Privacy Policy
This policy explains what Suno Cover Bot collects, why, how long it is kept, who else handles it, and what you can do about it. The data controller — the "business" under US state privacy laws — is Suno Cover Bot, an independent software business, contactable for all privacy matters at support@sunocoverbot.com. That address is monitored and is the correct route for any request or complaint under this policy.
The three things people ask first: we do not sell or share your data, we do not use your music or lyrics to train AI models, and the audio and text you submit are processed in real time rather than stockpiled.
1.What we collect
| Data | Why we have it | Legal basis |
|---|---|---|
| Telegram account identifiers — your numeric chat ID, and the username or display name Telegram provides | To know which conversation to reply to and to attach your subscription to the right account | Performance of a contract |
| Language preference | To reply in the language you chose | Performance of a contract |
| Content you submit — lyrics, text, audio files, voice recordings, song titles, references | To perform the processing you requested | Performance of a contract |
| Your own Suno session cookies and authorisation tokens, captured by the connection tool you install | To sign your technical requests so uploads and library writes are performed as you, on your own account. The bot cannot work without them. Your password is never requested or stored. | Consent (given in the bot before connecting) |
| Google Drive authorisation, if you choose to connect it | Only to read files you pick and to save finished songs to your own Drive, at your request | Consent (given in the bot before connecting) |
| Subscription status — plan, state, renewal date, and the customer identifier issued by Polar | To know what you have access to | Performance of a contract |
| Operational logs — timestamps, job outcomes, error records | To diagnose failures, prevent abuse and fraud, and keep the service working | Legitimate interests |
We never receive your payment card details. Card data is captured by Stripe on behalf of Polar, the merchant of record. Neither we nor Polar store full card numbers. We receive only your subscription state and a customer identifier.
2.What Polar collects when you pay
Your subscription is sold to you by Polar Software, Inc., 3500 South DuPont Highway, Dover, DE 19901, USA, acting as our authorised reseller and merchant of record. When you go through checkout you are dealing with Polar, and it collects information directly from you for that purpose:
| Collected by Polar at checkout | Purpose |
|---|---|
| Name, email address, and any password or unique identifier | Creating and managing your purchase and customer portal access |
| Payment card type, last four digits, billing address, phone, business name and tax number where provided | Taking payment, invoicing, and calculating tax |
| Purchase history | Order records, renewals, refunds and disputes |
| IP address, device, browser, referring page and coarse (IP-based) location | Fraud prevention, security, and platform analytics |
Roles. Under the data processing addendum between us, we are the controller (business) for this data and Polar acts as our processor (service provider), contractually restricted to processing it only to provide the checkout and related services. It may not sell or share it, and may not use it outside our business relationship. Polar's own Privacy Policy describes its practices in full.
3.What we do not do
- We do not sell, rent, trade, or "share" personal data for advertising, with anyone.
- We do not use your audio, lyrics, or any submitted content to train AI models — ours or anyone else's.
- We do not clone, model, or synthesise anyone's voice, and we do not build voice or likeness profiles.
- We do not use your data for advertising, profiling, or automated decisions with legal effect.
- We do not retain a permanent archive of the media you send.
4.How long we keep it
- Submitted audio and text: processed in real time and discarded once the job finishes or fails. Where you are offered the choice to save a finished song, it goes to your own Google Drive, not to storage of ours. Anything left unanswered is swept automatically within 24 hours.
- Account and subscription records: kept while your account is active, and for up to 12 months afterwards for support and dispute handling.
- Credentials (session cookies, Drive token, AI key): encrypted at rest, kept only while your account is connected, and deleted when you disconnect or when they expire. They are also wiped automatically after 60 days of inactivity — if you stop using the bot, we stop holding your keys, without you having to ask. You simply reconnect if you come back.
- Operational logs: typically 30–90 days.
- Billing and tax records: retained by Polar for as long as tax, accounting and card-network rules require, and beyond termination for the period needed to settle refunds and chargebacks.
5.Who processes data on our behalf
We use a small number of providers. Each processes data only to deliver the Software, under contract, and none is permitted to use it for its own purposes:
| Provider | Role | Where |
|---|---|---|
| Telegram | Message delivery — the channel the Software runs on | International |
| Supabase | Database for account and subscription records | EU |
| Vercel, Inc. | Website and API hosting | EU region (Frankfurt) |
| Hetzner Online GmbH | Server running the background processing workers | Germany |
| Polar Software, Inc. | Checkout, subscription billing, invoicing, tax, refunds and chargebacks — as reseller and merchant of record | USA |
| Stripe, Inc. / Stripe Payments Europe, Ltd | Payment processing, authorisation, settlement and fraud prevention, engaged by Polar | USA / Ireland |
| Groq, Inc. and Google LLC (Gemini API) | Language models used to structure lyrics and compose a matching style description, when you ask for that. See below. | USA |
| Google LLC (Drive API) | Reading files you pick and saving finished songs — only to your own Drive, only if you connect it | International |
| Suno, Inc. | The destination platform your results are delivered to, on your instruction, into your own account | USA |
About the language models
When you ask the bot to structure lyrics or write a style description, that text is sent to a language model provider (Groq, or Google's Gemini API) to produce the result, and the result is returned to you. We do not permit that content to be used for model training, we send no account identifiers with it, and we retain no copy beyond the job. If you prefer not to use this, the bot works without it — you can supply your own lyrics and your own style text directly.
