm that you have the consent of the people in it.

Uploaded audio and video. Using your own audio or a reference video is coming soon and is not available today. When it becomes available, the file will be stored privately, used only for that generation, and deleted 24 hours after upload.

Photos and settings kept in your browser. While you sign in or check out, your photos and settings stay in your own browser storage for up to 24 hours so you do not lose them. They are not sent to us until you submit them.

Purchase records. The order number, what was bought, the amount, the currency, the date, the payment status, and the payment record our processor returns to us. Card numbers and bank details never reach our servers — they go directly to our payment processor. We also keep your credit balance and a ledger of how credits were granted and spent.

Moderation records. The outcome of every automated content check on your prompts, photos and results, and any decision a person makes when reviewing it. When a text is blocked we also keep the blocked text (up to 500 characters) so it can be reviewed and appealed. When an uploaded photo is rejected we log the attempt (which account, when, and the classifier verdict) but do not store the image.

Support messages. Anything you send to one of our mailboxes, and our replies.

Usage and device data. Server logs generated by our hosting provider (IP address, URL, response code, timestamp, user agent, referrer), and product analytics events such as which tool was opened or whether a generation succeeded, tied to a random identifier. We may use privacy-friendly analytics; we will list any analytics provider here before enabling it.

Cookies and similar storage. A session cookie so you stay signed in; a random analytics identifier; a utm_source cookie for 30 days if you arrive from a campaign link; and local storage for interface preferences. Any optional cookies would be set only after you click Accept in the cookie banner, and you can change your choice at any time from Cookie settings in the footer. We do not use advertising cookies.

  • Running your account and delivering what you asked for — authentication, generation, credits, subscriptions. Legal basis: performance of a contract.
  • Taking payment and preventing fraud, including abuse of free credits. Legal basis: performance of a contract; legitimate interests.
  • Moderating prompts and generated content under the content policy. Legal basis: legitimate interests in running a safe, lawful service; legal obligation where content is illegal.
  • Support, billing and refund requests. Legal basis: performance of a contract.
  • Security and availability — rate limiting, abuse detection, logs. Legal basis: legitimate interests.
  • Improving the product through analytics. Legal basis: legitimate interests.
  • Service email — verification, password resets, receipts. Legal basis: performance of a contract.
  • Tax and accounting records. Legal basis: legal obligation.

We do not sell your personal data, we do not use it for targeted advertising, and we do not use it for automated decisions that produce legal effects for you.

Who we share it with

We use the following processors. Each receives only what it needs.

  • Cloudflare (hosting, Workers, D1 database, R2 storage) — everything the service stores or serves, including your uploaded photos in a private R2 bucket.
  • AI model providers — the third parties that run the models named in the AI models we use list: fal.ai (which hosts Kling, Seedance 2.0, nano-banana, ElevenLabs Music and the image safety classifier), and OpenRouter (which routes the lyrics request to DeepSeek). They receive the prompt text and the inputs a step needs, such as the performer photos for the booth photo and the video. They receive no account data. For the video steps, fal.ai forwards these inputs to the company that makes the model — Kuaishou (Kling) and ByteDance (Seedance) — which processes them and runs its own safety checks.
  • Waffo (payments and prompt screening) — as our payment processor and merchant of record it receives the details you enter at checkout directly; card numbers never reach our servers. Its Prompt Sift service also receives the prompt text and generated text only, to decide whether it is allowed, and does not store the text it checks.
  • Resend (transactional email) — your email address and the message content.
  • Google — only if you choose to sign in with Google.

We also disclose data where the law requires it, to respond to a lawful request from a public authority, to protect a child's safety, or to establish or defend a legal claim.

International transfers

Our processors operate in the European Economic Area, the United Kingdom and the United States. Where our processors move personal data out of the EEA or the UK, the transfer is covered by the European Commission's Standard Contractual Clauses (and the UK Addendum), or by an adequacy decision. The video model makers that fal.ai forwards inputs to (Kuaishou for Kling, ByteDance for Seedance) may process the performer photos, booth photo, AI rap track and prompt text outside the EEA, the UK and the United States.

How long we keep it

  • Performer photos — deleted 24 hours after upload.
  • Uploaded audio and video — when uploads of your own audio or video become available, deleted 24 hours after upload.
  • Booth photo previews — kept 7 days, then deleted.
  • Generated videos — kept 30 days, then deleted. Download anything you want to keep.
  • Generated rap tracks and automatic booth photos (made while a video is generated) — deleted as soon as the video is finished or fails. If a deletion fails we retry every hour, and our storage rules remove anything left within 2 days.
  • Account data — kept while the account exists.
  • Orders, invoices and the credit ledger — kept for at least 7 years, because tax and accounting law requires it.
  • Server logs — up to 7 days.
  • Support email — 2 years after the conversation ends.
  • Moderation records — kept while they may be needed for appeals and for compliance reviews by our payment partner. The blocked text in them is erased when you close your account; the decision itself is kept.

Closing your account. You can delete your account from Settings → Profile. This cancels any active subscription, deletes your performer photos, generated videos, generated rap tracks and automatic booth photos, ends your sessions, erases the blocked text kept in moderation records, and irreversibly anonymises your name, email address and profile picture. For the photos, videos, tracks and automatic booth photos: we delete them right away; if a deletion fails we retry hourly and our storage rules remove anything left within 2 days (videos within 31 days). The free booth previews you made yourself are removed on their normal 7-day retention schedule and are no longer reachable from any account. Order and credit records are kept for the accounting period above, no longer linked to a usable account.

Security

All traffic is encrypted with TLS. Passwords are stored as one-way hashes. Private results and uploads, including performer photos, live in private storage and are served only through short-lived signed links. Prompt content is redacted and truncated before anything is written to a log. No system is perfectly secure; if a breach is likely to put your rights at risk we will notify the competent authority within 72 hours and tell you directly where the law requires it. To report a vulnerability, write to legal@migosai.io.

Children’s privacy

Some of our visitors are young, so we take this seriously.

  • MigosAI is not directed at children under 13. We do not knowingly collect personal information from a child under 13 without verifiable consent from a parent or legal guardian, as required by the U.S. Children's Online Privacy Protection Act (COPPA) and similar laws.
  • With parental consent, a parent or guardian creates and manages the account for the child, and we collect only what is needed to provide the service: an email address for the account, the prompts and results, and the usage data described above. We do not show a child's name or email on anything public, and we do not use a child's data for advertising.
  • Parents and guardians can, at any time, review the personal information we hold about their child, ask us to delete it, and refuse further collection, by emailing privacy@migosai.io. We will verify that the request comes from the child's parent or guardian before acting on it.
  • If we learn that we have collected personal information from a child under 13 without parental consent, we delete it and close the account.
  • Where the age of digital consent in your country is higher than 13 (for example up to 16 in parts of the EU), that age applies instead.

Your rights

Wherever you are, you have the right to access, correct, delete, restrict or port your personal data, to object to processing based on legitimate interests, to withdraw consent, and to complain to your data protection authority. Email privacy@migosai.io from the address on your account; we answer within 30 days and do not charge for this.

Changes to this policy

We may update this policy. Material changes are reflected in the date at the top of this page and, where appropriate, announced through the service.

Contact

  • Privacy questions, data requests, parents and guardians: privacy@migosai.io
  • Anything else: support@migosai.io
  • Legal notices and security reports: legal@migosai.io
  • Copyright complaints: dmca@migosai.io