WeSyncApp Privacy Policy
Effective date: July 19, 2026
This Privacy Policy explains how We Sync Global, LLC ("WeSyncApp," "we," "us," or "our") collects, uses, shares, and protects personal information when you use the WeSyncApp web application, the WeSyncApp iOS application, our public smart-link pages, and related services (together, the "Service").
Please read this Policy together with our Terms of Service. If you do not agree with this Policy, please do not use the Service.
1. Who We Are and What This Policy Covers
In short: We run WeSyncApp, a marketing platform for independent artists. This Policy covers you (the account holder), the artists you manage, and the fans who sign up on your public pages.
The Service is operated by We Sync Global, LLC, [COMPANY ADDRESS]. WeSyncApp helps independent artists and their teams plan releases, run marketing campaigns, generate AI-assisted marketing plans and content, publish public "smart link" pages, and collect fan email signups.
This Policy applies to three kinds of people:
2. Information We Collect
In short: We collect your account email, the artist and campaign information you type in, the media you upload, fan emails submitted on your public pages, and basic in-app activity. We do not collect your precise location, contacts, or advertising identifiers; our application does not record or store visitor IP addresses; and our public pages use no tracking cookies. (Like any internet service, our hosting infrastructure still processes IP addresses to deliver requests — see Sections 8 and 12.)
2.1 Information you provide
2.2 Fan information (collected on your behalf)
When a fan submits the signup form on one of your public smart-link pages, we collect: their email address, an optional first name, the exact consent text they were shown, a timestamp of their consent, and which link and artist the signup came from. Our application does not record the fan's IP address, device information, or any cookies on public pages, though our hosting infrastructure processes IP addresses to deliver the page as any web server must.
2.3 Information created while you use the Service
2.4 Information we do NOT collect
We do not collect: precise location; contact lists; photos from your device library (the iOS app has no camera, microphone, or photo permissions); advertising identifiers (IDFA); biometric data; or payment card details (no billing is live today — see Section 10).
3. How We Use Information
In short: We use your information to run the product — nothing else. No advertising, no profiling for ads, no selling data.
We use the information described above to:
We do not use your information for third-party advertising, and we do not sell or rent personal information to anyone.
4. Legal Bases for Processing
In short: We process your data because you asked us to (contract), because you consented (fan signups, optional AI features), or because we have a legitimate reason (keeping the Service secure).
Where laws such as the EU/UK GDPR apply, our legal bases are:
5. AI Features and Your Content
In short: WeSyncApp's AI features send your artist and campaign information — and, for transcription and motion-art features, your uploaded audio and images — to the AI provider you choose and connect with your own API key. Fan emails are never sent to AI providers.
WeSyncApp's consultant, content, and media features work by sending data to third-party AI providers. In most cases you choose the provider and connect it with your own API key:
Important notes:
6. Fan Data — Your Responsibilities
In short: Fans who sign up on your pages are your audience. You are the data controller (or "business") for fan data; we process it for you. Honor the consent promise shown at signup — including unsubscribes.
When a fan signs up on your smart-link page, they see and agree to a consent statement (for example: "I agree to receive email updates from [artist name]. I can unsubscribe at any time."). We record the exact consent text and timestamp so you have proof of consent. Every public smart-link page also links to this Privacy Policy in its footer (alongside a "Report this page" link), and each fan signup stores the exact consent sentence shown plus a timestamp.
For fan data, you (the account holder) act as the data controller / business, and We Sync Global, LLC acts as your processor / service provider. That means:
7. Third-Party Service Providers
In short: A small set of infrastructure providers run the Service; a set of optional providers only receive data if you connect them. Here is every one, and exactly what each receives.
Core infrastructure (always used)
| Provider | Role | What it receives |
|---|---|---|
| Supabase | Authentication and hosted database | Your email and password (password stored hashed by Supabase); session tokens; the application database (all data described in Section 2). Supabase also sends signup-verification and password-reset emails. |
| Railway | Application hosting | All Service traffic and uploaded/generated media files stored on the application server; standard server logs. |
| Resend | Email delivery for the weekly digest and Settings test emails | Your account email address and the digest content (fans gained, link views, completed task titles, campaign and artist names, upcoming events/releases). |
| GitHub Actions | Scheduled trigger for the weekly digest | No personal data — only an authenticated trigger request. |
Optional providers (only if you connect them or we enable them)
| Provider | Role | What it receives |
|---|---|---|
| Anthropic (your API key) | AI text generation and web research | Consultation context described in Section 5 (no fan emails). |
| OpenAI (your API key) | AI text generation; Whisper transcription; image generation | Consultation context; uploaded audio (for transcription); image prompts. |
| Google Gemini / Veo (your API key) | Image and video generation | Prompts and uploaded cover images. |
| fal.ai (your API key) | Image and video generation (FLUX, Kling, MiniMax) | Prompts and uploaded cover images. |
| ElevenLabs (your API key) | Voiceovers and transcription | Voiceover text; full uploaded audio files (for transcription). |
| Soundcharts (your API key) | Artist audience statistics | Artist name only (as a search query). |
| Chartmetric (your API key) | Artist statistics | Artist name only (as a search query). |
| Cloudflare R2 or S3-compatible storage (if we configure it) | Backup mirror of media files so they survive redeploys | Copies of uploaded and generated media files. |
Our infrastructure providers process personal information under their data-processing agreements with us and do not use it for their own advertising. For AI providers you access with your own API key, your agreement with that provider governs how it may use the data you send — choose providers you trust.
8. No Advertising, No Tracking
In short: There are no ads, no analytics trackers, no pixels, and no fingerprinting anywhere in WeSyncApp — including on public fan-facing pages.
