Policy

Privacy policy

How dissed.io collects, uses and shares personal data. Operated by 41Flow Ltd. This is the long-form policy; the cookie specifics live in our cookie policy.

Last updated5 May 2026

We don't run advertising, we don't sell personal data, and we don't profile users for advertising purposes.

Who we are

dissed.io is operated by 41Flow Ltd, registered in England & Wales, company no. 17049682. We are the data controller for personal data processed through this site.

Our registered office is 50 Princes Street, Ipswich, IP1 1RJ.

Contact: hello@41flow.co.uk — for privacy questions, data subject requests, support, or any other matter related to this policy or to dissed.io.

What we collect and why

We work to data-minimisation and purpose-limitation: we collect only what's needed for the function or legal duty described next to each category, we don't repurpose data for unrelated uses, and we don't ask you for fields the product doesn't need. If a feature can be built without a piece of personal data, that's how we build it.

Lawful bases below are keyed to UK GDPR Art. 6.

The events we capture cover prompts (counts only, never the text), purchases, downloads, deletions, and takedown reports — labels and IDs only. We do not send free-form prompt or lyric text to analytics.

Track targets — when you name someone else

A diss track is built around a target: a name typed by the creator, often someone who hasn't signed up to dissed. That name is personal data about a third party, and we treat it that way.

Why we don't notify each target individually. UK GDPR Art. 14 normally requires us to give targets the same kind of notice we give signed-up users. We don't, because we have no way to contact someone we only know by a free-text name typed by the track's creator — that's the Art. 14(5)(b) "disproportionate effort" exception. To make the underlying right effective in practice, the takedown route is deliberately low-friction: any visitor of the share page can submit a report without an account, and a confirmed report hides the page immediately.

Sharing and public content

Cookies, browser storage and analytics

Full detail lives in our cookie policy. In short: strictly-necessary cookies set by Clerk keep you signed in; a single localStorage entry remembers your cookie choice; and PostHog analytics is opt-in in the UK/EEA and opt-out elsewhere, with GPC honoured. You can change your choice any time via in the footer.

Sub-processors and international transfers

VendorPurposeDataRegion
Vercel Inc.Hosting, CDN, edge runtimeAll inbound traffic; logsLondon (compute); US (controller)
Convex (Convex, Inc.)Application database, function runtime, Convex Agent threadsAll app data (account, tracks, lyrics, threads, takedowns)Ireland (EU); US (controller)
Clerk Inc.AuthenticationEmail, name, image, password hash, session cookiesUS
Cloudflare R2 + CDN (cdn.dissed.io)Audio + cover-art object storage, public deliveryTrack audio, cover imagesWestern Europe for storage; Cloudflare global edge for delivery; US (controller)
Polar Software Inc.Checkout, billing, invoicesEmail, name, billing detailsUS
ResendTransactional email (takedown verification only)Reporter email + verification linkEU (Ireland) sending node; metadata + logs stored in US
Sentry (Functional Software, Inc.)Crash and error monitoringErrors, breadcrumbs, Clerk user IDDE; US (controller)
PostHogProduct analyticsAnonymous ID, identified Clerk user ID after consent, event names + propertiesEU; US (controller)
AnthropicLyric generation (Claude), routed via Vercel AI GatewayPrompt + lyrics textUS
Replicate, Inc.Cover-art generation, lyric alignmentCover prompts, audio for alignmentUS
Black Forest LabsCover-art generation (FLUX models)Cover promptsDE (EU)
MiniMax (Nanonoble Pte. Ltd.)Music + audio generationMusic prompt + AI-generated lyrics; no Clerk ID, email, or payment dataSingapore controller; US data centre; group affiliates

Any transfer of data outside the UK or EEA is covered by the UK IDTA or EU Standard Contractual Clauses, with the EU-US Data Privacy Framework relied on where the recipient is DPF-certified.

This list is current as of the "Last updated" date at the top of the page. We'll update this section before adding a new sub-processor that materially changes the data exposure picture.

A note on MiniMax

MiniMax generates the audio in your tracks. We name them separately because their data picture is more nuanced than the one-line table row above.

How long we keep things

Where it's necessary to establish, exercise, or defend legal claims, we may retain limited data beyond the windows above for the duration of the relevant limitation period (in the UK, six years for contract claims).

Aggregated and de-identified data

We may compute and keep aggregated, statistical, or otherwise de-identified data — counts of tracks generated, model performance metrics, that kind of thing — that no longer identifies any individual. De-identified data isn't subject to the retention windows above and may be kept indefinitely. We don't re-link it to identifying data.

Children

dissed is 18+ only. The eligibility clause is in our terms. We don't knowingly process data from anyone under 18; if we learn that we have, we delete the account and content.

Security

Your rights

Under UK and EU GDPR you can: access your data, correct it, ask us to erase it, restrict or object to its processing, port it, withdraw consent where consent was the basis, and complain to a supervisory authority. To act on any of these, email hello@41flow.co.uk.

We respond within one month of receiving a valid request, in line with UK GDPR Art. 12(3). Where a request is particularly complex or you've sent us several at once, we may extend that window by up to two further months — if we do, we'll tell you within the original month and explain why.

How we verify identity depends on who you are:

You can also complain to the UK Information Commissioner's Office at ico.org.uk or to your local EEA supervisory authority.

Automated decision-making

We don't subject you to decisions based solely on automated processing that produce legal or similarly significant effects on you (UK GDPR Art. 22). The closest thing we run is the three-strike auto-suspension for creators with three upheld takedowns — but the upholds themselves are human-reviewed decisions; the suspension is just the bookkeeping that follows. Suspended creators can appeal to hello@41flow.co.uk for human review.

Marketing and contact preferences

We don't send marketing email and we don't run a mailing list. The only emails we send are transactional — takedown verification — and Polar sends purchase receipts directly from their own infrastructure. There's no marketing opt-out toggle because there's no marketing channel to opt out of.

Changes to this policy

questions land, data stays clean.

Privacy · hello@41flow.co.uk