Privacy Policy
Last updated: 17 September 2026
This policy explains how the Neva app and this website (the “App”) handle information. The App is operated by an independent individual developer in Sweden (“we”, “us”), not by a company. You can reach us at nevaapp@outlook.com.
By using the App you agree to what is described here. If you do not agree, please do not use it.
1. The short version
- There is no account. We never ask for your name, email or phone number.
- What you type is sent to AI providers — that is how the words get written and the song gets sung. Do not put anything in it you would not want processed by a third party.
- Nothing you make is public until you publish it. Songs, hooks and playlists are private by default.
- What you publish is public to anyone, including on the open web, until you unpublish it.
- A published song’s page carries its full lyrics and the name of the person it is for, on the open web, to anyone with the address.
- You can delete everything from inside the App, and it deletes on our side too — your songs, everything you published, your hooks, playlists, profile, @name and any voice you trained.
- No ads inside the App, and nothing you write or record is ever used to advertise. We do advertise Neva elsewhere, and to know which of those ads are worth paying for we ask you first: iOS shows you a permission prompt, and if you say no, nothing about you goes to the advertiser. This website sets analytics cookies only if you allow them.
- We do not sell your data and we do not use what you write to train our own models.
2. What we process
(a) What you type
To write a song the App uses what you give it: who it is for, your relationship to them, the occasion and any details you add, the memories you list, your topic, your tone, and — in Studio — your own lyrics and style words. It may also include a song title, a playlist name, a hook caption or a comment. This is personal information about you and, usually, about someone else.
(b) Pictures and recordings you choose to add
- Audio you record or upload to steer how a song sounds.
- A recording of your own singing, if you use “Sing it in your voice”. It is used to train a voice model on our AI provider’s systems so songs can be sung in your voice. It is private to you unless you choose to share it — a shared voice is listed on your profile and anyone using the App can make songs sung in it, and turning sharing off does not unmake the songs already made.
- A recording of you reading a phrase we show you, before we will accept your singing. It is sent to our AI provider’s speech-to-text model and compared with the phrase, so that a voice can only be made by someone able to say what we ask at that moment.
- A video, if you make a hook. The video is trimmed and combined with your song on your phone; only the finished clip is uploaded.
- Screenshots you attach to “What’s it about?” — up to three, when you want the song written from a conversation, a note or anything else with words in it. Your phone shrinks them before they leave it, and they are sent to our AI writing provider so it can read them. We do not store them: they exist for the length of that one request, and what is kept afterwards is the lyrics the model wrote, not your picture.
- A photo you choose as a song’s cover, if you replace the AI artwork. It becomes public if you publish that song.
- A profile photo and cover image, if you set them. Both are public from the moment you set them, at a plain web address.
(c) A device identifier and anonymous sign-in
The App creates a random identifier, stores it in your device’s keychain, and signs in anonymously so it can talk to our backend securely. It is not linked to a name, an email or a social account. It is what makes your songs and your remaining time follow you if you reinstall the App on the same device.
(d) A public name, if you choose one
If you publish something you pick a handle. You may also add a display name, a short bio and links to your other profiles. These are public by design — see section 4.
(e) Purchases
Purchases are handled by the Apple App Store. Through our subscription provider we receive your purchase status and a non-identifying purchase identifier so the App knows how much music time you have. We never receive or store your card details.
(f) What you do in the App
Which songs, hooks and comments you liked, who you follow and who follows you, the playlists you saved, the people you blocked or hid, the lyrics you saved in Studio, and which songs you have saved onto your phone this week. These are stored under your anonymous sign-in so the App can draw the right buttons and so a reinstall does not hand you a second weekly download allowance.
(g) Technical data and how the App is used
Our infrastructure providers process limited technical information — device type, app version, timestamps, error logs — as a normal part of running and securing the service.
We also use Google Firebase Analytics to see how the App is used in aggregate: that onboarding finished, that lyrics were written, that a song was made and roughly how long it was, that the purchase screen was shown and what the person was trying to do at the time, that a song was shared, published or saved to a phone. Firebase gives each install a random app-instance identifier and records the usual device and country information alongside those events.
Two things it never receives, and they are the two that matter: nothing you write or record — no lyric, no name, no title, no topic, no audio — and no advertising identifier. We deliberately link the Firebase library that has no access to the IDFA, so nothing in this paragraph can follow you anywhere. The events carry categories and counts: an occasion, a genre, a language, a number of seconds. Advertising measurement is a separate thing, described next, and it asks your permission first.
