Legal

Privacy policy

Last updated 4 August 2026.

What we collect

Account identity (email, display name, creator track), the records you create inside your workspace — releases, works, brand deals, campaigns, finance entries, contracts and service requests — and anonymous interaction events from the public site.

How your records are isolated

Every workspace row is bound to your user identifier and enforced at the database layer with row-level security. Other members cannot read, edit or export your records. Operators can access records only through the audited operations console.

Audit and tamper evidence

Administrative actions — status moves, invite issuance, bulk updates — are written to an append-only audit log chained with SHA-256 hashes, so any later alteration is detectable.

Exports and email

Scheduled reports are generated on our servers and stored for in-app download. Where you add recipient addresses, the report summary is emailed to exactly those addresses and nowhere else.

Retention and removal

You may delete any record at any time. Ask us to close your account and we remove your workspace data within 30 days, except audit entries required for operational integrity.

Questions about your data? Contact the team.