Matchy Labs

Whim Privacy Policy

Effective date: 1 October 2026

This policy explains what data Whim handles, why, who else sees it, how long we keep it, and what you can do about it. It covers the Whim iPhone app, Whim in ChatGPT, and the song listening pages Whim makes.

1. Who we are

Whim is run by Matchy Labs Ltd (company number 17479437, registered in England and Wales, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom). In this policy, "Matchy Labs", "we" and "us" mean that company. For data protection law, we are the "controller" of your data: we decide what is done with it.

Contact for anything in this policy: hello@onwhim.app

Which laws apply. We are based in the UK, so the UK GDPR and the Data Protection Act 2018 apply to all the data we handle. If you are in the EU or EEA, the EU GDPR applies to your data too.

Our EU representative. Our representative in the EU is D.Y.A., based in the Netherlands, reachable at hello@onwhim.app. People in the EU can contact our representative instead of us.

2. The short version

3. What we handle, and why

Your library and sign-in

When you first open Whim, the app makes a random ID and a secret key. The key is saved in your iPhone's keychain. If you use iCloud Keychain, it is saved there too, so it can follow you to a new iPhone signed in to the same Apple ID. Apple handles that under its own privacy policy.

In the guest TestFlight build, our server keeps the random ID and a one-way hash of the key so it can tell which songs are yours. A guest library has no password or email recovery. If the key is lost and does not return through iCloud Keychain, we may be unable to restore that library.

In the App Store version, you sign in with Apple after choosing how to start a song and before adding material for it. Apple sends the app an identity token and one-time authorization code. Our server verifies them with Apple and stores a SHA-256 label derived from Apple's user identifier, linked to your Whim library. This is a persistent, pseudonymous account identifier, not anonymous data. We store an Apple refresh credential encrypted on our server so we can revoke the connection when you delete the account. Random session keys are stored on your phone; our server keeps only one-way hashes of them. Sign in with the same Apple account can restore your library on another device independently of iCloud Keychain. After deletion, the encrypted credential may remain in a separate retry record until Apple accepts the revocation; that record has no account ID, songs or contact details.

Whim does not request your name or email address from Apple. We verify the identity token but do not save a name or email claim from it in your account record, and do not use Apple sign-in to email you. If guest-library import is offered, Whim does not silently merge a guest library with another library already linked to that Apple account.

What you put in, and your songs

When you make a song, you can give Whim:

We store your song records: the idea and words you gave, the lyrics, the sound you chose, the title and artist name, the finished audio, previews, cover art, and the song's status. We keep them so you can play, edit and share your songs.

Photos and screenshots are sent to our server and then to an AI model provider to read them. Our server does not save them. While a song is unfinished, the app keeps copies on your phone so your draft survives if you close the app. Starting a new draft or using the account or library deletion control removes those copies.

Chats in screenshots contain other people's messages. The words we read from them can end up in your lyrics and song record. Only use chats the other people would be okay with.

Voice notes and hums are recorded on your phone. Only the words (from speech-to-text) or a short text description of the hum are sent to our server. The recording itself is not sent to us. Speech-to-text runs on your phone when it can. If your phone can't do it for your language, the app asks before sending the voice note to Apple for speech-to-text. Apple handles that under its own privacy policy.

Reference audio clips are optional. If you choose a file in “From a song,” the app sends it to our server and then to an AI model provider to describe its sound. We use that description to guide your song. We do not add the source file to your library or keep it on our server after the request; the model provider may retain a copy under its own terms. Apple's catalog previews are not used for this analysis.

Song search

When you search for a song you like, the words you type are sent from our server to Apple's public music catalog. We keep recent searches and their results in memory for up to 24 hours, so repeated searches are fast. These are not saved to disk and are not stored with your ID. When you tap play on a result, or see its artwork, your phone loads the 30-second preview and artwork straight from Apple. We don't store or analyse that audio.

Song-ready alerts (optional)

If you tap "Remind me" and allow notifications, your phone gives us a push token from Apple. We store it with your ID so we can tell you when a song is ready. Apple delivers the alert. The token is removed when you turn the reminder off, when Apple tells us it no longer works, or when you use the account or library deletion control.

