Draft, not reviewed by a lawyer
Privacy policy
Last updated: draft of 6 October 2026
Here you can read what information hurra processes, why we do it, who helps us with it and how long we keep it. The policy applies both to you who buy hurra for a party and to the guests who tell stories and share photos. This is a translation; if it differs from the Danish version, the Danish version applies.
Who is responsible
hurra is run by Datastrøm ApS, Søborg Hovedgade 100B, 4. tv., 2860 Søborg, Denmark, CVR 39799804. Datastrøm ApS is the data controller for the information processed in hurra.
If you have questions about your data, write to hej@hurra.fm or call [Draft: phone number to be added].
When you buy and set up the party
We process:
- Your email address and details of the purchase: package, amount, time and Stripe's id for the payment. The payment itself happens at Stripe, so we never see your card details.
- The email addresses of the people you give access to the party.
- What you write in the setup: the names of the people being celebrated, the occasion, the date and the background facts the songs may use, including what the songs must not mention.
- The table card: text, design and the background painted for it.
- An invitation, if you upload one so the table card can match it. We do not keep the invitation itself. It is only sent to the suppliers who make the card, see below.
- The welcome message and the settings for the party's screen.
- A welcome portrait, if the party has one: an illustration of the people being celebrated, shown on the guests' welcome page and on the party's screen. [Draft: how the portrait is made, and what it is based on, to be added.]
- When you ask for a sign-in link, we store the link as a hash together with your IP address. The link works for 15 minutes.
We do this to deliver what you have bought (General Data Protection Regulation art. 6(1)(b)), and we keep purchase records because the Danish Bookkeeping Act requires it (art. 6(1)(c)).
We use the IP address only to limit how many sign-in links can be requested, so nobody can flood an inbox or abuse sign-in. This is based on our legitimate interest in keeping the service secure (art. 6(1)(f)).
Without an email address we cannot send you access to the party, and without payment we cannot deliver it.
When you are a guest
When you use hurra at a party, we process:
- Your name as you write it, your relationship to the people being celebrated, and your story.
- Your choice of genre and any wish you have for the voice.
- A selfie, if you choose to take one.
- The photos you share in the party's album, and which photos you have given a heart.
- The song and the lyrics made from your story.
- A random guest id that your phone stores, and that we store with your songs, photos and hearts so your own contributions belong together. The id does not contain your name, but it is linked to the name you write.
The song is played for the party together with your name and your relationship. Your story and your selfie are not shown on the party's screen or in the album. The host who bought the party, and the people the host has given access, can see your selfie and the first 160 characters of your story, so they can approve songs and look after the party.
Photos in the album can be seen by the party's guests and may be shown on the party's screen.
A song can be shared with a link, both by you and by the host. Anyone with the link can hear the song and see the lyrics, your name and your relationship, the first lines of your story, the names of the people being celebrated, and the occasion. Sharing can be stopped again.
Your selfie only appears on the sharing page if it is switched on when the song is shared from the guest page. This is based on consent (art. 6(1)(a)), and you can withdraw it at any time by stopping the sharing or writing to hej@hurra.fm.
Using hurra as a guest is voluntary. You can easily join the party without telling a story.
Otherwise we process the guests' information because we have a legitimate interest in delivering the service the host has bought, and which you choose to use (art. 6(1)(f)).
Do not write about health, religion, sexuality or other sensitive matters in your story if you do not want them in a song played for the party. [Draft: how we handle sensitive information, and information about people other than the guest, to be settled with a lawyer.]
When you ask for a demo as a partner
If you are a DJ, toastmaster or party planner, or run a venue, you can ask for a demo at hurra.fm/partner. We process:
- Company or venue, what you do, your name, your email and, if you give them, your phone number, your area, roughly how many parties a year and your message.
- Which version of the consent text you ticked, and which campaign you came from, if the link had one (utm_source and utm_campaign). We do not store your IP address.
- What we note ourselves about the conversation: status and next step.
We use the information to answer you about the demo, by the email or phone number you gave us. The basis is your request and your consent (art. 6(1)(a) and (b)). We only send offers and newsletters if you have separately said yes to them, and the form cannot do that today.
If you write stop, we delete your name, your email, your phone number and your message. We keep only the company name, a marker and a code made from your email and phone number (a hash), so we can recognise them and do not contact you again. If you fill in the form again after a stop, we do not store it. If you want to hear from us again, write to hej@hurra.fm. [Draft: deletion period for requests that come to nothing to be agreed.]
