Effective
1The short version
This policy explains how Artistplus LLC ("Artistplus", "we", "us") handles personal data, both for artists who hold an account with us and for visitors to the websites we host for them.
Data obtained through your optional Gmail connection is used only for the connected Messages features. It is excluded from advertising and AI training, regardless of your cookie choices. The stricter rules in section 16 apply wherever this policy discusses data use or sharing generally.
- We do not sell your data
- We have never taken money for your personal information and there is no version of our business that involves it. Selling and sharing are different things under California law, though, so the next line says what we do share.
- We do share limited data with ad networks, if you accept
- Accept advertising cookies and Meta, TikTok, and Google receive a record that a signup or subscription happened, its value, and a scrambled (hashed) version of your email, verified phone number, and name, which lets them recognise an account they already hold. Under California law this counts as sharing for cross-context behavioural advertising. Decline, or send a Global Privacy Control signal, and none of it is sent.
- No advertising trackers on artist sites
- The websites we publish for artists carry our own first-party analytics and nothing else. No ad pixels, no conversion tracking, no third-party tag manager, no social trackers. Nothing a fan does on an artist site reaches an ad network, whatever anyone has accepted on artistplus.io.
- Analytics on artistplus.io is opt-in where consent is required
- In the EEA, the UK, and Switzerland, optional product analytics does not start until you accept it. Declining stops optional collection; we still retain a minimal record of the choice itself.
- Your content is yours
- We host it and show it to the people you publish it to. We do not license it out and we do not train models on it.
You can reach us about anything on this page at privacy@artistplus.io, or by post at:
- Artistplus LLC
- Chicago, Illinois
- United States
2What we collect about you
Account data
Your name, email address, and password, handled by our authentication provider Clerk. If you sign in with Google, we receive your name, email address, and profile picture from Google, and never your Google password. We also store your chosen username, your plan, your notification preferences, and the phone number you provide at signup, which for US and Canadian numbers is verified by text message. A verified phone number is used to prevent duplicate free trials, and it is shared with ad networks in scrambled form only if you accept advertising cookies, as described below.
Content and files
Everything you build or upload: page content, biography, images, audio, video, documents, press kits, catalog and release metadata, tour dates, contacts you add, and invoices you issue. Page content and metadata live in our database (Convex); files live in object storage (Cloudflare R2).
Billing data
Your plan, billing cycle, subscription status, invoice history, and the last four digits and brand of your payment card. Card numbers go directly to Stripe from your browser and never reach our servers.
Purchase acknowledgments
Where a purchase is one-time and not refundable, such as custom website design, we record that you confirmed the terms before payment: the exact wording shown to you, the moment you accepted it, and the browser user agent that accepted it. We keep this to answer payment disputes and chargebacks, and for no other purpose. It is never used for advertising or profiling.
Domain registrant data
If you register a domain through us, we collect the registrant name, email address, postal address, and phone number that ICANN requires, and pass them to our registrar partner. This is a legal requirement of holding a domain, not a choice we made.
Support and communications
Messages you send us, the ticket they create, and our replies. Separately, you can connect Gmail to send replies to website inquiries and synchronise linked conversations in Messages. The permissions, stored data, and controls for that optional connection are explained in section 16.
Product usage
On signed-in dashboard, onboarding, and checkout pages, our first-party activity ledger can record pages and product areas visited; session, visibility, engagement, and scroll milestones; controls activated; form structure, field-change metadata, validity, selected file count/type/size bucket, and submission status without entered values or filenames; feature and lifecycle events; client error fingerprints without raw error messages; connectivity changes; and timing, layout-shift, long-task, and resource-performance summaries. These events are linked to your account and a random per-tab session id.