Error records

When something fails, we record what went wrong so we can fix it: the screen or step, the error message, timings, the app build and iOS version, the song's ID, and a short one-way label made from your ID. We also record how the music check and song endings went. Error records never include your ideas, lyrics, photos, screenshots or audio. We send limited server events to Sentry and PostHog, both in the EU, to find failed or stalled jobs. Those events contain only the job stage, type of job, engine, error code, queue size and timings. They do not contain your song ID, device ID, installation ID, words, images or audio. We don't use these tools for advertising or profiles of app users. Session replay is not active in the iPhone app or song listening pages.

Your phone may also send us iOS crash and performance summaries. These can include the crash type and signal, offsets of frames in our app, app build and device type, hang duration, scrolling smoothness, time to first draw and peak memory. We use them to fix crashes and slow screens. They do not contain your ideas, lyrics, photos, screenshots or audio.

Support emails

If you email hello@onwhim.app, we receive your email address and whatever you include in the message. Resend receives the message and forwards it to our support inbox. Resend stores email data in the United States, even when email is sent through its EU sending region. We use it to answer you, investigate the issue or handle a report. We keep the conversation while needed for that request and any related legal obligations. Please do not send private chats, photos or your installation key unless we ask for them through a secure process.

Whim Pro subscriptions

Whim Pro is purchased through Apple's in-app purchase system. Apple processes your payment details. RevenueCat receives purchase and subscription history, product and entitlement status, and the Whim account identifier needed to connect the subscription to your library. We use that information to unlock Whim Pro, restore purchases, prevent fraud and understand subscription performance. RevenueCat provides purchase analytics; we do not use subscription data for advertising or tracking across other companies' apps. We do not receive your payment card number. Deleting your Whim account does not cancel a subscription with Apple; you can cancel it in your Apple subscription settings. The separate guest TestFlight build remains free and does not make purchases.

Sharing and public picks (optional)

If you make a listening link, anyone with the link can see and hear the song, its lyrics, title, artist name and cover, and download the audio. If you offer a song for public picks and we approve it, other Whim users can see and hear it in the app.

Reports

If you report a song in public picks, we store the reason you picked, the time, and a one-way label made from your ID, so the same person can't report twice and the song stays hidden for you.

Invites and credits

If you use invites, we store invite codes, which ID each code belongs to, which ID used it, and your pending and confirmed credits. To count how many different people listen to a shared song each day, we store a one-way hashed value per listener per day, not the listener's IP address.

Keeping Whim safe

To stop abuse, the server remembers the IP address of each request that creates a new ID, in memory only, to limit how many IDs one address can create per hour. It is never written to disk and is cleared when the server restarts.

Our hosting provider may also keep network logs, including IP addresses.

Whim in ChatGPT

If you use Whim inside ChatGPT, ChatGPT sends us what you asked the song to be about, any lyrics, a title, a sound and the language. It also sends an anonymized user ID that OpenAI makes for Whim. We don't get your name, email or ChatGPT chats.

We keep a scrambled (salted hash) copy of that ID so each ChatGPT user can make one preview, and never store the ID itself. Your preview (the words, lyrics, cover and audio) is private to your player in ChatGPT, which fetches the audio and cover through links that expire after a day. If you tap "Get a link to share", we make a listening page on onwhim.app for that song: anyone with the link can play it and see its title, lyrics and cover. Unshared previews are deleted 30 days after they're made; shared ones stay until you ask us to take them down.

Before a preview plays, we check its title, lyrics and cover with an AI model, the same check a public listening link gets. OpenAI handles your use of ChatGPT under its own privacy policy.

Early-access list (optional)

Before the Whim app is in the App Store, you can leave your email for an invite: in the Whim player in ChatGPT, or on a song's listening page. It's optional, and you get your song whether you leave it or not.

