Privacy policy
Last updated 4 October 2026
This policy explains what personal data InnerHook collects on innerhook.com and in the app at app.innerhook.com, why, and what you can do about it. The short version: we collect what we need to run the waitlist and the app, analytics only if you allow it, your lyrics are yours, and they are never used to train AI models.
Who we are
InnerHook is run by Unreal Productions Oy, the controller of the personal data described here.
Unreal Productions OyLaippatie 5, 00880 Helsinki, Finland
Business ID 3196400-5 · VAT FI31964005
Contact for anything about your data: privacy@innerhook.com.
What we collect and why
The waitlist
- Your email address, and your name and what you write if you choose to tell us.
- When you gave your consent, so we can show that you asked to be emailed.
- A hashed (irreversibly scrambled) version of your IP address, to stop spam and abuse of the form.
Why: to invite you to the closed beta and to email you about InnerHook. Legal basis: your consent. The hashed IP address is kept for our legitimate interest in keeping the form free of abuse.
Analytics on innerhook.com
Only if you accept analytics in the cookie settings, we use Google Analytics to see how the site is used: pages viewed, the kind of device and browser, approximate location (country or city level) and events such as joining the waitlist. Until you accept, the Google tag is not loaded at all and nothing is sent to Google. If you withdraw your consent, it stops sending. Legal basis: your consent, which you can withdraw at any time. See Cookies for the details.
Your account in the app
- Your name and email address, and your workspace.
- Sign-in links: we store only a scrambled (hashed) form of each link, with the email address and the IP address it was asked from. A link works once and expires in 15 minutes.
- Sessions: while you are signed in we keep a session record with your IP address and browser (user agent), to keep you signed in and your account safe.
- How your account was made (an invite code, a waitlist invite or a song shared with you, and who invited you), so we can run the closed beta. We get an email about each new account with these details.
- Your settings, such as whether you want emails about comments.
What you write
- Your songs: the lyrics, their sections, versions and version history, and each song’s notes (the song brief).
- Your artist profiles. If you upload a profile picture, we keep only a cropped, resized copy of it (512 and 128 pixels). The file you uploaded isn’t stored, and its metadata (EXIF, such as where a photo was taken) is removed.
- Your daily pages, their days and word counts. Daily pages are private: only you see them.
- Comments you write on songs, and the people you mention in them.
Why: to provide the app to you. Legal basis: our contract with you (the terms of service). Session and sign-in details are also kept for our legitimate interest in keeping accounts and the service secure.
Sharing songs with co-writers
When you share a song, the people you share it with see the song, its comments and the names of the others with access. A co-writer sees the owner’s name and email address, and the owner sees each co-writer’s name and email address. Co-writers never see each other’s email addresses. If you invite someone by email, we send the invite to that address. People mentioned in a comment get an email about it, unless they have turned those emails off.
Public links to a song
A song’s owner can make a public link to it. Anyone who has the link can read the song without an account: its title, its lyrics as last saved, its tempo, time signature and key, and the owner’s name (the name on their account; if it has none, no name is shown). If the owner chooses, the page also shows the name of the song’s artist profile. The page never shows an email address, comments, versions or history, the song’s notes or the names of co-writers. The owner can replace the link or turn it off at any time, and deleting the song stops it too; people who already read or copied the lyrics may still have them.
A public page sets no cookies and has no analytics. To stop abuse, our server counts requests to these pages per IP address for a minute at a time, and our web server keeps its usual access logs. Public pages ask search engines not to index them.
Your public writer profile (optional)
If you turn on your public profile, the information you choose to show on it is public at app.innerhook.com/@your-handle: your handle, the name you give, your picture, your bio, the languages and styles you list, your links, and the songs you choose to show (their title, first lines and public read link). It never shows your email address. It is off until you turn it on, and search engines are asked not to list it unless you choose otherwise. You can change it or turn it off at any time; a page turned off stops showing at once. A handle you give up stays reserved for you for 30 days, so nobody else can use it in your name.
Requests sent through a writer’s profile. If a writer turns on Requests, visitors can send them a message with a form. We send the visitor’s name, email address and message to the writer by email (the writer’s reply goes from their own email to the visitor; the visitor does not see the writer’s address unless the writer replies). We keep the message only until it is delivered: while it waits to be sent it is stored encrypted, and a delivery that keeps failing is deleted after 7 days. To limit abuse we keep, for 30 days, a record that a request was sent to that profile, the time, and a one-way keyed hash of the sender’s IP address (not the address itself). Legal basis: the sender’s consent (the form’s checkbox) and our legitimate interest in preventing abuse; for the writer’s profile itself, our contract with the writer.
AI features
When you use an AI feature, the text it needs is sent to our AI provider, Anthropic, PBC (USA), through its Claude API: for example the lines you selected, the song as context, the song’s notes and the style fields of its artist profile. When the song has an artist profile with example songs, the request also carries up to 3 of those songs: their titles and excerpts of their lyrics, about 1,500 characters in all, so the suggestion matches the profile’s style. A profile’s name is never sent. The text is sent only to produce your suggestion. Anthropic does not use content sent through its API to train its models, under its commercial terms, and neither do we.
