Privacy Policy
1. The short version
This summary is not a substitute for the rest of the document, but it is accurate.
| Your songs | Generated on your device and stored on your device. We never receive the audio and have no server copy to retrieve. |
|---|---|
| Your lyrics | The text never leaves your device, whether you wrote it or the App did. We record only whether a generation had lyrics. |
| Your prompt | We do receive this. The free-text description you type is uploaded with a record of the generation. Treat a prompt as information you are sending to us, not as something that remains only on your device. |
| Who you are | There is no PocketGroove account or login, and by default we do not ask for your name or email. We use pseudonymous identifiers associated with the App or its installation. We may know your name or email if you voluntarily provide them as a beta tester or contact us. |
| Ads and tracking | None. The App contains no advertising SDK, does not use your data for advertising, and does not track you across apps or websites owned by other companies. |
| Selling data | We do not sell your personal information and do not share it for cross-context behavioural advertising. |
| Training AI | We do not use your prompts, lyrics, feedback, or songs to train AI models. |
| Deleting | Settings → Privacy → Your data → Delete my cloud data deletes the PocketGroove records described in §10. Analytics, crash reports, email, and provider retention are explained separately there because they do not all behave the same way. |
2. Who we are and how to contact us
This Privacy Policy explains how Liminal Studios LLC, a limited liability company organised under the laws of Colorado, of 1500 N Grant St #11258, Denver, CO 80203, United States (“we”, “us”, “our”) handles personal information in connection with the PocketGroove mobile application (the “App”).
Where an applicable privacy law treats the party responsible for deciding why and how personal information is processed as a controller or business, Liminal Studios LLC is that party for the processing we control and describe in this Policy. Whether a particular privacy statute applies depends on its territorial scope and, where relevant, its statutory thresholds.
For everything, including privacy questions, requests under §11 to §13, general support, and legal notices: support@liminalstudios.com. By post: Liminal Studios LLC, 1500 N Grant St #11258, Denver, CO 80203, United States. Inside the App, Settings → About → Contact opens an email to the same address.
The App is currently distributed only in the United States. We do not currently market or intentionally offer it through App Stores in the European Economic Area, the United Kingdom, or Switzerland. §11 explains what happens if one of those privacy regimes nevertheless applies to your use.
Our Terms of Service, which include the Content Policy, are a separate document. This Privacy Policy is not part of them.
3. Who this applies to
The App is for people aged 13 and over. It is not directed to children under 13, we do not knowingly collect personal information from children under 13, and the App is not in the App Store’s Kids Category. See §15.
4. What stays on your device
This is the most important section, because PocketGroove is designed so that the content of the music generation itself remains local.
PocketGroove generates music entirely on your iPhone or iPad. The models ship inside the App. There is no remote rendering or generation server, and generation works without a network connection.
Accordingly:
- Audio is not uploaded to us. Every song is written to the App’s private local storage. We have no server copy.
- Lyrics are not uploaded to us. Whether you wrote them or the App wrote them, they remain on your device. We record only whether a generation used lyrics. The generation record described in §5.2 has no field for lyric text.
- Your library is local. Song titles, cover art, playlists, favourites, ratings, play counts, and saved descriptions and lyrics live in the App’s local storage. PocketGroove does not upload or sync that library to our servers. If you back your device up to iCloud or a computer, the library is included in that backup; the backup is Apple’s and yours, not ours.
- Cover art is generated on your device from the song’s own properties. No cover image is uploaded to us.
- The App does not request access to your device’s precise location services, contacts, calendar, microphone input, Health data, browsing history, advertising or purchase history from other apps, or the list of apps installed on your device. It does not read your Photos library; §5.9 explains the limited add-only Photos permission used when you ask to save a video.
Firebase services used for analytics, performance monitoring, authentication, and crash reporting do receive certain technical device, network, and installation information described in §5.1 to §5.5. That can include device model, operating-system information, memory or storage characteristics, network information, IP-derived approximate location, and provider-generated identifiers. Those diagnostics are different from PocketGroove requesting access to protected device resources such as Contacts or Location Services.
We also cannot prevent you from putting personal or sensitive information into a free-text prompt or an email to us. We do not ask you to do that. See §5.2 and §5.6.
