Privacy Policy
Effective July 2026
Privacy Policy
Effective August 2026
Introduction
Veinote AB (“Veinote”, “we”, “us”, “our”) operates veinote.com and the Veinote platform. This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use Veinote, and the rights and choices available to you.
Veinote AB is the data controller responsible for the processing of personal data described in this policy.
For questions about your privacy or personal data, you can contact us at support@veinote.com.
Information we collect
Information you provide directly. When you create and use a Veinote account, we collect your name, email address, account information, and any information you choose to add to your profile. During onboarding we may also ask a few optional questions — for example what kind of songwriter you are and what you want to get out of Veinote — which we use to personalise your experience and understand our users better.
Your creative content. We store the creative content and project information you create or upload to Veinote, including lyrics, voice recordings, audio files, images, documents, notes, and other project data.
Waitlist signups. If you join our waitlist before having an account, we collect your email address, the page you signed up from, and any answers you choose to give to our signup questions. We use this to contact you about your access and, with your consent, to send you relevant updates before launch.
Technical and usage information. When you use Veinote, we may automatically collect certain technical and usage information, such as your IP address, browser and device information, pages and features you use, session information, and diagnostic or error data. We use this information to operate, secure, understand, and improve the service.
Support and feedback. If you contact us for support or provide feedback, we collect the information you choose to share with us in those communications.
How we use your information
We use your information to provide, maintain, secure, and improve Veinote.
This includes creating and managing your account, saving and syncing your projects and creative content, providing the features and tools available on the platform, enabling the collaboration and community features described below, responding to support requests and feedback, sending important account and service-related communications, moderating content shared with other users, preventing misuse and security threats, and understanding how Veinote is used so we can improve the service.
With your consent, we may also send you marketing communications — see “Marketing communications” below.
We do not sell your personal information.
Your content
Everything you create or upload to Veinote remains yours. This includes your lyrics, recordings, audio files, images, documents, notes, and other creative or project content.
Veinote does not claim ownership of your content. We store and process it only as needed to provide, maintain, secure, and support the service — including, where you choose to use them, the sharing and collaboration features described in the next section.
Sharing, collaboration & community
Veinote includes features that let you work and connect with other people. When you use these features, some of your information may become visible to other users.
Your public profile. Other signed-in Veinote users can see a limited profile: your name, your profile photo if you have added one, the type of songwriter you identified as during onboarding, and general activity information such as when you joined and when you were last active. You can change your name and photo at any time from your profile page. Your email address, account details, and private content are never part of this profile.
Collaboration. When you invite someone to collaborate by email, we use that address only to record and deliver the invitation. Invitations are handled the same way whether or not the address already belongs to a Veinote account, and the person inviting is not told whether an address is registered with Veinote. Collaborators you add to a project can see and work with the content in that project.
Publishing to the community. If you choose to publish a song to the Veinote community, the published content — such as the song, its lyrics, the names of its contributors, and any ownership split you have recorded — becomes visible to other Veinote users. Content you do not publish stays private to you and your collaborators.
Moderation. Content shared with other users may be reviewed by Veinote if it is reported or if we have reason to believe it violates our Terms or the law. If content is removed, we may retain a copy for a limited period where necessary to handle disputes, comply with legal obligations, or prevent repeated abuse.
When you report content, we record your report — including your account and the reason you give — so that we can review it, follow up where needed, and prevent misuse of the reporting system.
AI features and your creative content
We do not use your private creative content to train AI models.
Some Veinote features use AI to do their work — for example transcribing a voice recording, recognising an instrument in a recording, extracting text from a photo or document, or checking the spelling of a word. When you use one of these features, the specific content that feature needs — for example the recording you asked to have transcribed, or the individual word being spell-checked — is sent to our AI service provider, Google, and processed by its Gemini models to produce the result you asked for.
This processing happens only when you actively use an AI feature, and only on the content that feature needs. Google may keep logs of this processing for a limited period solely to detect and prevent abuse of its service. Your creative content is not used to train Veinote’s own AI models or general-purpose AI models provided by third parties, and we do not grant our AI providers the right to use your content for model training.
Legal bases for processing
We process personal information only when we have a valid legal basis to do so.
We rely on the following legal bases:
Performance of a contract — when processing is necessary to create and manage your account, store and sync your content, and provide the features and services you request, including the AI, collaboration, and community features you choose to use.
Legitimate interests — when necessary to maintain and improve Veinote, provide support, moderate shared content, prevent fraud or misuse, protect the security of the platform, and understand how the service is performing — including the cookie-free, aggregate-level analytics described below — where those interests do not override your privacy rights.
Consent — where we ask for your permission, for example for the optional analytics technologies described below, marketing communications, or optional features. You can withdraw your consent at any time.
Legal obligations — when we need to process or retain information to comply with applicable laws, regulations, accounting requirements, or lawful requests from authorities.
Cookies & analytics
We use cookies and similar technologies to operate Veinote, keep you signed in, remember your preferences, and understand how the platform is used. They fall into three groups.
Strictly necessary. Some cookies and storage are required for Veinote to function at all — for example keeping you signed in and remembering your cookie choice. These do not require consent.