(h) This website
This website uses Google Firebase Analytics (Google Analytics) to count visits and taps on the App Store button. Until you tap Allow on the bar at the bottom of the page it sets no cookies, and Google receives only a cookieless signal that a page was viewed. If you allow it, Google sets first-party analytics cookies (_ga) that recognise your browser on later visits to this site, for up to two years, alongside the usual device, browser and approximate location information.
Advertising features — Google signals, ad personalisation and advertising cookies — are switched off for every visitor, whatever you choose. You can change your answer at any time with Cookie settings at the bottom of the page; saying no removes the analytics cookies. The song, playlist, profile and gift pages this website shows for the App carry no analytics.
(h) Measuring our own advertising
We advertise Neva on Meta (Facebook and Instagram) and on the App Store. To know which of those adverts are worth paying for, we have to be able to tell that somebody who saw one later subscribed. On Meta that requires your permission, and iOS asks you for it in a standard prompt.
- If you allow it: your device’s advertising identifier goes to Meta through Meta’s own library in the App, and when you buy something, RevenueCat tells Meta that a purchase happened and what it was worth. That is what lets an advert be connected to a purchase.
- If you refuse, or never answer: no advertising identifier is read and no purchase of yours is sent to Meta at all. Meta’s library still records that the App was installed and opened, without anything that identifies you, and Apple’s own SKAdNetwork may tell Meta in aggregate that an install happened — a count, with no person in it.
- Apple Search Ads works differently and needs no permission: Apple gives us a token that names the campaign, not you.
- Whatever you choose, nothing you write, record or make is part of this — no lyric, no name, no song, no audio. What an advertiser can learn is that a purchase happened and what it cost.
- You can change your mind at any time in Settings > Privacy & Security > Tracking on your iPhone.
3. How a song is made, step by step
- Your brief is sent to OpenAI, which writes the lyrics and returns them to you to read and edit. No music is made yet and nothing is spent.
- When you approve the words, they are sent to ElevenLabs, which composes and sings the song and generates the cover artwork.
- The finished audio and cover are stored in our cloud storage, readable only by you, and appear in your library.
- If you asked for your own voice, the phrase you read aloud is sent to ElevenLabs’ speech-to-text model to check it is you speaking now, and then your training recording is sent to ElevenLabs and a voice model is trained there under our account.
We do not use anything you write or record to train our own models.
4. Publishing — what becomes public
Everything you make is private until you choose to publish it. When you do:
- A published song appears in Explore and also gets its own page on this website at
/s/<id>, open to anyone with no app and no account. That page carries its title, cover, your handle, its play count and the complete lyrics, and the song’s record also carries the name you said it was for. - Public pages can be found through search engines. We list published songs, hooks and profiles in a sitemap so that Google, Bing and AI assistants can find them, which means a published song — its title, its lyrics and the name in it — may turn up in a search. Unpublishing a song takes its page down and removes it from the sitemap; a search engine’s own copy can take some days to disappear after that.
- Posting a hook publishes the song it was made from. The song joins Explore and gets the page described above — its words and the name it is for included — even if you never published the song on its own, and even if you chose not to show the lyrics on the hook itself.
- A hook is a public video with your handle, its caption, its comments and its counts, and it gets a page at
/h/<id>that plays without the App. - A voice you share is listed on your profile under your handle, and anyone using the App can make songs sung in it for as long as sharing is on. Turning sharing off stops new ones; it does not unmake the songs already made in it.
- A playlist you publish or share by link gets a page on this website that anyone with the link can open and play.
- Your profile gets a page at
/u/<handle>once you have a handle, showing your name, picture, bio, links, counts and everything you have published. Nothing you have not published appears there. A profile picture or cover image is public from the moment you set it, at a plain web address. - A gift link opens a page showing the song’s cover, the name it is for and its full lyrics, to anyone who has the link — the link is the only secret. We count how often it is opened and when it was last opened, so you can see it arrived. You can revoke it.
The media files themselves get plain web addresses. Once a song is published or given a gift link, its audio — and a hook’s video, and any public cover or profile picture — can be opened, linked to or kept by anyone who knows the address, with no expiry and without the App. Unpublishing stops the page and stops the file being served, unless the song also has a gift link out, in which case revoke that too.
Every page we serve is on the open web with nothing telling search engines to stay away, so any of them — a gift link included — may be indexed or cached by other services once its address is known. Unpublishing removes the page, but we cannot remove copies other people have already made.
