Security overview
Last updated: August 9, 2026
This page summarizes how we protect AI YourSong accounts, creative content, payments, and infrastructure. It is a product security overview — not a guarantee that systems are invulnerable. For personal-data details, see the Privacy Policy. For account deletion, see Delete account & data.
Report a vulnerability: innovatejds@gmail.com — please include steps to reproduce and avoid public disclosure until we have had a reasonable chance to investigate and fix.
Authentication & sessions
- Sign-in is powered by Google Firebase Authentication.
- Supported methods may include Google, Sign in with Apple, email/password, and other providers we enable in the product.
- We never receive or store your Google or Apple account passwords.
- For email/password accounts, we require email verification before full access and welcome benefits are unlocked.
- Song generation, music-video jobs, wallet verification, and other privileged API routes require a valid Firebase ID token.
- We discourage OAuth flows inside untrusted in-app browsers where redirect state can break; use a system browser when prompted.
Transport & storage
- App and API traffic use HTTPS / TLS.
- Cleartext HTTP is disabled in the Android network security configuration.
- Firestore and Cloud Storage data are encrypted at rest by Google Cloud.
- Generated media is stored in access-controlled cloud storage and delivered over HTTPS.
- Our legal/static site sends modern browser headers (HSTS, framing protection, content-type nosniff, referrer policy, and Content-Security-Policy where configured).
Data access controls
- Firestore / Storage security rules restrict reads and writes by ownership, role, and documented admin allowlists.
- Users can read and update their own profile fields; sensitive fields (tokens, purchases, license acceptance, admin entitlements) are protected by rules and/or server-side logic.
- Generation and credit operations that affect balances run through authenticated backend endpoints, not open client writes.
- Admin Pro and similar entitlements are limited to configured operator accounts and enforced in product logic plus rules where applicable.
Abuse, fraud, and rate limits
- Device / install fingerprinting helps limit duplicate free-account abuse on the same device.
- Client and server checks rate-limit high-cost actions such as generations and gifting.
- Email signup guards reduce disposable and alias abuse where practical.
- Store purchase processing credits entitlements only after verified purchase; restores do not re-credit consumable packs.
- Community report / block tools and automated text screening help reduce harassment and prohibited content — see Community Guidelines.
Payments
App stores
Token packs and memberships can be purchased through Google Play and the Apple App Store. Card numbers and store credentials are handled by those platforms — we never receive your full payment card number. We receive purchase confirmation signals needed to unlock tokens or membership.
Application & API protections
- Backend API responses include Helmet-based security headers when served from our servers.
- CORS and authentication middleware limit which clients can call privileged routes.
- Content license acceptance is versioned on the account so downloads and commercial-use gates stay aligned with the current AI Content License.
- We do not ask for your private keys, seed phrases, or Google/Apple passwords. Anyone who does is not us.
Protecting your account
- Use a unique, strong password for email accounts and enable provider 2FA (Google / Apple) where available.
- Do not share verification links, wallet signatures, or recovery codes.
- Sign out on shared devices; revoke access from your Google/Apple account settings if a device is lost.
- Be cautious of phishing emails or DMs asking you to “verify” AI YourSong by sending crypto or passwords.
- You can delete your account and request data deletion via Delete account & data.
Limitations
No method of transmission or storage is 100% secure. Cloud providers, devices, browsers, and third-party AI vendors introduce residual risk. If we learn of a security incident affecting personal data, we will take steps required by applicable law, which may include notifying affected users and regulators.
Responsible disclosure
If you believe you found a security vulnerability in AI YourSong (app, API, or legal site), email innovatejds@gmail.com with:
- A clear description of the issue and potential impact
- Steps to reproduce (or a proof-of-concept that does not harm other users)
- Your contact details for follow-up
Please do not access data that is not yours, disrupt the service, or publicly disclose the issue until we have had a reasonable chance to investigate and remediate. We appreciate good-faith researchers.
Contact
Security and privacy: innovatejds@gmail.com
Privacy Policy Terms of Service AI Content License Legal home