Cookie-free, aggregate analytics. We use PostHog, hosted in the European Union, to understand overall traffic and usage — pages viewed, referrers, device type, and country. For visitors who have not accepted analytics, this runs in a strictly limited mode: nothing is stored on your device (no cookies, no local storage), you are not identified, no profile is created, your visit cannot be connected to any other visit, and sessions are never recorded. This includes approximate, country-level location derived from your IP address. No precise location is ever collected. We rely on our legitimate interest in understanding how Veinote is used to run this aggregate measurement.
Optional analytics (only with your consent). If you choose “Accept all” in our cookie banner, we additionally enable:
- PostHog in full mode — your usage is connected to your account across visits, and sessions may be recorded to help us understand and improve the product. Session recordings capture your navigation and interactions, not your words: all text on the page — including anything you type and any lyrics or other creative content shown on screen — is masked and never included in a recording.
- Microsoft Clarity — usage analytics and session insights such as pages viewed, clicks, and scrolling.
- Google Analytics for Firebase — aggregate usage statistics.
You can withdraw or change your consent at any time using the cookie settings available on this page and in the footer. Withdrawing consent stops the optional technologies from that point onward.
Embedded media. Some pages contain embedded content such as YouTube videos (which we embed in privacy-enhanced mode where possible), Vimeo videos, or Spotify players. When you play embedded media, the provider may collect data and set cookies under its own privacy policy.
Marketing communications
With your consent, we may send you emails about Veinote — for example news about your waitlist access, new features, or offers.
Every marketing email we send includes a working unsubscribe link, and you can opt out at any time without affecting your account. Service and account emails — such as security notices, receipts, collaboration invitations, or responses to your support requests — are not marketing and are sent as part of providing the service.
Third-party services
Veinote relies on trusted third-party service providers to operate and support the platform. Our current providers include:
- Firebase (Google) — authentication, database services, file storage, and (with your consent) analytics.
- Google (Gemini API) — processing for the AI features described above.
- PostHog — product analytics, hosted in the EU.
- Microsoft Clarity — analytics, with your consent.
- Paddle — our payment partner. Paddle acts as the merchant of record for purchases, which means Paddle processes your payment and billing details directly under its own privacy policy. Your card details are handled by Paddle and never touch Veinote’s servers.
- Email delivery providers — to send the account, service, and (with consent) marketing emails described in this policy.
These providers may process personal information on our behalf or, in some cases — such as Paddle — as independent controllers for their own purposes. We select providers that offer appropriate privacy and security safeguards and require those acting on our behalf to handle personal information in accordance with applicable data protection laws.
International data transfers
Veinote is based in Sweden, and our product analytics is hosted within the European Union. However, some of the service providers we use — including Google and Microsoft — may process or store personal information in countries outside the European Economic Area (EEA), such as the United States.
When personal information is transferred outside the EEA, we take appropriate steps to protect it in accordance with applicable data protection laws. Depending on the destination and provider, these safeguards may include an adequacy decision by the European Commission (such as the EU–U.S. Data Privacy Framework for certified U.S. providers) or approved contractual safeguards such as Standard Contractual Clauses.
You can contact us at support@veinote.com if you would like more information about how we protect personal information transferred internationally.
Data security
We use appropriate technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure.
These measures include encrypted connections, access controls, secure authentication, restricted administrative access, and monitoring designed to help protect Veinote and its users.
No system can be guaranteed to be completely secure. If a personal data breach occurs, we will investigate it and notify affected users and relevant authorities where required by law.
Data retention & deletion
We keep personal information only for as long as necessary to provide Veinote, fulfil the purposes described in this policy, and comply with applicable legal obligations.
Your account information and creative content are generally retained for as long as your account remains active. If you delete content or close your account, some information may remain temporarily in backups, system logs, or other technical systems before it is permanently deleted.
Waitlist information is kept until we have completed our launch communications or you unsubscribe, whichever comes first. Support correspondence is kept for as long as needed to handle your request and for a reasonable period afterwards. Content removed through moderation may be retained for a limited period as described in “Sharing, collaboration & community”.
Certain information may also be retained for longer where required by law, for security purposes, to prevent fraud or misuse, or to establish, exercise, or defend legal claims.
You can request deletion of your account and associated personal information at any time by contacting us at support@veinote.com.
Your rights
Depending on where you live and the applicable law, you may have rights regarding your personal information.
These may include the right to access the personal information we hold about you, correct inaccurate information, request deletion or restriction of processing, receive certain information in a portable format, object to certain types of processing (including processing based on our legitimate interests), and withdraw consent where processing is based on your consent.
You also have the right to lodge a complaint with a relevant data protection authority. For Veinote AB, the lead supervisory authority in Sweden is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
To exercise your rights, contact us at support@veinote.com. We will normally respond to verified requests within one month, as required by applicable law.
Children’s privacy
Veinote is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under the age of 18.
If we become aware that we have collected personal information from someone under 18, we will take appropriate steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to Veinote, our services, or applicable laws and regulations.
When we make material changes, we will take reasonable steps to inform you, for example by posting a notice on the platform or sending you an email where appropriate.
The effective date at the top of this Privacy Policy will always show when the latest version became effective.
Contact us
If you have questions about this Privacy Policy, how we handle your personal information, or if you would like to exercise any of your privacy rights, you can contact us at:
Veinote AB
Registration number: [XXXXXX-XXXX]
Registered address: [ADDRESS]
Sweden
Email: support@veinote.com
Veinote AB is the data controller responsible for the processing of personal information described in this Privacy Policy.
You haven't chosen yet on this browser.