Legal center

Privacy policy

What data Amplify holds, why, who can see it, and how to export or delete it.

Version
2026.09-draft-1
Effective
September 1, 2026
Acceptance
Required at signup

Draft, pending legal review. This document is a working draft written by the Amplify team, not by a lawyer. It describes how we actually intend to operate the product. It has not been reviewed by counsel and is not legal advice.

1. Who this covers

This describes data held about Amplify account holders and workspace members, and data you bring into a workspace about other people — your fans, customers, collaborators and press contacts.

For your own account data, Amplify is the controller. For the fan and customer records you import, you are the controller and Amplify processes that data on your instruction.

2. What we hold

  • Account: email address, name and display name, password hash held by Supabase Auth, sign-in timestamps, and any linked sign-in identity.
  • Workspace: artist name, slug, type, timezone, currency, plan and subscription status, membership roles and invitations.
  • Your work: ideas, songs and version history, releases, tracks, credits, milestones, campaigns, posts, tasks and calendar events.
  • Relationships: fan contacts, consent state, tags, segments and interaction history you record.
  • Money: transactions in whole cents, budgets, royalty statements and statement lines, splits and payouts.
  • Store: products, variants, customers, orders, payments and fulfilment records.
  • Press: press kit sections, quotes, assets, and view counts on published kits.
  • Files: uploads in workspace storage — artwork, audio, images and documents.
  • Operational: support requests and messages, notifications, activity logs, AI usage metadata, integration connection state and sync run results, and error reports.

AI usage records hold metadata only — feature, model, timing and outcome. They do not store your prompts or the generated text.

3. Why we hold it

To provide the features you use, authenticate you, scope every record to the right workspace, take payment, answer support requests, keep an audit trail of meaningful workspace actions, and diagnose faults.

We do not sell personal data, do not run advertising, and do not build profiles of you or your fans for anyone else.

4. Who can see it

Members of a workspace see that workspace's data at the level their role allows. Database row-level security enforces workspace scoping — it is not a UI convention.

Amplify staff can access support requests you submit and, where genuinely necessary to investigate a fault or a security issue, underlying records. Privileged access runs through server-side paths, never from a browser.

5. Fan and customer data you import

When you import a fan list or record a customer, you are asserting you have a lawful basis to hold and contact those people. Amplify records consent state honestly and does not invent it.

You are responsible for answering access and deletion requests from your own fans and customers. Amplify will help you locate and remove those records.

6. Processors and third parties

  • Supabase — database, authentication, file storage and server-side functions. Holds effectively all workspace data.
  • Stripe — subscription billing and payment method handling. Amplify does not store card numbers.
  • Resend — transactional email, including support notifications.
  • OpenAI — AI assistance features. Receives only the specific text you send to an AI action.
  • Google / YouTube — only if you connect the integration, and only to read the metrics and calendar data that integration covers.
  • Lovable — application hosting and deployment.

Where these processors are located, the transfer mechanism used, and a formal subprocessor list with data-processing terms are open items that require owner and counsel sign-off before launch outside the founding beta.

7. Payments

Card details are entered on Stripe's own surfaces and are handled by Stripe. Amplify stores subscription state and identifiers needed to reconcile your plan, not payment instruments.

8. Cookies and local storage

Amplify runs no advertising trackers, no third-party analytics scripts and no cross-site tracking pixels. There is no behavioural profiling to consent to, which is why you are not shown a cookie banner.

What the product does store in your browser is strictly functional: your Supabase authentication session, which artist workspace you last had open, your dashboard layout preferences, an anonymous identifier used to avoid double-counting a public press-kit view, and a cookie remembering whether a sidebar was collapsed.

If Amplify ever adds analytics or any non-essential tracking, this section and a real consent control must ship in the same change.

9. Retention

Workspace data is kept while the workspace exists. Deleting a record removes it from the product; backups age out on their own schedule.

Some records survive account deletion because removing them would corrupt someone else's books or audit trail — financial transactions, orders, and activity logs, for example. Those are retained in the workspace, with your profile anonymised.

10. Your choices

  • Export: Settings → Your data downloads a JSON file of your account, profile, memberships, invitations and the records you are authorised to see.
  • Correction: edit your profile and workspace details in Settings at any time.
  • Deletion: Settings → Delete account submits a reviewed deletion request. Deletion consequences are listed there before you confirm.
  • Questions or a privacy complaint: privacy@amplifyforartists.com.

11. Security

See the Trust page for the practices Amplify actually implements. It deliberately describes only what is in place, with no certification or compliance claims.

12. Changes and contact

This policy is versioned. The version and effective date above identify what currently applies, and material changes are recorded as a new version. Contact: privacy@amplifyforartists.com.