The Service contains no third-party advertising, analytics, or tracking technologies — no Google Analytics, no Meta pixel, no session-recording tools, no crash-analytics SDKs, and no advertising SDKs in the iOS app. The iOS app does not use Apple's advertising identifier (IDFA) and does not perform "tracking" as defined by Apple's App Tracking Transparency framework. Our smart-link statistics are strictly first-party counts (views, clicks, signups) with no visitor identifiers or cookies, and our application does not record or store visitor IP addresses. Our hosting infrastructure necessarily processes IP addresses to deliver requests and may retain short-term server logs, which we do not use to build any visitor profile.
9. Cookies and Local Storage
In short: We use only the cookies needed to keep you signed in. Public fan pages set no cookies at all.
Because we use only strictly necessary cookies, no cookie-consent banner is required, and there is no advertising or analytics cookie to opt out of.
10. Payments and Subscriptions
In short: Nothing is billed today. When paid plans launch, payments will be handled by Stripe (web) or Apple (iOS) — we will never see your full card number.
The Service currently offers Core and Pro plan tiers, but no payment processing is live and we collect no payment information today.
When paid subscriptions launch:
We will update this Policy before enabling billing.
11. Data Retention
In short: We keep your data while your account is active. Media edit history is auto-pruned. Deleting your account deletes your data.
12. Security
In short: Encryption in transit, hashed passwords, strict per-organization access controls, and masked API keys — but no system is 100% secure.
We use commercially reasonable measures to protect personal information, including:
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a breach affecting your personal information, we will notify you as required by applicable law.
13. Your Rights and Choices
In short: You can access, correct, export, and delete your data — including deleting your whole account, on the web at Settings → Account → "Delete my account…" and on iOS at Settings → Delete Account.
Regardless of where you live, we offer everyone the following:
We will respond to rights requests within the timeframe required by applicable law and will not discriminate against you for exercising your rights. We may need to verify your identity (for example, by confirming control of your account email) before acting on a request.
14. International Data Transfers
In short: Our servers are in the United States; using WeSyncApp means your data is processed there.
We Sync Global, LLC is based in the United States, and the Service is hosted on infrastructure located in the United States (and, for providers you connect, wherever those providers operate). If you use the Service from outside the United States — including the EEA, the United Kingdom, or Switzerland — your personal information will be transferred to and processed in the United States, which may not provide the same level of data protection as your home jurisdiction. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission's Standard Contractual Clauses and the data-protection terms offered by our infrastructure providers.
15. Children's Privacy
In short: WeSyncApp is for people 13 and older, and we don't knowingly collect data from children under 13.
The Service is not directed to children under 13 (or the higher minimum age required in your jurisdiction, such as 16 in parts of the EEA), and you must be at least 13 to create an account or submit a fan signup. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information through the Service, contact us at julzmuzix@icloud.com and we will delete it.
16. California Privacy Notice (CCPA/CPRA)
In short: California residents get specific rights. We do not sell or share personal information as those terms are defined in California law.
This section supplements the rest of this Policy for California residents.
Categories of personal information collected (in the preceding 12 months), the sources, purposes, and recipients:
| CCPA category | What we collect | Source | Disclosed to |
|---|---|---|---|
| Identifiers | Account email; artist name; fan email and first name | You; fans who sign up on your pages | Supabase, Railway, Resend (your email only); never AI providers for fan emails |
| Customer records | Artist profile details; consultation intake; imported metrics | You | Supabase, Railway; AI providers you connect (Section 5) |
| Commercial information | Plan tier (Core/Pro); campaign and task history | You; your use of the Service | Supabase, Railway |
| Internet or network activity | In-app activity events; anonymous smart-link counts (no IP or identifiers) | Your use of the Service | Supabase, Railway |
| Audio/visual information | Uploaded audio, video, artwork, photos; transcripts | You | Supabase, Railway, storage mirror; transcription/generation providers you connect |
| Professional information | Team notes, budget, catalog performance (as you provide them) | You | Same as customer records |
| Inferences | AI-generated research reports, plans, and brand kits about the named artist | Generated by AI providers you connect | Stored with Supabase/Railway |
We do not collect: precise geolocation, biometric information, government identifiers, health or financial account information, or sensitive personal information beyond your account login credentials (which we use only for authentication).
No sale or sharing. We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. We have not done so in the preceding 12 months, and we have no actual knowledge of selling or sharing the personal information of consumers under 16. Because we do not sell or share, no "Do Not Sell or Share" opt-out is needed; we also honor this policy for browsers sending Global Privacy Control signals, which require no action given our practices.
Your California rights: the right to know/access, correct, delete, and port your personal information; the right to limit use of sensitive personal information (we already use login credentials only for authentication); and the right to non-discrimination. Exercise these rights through the in-app tools described in Section 13 or by emailing julzmuzix@icloud.com. You may use an authorized agent; we will verify the request as described in Section 13.
Service-provider role for fan data: for fan information collected on an artist's behalf, we act as a "service provider" to that artist under the CCPA (see Section 6).
17. Information for EEA, UK, and Swiss Users (GDPR)
In short: If you're in Europe, you have GDPR rights, and Section 4 lists our legal bases.
If you are in the European Economic Area, the United Kingdom, or Switzerland:
18. Changes to This Policy
In short: If we change this Policy in a meaningful way, we'll tell you before it takes effect.
We may update this Policy from time to time. If we make material changes, we will notify you before the changes take effect — for example, by email to your account address and/or a prominent notice in the Service — and we will update the effective date above. Your continued use of the Service after the effective date of an updated Policy means the update applies to you. Material changes affecting fan data will be communicated so that you can meet your own obligations to your fans.
19. Contact Us
Questions, concerns, or privacy requests:
This Privacy Policy applies to the WeSyncApp web application, the WeSyncApp iOS application, and WeSyncApp public smart-link pages.