Privacy Policy
Effective 26 September 2026
This policy explains what StudioForge AI (studio.viraltrending.online, "StudioForge", "we") collects when you use the service, why, who processes it for us, and how long we keep it.
What we collect
- Account data from Google sign-in: your email address, name and Google account identifier. We request only the
openid,emailandprofilescopes and never receive your Google password. - Audio you upload and the files we generate from it (stems, mixes, mashups, masters, previews), plus the job settings and the directives you type.
- Billing data: your Stripe customer and subscription identifiers and your plan. Card details are entered on Stripe's pages and never reach our servers.
- Usage records: job status and processing time, download events (which file, which format, when) and, on the Free plan, rewarded-ad sessions used to unlock a download.
- Technical data such as IP address and request logs kept by our hosting providers for security and reliability.
How we use it
To sign you in, process the audio you submit, deliver your renders, enforce plan limits (daily downloads, formats, queue priority), bill subscriptions, prevent abuse, and keep the service running. We do not sell your personal data and do not use your audio to train machine-learning models.
Who processes data for us
- Google: sign-in (OAuth) and advertising (Google AdSense display ads and, where enabled, rewarded video ads through the IMA SDK).
- Cloudflare: private storage of uploads and renders (R2) and network protection.
- RunPod: GPU processing for stem separation. Audio is transferred through short-lived signed links.
- Stripe: subscription payments and the billing portal.
- Our application hosting and database providers.
Each provider processes data under its own terms and privacy policy. The ad SDK may set cookies or use device identifiers according to Google's policies and your consent choices where required.
Cookies
StudioForge sets one essential, httpOnly session cookie (sf_session) to keep you signed in, and a short-lived cookie during Google sign-in to protect against request forgery. We do not use analytics or advertising cookies of our own. Pages that show Google ads load Google's ad code, which may set advertising cookies or use device identifiers to serve and measure ads. Visitors in the EEA, the UK and Switzerland are asked for consent through Google's consent message first. You can manage personalised advertising at adssettings.google.com.
Retention and deletion
- Uploads and renders are stored privately until you delete the render from My renders, which removes its files from storage.
- Temporary stems produced during GPU processing are deleted when the job ends.
- Download links are signed and expire after five minutes.
- Account, billing and usage records are kept while your account exists and as long as required for tax, accounting or abuse-prevention purposes. To delete your account, contact us using the address below.
Security
Data is encrypted in transit, storage buckets are private, each user can access only their own jobs (enforced in the database with row-level security), and uploads are validated before processing.
Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal data and to object to or restrict processing. Contact us and we will respond within the time required by applicable law. You can also revoke StudioForge's access in your Google account settings.
Children
StudioForge is not directed to children under 13, and we do not knowingly collect their data.
Changes
We will post updates on this page and change the effective date above.
Questions: bph@abv.bg. See also the Privacy Policy and Terms of Service.