Hear it sung (a song sung by AI): when you ask for it, the lines of the part of the song you chose and the style you set for it — genre, mood, tempo, time signature, key, the kind of singer and a short description of the sound — are sent to our music provider, ElevenLabs, Inc. (USA), through its Eleven Music API, to produce the audio. We never add your profile’s name to it (if the words or the style you write mention it, they are sent as you wrote them). The audio it returns (a “take”) is kept with the song, so the people who can open the song can listen to it; we keep who made it, when, its name and the style used. Legal basis: our contract with you.
For each AI request we keep a usage record: who made it, which feature, the song, the number of tokens, the estimated cost and whether it worked. It never contains your text. We use it to run fair limits and keep costs in check.
Payments (when payments start)
Paid plans are handled by Stripe Payments Europe, Ltd. (Ireland). Your card details go straight to Stripe, never to us. We keep your Stripe customer and subscription identifiers, your plan, and for each purchase what you bought, the amount, the VAT, its date and Stripe’s identifiers of the payment, your request to start right away and your confirmation of your age (and when you gave them). Stripe also processes some data as a controller under its own privacy policy, for example to prevent fraud and to meet its legal obligations. Legal basis: our contract with you, and our legal obligation to keep accounting records.
Copies on your device
The app keeps some data in your browser’s storage (IndexedDB and local storage) on your device: the songs you have open, so you can keep writing without a connection, and the text of a daily page or profile until our server has saved it, so nothing is lost if the connection drops. It also remembers view preferences such as the font size. These copies stay on your device. Signing out removes your songs from the device, except changes that haven’t reached our server yet.
Your lyrics are yours
Everything you write in InnerHook belongs to you. Your songs are private to your account unless you share them or make a public link to them, and your lyrics are not used to train AI models.
Who processes data for us
We use a few service providers who process personal data on our behalf, under data processing agreements:
- Hetzner Online GmbH (Germany): hosting, in a data centre in Helsinki, Finland.
- Stripe Payments Europe, Ltd. (Ireland): payments, when paid plans start.
- Anthropic, PBC (USA): the AI model behind the AI features in the app.
- ElevenLabs, Inc. (USA): the music model behind Hear it sung (songs sung by AI).
- Resend (USA): delivers our emails, such as sign-in links, invites and comment notifications.
- Google (Google Analytics): website analytics on innerhook.com, only with your consent.
Transfers outside the EU/EEA: Anthropic, ElevenLabs, Resend and Google process data in the United States. For each of them we rely on the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission’s standard contractual clauses. Hetzner hosts the app in Helsinki, Finland. Stripe Payments Europe (Ireland) may transfer data to other Stripe group companies and its subprocessors outside the EU; as Stripe describes in its privacy center, it relies on the EU–US Data Privacy Framework and standard contractual clauses for that. You can ask for a copy of these safeguards at privacy@innerhook.com. We do not sell your personal data.
How long we keep it
- Waitlist: until you are invited and have had the chance to join, you unsubscribe or ask us to delete your details, or we close the waitlist.
- Analytics: according to our Google Analytics data retention setting, at most 14 months.
- App account and what you write: for as long as you have an account. When you ask us to delete your account, we delete your data, except what the law requires us to keep and the following:
- Comments you wrote in songs owned by others stay with those songs, shown as by a “Deleted account”. If you want them gone, delete them before you delete your account.
- Emails we have already sent, for example comment notifications, stay in their recipients’ mailboxes.
- Deleted songs, profiles and daily pages: kept in Recently deleted for 30 days, so you can restore them, then removed for good.
- Sign-in links: removed in a daily clean-up shortly after they expire.
- AI usage records: 180 days.
- Songs sung (takes): kept with their song until the person who made one, or the song’s owner, deletes it. A deleted take is removed for good after 30 days, and every take goes when its song is removed for good.
- Public writer profile: until you change it or turn it off, or your account is deleted.
- Requests to a writer: the message until it is delivered (encrypted while it waits; a delivery that keeps failing is deleted after 7 days); the record that a request was sent (profile, time, hashed IP address) for 30 days.
- Comment notification records (who is to be emailed about which comment): removed in a daily clean-up once they are 30 days old.
- Payment records: what you bought and when, the amount, the VAT, the Stripe identifiers of the payment and the email address of the account, for as long as the Finnish Accounting Act requires (currently six years from the end of the financial year), also after your account is deleted.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy of it, also in a machine-readable form;
- have inaccurate data corrected;
- have your data erased;
- restrict how we process your data in some cases;
- object to processing based on our legitimate interest;
- withdraw your consent at any time (for emails: unsubscribe; for analytics: ), without affecting processing before it;
- lodge a complaint with a supervisory authority. In Finland that is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.
To use your rights, email privacy@innerhook.com. We answer within one month.
Changes
If we change this policy, we update the date at the top. For significant changes we will let waitlist members and app users know by email.