Resona AI

Privacy Policy

Last updated: 27 September 2026

This policy explains how Weresona (“we”, “us”) collects, uses and protects personal data when you use Resona AI (the “Service”), in line with Singapore’s Personal Data Protection Act 2012 (PDPA).

1. Contact and Data Protection Officer

For any privacy question or request, contact our Data Protection Officer at numi@weresona.com.

2. What we collect

DataExamples
Account detailsEmail address, name and job role (if you add them), password (stored only in encrypted, hashed form)
Business detailsCompany name, business type, music preferences you choose during setup
Store detailsStore name, address and the email address used for the store’s player account
AnnouncementsThe text you write for jingles and the audio generated from it
Usage dataWhen store players are online and how many minutes of music they play; server logs with IP addresses and browser details
Cookies and device storageA session cookie that keeps you signed in and protects forms; on store devices, the offline-music setting and any music the store chooses to save

We don’t use advertising or tracking cookies.

3. How we use it

By using the Service you consent to this use. You can withdraw consent at any time by contacting us, but we may then be unable to provide some or all of the Service.

4. Who we share it with

We don’t sell personal data. We use these service providers to run the Service:

ProviderWhat forWhere
VultrServers that run the Service and store its databaseSingapore
SupabaseStorage for music and audio filesSingapore
ElevenLabsTurning announcement text into voice audioUnited States and other regions
Google WorkspaceSending account emailsGlobal
Google Fonts and Cloudflare (cdnjs)Fonts and scripts loaded by our pages; they receive your IP address when a page loadsGlobal

We may also disclose personal data where the law requires it.

5. Transfers outside Singapore

Some providers process data outside Singapore. We rely on their contractual commitments to protect personal data to a standard comparable to the PDPA.

6. How long we keep it

We keep personal data while your account is active. After an account is closed, we delete or anonymise its personal data within 90 days, unless we must keep it longer by law. Backups are overwritten within 30 days.

7. How we protect it

Connections are encrypted (HTTPS), passwords are stored only as secure hashes, access to systems is restricted, and backups are kept. No system is perfectly secure, so please use a strong password and keep it private.

8. Your rights

Under the PDPA you can:

Email numi@weresona.com. We aim to respond within 30 days.

9. Who the Service is for

The Service is for businesses and isn’t intended for anyone under 18.

10. Changes to this policy

We may update this policy. We will post the new version here and, for important changes, email you.