WeSyncAppLegal & Privacy

WeSyncApp Privacy Policy

Effective date: July 19, 2026

This Privacy Policy explains how We Sync Global, LLC ("WeSyncApp," "we," "us," or "our") collects, uses, shares, and protects personal information when you use the WeSyncApp web application, the WeSyncApp iOS application, our public smart-link pages, and related services (together, the "Service").

Please read this Policy together with our Terms of Service. If you do not agree with this Policy, please do not use the Service.


1. Who We Are and What This Policy Covers

In short: We run WeSyncApp, a marketing platform for independent artists. This Policy covers you (the account holder), the artists you manage, and the fans who sign up on your public pages.

The Service is operated by We Sync Global, LLC, [COMPANY ADDRESS]. WeSyncApp helps independent artists and their teams plan releases, run marketing campaigns, generate AI-assisted marketing plans and content, publish public "smart link" pages, and collect fan email signups.

This Policy applies to three kinds of people:

Users — you, the person who creates a WeSyncApp account.
Artists — the artist profiles you create in the Service. An artist profile may describe you, or it may describe another person (for example, an artist you manage). If you enter information about another person, you are responsible for having the right to do so.
Fans — people who submit their email address on a public smart-link page you publish. We process fan data on your behalf — see Section 6, which explains your responsibilities for fan data.

2. Information We Collect

In short: We collect your account email, the artist and campaign information you type in, the media you upload, fan emails submitted on your public pages, and basic in-app activity. We do not collect your precise location, contacts, or advertising identifiers; our application does not record or store visitor IP addresses; and our public pages use no tracking cookies. (Like any internet service, our hosting infrastructure still processes IP addresses to deliver requests — see Sections 8 and 12.)

2.1 Information you provide

Account information. Your email address and a password. Passwords are handled by our authentication provider (Supabase) in hashed form — we never store your plaintext password. We also store your organization's name, plan level (Core or Pro), and your email address in our application database so we can send you your weekly digest (if enabled).
Artist profile information. Artist name, genre, bio, city, country, platform links (for example, Spotify or Instagram URLs), and an optional uploaded artist photo.
Consultation and intake information. Free-text answers you give during consultations: release details, goals, budget, team notes, audience notes, brand-interview answers (origin story, differentiators, how you want fans to feel, color and style preferences), and catalog performance history. Please only include information you are comfortable sending to the AI provider you configure (see Section 5).
Imported analytics. Platform metrics you import via CSV or paste in as text (for example, streaming or social statistics). Pasted analytics text is stored as you provided it.
Uploaded media. Audio files (up to 60 MB), video files (up to 500 MB / 30 minutes), smart-link artwork, and artist photos.
Your own API keys ("bring your own key"). If you connect optional AI or analytics providers (Anthropic, OpenAI, Google Gemini, fal.ai, ElevenLabs, Soundcharts, Chartmetric), we store the API keys you provide in our database so our servers can call those providers for you. Keys are used server-side only and are never displayed back in full — the interface shows only the last four characters. See Section 12 for how we protect them.

2.2 Fan information (collected on your behalf)

When a fan submits the signup form on one of your public smart-link pages, we collect: their email address, an optional first name, the exact consent text they were shown, a timestamp of their consent, and which link and artist the signup came from. Our application does not record the fan's IP address, device information, or any cookies on public pages, though our hosting infrastructure processes IP addresses to deliver the page as any web server must.

2.3 Information created while you use the Service

AI inputs and outputs. Research reports, marketing plans, brand kits, generated captions/scripts, generated images, videos, and voiceovers, and the prompts used to create them. Research reports may include information about the named artist gathered from public web sources (see Section 5).
Media analysis. For media you upload, we may generate and store speech transcripts (with word timestamps) and audio analysis data (silence, energy, and beat information) to power editing features.
Activity data. In-app events such as completing a task, with the task title, related artist, and a timestamp. This powers streaks, "since you were last here," and your weekly digest.
Smart-link statistics (anonymous). For each public link we count views, clicks (with the destination label), and signups, with timestamps only. No visitor identifiers of any kind are stored.

2.4 Information we do NOT collect

We do not collect: precise location; contact lists; photos from your device library (the iOS app has no camera, microphone, or photo permissions); advertising identifiers (IDFA); biometric data; or payment card details (no billing is live today — see Section 10).