4.1 What is inside your song files
Every song file the App writes carries an inaudible audio watermark that identifies the audio as machine-generated. It is the same fixed pattern in every song for every user. It contains no identifier for you, your device, or your installation, and nothing is sent to us when it is written.
Every file you share out of the App also carries Content Credentials, a signed manifest in the open C2PA format declaring the file to be AI-generated. The manifest records the song’s title, the App’s name and version, and our signature. If you typed the title yourself, that text travels with the file. The manifest contains no identifier for you or your device.
5. What we collect and why
Most information that PocketGroove sends off your device is processed using services from Google Firebase. Firebase services use several different technical identifiers, so we describe them rather than referring to all of them as one anonymous ID.
5.1 Pseudonymous installation and service identifiers
When the App first configures its cloud features, it uses Firebase Anonymous Authentication. Firebase assigns a random user identifier (a Firebase Authentication UID). PocketGroove does not derive that identifier from your name, Apple ID, email address, or the content you generate.
We use that UID as a pseudonymous handle for the PocketGroove records associated with that installation. It lets us associate generation records with one installation and lets the App identify which Firestore records should be deleted when you use Delete my cloud data. You can see and copy the UID under Settings → Privacy → Your data, where the App calls it your installation ID.
Firebase Authentication itself may also process your device’s IP address and user-agent information to provide authentication security and prevent abuse. We do not use those values to identify you.
Other Firebase services generate their own technical identifiers, including:
- an Analytics app-instance ID used by Google Analytics for Firebase;
- a Firebase installation ID used by Remote Config, Performance Monitoring, and Crashlytics; and
- a Crashlytics installation UUID used to associate crash reports with an app installation.
PocketGroove’s build configuration switches off Google Analytics’ collection of Apple’s Identifier for Vendor (IDFV), and the App does not use the advertising identifier (IDFA). None of the identifiers above are used by us for advertising or cross-context tracking.
These identifiers are pseudonymous, not proof of your real-world identity. Different Firebase services retain or reset them on different schedules, which is why §9 and §10 describe deletion service by service rather than promising that deleting one identifier automatically erases every other Firebase dataset.
Purpose: operating and securing the App, associating records with an installation, configuring features, measuring usage and performance, diagnosing faults, and honouring deletion requests.
5.2 A record of each song you generate
When you generate a song, the App sends one record to Cloud Firestore. It contains:
- The free-text description (“prompt”) you typed. This is the only free-text generation content we receive automatically, and we receive all of it.
- The requested duration and, where you set them, the tempo, vocal language, and vocal style.
- Whether the song had lyrics or was instrumental. Not the lyrics.
-
The quality step count, App version, your device model identifier (for example
iPhone16,1), your device’s installed memory in whole gigabytes, and your iOS version (major and minor only). - Whether generation succeeded and, if not, an error category. The record has no field for a raw error message, so your prompt or lyrics cannot arrive inside one.
- Whether you kept or discarded the result, and any rating you give it.
- A timestamp, and whether the installation is a beta build.
Purpose: understanding which musical requests the App handles well and which it fails, sizing and prioritising engineering work, and diagnosing faults on specific hardware.
Where a law requiring a stated legal basis applies: we rely on our legitimate interests in operating, debugging, securing, and improving the App, except where applicable law requires a different basis.
5.3 Product analytics
The App uses Google Analytics for Firebase to record named events describing how the App is used: onboarding steps completed, generations started and finished, songs kept, discarded, played, or shared, playlists created, searches run, settings opened, legal documents opened, and error conditions encountered.
Two properties of our analytics instrumentation are deliberate:
- We do not send free-text user content to Analytics. Our custom Analytics events do not include your prompt, lyrics, song title, or search text as parameters. Parameters are drawn from a fixed set of enumerated values, counts, and durations, and automated tests in our build fail if a free-text parameter is added to a custom event or the event schema changes without review.
- We do not export Analytics event data to BigQuery or another data warehouse. We ordinarily use aggregate Analytics reports. Google Analytics itself nevertheless stores user- and event-level data for its configured retention period and provides tools that can show activity associated with an individual Analytics user or app-instance identifier.
