1. Who we are
Apni Dhoon (“Apni Dhoon”, “we”, “us”) is a music discovery, streaming and AI song-creation service. It is available as an Android app (package com.apnidhoon.app) and is supported by our servers at api.letspahal.online and this website, apnidhoon.letspahal.online. The service is operated by Apni Dhoon (LetsPahal), which is the Data Fiduciary (data controller) for the personal data described here, as defined in India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).
This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it and the rights you have. It applies to the app, our API and this website. If you don’t agree with it, please don’t use Apni Dhoon.
2. Summary
- You can browse, search and listen without an account.
- With an account we store your email, name, library, playlists, listening activity, and any songs you create or upload, so the app can work and recommend music.
- When you create an AI song, your prompt or lyrics are processed by our own AI music servers and, where needed, by Google Cloud (Vertex AI) and Sarvam AI.
- The app contains no advertising SDKs and no third-party analytics or crash-reporting SDKs. We do not sell your personal data or use it for targeted advertising.
- You can access, correct and delete your data, and delete your account at any time (see Delete account).
3. Personal data we collect
3.1 Data you give us
| Category | What it includes | Required? |
|---|---|---|
| Account (email sign-up) | Email address, display name and password. We store only a one-way hash of your password, never the password itself. | Yes, to create an account |
| Account (Google Sign-In) | If you choose “Continue with Google”: your Google account ID, verified email address, name and profile picture URL, taken from the sign-in token Google gives us. We never receive your Google password. | Optional sign-in method |
| Profile & preferences | Display name, profile picture link, app language, the music languages you listen to, preferred genres and moods, onboarding status and notification preferences. | Optional (name is required) |
| Library | Liked songs, playlists you create (names, descriptions, artwork, song order, public/private setting) and songs you save. | Optional |
| AI creations | Your text prompts, lyrics and song titles; your chosen language, genre, mood, vocal type and duration; the language and script we detect in your text; and the generated audio and artwork. | Only if you create songs |
| Uploads | Audio files and artwork you upload, plus title, description, lyrics, language, genre, mood, vocal type and your confirmation that you hold the rights. | Only if you upload |
| Reports & support | Content reports you submit (reason and details), plus anything you send when you email us. | Optional |
3.2 Data created when you use the service
| Category | What it includes |
|---|---|
| Listening activity | Songs you play, how long you listen, and player events: started, reached 25%, 50% or 75%, completed, skipped, liked and shared. These are linked to a random playback-session ID and, if you’re signed in, to your account. |
| Search history | Your search queries and the number of results. Guest searches are stored without any account link and are only used to work out what’s trending. |
| Credits | Your credit balance and a ledger of credit grants, reservations, charges, refunds and adjustments, each linked to the song creation it relates to. |
| Generation records | Status and timing of each song creation, which AI model and provider handled it, the credits used, error codes, and a hash of the prompt for rights tracking and abuse prevention. |
| Safety (moderation) records | The result of the automated safety check on your prompt, lyrics or title, including the checked text, the categories flagged (for example hate, sexual content, impersonation or copyright imitation) and any review by our team. |
| Sign-in sessions | A hashed refresh token, your device’s user-agent string (app/OS version), your IP address when the session was created or refreshed, and session timestamps. These let you stay signed in, and let us detect stolen tokens. |
| Technical & security logs | IP address, request time, endpoint, response status and a request ID in our server logs. We use IP addresses and account IDs for rate limiting, to stop abuse and brute-force attacks. Rate-limit counters are short-lived. |
| Notifications | In-app notifications we send you (such as “Your Dhoon is ready”) and whether you’ve read them. |
| Account metadata | Account creation date, last activity time, account status and role. |
4. What we don’t collect
- No precise or approximate location from your device’s GPS or location services.
- No access to your contacts, camera, microphone, SMS or call logs.
- No advertising ID, no advertising SDKs, and no third-party analytics or crash-reporting SDKs in the app.
- We access your device files only when you pick an audio or image file to upload, and only the file you pick.
- We don’t currently process any payments, so we hold no card or bank details. If we add paid credits in future, payments will be handled by a payment provider (such as Google Play Billing) and we’ll update this policy.
5. How we use your data
- To provide the service: create and secure your account, sign you in, stream music, keep your library and playlists, and save and play your creations and uploads.
- To create AI songs: send your prompt, lyrics and settings to the AI systems described in section 7, then store and deliver the result.
