Privacy Policy
Last updated June 21, 2026
1. Who we are
Tunaura ("we", "us") operates the lyric-video studio at tunaura.com and app.tunaura.com. This policy explains what we collect, how we use it, who we share it with, and the choices you have. For any privacy question, contact us at contact@arcticsgroup.com.
2. Information we collect
We collect the following, depending on how you use Tunaura:
- Account details — your name, email, profile photo, and authentication identifiers from Google sign-in or email/password (handled by Firebase Authentication).
- Content you upload — audio tracks, video clips, images, and the lyrics we transcribe from your audio.
- Content you import — media you bring in from sources you connect or supply, such as YouTube videos you confirm you own and images from Pinterest searches.
- Connected-platform data — profile and permission data from TikTok, YouTube, or Meta when you link those accounts (see “Connecting social platforms”).
- Usage data — basic logs, device and browser information, and product analytics (via Firebase Analytics, when enabled) used to operate and improve the service.
- Support & community content — messages you send to support, feedback, and anything you post in community features.
3. How we use it
We use your information to:
- Authenticate you and keep your account secure.
- Transcribe your audio, render your videos, and deliver your exports.
- Manage your plan, credits, and export limits.
- Publish, schedule, or upload your videos to the platforms you connect — only when you ask us to.
- Provide support and respond to your requests.
- Monitor, debug, and improve Tunaura, and enforce our Terms.
4. Connecting social platforms
When you link a social account, you authorise Tunaura to act on your behalf to publish, schedule, or import content. We request the narrowest permissions needed for what you asked us to do, store any access tokens encrypted on our servers, never expose them to your browser, and use them only for the actions you initiate. You can disconnect any platform at any time from inside Tunaura, which revokes the access we hold.
5. TikTok
If you connect TikTok (through TikTok Login Kit and the Content Posting API), we receive your TikTok profile and use it to post or upload the videos you choose.
- Permissions we request: user.info.basic (your display name and avatar), video.publish (post a video directly to your feed), and video.upload (send a video to your TikTok inbox/drafts to finish posting yourself).
- Data we receive: your TikTok display name, avatar, and account identifier (open ID), plus the posting options your account allows (privacy level and comment/duet/stitch settings).
- Data we send: the video file you render in Tunaura together with the caption and posting options you set.
- Storage: your TikTok access and refresh tokens are encrypted and held only in a secure, server-side cookie; they are never shared with third parties.
- Our use of TikTok data complies with the TikTok Developer Terms and Community Guidelines.
6. YouTube
If you connect YouTube to upload videos, Tunaura uses YouTube API Services. By connecting YouTube you also agree to the YouTube Terms of Service, and Google's Privacy Policy applies to Google's handling of your data.
- Permissions we request: permission to upload videos to your channel on your behalf (the YouTube Data API upload scope) and to read the basic channel information needed to publish.
- Data we receive: basic channel and profile information needed to identify the destination channel.
- Data we send: the video file you render, plus the title, description, and visibility you set.
- Storage: your Google/YouTube tokens are encrypted on our servers and used only to upload at your direction; we do not retain your YouTube content beyond what is needed to complete the upload.
- Revoking access: you can revoke Tunaura's access to your Google account at any time from Google's Security settings, in addition to disconnecting inside Tunaura.
7. Meta (Instagram & Facebook)
If you connect Meta (using Facebook Login and the Instagram/Facebook Content Publishing APIs), Tunaura publishes content to the Instagram or Facebook accounts you authorise.
- Permissions we request: access to the Facebook Pages and Instagram professional accounts you select, and permission to publish content to them (such as Reels, photos, and videos) on your behalf.
- Data we receive: the connected Page/Instagram account name and ID and the tokens needed to publish.
- Data we send: the video or image you render together with the caption you set.
- Storage: your Meta access tokens are encrypted on our servers and used only for the publishing actions you initiate.
- Our use of Meta data complies with the Meta Platform Terms and Developer Policies. You can remove Tunaura from your Facebook settings and request deletion of data we hold (see “Your rights & choices”).
8. Third-party providers
We rely on a small set of providers to run Tunaura. Each receives only the data needed for its function, and none is permitted to use your content for its own purposes:
- Google Firebase — authentication, database (Firestore), and optional analytics.
- Amazon Web Services (S3 & Lambda) — file storage and video rendering.
- Groq — speech-to-text transcription of your audio into lyrics.
- LALAL.ai and Replicate — optional vocal isolation to improve transcription accuracy.
- Vercel — application hosting and delivery.
- TikTok, YouTube/Google, and Meta — only when you connect them, as described above.
9. Storage, processing & retention
Your account data and content are stored on Google Firebase and Amazon Web Services. We keep your content for as long as your account is active or as needed to provide the service. When you delete a project or your account, we delete the associated content within a reasonable period, except where we must retain it to comply with the law. Analytics data follows the provider's default retention.
10. Sharing
We do not sell your personal data and we do not use your content to train third-party AI models. We share data only with the providers listed above to operate Tunaura, with the social platforms you choose to publish to, and where required by law or to protect our rights and users.
11. Cookies & local storage
We use strictly necessary cookies to sign you in and to hold encrypted social-platform tokens, and we use your browser's local storage to remember preferences and any scheduled post. We do not use third-party advertising or cross-site tracking cookies.
12. Your rights & choices
You can access, correct, export, or delete your personal data and content. You can disconnect any social platform at any time inside Tunaura and revoke access from the platform's own settings (linked above). To exercise any right, contact contact@arcticsgroup.com. Depending on where you live, you may have additional rights under the GDPR, UK GDPR, or CCPA, including the right to lodge a complaint with your data-protection authority.
13. Data security
We protect your data with encryption in transit and at rest, encrypted server-side tokens, and access controls that limit each account to its own data. No method of transmission or storage is completely secure, but we work hard to protect your information.
14. International transfers
Tunaura and its providers may process your data in countries other than your own, including within the European Union and the United States. Where required, we rely on appropriate safeguards for these transfers.
15. Children
Tunaura is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their data.
16. Changes
We may update this policy from time to time. We will note the effective date and, where appropriate, notify you of material changes.