3. How We Use Information

In short: We use your information to run the product — nothing else. No advertising, no profiling for ads, no selling data.

We use the information described above to:

1.Create and secure your account, and scope all data to your organization;
2.Provide the core Service: consultations, marketing plans, content generation, smart links, media editing, and campaign tracking;
3.Send AI requests to the provider(s) you configure, and store the results for you (Section 5);
4.Build and export your fan email list (Section 6);
5.Show you first-party statistics about your smart links;
6.Send you a weekly activity digest email (you can turn this off in Settings at any time) and essential account emails such as email verification and password reset;
7.Maintain, troubleshoot, and secure the Service; and
8.Comply with legal obligations.

We do not use your information for third-party advertising, and we do not sell or rent personal information to anyone.

4. Legal Bases for Processing

In short: We process your data because you asked us to (contract), because you consented (fan signups, optional AI features), or because we have a legitimate reason (keeping the Service secure).

Where laws such as the EU/UK GDPR apply, our legal bases are:

Performance of a contract — account data, artist profiles, consultations, media, plans, and everything needed to deliver the Service you signed up for.
Consent — fan email signups (the fan checks a consent statement on the public page); and your connection of optional third-party providers via your own API keys.
Legitimate interests — keeping the Service secure, preventing abuse, maintaining first-party aggregate link statistics (which contain no visitor identifiers), improving the Service, and sending the weekly activity digest (which is on by default; you can turn it off with one click in Settings → Notifications, and every digest email also includes an unsubscribe path). We balance these interests against your rights.
Legal obligation — where we must retain or disclose information under applicable law.

5. AI Features and Your Content

In short: WeSyncApp's AI features send your artist and campaign information — and, for transcription and motion-art features, your uploaded audio and images — to the AI provider you choose and connect with your own API key. Fan emails are never sent to AI providers.

WeSyncApp's consultant, content, and media features work by sending data to third-party AI providers. In most cases you choose the provider and connect it with your own API key:

Text generation and research (Anthropic, OpenAI, or any OpenAI-compatible endpoint you configure): we send the consultation context — artist name, genre, bio, city, country, platform links, your intake and brand-interview answers, imported metrics summaries, aggregate fan/link counts, and excerpts of prior research reports. When Anthropic is configured, its web-search tool may be used to research the named artist on the public web, and the resulting report is stored in your account. Pasted analytics text (up to roughly 14,000 characters) may also be sent for extraction.
Speech-to-text (ElevenLabs Scribe, with OpenAI Whisper as fallback): the full audio track of media you transcribe is converted to WAV and sent to the provider. Transcripts are cached in your account.
Image and video generation (Google Gemini/Veo, OpenAI, or fal.ai): we send generated text prompts and, for Motion Art / image-to-video, the cover image you selected.
Voiceovers (ElevenLabs): we send the voiceover script text and your chosen voice.
Artist statistics (Soundcharts / Chartmetric, optional): we send only the artist's name as a search query.

Important notes:

Fan email addresses are never sent to any AI provider. AI prompts receive only aggregate counts (for example, "42 fans").
Because these providers are connected under your own account and API key, your relationship with each provider is also governed by that provider's own terms and privacy policy. Choose providers you trust with the content you plan to send.
AI-generated research reports may contain information about identifiable people (the named artist) gathered from public sources. You control these reports and can review the sources cited in them.
If no AI provider is configured, AI features either run in a limited demonstration mode or are unavailable; nothing is sent externally.

6. Fan Data — Your Responsibilities

In short: Fans who sign up on your pages are your audience. You are the data controller (or "business") for fan data; we process it for you. Honor the consent promise shown at signup — including unsubscribes.

When a fan signs up on your smart-link page, they see and agree to a consent statement (for example: "I agree to receive email updates from [artist name]. I can unsubscribe at any time."). We record the exact consent text and timestamp so you have proof of consent. Every public smart-link page also links to this Privacy Policy in its footer (alongside a "Report this page" link), and each fan signup stores the exact consent sentence shown plus a timestamp.

