Privacy Policy

Effective date: 9 August 2026  ·  Last updated: 9 August 2026

This policy explains what Suno Cover Bot collects, why, how long it is kept, who else handles it, and what you can do about it. The data controller — the "business" under US state privacy laws — is Suno Cover Bot, an independent software business, contactable for all privacy matters at support@sunocoverbot.com. That address is monitored and is the correct route for any request or complaint under this policy.

The three things people ask first: we do not sell or share your data, we do not use your music or lyrics to train AI models, and the audio and text you submit are processed in real time rather than stockpiled.

1.What we collect

DataWhy we have itLegal basis
Telegram account identifiers — your numeric chat ID, and the username or display name Telegram provides To know which conversation to reply to and to attach your subscription to the right account Performance of a contract
Language preference To reply in the language you chose Performance of a contract
Content you submit — lyrics, text, audio files, voice recordings, song titles, references To perform the processing you requested Performance of a contract
Your own Suno session cookies and authorisation tokens, captured by the connection tool you install To sign your technical requests so uploads and library writes are performed as you, on your own account. The bot cannot work without them. Your password is never requested or stored. Consent (given in the bot before connecting)
Google Drive authorisation, if you choose to connect it Only to read files you pick and to save finished songs to your own Drive, at your request Consent (given in the bot before connecting)
Subscription status — plan, state, renewal date, and the customer identifier issued by Polar To know what you have access to Performance of a contract
Operational logs — timestamps, job outcomes, error records To diagnose failures, prevent abuse and fraud, and keep the service working Legitimate interests

We never receive your payment card details. Card data is captured by Stripe on behalf of Polar, the merchant of record. Neither we nor Polar store full card numbers. We receive only your subscription state and a customer identifier.

2.What Polar collects when you pay

Your subscription is sold to you by Polar Software, Inc., 3500 South DuPont Highway, Dover, DE 19901, USA, acting as our authorised reseller and merchant of record. When you go through checkout you are dealing with Polar, and it collects information directly from you for that purpose:

Collected by Polar at checkoutPurpose
Name, email address, and any password or unique identifierCreating and managing your purchase and customer portal access
Payment card type, last four digits, billing address, phone, business name and tax number where providedTaking payment, invoicing, and calculating tax
Purchase historyOrder records, renewals, refunds and disputes
IP address, device, browser, referring page and coarse (IP-based) locationFraud prevention, security, and platform analytics

Roles. Under the data processing addendum between us, we are the controller (business) for this data and Polar acts as our processor (service provider), contractually restricted to processing it only to provide the checkout and related services. It may not sell or share it, and may not use it outside our business relationship. Polar's own Privacy Policy describes its practices in full.

3.What we do not do

4.How long we keep it

5.Who processes data on our behalf

We use a small number of providers. Each processes data only to deliver the Software, under contract, and none is permitted to use it for its own purposes:

ProviderRoleWhere
TelegramMessage delivery — the channel the Software runs onInternational
SupabaseDatabase for account and subscription recordsEU
Vercel, Inc.Website and API hostingEU region (Frankfurt)
Hetzner Online GmbHServer running the background processing workersGermany
Polar Software, Inc.Checkout, subscription billing, invoicing, tax, refunds and chargebacks — as reseller and merchant of recordUSA
Stripe, Inc. / Stripe Payments Europe, LtdPayment processing, authorisation, settlement and fraud prevention, engaged by PolarUSA / Ireland
Groq, Inc. and Google LLC (Gemini API)Language models used to structure lyrics and compose a matching style description, when you ask for that. See below.USA
Google LLC (Drive API)Reading files you pick and saving finished songs — only to your own Drive, only if you connect itInternational
Suno, Inc.The destination platform your results are delivered to, on your instruction, into your own accountUSA

About the language models

When you ask the bot to structure lyrics or write a style description, that text is sent to a language model provider (Groq, or Google's Gemini API) to produce the result, and the result is returned to you. We do not permit that content to be used for model training, we send no account identifiers with it, and we retain no copy beyond the job. If you prefer not to use this, the bot works without it — you can supply your own lyrics and your own style text directly.