Polar's own sub-processors
To operate the checkout, Polar engages its own sub-processors — currently including Render, Tinybird, Amazon Web Services, Vercel, Resend, Stripe, Numeral, ChargebackStop, PostHog, Sentry, Logfire and Plain. The current list, with the data and purpose for each, is published and kept up to date at polar.sh/legal/sub-processors, and Polar's payment partners at polar.sh/legal/payment-processor-partners. Polar must give at least 30 days' notice before adding or replacing a sub-processor, and we may object on data-protection grounds.
6.International transfers
Some of these providers operate outside your country, including in the United States. Where personal data leaves the European Economic Area or the United Kingdom without an adequacy decision, the transfer is made under the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914, Module 2), and for the UK under the ICO's International Data Transfer Addendum, together with the additional safeguards those instruments require. As between us and Polar, those clauses are governed by the law of Sweden and disputes under them go to the Swedish courts.
7.Security and breach notification
Your stored credentials are encrypted at rest. Every credential we hold on your behalf — your Suno session, your Google Drive token and your own AI API key — is encrypted with AES-256-GCM before it is written to the database. The key is held in the server environment and never in the database, so a copy of the database on its own is unreadable. The encryption is authenticated, meaning a value that has been altered is rejected rather than used.
Access to production data is restricted to the operator and protected by provider-level authentication. Credentials are never exposed in the bot interface or on this website. Our providers maintain their own technical and organisational measures; card handling is PCI DSS compliant at Stripe, and neither we nor Polar store full card numbers.
Being straight about the limit of this: the server has to use these credentials to do the work you asked for, so it must be able to decrypt them. Encryption at rest means a stolen database is useless — it does not mean the operator is technically incapable of reading a credential. Any service that stores a working credential for you is in the same position, and we would rather say so than imply otherwise.
No system is perfectly secure and we cannot guarantee absolute security. If a breach affects your personal data we will notify you and the competent supervisory authority as the law requires — within 72 hours of becoming aware, where that deadline applies. Polar is contractually bound to notify us of any breach affecting this data within 72 hours of becoming aware of it.
8.Your rights
Depending on where you live — in particular under the EU and UK GDPR, under Israeli privacy law, and under US state privacy laws such as the CCPA/CPRA — you have the right to:
- Access the personal data we hold about you, and know the categories collected and disclosed
- Correct data that is wrong or incomplete
- Delete your data ("right to be forgotten")
- Restrict or object to certain processing
- Receive your data in a portable, machine-readable format
- Opt out of any "sale" or "share" of personal information — we do neither
- Withdraw consent at any time, including by disconnecting your Suno or Google Drive account in the bot
- Not be discriminated against for exercising any of these rights
- Lodge a complaint with your local data protection authority
To exercise any of these, email support@sunocoverbot.com. We respond within 30 days, and there is no charge for a reasonable request. If we decline a request you may appeal by replying to our answer, and we will reconsider and respond in writing.
For data held by Polar in connection with your purchase, you may also contact Polar directly at privacy@polar.sh, which operates its own request and appeal process.
9.Cookies — two different things, and the difference matters
Cookies on this website
This marketing website sets no advertising and no analytics cookies. Polar's checkout, hosted by Polar on its own domain, sets the cookies described in its Privacy Policy, where its cookie preferences control is also available.
Your Suno session cookies — used by the bot, with your consent
These are a different thing entirely, and we want to be direct about it because it is central to how the product works. The Software uses your own session cookies to connect to and operate on your account. They are not cookies this website places on your device — they are the credentials your browser already holds for Suno, which you hand over deliberately when you connect.
- Why: those platforms have no public API for this. Signing requests with your session is the only way the bot can upload to your library as you. Without it, nothing works.
- Your password is never requested, seen, or stored. Only the session credentials.
- They are used strictly to perform the jobs you ask for — never sold, never shared, never used to act on your account for anything you did not request.
- They are stored in access-restricted storage, kept only while your account is connected, and deleted when you disconnect or when they expire.
- You can end it two ways: disconnect inside the bot, or simply sign out of Suno in your own browser — that invalidates the session and cuts off access.
The connection tool you install
Capturing that session needs a small helper on your own device: a Chrome extension on desktop, a connection app on Android, or a Terminal command on macOS that downloads and runs the connection tool. Each is optional and installed by you.
They read the session for the account you sign in to, and nothing else. They do not read unrelated browsing history, do not monitor your activity, do not run in the background harvesting data, and send nothing to us beyond the credentials needed for the connection you asked for. Uninstall the extension or app, or disconnect in the bot, and their access ends.
10.Children
The Software is not intended for, directed at, or advertised to anyone under 18, and we do not knowingly collect data from children. Polar does not knowingly collect personal information from children under 13, and does not sell or share the personal information of consumers under 16 without the authorisation the law requires. If you believe a child has provided us with personal data, contact us and we will delete it.
11.Changes to this policy
We may update this policy. The effective date above will change, and material changes will be communicated through the bot before they take effect.
12.Contact
Privacy questions or requests: support@sunocoverbot.com. We reply within two business days.