We store the email, when you left it, where (ChatGPT or a listening page), the words you saw next to the field, and, from ChatGPT, the scrambled ID above, so one person can't fill the list. From a listening page we also note which song page it came from. We use your email only to send your invite to Whim and then the launch news it needs, never for ads, and we don't share it with anyone except the email service that sends the invite.

What we don't collect

The app does not ask for your name, email, phone number, contacts, location, advertising ID or payment card details. Apple and RevenueCat handle subscription purchase history as described above. If you email support, we receive your email address and message as described above. If you join the early-access list, we receive the email you leave. We don't use ad tools or follow you across other apps or websites. Our limited server diagnostics are described above.

UK and EU data protection law says we need a legal reason for each use of your data.

WhatLegal reason
Your ID or account label, verifying Apple sign-in where enabled, making songs, sending your input to the services that make them, storing and restoring your library, listening links and public picks you chooseContract: we need it to give you the service you asked for.
Error records and server reliability metrics, the IP limit on new IDs, reports, reviewing public picks, stopping credit farmingLegitimate interest: keeping Whim working, fair and safe. We keep this data small and don't link it to who you are.
Subscription status and purchase historyContract: to unlock and restore Whim Pro. Legitimate interest: to check purchases, prevent fraud and understand whether subscriptions work as intended. Legal obligation: for records we must keep by law.
Support email and what you send usLegitimate interest: answering requests, fixing problems and handling reports.
Other people's details in the chats and photos you useLegitimate interest: yours in making a song from your own conversations, weighed against theirs. That is why we ask you to only use chats they would be okay with.
Song-ready alerts, and sending a voice note to Apple for speech-to-textConsent: you turn these on. You can turn them off at any time.
Making a song in ChatGPT and showing it in your playerContract: we need it to give you the song you asked for.
The one-song limit in ChatGPT, the scrambled ChatGPT ID, and the safety check before a ChatGPT preview playsLegitimate interest: keeping the free preview fair, our costs in check, and harmful content out.
Your email on the early-access listConsent: you choose to leave it. Ask us to remove it at any time.
Answering authorities or keeping records the law asks forLegal obligation.

The "Before we start" screen in the app tells you what is sent and asks you to confirm before your input leaves your phone.

We don't make decisions about you by automated means that have legal or similarly serious effects. When two different people report a song, it is taken out of public picks automatically until we review it. That is a safety step, not a decision about you.

5. Sensitive information

Please don't put sensitive details in your songs, about yourself or others, such as health, religion, sex life, politics, or anything about a crime. If a chat you use happens to contain them, the AI models will read them to write lyrics. We don't look for or use sensitive details for any other purpose.

6. Who else handles your data

We use these kinds of services to run Whim. Each only gets what it needs for its job.

ServiceWhat it doesWhat it gets
A cloud hosting provider (servers in the EU)Runs our server and stores your library, with daily backupsEverything our server stores (section 3)
A GPU computing providerMakes the music, on our own copy of a music modelThe lyrics and sound description for each song. It returns the audio.
A model routing serviceSends text, images and optional reference audio to AI model providersYour words, lyrics, sound choice, song title and artist, and photos, screenshots or reference clips when you choose them
AI model providers, reached through that routing serviceWrite lyrics, read images and reference clips, make covers, describe soundsWhat the routing service passes on for that one request
Apple's public music catalogFinds songs you search forThe words you type, sent from our server
Apple, for notifications and speech-to-text you choose to useDelivers song-ready alerts, and turns a voice note into words when your phone can'tYour push token and the alert text (the song title); the voice note, only if you agree
Apple, for Sign in with Apple in the App Store versionVerifies sign-in and revokes Whim's connection when you delete the accountApple handles your Apple account; our server receives sign-in tokens and a one-time code, and retains the derived account label and an encrypted refresh credential
Apple and RevenueCat, for Whim ProApple processes subscriptions and payments; RevenueCat verifies them, restores access and provides subscription analyticsPurchase history, product and entitlement status, and the Whim account identifier needed to link a purchase to its library. Apple handles payment card details; we do not receive them.
Sentry and PostHog (EU projects)Help us find failed and stalled song jobsLimited server event codes, stages and timings; no song content or user identifiers
OpenAI (ChatGPT)Runs ChatGPT, where the Whim player appearsWhat you type in ChatGPT, under OpenAI's own terms. It sends us only the song request and an anonymized ID.
Resend and our support inboxReceive and forward support messagesYour email address, message and any attachments you choose to send

Want the names of the companies we use? Email hello@onwhim.app and we'll send you the current list.

