Privacy Policy
Last updated: July 9, 2026
Your privacy matters. This policy explains what data Safi collects, how we use it, who we share it with, and how long we keep it. Safi is operated by Akili Tech.
1. Data We Collect
- Account information — email address, display name (optional), and authentication identifiers from Google or Apple if you sign in via OAuth.
- Content you submit for analysis — song lyrics, melody notes, voice notes, style tags, and (when you choose to upload one) uploaded audio files.
- Analysis reports — the structured similarity assessment we generate from your submitted content.
- Billing information — handled entirely by Stripe. We receive a customer ID and subscription status; we never see or store your card details.
- Usage data — counts of analyses run, timestamps, and basic technical logs for service operation.
2. Audio Retention — How It Works
Uploaded audio files are deleted after analysis by default. If you opt in via “Keep my file” when uploading, your audio is stored for 30 days so you can re-run the check, then deleted. Fingerprint data and analysis results are retained as part of your report history so you can revisit them. We do not use your music to train any AI model.
3. How We Use Your Data
- To run analyses and deliver reports to you.
- To improve accuracy of our matching and citation verification.
- To process payments and manage your subscription.
- To send transactional emails (password reset, payment failures, account notifications).
- To diagnose technical issues and prevent abuse.
We do not sell your personal data. We do not share your content with third parties for marketing.
4. Third-Party Processors
Safi is built on a small set of trusted infrastructure providers. Each processes a specific category of data on our behalf:
| Provider | Purpose | Data shared |
|---|---|---|
| Anthropic (Claude) | AI analysis of lyrics, melody, structure, voice | Submitted song content (no account identifiers) |
| Stripe | Payment processing, subscriptions, invoicing | Email, customer ID, billing details |
| Supabase (Postgres) | Application database (accounts, reports, usage) | Account info, analysis reports, usage records |
| Firebase | Authentication (Google/Apple OAuth) | Email, OAuth identifier |
| Resend | Transactional email delivery | Email address, message content |
| Railway | Application hosting | Standard server logs (IP, request timing) |
| AudD & music data sources | Audio fingerprint match against commercial catalogs | Audio file URL (when you upload one) |
5. Data Retention
- Audio files — deleted after analysis by default; kept 30 days only if you opt in via “Keep my file”, then deleted.
- Analysis reports & account data — retained while your account is active.
- Payment records — retained by Stripe per their policies and applicable financial regulations.
- Account deletion — you may request deletion of your account at any time; we will remove your reports and account record within 30 days.
6. Cookies & Local Storage
We use first-party cookies to keep you signed in (NextAuth session). We do not use third-party advertising cookies or cross-site tracking. We may use first-party analytics to understand basic usage patterns; we do not enrich this data with personal identifiers.
7. Safi for Suno (Chrome Extension)
The Safi for Suno browser extension adds a right-click action on suno.com. It is optional and separate from the website.
- What it sends — when you choose “Run Safi on this song”, the extension sends that song’s Suno URL, its title, and — when you are on the song’s own page and it displays lyrics — the lyric text shown there, to getsafi.app so the check can run. The lyrics are used for the similarity analysis and stored with that report under the retention rules in section 5; they are never used to train any model. Nothing is sent unless you trigger it.
- How it authenticates — it relies on the Safi session cookie already in your browser. The extension never reads, stores, or transmits your password.
- What it does not do — it does not read other tabs, does not access your browsing history, stores nothing on your device, contains no analytics or trackers, and shares nothing with third parties.
- Results — analyses started from the extension are stored in your Safi account exactly like any other check, and are covered by the retention rules in section 5.
8. Your Rights
You have the right to access, correct, export, or delete your personal data. You can manage account information from your account page or contact us to make these requests. Residents of jurisdictions with specific data-protection laws (GDPR, CCPA, etc.) have additional rights as defined by those laws.
9. Security
Data is transmitted over HTTPS and stored on infrastructure that maintains industry-standard security controls. No system is fully secure; we recommend using a unique password and enabling two-factor authentication on your linked Google or Apple account.
10. Children
Safi is not intended for users under 13 (or under 16 in jurisdictions where applicable). We do not knowingly collect data from children.
11. Changes to This Policy
We may update this policy as our practices evolve. Material changes will be communicated by email and reflected by the “Last updated” date above.
12. Contact
Questions about privacy or data requests: support@akilitech.io
← Back to Safi