For fan data, you (the account holder) act as the data controller / business, and We Sync Global, LLC acts as your processor / service provider. That means:

We collect, store, and export fan data only on your instructions (currently: signup capture and CSV export to you). We do not email your fans, and we do not use fan data for our own purposes.
You are responsible for how you use exported fan data, including complying with email-marketing laws (such as CAN-SPAM, GDPR, and CASL), honoring the unsubscribe promise in the consent text, processing fan opt-out and deletion requests, and using a mailing tool that supports unsubscribes.
If a fan contacts us directly with a privacy request about their data, we will honor it and/or refer it to the relevant artist, and we will cooperate with you to fulfill fan requests. Fans may contact us at julzmuzix@icloud.com.

7. Third-Party Service Providers

In short: A small set of infrastructure providers run the Service; a set of optional providers only receive data if you connect them. Here is every one, and exactly what each receives.

Core infrastructure (always used)

ProviderRoleWhat it receives
SupabaseAuthentication and hosted databaseYour email and password (password stored hashed by Supabase); session tokens; the application database (all data described in Section 2). Supabase also sends signup-verification and password-reset emails.
RailwayApplication hostingAll Service traffic and uploaded/generated media files stored on the application server; standard server logs.
ResendEmail delivery for the weekly digest and Settings test emailsYour account email address and the digest content (fans gained, link views, completed task titles, campaign and artist names, upcoming events/releases).
GitHub ActionsScheduled trigger for the weekly digestNo personal data — only an authenticated trigger request.

Optional providers (only if you connect them or we enable them)

ProviderRoleWhat it receives
Anthropic (your API key)AI text generation and web researchConsultation context described in Section 5 (no fan emails).
OpenAI (your API key)AI text generation; Whisper transcription; image generationConsultation context; uploaded audio (for transcription); image prompts.
Google Gemini / Veo (your API key)Image and video generationPrompts and uploaded cover images.
fal.ai (your API key)Image and video generation (FLUX, Kling, MiniMax)Prompts and uploaded cover images.
ElevenLabs (your API key)Voiceovers and transcriptionVoiceover text; full uploaded audio files (for transcription).
Soundcharts (your API key)Artist audience statisticsArtist name only (as a search query).
Chartmetric (your API key)Artist statisticsArtist name only (as a search query).
Cloudflare R2 or S3-compatible storage (if we configure it)Backup mirror of media files so they survive redeploysCopies of uploaded and generated media files.

Our infrastructure providers process personal information under their data-processing agreements with us and do not use it for their own advertising. For AI providers you access with your own API key, your agreement with that provider governs how it may use the data you send — choose providers you trust.

8. No Advertising, No Tracking

In short: There are no ads, no analytics trackers, no pixels, and no fingerprinting anywhere in WeSyncApp — including on public fan-facing pages.

The Service contains no third-party advertising, analytics, or tracking technologies — no Google Analytics, no Meta pixel, no session-recording tools, no crash-analytics SDKs, and no advertising SDKs in the iOS app. The iOS app does not use Apple's advertising identifier (IDFA) and does not perform "tracking" as defined by Apple's App Tracking Transparency framework. Our smart-link statistics are strictly first-party counts (views, clicks, signups) with no visitor identifiers or cookies, and our application does not record or store visitor IP addresses. Our hosting infrastructure necessarily processes IP addresses to deliver requests and may retain short-term server logs, which we do not use to build any visitor profile.

9. Cookies and Local Storage

In short: We use only the cookies needed to keep you signed in. Public fan pages set no cookies at all.

Authentication cookies (essential). The web app sets Supabase session cookies to keep you signed in and refresh your session. These are strictly necessary for the Service to function and are the only cookies we set.
Local storage (not a cookie). Your light/dark theme preference is stored in your browser's local storage on your device and is never transmitted to us.
Public pages. Smart-link pages set no cookies and use no local storage for visitors.

Because we use only strictly necessary cookies, no cookie-consent banner is required, and there is no advertising or analytics cookie to opt out of.

10. Payments and Subscriptions

In short: Nothing is billed today. When paid plans launch, payments will be handled by Stripe (web) or Apple (iOS) — we will never see your full card number.

The Service currently offers Core and Pro plan tiers, but no payment processing is live and we collect no payment information today.

When paid subscriptions launch:

Web purchases will be processed by Stripe. Stripe will receive your payment details directly; we will receive only a customer reference, subscription status, and billing metadata — never your full card number.
iOS purchases will be offered as auto-renewable subscriptions through Apple In-App Purchase. Apple will process payment and will share with us only your subscription status — not your payment details. Subscriptions renew automatically unless canceled at least 24 hours before the end of the current period, and can be managed or canceled in your App Store account settings. The app will provide a "Restore Purchases" option.