Our custom events use the Firebase Authentication UID from §5.1 as an Analytics user ID. Analytics user properties also record whether an installation is a beta build and whether beta contact details were provided under §5.7. Those properties do not contain the contact details themselves.
Google Analytics also receives technical information needed to provide the service, including provider-generated identifiers and app/device information.
IP address and approximate location. When the App communicates with Google, Google’s servers necessarily receive network information including your IP address. Google Analytics uses IP information for service operation and can derive approximate geographic information such as country, region, and city. PocketGroove does not request access to iOS Location Services and does not receive your precise GPS location.
Purpose: understanding how the App is used, finding features that are confusing or unsuccessful, and improving the product.
Where a law requiring a stated legal basis applies: we rely on legitimate interests in understanding and improving the App, subject to any consent requirement that applicable law imposes on analytics or information stored on or read from your device.
5.4 Performance measurements
The App uses Firebase Performance Monitoring to measure technical performance. The measurements include generation duration, time until first audible sound, per-stage timings, audio-decode timings, and other performance traces.
Firebase Performance Monitoring can process a Firebase installation ID, IP address, session and App information, device and operating-system characteristics, hardware characteristics such as memory or storage information, network characteristics, and performance measurements. IP addresses are used by Firebase Performance Monitoring to map events to a country.
Where Performance Monitoring measures a network request, the service may process information about the network resource and response needed to measure performance. PocketGroove does not put your prompt, lyrics, song title, audio, or network payload content into performance attributes.
Purpose: measuring and improving generation speed, reliability, resource use, and performance across supported hardware.
Where a law requiring a stated legal basis applies: we rely on legitimate interests in operating, debugging, and improving the App, subject to any consent requirement imposed by applicable law.
5.5 Crash and error reports
The App uses Firebase Crashlytics for crash reports and selected non-fatal error reports. Crashlytics may receive information such as a Crashlytics installation UUID, Firebase installation ID, timestamps, App and build version, device and operating-system characteristics, memory or storage state relevant to the failure, stack traces, thread and process information, and the technical error or exception information needed to diagnose the problem.
PocketGroove sets the Firebase Authentication UID from §5.1 as a Crashlytics user identifier so that repeated problems associated with the same pseudonymous installation can be recognised.
Because PocketGroove also uses Google Analytics, Crashlytics may include Analytics breadcrumb events describing actions immediately before a crash or non-fatal error. Our custom Analytics events are subject to the no-free-text controls described in §5.3.
We do not attach your prompt, lyrics, generated audio, song title, or search text to Crashlytics reports. If you are a beta tester and voluntarily give us contact details, §5.7 explains the additional information we attach.
Purpose: finding, reproducing, and fixing crashes and other software faults.
Where a law requiring a stated legal basis applies: we rely on legitimate interests in maintaining the security, reliability, and quality of the App, subject to any consent requirement imposed by applicable law.
5.6 Email you send us
The App has no built-in feedback form. If you write to support@liminalstudios.com, whether from Settings → About → Contact or on your own, we receive your email address, whatever you write, and anything you attach.
This is free text, and we read it. Please do not include information you do not want us to have. The in-app Delete my cloud data action does not delete email correspondence. If you want correspondence deleted, contact us and identify the messages.
Purpose: responding to support, privacy, legal, and product-feedback messages, maintaining records where reasonably necessary, and improving the App.
5.7 Beta testers: an optional name and email
If you are testing the App through TestFlight, the App may ask you once, under the heading “Put a name to your feedback”, whether you would like to tell us who you are. This is optional, you can skip it, and skipping it does not restrict the beta.
If you provide a name and/or email address:
- It is stored on your profile record in Firestore.
- It is also set as information associated with Crashlytics so that we can connect a diagnostic report with the tester who experienced it and, where appropriate, follow up.
- The contact details themselves are not sent as Analytics user properties. Analytics receives only a flag indicating that beta contact details were supplied.
Purpose: running a beta programme in which we can communicate with a tester who experienced a bug. Where consent is a required legal basis: we rely on the consent you give when you choose to provide the information, and you may withdraw it.
Separately, if you submit feedback or screenshots through TestFlight itself, Apple processes that information under Apple’s privacy policy. Apple may make TestFlight feedback and diagnostic information available to us as the developer.
