Gana

Gana — Legal

Privacy

Privacy Policy · Effective July 16, 2026

Gana turns text into songs. To do that we need very little about you, and this page says exactly what that is — in plain English, because a privacy policy you can’t read isn’t a policy.

The short version

What we collect and why

Your song inputs

The text you type, any optional names you specifically ask Gana to sing, and the vibe and mood choices you make are used for one purpose: creating and saving your song. If you sign in, Gana may privately sync this draft to your Gana account so it can survive an app restart and be restored on your devices. Private draft sync sends the draft only to Gana’s backend; it does not send the draft to an AI model provider. When you tap the clearly named generation action or confirm the final check, Gana sends the minimum content needed from our server to Google’s Gemini and Lyria models through OpenRouter. If you are not signed in and do not start generation, your input stays on your device. We do not sell your content or use it for advertising.

Microphone access

The shipping version of Gana does not request microphone access and does not upload, analyze, or clone microphone audio. If a future version adds humming or voice-reference creation, Gana will update this policy and ask for permission at the moment that feature is used.

Apple sign-in

When you sign in with Apple, we receive a short-lived identity token and single-use authorization code that prove it’s you, then issue a Gana session. Our server keeps Apple’s refresh token encrypted and linked through a one-way account index only so we can ask Apple to disconnect Gana when you delete your account. We never see your Apple password, and if you use Hide My Email we only ever see the relay address.

When you delete your Gana account, the refresh token is detached from your account and placed in an encrypted revocation queue. During that bounded retry only, a one-way account index prevents a newly recreated account from racing the older revocation. We try Apple immediately and retry for up to seven days without delaying deletion of your Gana account or songs. When Apple confirms, both the token and index are removed. If Apple still has not confirmed at the seven-day boundary, we destroy both and keep only a random, token-free, owner-free operational failure record until the incident is acknowledged. Gana tells you how to remove the authorization manually in Apple Account settings; the record cannot identify you or restore the token.

If you disconnect Gana from Sign in with Apple outside the app, a physical iPhone reports that credential change so Gana can invalidate its session and sign the device out. That action does not itself delete your saved Gana songs or purchase history; use Delete account in Gana or contact support for deletion.

Purchases

All payments go through Apple. RevenueCat processes an opaque Gana billing identifier, purchase history, and entitlement status so credits and subscriptions work across reinstalls, and so we can measure and diagnose purchase completion. The identifier is a random UUID and does not contain your email address or Apple sign-in subject. If you delete your Gana account, Apple may still finish a purchase awaiting approval or continue an active subscription. We therefore keep a content-blind purchase-continuity record keyed by that opaque UUID for at least 31 days and, for an active subscription, through 31 days after its current expiration. It contains only the minimum product, transaction-chain, expiration, cadence, and remaining subscription-allowance fields needed for the same verified sign-in to resume that paid period; it never contains song content, contact data, a canonical sign-in identifier, or consumable credits. The continuity record is consumed when that verified account returns or erased at the end of the bounded window. A separate pseudonymous purchase-event audit may remain longer and can include the opaque UUID, product and event type, transaction and payload hashes, event timing, environment, and processing outcome. That audit is used only to prevent duplicate grants, reconcile refunds or chargebacks, and preserve transaction integrity; it is not account-routing or entitlement-recovery authority. After operational continuity ends, a content-free UUID, secret-keyed one-way account match, and deletion timestamps also remain so the same verified sign-in can reuse its original RevenueCat identity without moving an Apple purchase to another Gana account. We never see or store your card number, and purchase data is not used for advertising or cross-app tracking.

Basic technical data

Like nearly every online service, our servers see your IP address when your app talks to them. We use it for rate limiting and abuse prevention (for example, protecting the one-preview offer and capping automated preview abuse) and for nothing else.

Product interaction analytics

We record a small, first-party event trail so we can tell whether onboarding, preview playback, purchases, generation, and sharing work. On an unlisted share page, this includes page load, player start/completion/error, Create your own, and Report taps. Events use a random session identifier and may include the app or web screen, product identifier, stable error code, model name, or coarse timing bucket. Public-share analytics do not include the bearer share ID or song title. Events never include your prompt, names to sing, lyrics, audio, voice recording, email, Apple token, purchase receipt, advertising identifier, or raw device identifier. Raw events are deleted after 30 days and are not used for advertising or cross-app tracking.