AI services we use and what they keep. To write lyrics, read your photos or chat screenshots, suggest sounds, describe a song's style and make covers, we send the words, lyrics, song title and artist, and images or reference clips you choose to a model routing service, which passes each request to an AI model provider. The routing service does not routinely store input content after routing, but may retain it for abuse detection, security, billing or legal compliance. The AI model providers we currently use are not listed as using the data we send to train their models, based on the provider terms and settings currently applicable to the services we use. Depending on which provider handles a request, it either keeps nothing or may keep a copy for a limited time for abuse monitoring: up to 30 days for lyric writing and photo or chat reading, up to 55 days for cover images and cover descriptions. The provider does not publish a specific retention period for song style descriptions, sound suggestions or reference audio analysis. Provider terms and retention practices may change.

To make music, we send your lyrics and sound description to a GPU computing provider running our own copy of a music model. It returns the audio, and the provider keeps the request and result for up to 30 minutes after the song is made. Our own server stores what you create in your library until you delete it. Our error logs do not record your ideas, lyrics or images.

We don't sell your data or share it for advertising. We only give it to others if the law makes us, to protect someone's safety, or if Whim is taken over by another person or company, who would then have to follow this policy.

7. Data sent to other countries

We are in the UK, and our server is with a cloud hosting provider in the EU. The UK treats the EU as giving data the same protection, so data can go there without extra steps.

Some of the services above are based in, or may process data in, countries outside the UK and EU, including the United States, Singapore and potentially other countries. Resend stores support email data in the United States, even when email is sent through its EU sending region. The exact processing location of a reference-audio request can vary. When your data goes abroad, we use one of these safeguards where required, depending on the provider and country:

You can ask us for more detail, or a copy of the safeguard, by email.

8. How long we keep it

DataHow long
Guest installation ID and hashed key, or account library ID, hashed Apple account label and hashed session keysUntil you use the account or library deletion control. Deleted records may remain in daily backups for about 5 days.
Encrypted Apple refresh credential for a signed-in accountKept with your account until deletion. If Apple cannot revoke it immediately, retained separately with a random retry ID, attempt count and next-attempt time until revocation succeeds, then removed. It may remain in daily backups for about 5 more days. No fixed retry deadline is promised.
Apple identity token and one-time authorization codeUsed to verify sign-in; not saved in the account record.
Songs, previews, lyrics, covers, audio and what you gave to make themUntil you delete the song or use the account or library deletion control. There is no automatic expiry.
Backups of our serverOur hosting provider keeps daily copies of our storage for about 5 days. Deleted songs can stay in these copies until they roll off.
Photos and screenshotsNot stored on our server. On your phone, until you finish or replace the draft or use the account or library deletion control.
Song search cacheIn memory only, up to 24 hours, and gone if the server restarts.
Push tokenUntil you turn the reminder off, Apple says it no longer works, or you use the account or library deletion control.
Error recordsIn a small log on our server that keeps the newest entries (up to about 4 MB) and overwrites the oldest. How long that is depends on how busy Whim is. Error lines also go to our hosting provider's logs.
Limited server events at Sentry and PostHogSentry keeps events for 30 days. PostHog keeps events for up to 12 months and recordings for 30 days; no recording is currently made in the iPhone app or song listening pages. These events contain no song content or user identifiers.
Whim Pro purchase history and entitlement statusKept while needed to provide and restore the subscription, keep required transaction records and resolve payment issues. Apple and RevenueCat also keep purchase records under their own policies. Deleting a Whim account does not cancel the Apple subscription.
Support emailsWhile needed to handle your request and related legal obligations.
ReportsWhile the reported song exists.
Listening linkUntil you turn it off, delete the song, or use the account or library deletion control.
Invites and creditsInvite codes and credits: until you use the account or library deletion control. Listener values: only the current day's are kept. They are replaced with a new random set the next day your song is played.
Whim in ChatGPT: your preview (words, lyrics, cover, audio)30 days after it's made, then deleted. If you made a share link, until you ask us to take it down.
Whim in ChatGPT: the scrambled user ID and how many songs it has madeKept, so the one-song limit keeps working. It can't be turned back into your ChatGPT ID.
Whim in ChatGPT: count of songs made each day8 days. Not linked to anyone.
Early-access emailUntil we've sent the launch invites, plus 6 months, then deleted. Sooner if you ask us to remove it.
IP addresses for the new-ID limitIn memory only, never on disk, until the server restarts.
Copies at AI model providersDepending on the provider and request: none, up to 30 days for lyric writing and photo or chat reading, or up to 55 days for cover images and cover descriptions. No specific period is published for song style descriptions, sound suggestions or reference audio.