5.8 Data queued on your device
If your device is offline, or the Firebase authentication/configuration needed to send a record has not completed, records that the App intends to send are held in an outbox file inside the App’s private storage and sent when possible.
The outbox lives in the App’s private Application Support storage. It is protected by iOS data protection until the device is first unlocked after a restart, and it is not exposed to other apps. Because of where it lives, it is included in an iCloud or computer backup of your device if you make one. It is erased by Delete my cloud data and by deleting the App.
5.9 Adding a video to your Photos library
If you choose Save Video from the share sheet, iOS asks for permission to add to your Photos library. The App uses add-only access: it can write the video you asked it to save and does not use that permission to read your Photos library. Nothing about your Photos library is sent to us.
5.10 Notifications
The App can show a notification on your device when a song finishes rendering. It is off by default, and the App asks for notification permission only when you turn it on under Settings → Notifications. These are local notifications scheduled by the App on your device. PocketGroove does not use a remote push-notification service for this feature, and you can turn notifications off in the App or in iOS Settings.
6. Advertising and tracking
The App does not serve advertisements, does not use your information for advertising, does not request the advertising identifier (IDFA), and does not ask for App Tracking Transparency permission because PocketGroove does not track you across apps or websites owned by other companies.
The pseudonymous identifiers described in §5.1 are used for App operation, analytics, configuration, performance, and diagnostics, not for cross-context behavioural advertising or data-broker tracking.
Our App Store privacy disclosures and privacy manifest must remain consistent with the data practices of the App and the third-party software development kits it contains. If those practices change, we will update the applicable disclosures and this Policy.
7. Who receives information
We do not sell your personal information. We do not share it for cross-context behavioural advertising. We do not disclose it to data brokers.
7.1 Google Firebase and Google Analytics
We use services from Google LLC, including Firebase Authentication, Cloud Firestore, Google Analytics for Firebase, Firebase Performance Monitoring, Firebase Crashlytics, and Firebase Remote Config.
Those services receive the information described in §5 as applicable to each service. Google processes Firebase customer data under its applicable service and data-processing terms. Certain service or operational data may also be processed by Google under the terms applicable to the Google service providing it.
7.2 Apple
Apple distributes the App through the App Store and TestFlight. Information that Apple collects in connection with your Apple account, App Store activity, downloads, TestFlight participation, or feedback submitted directly through Apple is processed by Apple under Apple’s own privacy terms. Apple may provide us with developer-facing distribution, TestFlight, diagnostic, or feedback information.
7.3 Protection by third parties
Third parties to whom the App discloses user data as service providers are required to provide protection of that data consistent with the commitments in this Policy, our agreements with them, applicable law, and the requirements governing distribution of the App.
We may also disclose information:
- When you direct a disclosure. For example, the iOS share sheet sends a song or share video to the app, service, or person you choose. Once it leaves PocketGroove, that recipient’s own terms and privacy practices apply.
- To comply with law. We may disclose information when required by a valid legal obligation, court order, subpoena, or other lawful process.
- To protect rights and safety. We may disclose information where reasonably necessary to investigate or address fraud, abuse, security incidents, threats to safety, violations of our Terms, or legal claims.
- In a corporate transaction. Information may be transferred in connection with a merger, acquisition, financing, reorganisation, bankruptcy, or sale of all or part of our business or assets, subject to applicable privacy law.
8. Where information is stored and processed
We are established in the United States. Google and other providers may process information in the United States and in other locations in which they or their subprocessors operate. Some Firebase services have service-specific processing locations.
If European, UK, Swiss, or another jurisdiction’s international-transfer rules apply to a particular processing activity, we use or rely on the transfer mechanisms made available under the applicable provider agreements and law, such as an applicable adequacy framework or contractual transfer clauses.
Apple independently processes information it receives through the App Store and TestFlight under Apple’s own privacy arrangements and international-transfer mechanisms.