Polar's own sub-processors

To operate the checkout, Polar engages its own sub-processors — currently including Render, Tinybird, Amazon Web Services, Vercel, Resend, Stripe, Numeral, ChargebackStop, PostHog, Sentry, Logfire and Plain. The current list, with the data and purpose for each, is published and kept up to date at polar.sh/legal/sub-processors, and Polar's payment partners at polar.sh/legal/payment-processor-partners. Polar must give at least 30 days' notice before adding or replacing a sub-processor, and we may object on data-protection grounds.

6.International transfers

Some of these providers operate outside your country, including in the United States. Where personal data leaves the European Economic Area or the United Kingdom without an adequacy decision, the transfer is made under the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914, Module 2), and for the UK under the ICO's International Data Transfer Addendum, together with the additional safeguards those instruments require. As between us and Polar, those clauses are governed by the law of Sweden and disputes under them go to the Swedish courts.

7.Security and breach notification

Your stored credentials are encrypted at rest. Every credential we hold on your behalf — your Suno session, your Google Drive token and your own AI API key — is encrypted with AES-256-GCM before it is written to the database. The key is held in the server environment and never in the database, so a copy of the database on its own is unreadable. The encryption is authenticated, meaning a value that has been altered is rejected rather than used.

Access to production data is restricted to the operator and protected by provider-level authentication. Credentials are never exposed in the bot interface or on this website. Our providers maintain their own technical and organisational measures; card handling is PCI DSS compliant at Stripe, and neither we nor Polar store full card numbers.

Being straight about the limit of this: the server has to use these credentials to do the work you asked for, so it must be able to decrypt them. Encryption at rest means a stolen database is useless — it does not mean the operator is technically incapable of reading a credential. Any service that stores a working credential for you is in the same position, and we would rather say so than imply otherwise.

No system is perfectly secure and we cannot guarantee absolute security. If a breach affects your personal data we will notify you and the competent supervisory authority as the law requires — within 72 hours of becoming aware, where that deadline applies. Polar is contractually bound to notify us of any breach affecting this data within 72 hours of becoming aware of it.

8.Your rights

Depending on where you live — in particular under the EU and UK GDPR, under Israeli privacy law, and under US state privacy laws such as the CCPA/CPRA — you have the right to:

To exercise any of these, email support@sunocoverbot.com. We respond within 30 days, and there is no charge for a reasonable request. If we decline a request you may appeal by replying to our answer, and we will reconsider and respond in writing.

For data held by Polar in connection with your purchase, you may also contact Polar directly at privacy@polar.sh, which operates its own request and appeal process.

9.Cookies — two different things, and the difference matters

Cookies on this website

This marketing website sets no advertising and no analytics cookies. Polar's checkout, hosted by Polar on its own domain, sets the cookies described in its Privacy Policy, where its cookie preferences control is also available.

Your Suno session cookies — used by the bot, with your consent

These are a different thing entirely, and we want to be direct about it because it is central to how the product works. The Software uses your own session cookies to connect to and operate on your account. They are not cookies this website places on your device — they are the credentials your browser already holds for Suno, which you hand over deliberately when you connect.

The connection tool you install

Capturing that session needs a small helper on your own device: a Chrome extension on desktop, a connection app on Android, or a Terminal command on macOS that downloads and runs the connection tool. Each is optional and installed by you.

They read the session for the account you sign in to, and nothing else. They do not read unrelated browsing history, do not monitor your activity, do not run in the background harvesting data, and send nothing to us beyond the credentials needed for the connection you asked for. Uninstall the extension or app, or disconnect in the bot, and their access ends.

10.Children

The Software is not intended for, directed at, or advertised to anyone under 18, and we do not knowingly collect data from children. Polar does not knowingly collect personal information from children under 13, and does not sell or share the personal information of consumers under 16 without the authorisation the law requires. If you believe a child has provided us with personal data, contact us and we will delete it.

11.Changes to this policy

We may update this policy. The effective date above will change, and material changes will be communicated through the bot before they take effect.

12.Contact

Privacy questions or requests: support@sunocoverbot.com. We reply within two business days.