When we fix errors and improve the songs
If something goes wrong, or we want to make the songs better, we may read the party's content, including stories, facts and lyrics. This is based on our legitimate interest in fixing errors and improving the service (art. 6(1)(f)). [Draft: whether and how this happens to be confirmed.]
Who helps us
We never sell information and do not use it for advertising. These suppliers process data for us so hurra can work:
- Hetzner Online, Germany: the server where the party's content is stored.
- Stripe: the payment. Stripe may transfer information to the USA.
- Anthropic, USA: the AI model Claude writes the lyrics. It receives the guest's name, relationship and story, the party's background facts, and titles and facts used in the party's latest songs. It also reads an uploaded invitation for the table card.
- sunoapi.org: makes the music from the lyrics. We have not yet had it confirmed who runs the service, or in which country it processes data.
- OpenAI, USA: paints the background for the table card from a description or an uploaded invitation.
- Brevo, EU: sends emails with sign-in links and news about the party.
- Sentry: error and performance monitoring on our server, with data in Sentry's EU region in Germany. For every request to the server it records which address was called and how long it took. If an error occurs, the error report may also contain information from the request that failed. This is based on our legitimate interest in finding and fixing errors and keeping the service fast (art. 6(1)(f)).
When information is sent to a supplier outside the EU, it must happen on a lawful transfer basis, for example the EU's Data Privacy Framework or the European Commission's standard contractual clauses. [Draft: the basis for each supplier has not been settled yet and must be stated here before we sell.]
Suppliers keep data under their own rules. This also applies to copies of the songs at sunoapi.org, where we do not know the period. [Draft: the period for each supplier to be added.]
How long we keep data
- Photos and Party: songs, stories, selfies and photos are deleted 30 days after the party's date.
- Wedding and Premium: they are deleted 12 months after the party's date.
- If the party has no date yet, there is no deadline. The clock only starts once a date is set.
- 14 days before deletion, everyone with access to the party gets an email with a link so you can download the album.
- The welcome portrait is deleted together with the songs and photos.
- The host can always delete a song or a photo early.
- Sign-in links and the IP addresses they were requested from are deleted automatically once they are more than a day old.
- Deleted information may remain in the server's backups at Hetzner for up to [Draft: number] days before it disappears from there too.
- After deletion we keep the purchase and the party's basic details: email address, package, amount, payment id, the party's address, the names of the people being celebrated, occasion and date, the table card, the welcome message, the screen settings and the email addresses of the people who were given access. The Danish Bookkeeping Act requires the purchase to be kept for 5 years from the end of the financial year. [Draft: deletion after the 5 years, and deletion of the information the Bookkeeping Act does not require, is not automated yet.]
Cookies and storage in the browser
hurra only uses what it needs for the service to work:
- hurra_session keeps you signed in to your party. It expires after 90 days.
- hurra_gaest gives guests access to the party from the QR code on the table card. It expires after 120 days.
- hurra_gid_ followed by the party's name stores your random guest id. It expires after 400 days.
- In the guest's browser we also store a draft of the story, the guest id, a list of the songs that have been sent, the photos that have been given a heart, whether the welcome has been shown, and the names of the latest up to 12 people who have told a story from that phone. So if the phone is passed around, the next person can see those names.
- The party's screen stores a copy of the songs in the browser so they can play even if the wifi is poor. The copy stays until the browser's data is cleared.
- The party's screen also stores a random screen id (hurra-player-screen) while the tab is open.
- On the host's own phone or computer, hurra remembers whether the remote is light or dark, and how photos should be shown (hurra-fjern-theme, hurra-fjern-photo-view and hurra-host-photo-view).
All of this is necessary for hurra to work and therefore does not require consent. We use no cookies for statistics or advertising.
Your rights
You have the right to see the information we hold about you, and to have it corrected or deleted. You can also ask us to restrict the processing, object to it, and have your information handed over so you can take it elsewhere. If you have given consent, you can always withdraw it. Write to hej@hurra.fm and we will reply within a month.
We make no automated decisions about you (art. 22).
If you are unhappy with how we process your information, you can complain to the Danish Data Protection Agency at datatilsynet.dk.
Changes
We update the policy when hurra changes. The date at the top shows when it was last changed.