9. How long information is kept
| Information | Retention |
|---|---|
| PocketGroove Firestore profile and generation records, including prompts (§5.2, §5.7) | Until you use Delete my cloud data, submit an applicable deletion request, or we otherwise delete the records. We do not currently apply an automatic expiry to these Firestore generation records because they are used as the historical record of App performance across hardware and musical requests |
| Firebase Authentication UID (§5.1) | Until the corresponding Firebase Authentication user is deleted, which Delete my cloud data does. Firebase Authentication keeps logged IP addresses for a few weeks; after deletion, Google removes the associated authentication information from live and backup systems within 180 days |
| Firebase installation ID (§5.1; used by Remote Config, Performance Monitoring, and Crashlytics) | Until Delete my cloud data deletes it. Google then removes the identifier, and the Performance Monitoring, Remote Config, and Crashlytics data tied to it, from live and backup systems within 180 days. Google states that deleting an installation ID does not delete Analytics data; see the Analytics row. The App receives a fresh installation ID afterwards, which Google treats as a new, unrelated installation |
| Google Analytics user- and event-level data (§5.3) | Our Analytics property is configured for a 14-month user/event-data retention period. Aggregate reports may remain after underlying user-level data expires |
| Firebase Performance Monitoring (§5.4) | Firebase currently keeps IP-associated performance events for 30 days and installation-associated and de-identified performance data for 60 days before beginning removal from its systems |
| Firebase Crashlytics reports (§5.5) | Firebase currently retains crash stack traces and associated Crashlytics/Firebase installation identifiers for 90 days before beginning removal, unless associated user reports are deleted sooner through an available deletion mechanism |
| Email (§5.6) | For as long as reasonably necessary to respond to and maintain the correspondence, satisfy legal or security needs, or until an applicable deletion request requires earlier removal |
| Outbox on your device (§5.8) | Until sent, or until you delete your cloud data or delete the App |
| Songs, library, playlists, artwork, and lyrics | On your device and under your control for as long as you keep them. PocketGroove holds no server copy |
If you delete the App without first using Delete my cloud data, server records already sent to us are not automatically deleted merely because the App is gone. A new installation receives different identifiers and is therefore unable to request deletion of the old installation’s Firestore records from inside the App. If you want those records removed, use the in-App deletion action before uninstalling, or contact us while you still have the installation ID.
Deletion from an active database does not necessarily mean every backup or disaster-recovery copy disappears at the same instant. Our providers may take additional time to complete deletion from live and backup systems under their applicable retention schedules.
We may retain information longer where required by law, reasonably necessary to establish, exercise, or defend legal claims, or necessary to investigate fraud, abuse, or security incidents. We may retain genuinely aggregated or de-identified information that cannot reasonably be associated with you or an installation.
10. Your controls and deletion
| Control | Where | What it does |
|---|---|---|
| Delete my cloud data | Settings → Privacy → Your data | Deletes the Firebase installation ID (§9), then the PocketGroove Firestore records associated with the displayed installation ID (your profile, including any beta contact details, and every generation record and prompt), the local outbox, and the corresponding Firebase Anonymous Authentication account. It requires an internet connection and is confirmed against the server before the App reports success. Afterwards the App detaches the deleted identifier from analytics and crash reporting for the rest of the session and generates a new Analytics app-instance ID |
| Your installation ID | Settings → Privacy → Your data | Shows the Firebase Authentication UID used by PocketGroove so you can identify the corresponding records in a request to us |
| Notifications | Settings → Notifications | Turns the finished-song local notification on or off (§5.10) |
| Manage storage | Settings → Manage storage | Deletes songs from your device. This is local; nothing is sent to us |
| Delete the App | iOS Home Screen | Removes the App and its local data from that installation. It does not automatically delete server records that were already transmitted. Use Delete my cloud data first if you want the App to delete the server records it can identify |
What “Delete my cloud data” does not do:
- It does not delete your songs or library. Those are local and were never uploaded to us.
- It does not by itself guarantee immediate deletion of every historical Google Analytics event associated with the old Analytics identifiers. Google Analytics provides user-level deletion mechanisms; if you want us to make an additional Analytics deletion request for data we can associate with your identifier, contact us.
- It removes your beta contact details from your profile and from future crash reports, and deleting the installation ID makes Google purge Crashlytics reports already uploaded within 180 days, but it does not rewrite those reports sooner than that. Firebase provides a mechanism for developers to request earlier deletion of crash reports associated with a Crashlytics user ID. If you want us to use it for your identifier, contact us.
- It cannot retroactively remove information from genuinely aggregated reports that no longer contain an identifier attributable to your installation.