We will update this Policy before enabling billing.

11. Data Retention

In short: We keep your data while your account is active. Media edit history is auto-pruned. Deleting your account deletes your data.

Account and content data (profiles, consultations, plans, reports, metrics, fan lists, activity history) are retained while your account is active, so your campaign history and streaks keep working.
Media files are retained until you delete them. Deleting a media item removes the database record, the server file, and any backup-mirror copy. Editor export versions are automatically pruned to the three most recent per original file (originals are never auto-deleted).
Temporary job records for AI consultations are deleted when the job completes.
Account deletion (Section 13) deletes your organization's data from our live systems immediately, after which only residual copies in our hosting providers' backups (Supabase, Railway) persist until they age out on those providers' retention schedules — typically within about 35 days, which we do not control directly — plus any records we must keep to meet legal obligations.

12. Security

In short: Encryption in transit, hashed passwords, strict per-organization access controls, and masked API keys — but no system is 100% secure.

We use commercially reasonable measures to protect personal information, including:

Encryption in transit. All traffic between your browser or the iOS app and our servers uses HTTPS/TLS.
Hashed passwords. Passwords are hashed by Supabase Auth; we never see or store them in plaintext.
Organization scoping. Every piece of data is scoped to your organization; authenticated routes verify your session on every request, and media files are served only through authenticated routes — except for the content on published smart-link pages and their artwork, which are public by design because you chose to publish them.
Credential handling on iOS. The iOS app stores session tokens in the iOS Keychain and never stores your password on the device.
API key handling. The API keys you connect are used server-side only and are never returned in full by our interfaces (only a last-four-characters hint). They are stored in our database as you provided them — protected by our hosting provider's disk-level encryption and access controls, but not additionally encrypted by the application — so treat them like any credential you hand to a service. You can remove a saved key at any time in Settings, and you should revoke a key with the issuing provider if you believe it may have been exposed.
Secret hygiene. Operator secrets (database credentials, email and cron keys) are kept in environment configuration, not in code.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a breach affecting your personal information, we will notify you as required by applicable law.

13. Your Rights and Choices

In short: You can access, correct, export, and delete your data — including deleting your whole account, on the web at Settings → Account → "Delete my account…" and on iOS at Settings → Delete Account.

Regardless of where you live, we offer everyone the following:

Access and correction. You can view and edit your profile, artist, and campaign data directly in the Service, or contact us at julzmuzix@icloud.com for a copy of your personal information.
Portability / export. You can export your fan list as a CSV at any time from the Service. Contact us at julzmuzix@icloud.com for exports of other data in a machine-readable format.
Deletion — in the app. You can delete your account yourself: on the web app, go to Settings → Account → "Delete my account…" and type DELETE to confirm; on the iOS app, go to Settings → Delete Account and confirm at the double-confirmation prompt. Deletion takes effect immediately — all of your workspace data (artists, campaigns, plans, tasks, consultations, fan records, and media files, including any cloud-storage mirror copies) is deleted right away, your smart-link pages go offline immediately, and the sign-in record for your account is deleted along with it. Residual copies may remain in our hosting providers' backups (Supabase and Railway) and age out on those providers' retention schedules — typically within about 35 days — though we do not control these schedules directly. See Section 11. You can also delete individual media items at any time.
Deletion — by email. You may also request deletion by emailing julzmuzix@icloud.com.
Email choices. The weekly digest can be turned off in Settings at any time. Verification and password-reset emails are essential service emails.
Fan requests. If you are a fan whose email was collected on an artist's page, contact us at julzmuzix@icloud.com and we will remove your record and/or route your request to the responsible artist (see Section 6).

We will respond to rights requests within the timeframe required by applicable law and will not discriminate against you for exercising your rights. We may need to verify your identity (for example, by confirming control of your account email) before acting on a request.

14. International Data Transfers

In short: Our servers are in the United States; using WeSyncApp means your data is processed there.

We Sync Global, LLC is based in the United States, and the Service is hosted on infrastructure located in the United States (and, for providers you connect, wherever those providers operate). If you use the Service from outside the United States — including the EEA, the United Kingdom, or Switzerland — your personal information will be transferred to and processed in the United States, which may not provide the same level of data protection as your home jurisdiction. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission's Standard Contractual Clauses and the data-protection terms offered by our infrastructure providers.