- To personalise: build Home sections like Quick Picks, Recently Played, “Because you listened to…” and your personal mix from your listening activity, likes and language, genre and mood preferences. This uses rules we define, not profiling for advertising, and has no legal or similarly significant effect on you.
- To manage credits: calculate, reserve, charge and refund credits correctly, and prevent double charges.
- To keep people safe: screen prompts and uploads for illegal, hateful, sexual or infringing content and impersonation, act on reports, prevent fraud, spam and abuse, and enforce our Terms.
- To understand and improve the service: aggregate statistics such as plays, trending songs and searches, active users, listening minutes, and generation failures and costs. We do not use your prompts, lyrics, uploads or creations to train AI models.
- To communicate with you: service notifications (such as “Your Dhoon is ready”), important account, security and policy notices, and replies to your messages. We send marketing only if you turn it on, and it’s off by default.
- To meet legal obligations: respond to valid legal requests, keep records the law requires, and establish or defend legal claims.
6. Consent and legal basis
Under the DPDP Act we process your personal data on the basis of:
- Your consent, given when you create an account and accept this policy and our Terms, and when you choose to use optional features such as AI creation, uploads, Google Sign-In or marketing notifications. Your consent covers only the data and purposes described here.
- Legitimate uses allowed by Section 7 of the DPDP Act, including data you’ve voluntarily provided for a specific purpose (such as an email you send us), compliance with law or court orders, and responding to emergencies.
Withdrawing consent. You can withdraw consent at any time, as easily as you gave it, by turning off optional features in Settings, deleting content, or deleting your account. Withdrawing consent doesn’t affect processing that already happened. Some features, and the account itself, can’t work without the data they need.
If you live outside India, we rely on the equivalent bases under your local law, such as performance of our contract with you, consent and our legitimate interests in keeping the service secure.
7. AI song creation
When you tap Create, this happens:
- Safety check. Your prompt, lyrics and title are checked automatically for disallowed content. Blocked or flagged requests may be reviewed by our team.
- Lyrics and language. If you ask us to write lyrics, or the system needs to transcribe or process lyrics, the relevant text may be sent to Sarvam AI, an Indian AI company, for lyric writing and transcription.
- Music generation. Your request (prompt or lyrics plus your chosen settings) is processed by our own AI music model on GPU servers we operate, based on the open-source ACE-Step model. If our model is unavailable, the request may instead be processed by Google Cloud Vertex AI (Lyria) as a fallback.
- Storage. The finished audio and artwork are stored on Google Cloud Storage and added to your My Dhoons, private by default.
We send these providers only what they need to create your song, which is your text and settings. We do not send your name, email or contact details. Every AI-created song is labelled “AI Generated” in the app. Please don’t put personal or sensitive information about yourself or others into prompts or lyrics.
8. Who we share data with
We do not sell or rent your personal data, and we don’t share it with advertisers or data brokers. We share it only as follows.
8.1 Service providers (Data Processors)
These providers process data on our behalf, under contract and only on our instructions:
| Provider | Purpose | Data involved |
|---|---|---|
| Google Cloud (Google LLC / Google Cloud India) | Cloud storage of audio and artwork (Cloud Storage), and AI music generation fallback (Vertex AI, Lyria) | Generated and uploaded audio and artwork; prompts, lyrics and settings when the fallback is used |
| Sarvam AI (India) | Lyric writing, language processing and transcription | Prompt and lyric text; audio where transcription is needed |
| Our hosting and GPU infrastructure providers | Running our API, database, cache, queue and our own AI music model | All service data, stored and processed on our behalf |
| Google (Sign-In) | Verifying your identity when you choose Google Sign-In | The sign-in token Google issues to the app |
| Email provider | Receiving and replying to support and privacy emails | Your messages and email address |
8.2 Other people, when you choose
Public playlists and anything you share (for example a share link to one of your Dhoons) can be seen by whoever you share it with, or by other users if you make it public. Your display name may appear next to public content.
8.3 Legal and safety reasons
We may disclose data if the law requires it, or to respond to a valid order from a court or government authority, protect the rights, safety or property of our users, the public or Apni Dhoon, or investigate fraud, infringement or abuse.
8.4 Business transfers
If Apni Dhoon is involved in a merger, acquisition or sale of assets, personal data may be transferred under this policy, and we’ll notify you beforehand.
9. Where your data is stored
Our primary database and media storage run on Google Cloud. We aim to keep data in Google Cloud regions in India where available. Some providers, such as Google Cloud Vertex AI, may process data outside India. Any transfer outside India follows the DPDP Act and any restrictions the Government of India notifies under Section 16, with appropriate contractual safeguards.