- It does not delete email correspondence you sent us. Contact us if you want email deleted.
To request earlier deletion of Analytics or Crashlytics data associated with the PocketGroove identifiers we use, or to make another privacy request, email support@liminalstudios.com and include the installation ID shown under Settings → Privacy → Your data.
There is no in-App switch that separately disables Analytics, Performance Monitoring, or Crashlytics after they have been enabled, and no separate control for withdrawing beta contact details. We state that because we do not want to imply that a control exists when it does not. Where applicable law gives you a right to object to or withdraw consent from a particular processing activity, contact us and we will honour the right to the extent required by that law.
11. European Economic Area, United Kingdom, and Switzerland
PocketGroove is currently distributed only in the United States and is not intentionally offered in these markets. This section does not assert that European, UK, or Swiss data-protection law necessarily applies merely because someone can access information about PocketGroove from there.
If one of those privacy regimes applies to our processing of your personal data, you may have rights including:
- Access to personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure where the law entitles you to it. The in-App deletion action handles the Firestore/Auth records described in §10; contact us for other identifiable datasets.
- Restriction of processing in circumstances provided by law.
- Objection to processing based on legitimate interests where the applicable law gives you that right.
- Portability of qualifying data in a structured, commonly used, machine-readable form.
- Withdrawal of consent where a particular processing activity is based on consent. Withdrawal does not make earlier lawful processing unlawful.
- Complaint to the competent supervisory authority where applicable.
To exercise a right, write to support@liminalstudios.com. Where an applicable law sets a response deadline, we will respond within that deadline and use any extension that law permits only in accordance with its requirements.
A limitation created by the App’s pseudonymous design: most PocketGroove records are associated with an installation identifier rather than a verified identity. To act on an access, correction, portability, or similar request, we may need the installation ID shown under Settings → Privacy → Your data. We will not collect additional identifying information merely for the purpose of linking data to you where applicable law does not require us to do so.
We do not use the information described in this Policy to make automated decisions about you that produce legal or similarly significant effects. The App’s AI generates music locally; it does not score or make eligibility, employment, credit, insurance, or similar decisions about you.
12. United States privacy disclosures and rights
Different U.S. privacy statutes have different scope and applicability thresholds. Nothing in this section is intended to claim that every comprehensive state privacy law applies to Liminal Studios LLC. Where a law does apply, we honour the rights and disclosures it requires. We also provide the practical controls described in §10 regardless of whether a particular statutory threshold has been met.
The categories of information PocketGroove may collect or receive include:
| Category | Examples in PocketGroove |
|---|---|
| Pseudonymous identifiers | Firebase Authentication UID, Analytics app-instance ID, Firebase installation ID, and Crashlytics installation UUID, as described in §5.1 |
| Contact information | Name and/or email if you voluntarily provide them for beta testing, and your email address if you contact us |
| User-provided content | Your generation prompt and anything you voluntarily send by email. Your lyrics and generated audio are not uploaded to us |
| Usage information | App interactions and Analytics events described in §5.3 |
| Device and diagnostic information | Device and operating-system information, generation diagnostics, performance measurements, crash information, and provider-generated technical identifiers described in §5 |
| Approximate location | Approximate geographic information derived from IP addresses by services such as Google Analytics or Performance Monitoring. We do not collect precise location through iOS Location Services |
| Network information | IP addresses and technical network information processed by Firebase services as described in §5 |
We do not request sensitive personal information as a dedicated field. But a prompt or email is free text. If you voluntarily type health information, precise location, account credentials, racial or ethnic information, sexual information, government identifiers, or other sensitive information into free text, we can receive what you typed. Please do not put that information into a PocketGroove prompt.
Information comes directly from you, from the App and device when you use it, or from the service providers described in §7. We do not buy personal information about you from data brokers.
We use each category for the purposes described in §5, disclose it as described in §7, and retain it as described in §9.
We do not sell personal information, share it for cross-context behavioural or targeted advertising, or profile you in furtherance of decisions that produce legal or similarly significant effects.
Depending on your state and whether the relevant law applies, you may have rights to access, correct, delete, or obtain a portable copy of personal information and to appeal certain decisions about privacy requests. You may also have rights concerning sale, targeted advertising, or qualifying profiling; because PocketGroove does none of those things, there is no such processing to opt out of.