9. Deleting your data

Some things can stay after deletion: backups (about 5 days), error records (which don't contain your songs and carry only a one-way label), reports you made on other songs, the encrypted Apple credential while a revocation is pending, and anything the AI model providers still keep. Songs other people already downloaded from a link can't be taken back.

10. Your rights

You have the right to:

To use these rights, email hello@onwhim.app. We'll answer within one month. We may need to check the request is really from you. If we cannot verify that a library belongs to you, we'll tell you.

You can also complain to the UK Information Commissioner's Office (ico.org.uk), which oversees us. If you are in the EU, you can also complain to the data protection authority where you live or work. We'd like the chance to fix it first, so please write to us.

11. People in California and other US states

We don't sell or "share" personal information as California law defines it, and we don't use it for targeted ads. In the last 12 months we have handled these kinds of information, for the purposes in section 3: identifiers (your guest ID or, for a signed-in account, a derived Apple account label, session records and push token), content you give us (words, lyrics, images, songs), subscription purchase history when you use Whim Pro, and technical error records. You can ask to know, correct or delete your information by writing to hello@onwhim.app. We won't treat you differently for asking.

12. Children

Whim is not for children under 13. We don't knowingly collect data from children under 13. If you think a child under 13 is using Whim, email us and we'll delete their data.

If you are in the EU, your country may set a higher age, up to 16, for using apps like Whim on your own. If you're under that age, please ask a parent before using Whim. We don't rely on consent for making songs, but we still think a parent should know.

Whim isn't designed for children. Because teenagers can use it, we keep privacy settings on by default: your songs are private, and nothing is shared publicly unless you choose to share it. There is no tracking, no ads and no location data.

You don't need the app to listen to a shared song. The listening page shows the song, lyrics, title, artist name and cover. It uses no cookies, no trackers and no analytics. Our hosting provider sees your IP address to deliver the page. Before the Whim app is out, the page also has an optional field to leave your email for an invite, described in section 3.

14. Security

Traffic between the app and our server is encrypted (HTTPS). We store one-way hashes of access and session keys. In an account-enabled build, we also store a one-way label derived from your Apple user identifier and encrypt the Apple refresh credential before storing it. Stored files and backups are encrypted by our hosting provider. Only we can get into the server. No system is perfectly safe. If a breach puts your data at risk, we'll act as the law requires, including telling the authority and, where needed, you.

15. App Store privacy information

Apple asks apps to list the data they collect. These are the data types Whim handles for app operation and diagnostics, including optional inputs; we do not use them to track you across other apps:

16. Changes

We'll update this policy when Whim or the way we handle data changes, and change the date at the top. If a change matters, we'll tell you in the app before it takes effect.

17. Contact

Matchy Labs Ltd
Company number 17479437, registered in England and Wales
Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Company email: hello@matchylabs.xyz
Whim support and privacy: hello@onwhim.app

EU representative
D.Y.A., Netherlands
Email: hello@onwhim.app