15. Children's Privacy

In short: WeSyncApp is for people 13 and older, and we don't knowingly collect data from children under 13.

The Service is not directed to children under 13 (or the higher minimum age required in your jurisdiction, such as 16 in parts of the EEA), and you must be at least 13 to create an account or submit a fan signup. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information through the Service, contact us at julzmuzix@icloud.com and we will delete it.

16. California Privacy Notice (CCPA/CPRA)

In short: California residents get specific rights. We do not sell or share personal information as those terms are defined in California law.

This section supplements the rest of this Policy for California residents.

Categories of personal information collected (in the preceding 12 months), the sources, purposes, and recipients:

CCPA categoryWhat we collectSourceDisclosed to
IdentifiersAccount email; artist name; fan email and first nameYou; fans who sign up on your pagesSupabase, Railway, Resend (your email only); never AI providers for fan emails
Customer recordsArtist profile details; consultation intake; imported metricsYouSupabase, Railway; AI providers you connect (Section 5)
Commercial informationPlan tier (Core/Pro); campaign and task historyYou; your use of the ServiceSupabase, Railway
Internet or network activityIn-app activity events; anonymous smart-link counts (no IP or identifiers)Your use of the ServiceSupabase, Railway
Audio/visual informationUploaded audio, video, artwork, photos; transcriptsYouSupabase, Railway, storage mirror; transcription/generation providers you connect
Professional informationTeam notes, budget, catalog performance (as you provide them)YouSame as customer records
InferencesAI-generated research reports, plans, and brand kits about the named artistGenerated by AI providers you connectStored with Supabase/Railway

We do not collect: precise geolocation, biometric information, government identifiers, health or financial account information, or sensitive personal information beyond your account login credentials (which we use only for authentication).

No sale or sharing. We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. We have not done so in the preceding 12 months, and we have no actual knowledge of selling or sharing the personal information of consumers under 16. Because we do not sell or share, no "Do Not Sell or Share" opt-out is needed; we also honor this policy for browsers sending Global Privacy Control signals, which require no action given our practices.

Your California rights: the right to know/access, correct, delete, and port your personal information; the right to limit use of sensitive personal information (we already use login credentials only for authentication); and the right to non-discrimination. Exercise these rights through the in-app tools described in Section 13 or by emailing julzmuzix@icloud.com. You may use an authorized agent; we will verify the request as described in Section 13.

Service-provider role for fan data: for fan information collected on an artist's behalf, we act as a "service provider" to that artist under the CCPA (see Section 6).

17. Information for EEA, UK, and Swiss Users (GDPR)

In short: If you're in Europe, you have GDPR rights, and Section 4 lists our legal bases.

If you are in the European Economic Area, the United Kingdom, or Switzerland:

Controller. We Sync Global, LLC, [COMPANY ADDRESS], is the controller of your account and content data. For fan data collected on an artist's behalf, the artist is the controller and we are the processor (Section 6).
Legal bases are described in Section 4.
Your rights include: access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent at any time (without affecting prior processing). Exercise them via Section 13 or julzmuzix@icloud.com.
Automated decision-making. The Service's AI features generate marketing suggestions and content; they do not make legal or similarly significant automated decisions about you.
Transfers to the United States are described in Section 14.
Complaints. You have the right to lodge a complaint with your local supervisory authority (in the UK, the ICO), though we would appreciate the chance to address your concern first at julzmuzix@icloud.com.

18. Changes to This Policy

In short: If we change this Policy in a meaningful way, we'll tell you before it takes effect.

We may update this Policy from time to time. If we make material changes, we will notify you before the changes take effect — for example, by email to your account address and/or a prominent notice in the Service — and we will update the effective date above. Your continued use of the Service after the effective date of an updated Policy means the update applies to you. Material changes affecting fan data will be communicated so that you can meet your own obligations to your fans.

19. Contact Us

Questions, concerns, or privacy requests:

Privacy requests: julzmuzix@icloud.com
General support: julzmuzix@icloud.com
Mail: We Sync Global, LLC, [COMPANY ADDRESS]

This Privacy Policy applies to the WeSyncApp web application, the WeSyncApp iOS application, and WeSyncApp public smart-link pages.

Privacy Policy — WeSyncApp