We will not discriminate against you for exercising a privacy right protected by applicable law. We do not offer a financial incentive in exchange for personal information.
Submit a request to support@liminalstudios.com. Because we do not maintain a conventional user account, we may ask you for the installation ID displayed under Settings → Privacy → Your data so we can associate the request with the appropriate records. We may take other reasonable steps required to verify a request without collecting more information than necessary.
Where applicable law permits an authorised agent to submit a request, we will honour a valid agent request subject to the verification and proof-of-authority requirements of that law. We respond to requests and appeals within the periods required by the law that applies.
Global Privacy Control, Do Not Track, and similar signals. PocketGroove is a native mobile app and does not sell personal information, use it for cross-context behavioural advertising, or permit advertising trackers to follow you across unrelated apps or websites. Browser-based signals therefore do not change the App’s behaviour because there is no such processing for them to stop.
California “Shine the Light” (Cal. Civ. Code §1798.83): we do not disclose personal information to third parties for those third parties’ own direct-marketing purposes.
13. If you are elsewhere
If a privacy or data-protection law that applies to you gives you rights concerning information we process, contact support@liminalstudios.com. We will provide the rights required by the law that applies to the request.
14. Security
We use technical and organisational measures appropriate to the information we process:
- Generation happens on your device, so generated audio and lyric text are not stored on our servers as part of the generation process.
- Communications between the App and our providers use encrypted transport such as TLS. Firebase services provide encryption for applicable customer data at rest.
- Our database rules ensure that an authenticated PocketGroove installation can read and write only the Firestore records associated with its own identifier, and they validate the shape and size of every permitted write.
- Firebase telemetry collection is switched off in the App’s build configuration and enabled at runtime only in a build configured to talk to our servers.
- Access to production data is limited to people who need it for their work.
No system is perfectly secure, and we cannot guarantee absolute security. If a security incident involving personal information triggers a legal notification requirement, we will make the notifications required by applicable law.
15. Children
The App is for people aged 13 and over, is not directed to children under 13, and is not in the App Store’s Kids Category. We do not knowingly collect personal information from children under 13.
We do not sell personal information or share it for targeted or cross-context behavioural advertising for anyone, including minors.
If we learn that we have collected personal information from a child under 13 in circumstances where we are not permitted to retain it, we will delete it. If you believe this has happened, contact support@liminalstudios.com.
Because PocketGroove does not maintain conventional user accounts or ask for a date of birth, we may need the installation ID shown under Settings → Privacy → Your data to locate relevant records. Where a law imposes additional protections because we know or are required to treat a user as a minor, we will apply those protections as required.
16. About the AI in this App
The App generates music with machine-learning models that run on your device. Because people reasonably associate AI applications with cloud processing and model training, we want the distinction to be explicit:
- Your prompts, lyrics, feedback, and generated songs are not used to train AI models, ours or anybody else’s. We have not used them for that purpose. If that ever changes, we will not apply the new use retroactively to material collected under this commitment, and we will provide the notice and obtain any consent required by law before the new use begins.
- No prompt is sent to a third-party AI model or model API. The prompt is, however, sent to our Firebase-backed generation-record storage as described in §5.2. That storage is separate from the music-generation process.
- Generated audio and lyrics are not sent to an external AI model. Generation runs locally.
- Every song file is marked as AI-generated in ways that identify the App but not you. See §4.1.
17. Changes to this Policy
We may update this Privacy Policy. When we do, we will change the “Last updated” date at the top and publish the new version at the same address.
If a change is material, for example if we begin collecting a materially new category of information, use information for a materially different purpose, or disclose it to a new category of recipient, we will provide prominent notice where appropriate before the new practice takes effect.
A Privacy Policy is a notice, not a substitute for consent. If applicable law or an App Store requirement requires us to obtain your consent before beginning new processing, we will obtain that consent rather than treating continued use of the App as permission.
The version in effect describes our processing practices from its stated effective date. Previous versions are available on request from support@liminalstudios.com.
18. Questions
Write to support@liminalstudios.com, or Liminal Studios LLC, 1500 N Grant St #11258, Denver, CO 80203, United States.