10. How long we keep data
We keep personal data only as long as we need it for the purposes above, or as the law requires:
| Data | Retention |
|---|---|
| Account, profile, library, playlists, creations, uploads, listening and search history | While your account is active. You can delete individual items (playlists, songs, recent searches) at any time. Everything is deleted within 30 days of an account deletion request. |
| Sign-in sessions | Refresh tokens expire after 30 days unused. Session records are deleted with your account. |
| Server and security logs (including IP addresses) | Up to 90 days, unless needed longer to investigate a specific security incident. |
| Rate-limiting counters | Minutes. They expire automatically. |
| Credit ledger | Deleted with your account. If we offer paid credits in future, purchase records will be kept for the period required by Indian tax and accounting law (generally up to 8 years). |
| Safety records for blocked or flagged prompts, and reports | Up to 1 year, unlinked from your account after deletion, to prevent repeat abuse and meet legal obligations. |
| Aggregated or anonymised statistics (for example play counts) | May be kept indefinitely, because they no longer identify you. |
| Backups | Deleted data may remain in encrypted backups for up to 35 days before it’s overwritten. |
As the DPDP Act requires, if you haven’t used your account for an extended period and we no longer need the data, we’ll notify you before erasing it.
11. Security
We use reasonable security safeguards, including:
- Encryption in transit (HTTPS/TLS) for all app and API traffic, and encryption at rest on our cloud storage.
- Passwords stored only as strong one-way hashes. Refresh tokens stored only as hashes on our servers and kept in secure storage on your device.
- Short-lived access tokens, rotating refresh tokens with reuse detection, and the ability to revoke all sessions.
- Media delivered through time-limited signed URLs. Private songs are visible only to you.
- Role-based access for our staff, audit logs of admin actions, rate limiting and input validation.
No system is perfectly secure. If a personal data breach happens, we’ll notify the Data Protection Board of India and affected users as the DPDP Act requires.
12. Your rights
Under the DPDP Act, and subject to its conditions, you have the right to:
- Access: get a summary of the personal data we process about you and the processing activities, and the identities of others we’ve shared it with.
- Correction and completion: fix inaccurate or incomplete data. You can edit your name, picture and preferences in the app.
- Erasure: have your personal data deleted when it’s no longer needed or when you withdraw consent, unless the law requires us to keep it.
- Withdraw consent at any time (see section 6).
- Grievance redressal: raise a complaint with our Grievance Officer and get a response.
- Nominate another person to exercise your rights if you die or become incapacitated.
- If you aren’t satisfied with our response, complain to the Data Protection Board of India.
To exercise a right, email our privacy contact from the email address on your account (so we can verify it’s you) with the subject “Privacy request”. We’ll reply within 30 days. If you live in another country, you may have similar rights under local law, and we’ll honour them.
13. Deleting your account
You can ask us to delete your account and associated data at any time. Our Delete your account page has the steps and explains exactly what’s deleted and what’s kept.
14. Children
Apni Dhoon is not meant for children under 13, and children under 13 must not create an account.
Under the DPDP Act, anyone under 18 is a child. If you’re under 18, you may create an account only with the verifiable consent of your parent or lawful guardian, and your parent or guardian must accept this policy and our Terms for you. For users we know are under 18, we don’t do tracking or behavioural monitoring beyond what the service needs to work, and we don’t send marketing.
If you believe a child has given us personal data without the required consent, contact us and we’ll delete it.
15. Storage on your device
The app stores some data on your device to work properly: your sign-in tokens (in Android’s encrypted secure storage), app settings and your playback queue (in app preferences), and cached artwork and audio for faster playback. This data stays on your device. It’s removed when you sign out (tokens), clear the app’s storage, or uninstall the app.
This website uses no cookies and no analytics or tracking scripts. Fonts are loaded from Google Fonts, which receives your IP address as part of the normal web request.
16. Changes to this policy
We may update this policy as Apni Dhoon changes or as the law changes. The “Last updated” date at the top will show the latest version. If a change is significant, we’ll tell you in the app or by email before it takes effect, and ask for fresh consent where the law requires.
17. Contact and Grievance Officer
For questions, privacy requests or complaints, contact our Grievance Officer:
We’ll acknowledge grievances within 24 hours and aim to resolve them within 30 days. You may also contact the Data Protection Board of India once it’s operational for your complaint.