5. Who processes your data
- Google Firebase — anonymous sign-in, the database, file storage and the backend functions.
- OpenAI — writes the lyrics, and rewrites a section when you ask.
- ElevenLabs — composes and sings the song, generates the cover, and trains a voice model if you ask for one.
- RevenueCat — verifies your purchase, tracks how much music time you have left, and, if you allowed tracking, tells Meta that a purchase happened.
- Meta Platforms — measures whether its adverts for Neva lead to installs and purchases. Only if you allowed tracking; see 2(h).
- Apple — processes the purchase and provides the platform.
- Netlify — serves this website and the public pages.
Each operates under its own terms. We encourage you to read the policies of OpenAI, ElevenLabs, Google, RevenueCat, Meta and Apple.
6. How long we keep things
- Your songs and covers stay until you delete them or delete everything.
- A trained voice stays until you delete it, and deleting it deletes the model on our provider’s side too.
- Published items stay public until you unpublish or delete them. Deleting a hook removes its video and its comments; the song it published stays in Explore until you unpublish that too.
- Audio you add with “+ Audio” is held on ElevenLabs’ systems. Deleting it in the App removes our record of it, which is what makes it unusable; the copy on their side is theirs to expire.
- Lyrics you save in Studio — up to a hundred sets — stay until you delete them.
- Which songs you have saved onto your phone, and the week you did it, so the weekly download allowance survives a reinstall.
- Reports — if you report something, we keep the report so it can be reviewed and to prevent repeat abuse.
- Usage events are kept by Firebase Analytics under its own retention setting; they are aggregate counts and carry no content you wrote.
- Our providers may keep limited technical or transaction records for as long as their own operations, security and legal duties require.
7. Deleting your data
Settings → Delete everything removes, on our side: your songs and their audio and covers; everything you published, including the pages those songs and hooks had on this website; your hooks, their videos and the comments on them; your playlists; your gift links; your profile, its pictures and the reservation on your @name; your likes, follows, blocks and saved lyrics; any audio references; and any voice model you trained — including the model held on our AI provider’s systems. Your anonymous sign-in is deleted with it.
Two things are deliberately kept. Reports filed by you or about you survive, because a moderation record that disappears when the reported account deletes itself is not a moderation record; they hold an anonymous id and no content. And copies other people already made — a page they saved, a file they downloaded, a link they forwarded — are not ours to reach.
This cannot be undone, and it does not cancel an App Store subscription; cancel that in your device’s subscription settings.
For anything else, write to nevaapp@outlook.com.
8. Songs about other people
Most songs made with this App are about someone else, and the details you add are usually about them. You are responsible for having the right to use those details, and for not writing something that would harm the person it is about. Please do not add sensitive information about anyone — health, beliefs, sexuality, anything they would not want sung — and do not publish a song about someone who would not want it published.
The same goes for a screenshot: a picture of a conversation is somebody else’s words as well as yours, and adding one sends those words to our AI writing provider. Add one only if you are comfortable with that, and do not publish a song that exposes something the other person would not want public.
If a song, hook, comment or profile is about you and you want it taken down, email us and we will act on it within 24 hours.
9. Legal bases (EEA/UK)
Where a legal basis is required we rely on: your consent, given by choosing to submit a brief, a recording or a picture; performance of a contract, to provide the features you ask for including purchases; and our legitimate interests, to run and secure the App and prevent abuse. You can withdraw consent by not submitting anything further and by deleting what you have made. Analytics cookies on this website rely on your consent alone, which you can withdraw with Cookie settings at the bottom of the page.
10. Your rights
Depending on where you live you may have rights to access, correct, delete or restrict your personal information, to object to processing, and to portability. Because we hold no name or email, the most direct route is “Delete everything” in the App. For anything else, contact us and we will respond as the law requires.
11. International transfers
Our providers process data on servers in the United States and elsewhere. By using the App you understand your information may be processed outside your country, where data-protection law may differ.
12. Security
We use encrypted transport, access-controlled storage scoped to your anonymous session, and rules that keep unpublished work readable only by you. That access control applies while work is unpublished: once you publish a song or mint a gift link, its file gets a plain web address that anyone who knows it can open, as described in section 4. No system is perfectly secure and we cannot guarantee absolute security.
13. Children
The App is not for children. You must be at least 17. We do not knowingly collect information from children; if you believe a child has given us information, contact us and we will remove it.
14. Changes
We may update this policy. The date at the top changes when we do, and continuing to use the App after a change means you accept it.