What we don’t do

How long we keep things

Finished songs appear in your Gana library and can be exported to your device when that feature is included in your purchase. If you choose to create a Gana share link, we host that MP3 and its title so the recipient can play it from the link. A share link is unlisted, not access-controlled: anyone who receives or forwards it can listen until you revoke the link or delete the song. To make the one free preview recoverable, we privately retain the earned 15-second preview, limited preview lyrics, and a private 30-second source clip. They are keyed to a one-way hash of the app installation’s random identifier; the private source clip is never returned by the free-preview route or made public. If you sign in to create a full song from the saved brief, Gana associates the hashed installation identifier with your account to authorize that saved brief and prevent duplicate grants. Buying completion creates a separate Lyria Pro song from the same confirmed brief and lyrics; melody, vocal, timing, and arrangement may vary. The saved preview remains replayable and is not the purchased full performance. We retain the private preview package until an explicit preview-deletion request is sent from that installation or we complete a verified account-deletion request. Deleting the saved concept removes its preview audio, private source audio, and limited lyrics, but leaves a content-free “preview used” tombstone so deletion cannot reset the one-preview offer. Otherwise, on our servers we keep the minimum needed to run the service: your Apple-linked account reference, your purchase entitlements, incomplete or failed generation jobs for up to seven days, and content-blind product interaction events for up to 30 days. A successfully purchased finished-song recording, including its MP3, is retained privately until you delete your account so we can replay the exact paid result and refresh short-lived sharing authorization without charging you again. It is not available through a share link unless you intentionally create one. Account deletion removes retained paid recordings, private preview packages, hosted shares, contact data, and existing unused consumable credits. If Apple sends a supported purchase or subscription event after deletion, its validated RevenueCat event is held without song content and applied only if the same verified account returns before the bounded settlement window closes. If an Apple subscription is still active, we retain the minimum subscription-continuity fields needed to recognize its product, expiration, transaction chain, cadence, and remaining subscription allowance. The operational continuity record and deferred events are consumed when the same verified sign-in reactivates or erased when that window ends. The separate pseudonymous purchase-event audit described above may remain longer, but cannot reactivate an account or restore credits by itself.

Deleting your data

For an anonymous earned preview, open Settings → Privacy & data → Delete saved concept. Gana sends an installation-authenticated deletion request that removes its preview audio, private source audio, and limited lyrics while keeping a content-free one-preview-used tombstone. For a signed-in account, open Settings → Account → Delete account and confirm. After the authenticated request succeeds, Gana removes the account and associated server-side data described above, signs the device out, and erases that account’s songs stored inside Gana on the device. Files you previously exported to Files or another app are outside Gana and are not removed. Deleting Gana does not cancel a subscription billed by Apple. Manage or cancel renewal in Gana’s subscription support screen or Apple’s subscription settings; access normally continues through the paid period. If you later return, use the same sign-in and Restore Purchases. Email support@trygana.app if you cannot access the app; we’ll verify the request and complete it within 30 days.

Children

Gana is designed as a 17+ experience for App Store review. We don’t allow accounts for anyone under 13, and we don’t knowingly collect data from children. If you believe a child has used Gana, contact us and we’ll delete the data.

Your rights

Everyone: you can ask us what we hold about you, ask us to correct it, ask for a copy, or ask us to delete it — all via support@trygana.app. We’ll never treat you worse for exercising a privacy right.

If you’re in the EU/UK (GDPR): our legal bases are performance of a contract (making the songs you asked for), legitimate interests (keeping the service safe and un-abused), and consent (third-party AI processing). You also have the right to withdraw consent before a future generation, to object, to restrict processing, and to lodge a complaint with your local supervisory authority.

If you’re in California (CCPA/CPRA): you have the right to know, delete, and correct. We do not sell or share personal information, so there is nothing to opt out of — but the right is yours regardless, and requests go to the same address.

Security

Traffic between the app and our servers is encrypted in transit (TLS). Sign-in tokens are signed and expire. No one can promise perfect security — anyone who does is selling something — but we keep the surface small by simply not collecting much.

Where data is processed

Our servers and providers process data in the United States. If you use Gana from elsewhere, your inputs travel there to be turned into songs.

Changes

If this policy changes, we’ll update the effective date at the top and, for anything meaningful, say so in the app. We won’t quietly weaken it.

Contact

Questions, requests, complaints: support@trygana.app. Operator: Fahad Khan, an individual. Service address: 1321 South Philly Road, Lombard, Illinois 60148, United States.