When optional analytics is allowed, we also collect campaign and referral parameters, first- and last-touch attribution, and broad browser environment data: language and time zone, browser and operating system, device and screen characteristics, accessibility display preferences, network quality, navigation timing, storage usage and quota, browser permission states, and browser client hints. We use this to understand acquisition, adoption, retention, conversion, product quality, and customer segments. PostHog may receive the explicit product events described in our Cookie Policy; our own database keeps a separate first-party marketing projection that excludes IP values, request headers, encrypted material, names, emails, credentials, and private form values.
Technical and security data
For signed-in product activity we add server-observed request time, request id, approximate country, region, and city, browser headers and client hints, and IP-derived protections. A masked IP may appear in the owner-only activity ledger. The raw IP is isolated from event tables, encrypted with AES-256-GCM, available only to the platform owner in our admin console after a written reason, and permanently redacted after 30 days. A keyed one-way IP hash used for abuse detection and correlation is permanently redacted after 24 months. Every raw-IP reveal is separately audited. Our hosting provider also processes request metadata to serve and secure requests, and Sentry receives diagnostic context when something errors.
3Analytics on artist websites
Every website we publish for an artist includes our own first-party analytics. There is no third-party analytics, advertising, or social tracking on those sites. This section describes what a VISITOR to an artist site generates, and it applies whether or not that visitor has an Artistplus account.
What is recorded
- The page that was viewed and the site it belongs to.
- Country and city, taken from the edge network that served the request. This is approximate, derived from the IP by our hosting provider, and is never more precise than a city.
- The referring website, if the visitor arrived from a link.
- Browser, operating system, and whether the screen is phone, tablet, or desktop sized.
- A one-way hash of the IP address, used to rate-limit the endpoint and to give server-side page views a stable pseudo-identifier.
What is not recorded
- The raw IP address. It is hashed before anything is stored, and the hash cannot be reversed to the address.
- Names, email addresses, or anything else that identifies a visitor by name.
- Anything a visitor types into a page, including form fields.
- Behaviour on any website other than the artist site being viewed.
- A profile that follows a visitor from one artist site to another. Each site's figures stand alone.
Visitor identity, and how to avoid it
To count returning visitors as one person rather than several, the page stores an identifier in your browser's local storage under the key ap_visitor_id, plus a per-session identifier under ap_session_id. The value is generated from coarse browser characteristics and a timestamp. It is not a cookie, it does not leave the site that set it, and it carries no personal data.
To avoid it: browse in a private window, block storage for the site in your browser settings, or clear site data afterwards. Doing so does not degrade the site in any way. Without it, the visit is still counted, but as a new visitor rather than a returning one.
Link Pages use a separate random identifier for each artist page, stored under ap_lp_visitor.<pageId> for up to 400 days after your last visit, and a session identifier that rotates after 30 minutes of inactivity. These identifiers contain no browser fingerprint and cannot connect visits across artists. When storage is blocked, the page uses a temporary identifier and records the reduced identity coverage. Server-only counts use an artist-scoped hash that changes daily; raw IP addresses are not stored in analytics.
What the artist sees
Artists see aggregate figures about their own site: totals, trends, top pages, countries and cities, referrers, and device split. They cannot see individual visitors, IP addresses, hashes, or anything that identifies one person, and there is no view in the product that would let them.
Raw event records are deleted after 400 days, which is about 13 months. The daily totals we roll them up into contain no visitor identifiers and are kept for as long as the artist's account is open.
4Why we collect it, and the legal basis
| What we do | Why | Legal basis (UK and EU GDPR) |
|---|---|---|
| Run your account, publish your site, store your files | It is the service you asked for | Performance of a contract |
| Charge your subscription and keep billing records | To get paid, and to satisfy tax law | Contract, and legal obligation |
| Register and renew a domain in your name | ICANN requires registrant details | Contract, and legal obligation |
| Send transactional email about your account | You need to know about payments, expiry, and security | Contract |
| Answer your support messages | To help you | Contract, and legitimate interests |
| Detect abuse, spam, and fraud, and rate-limit endpoints | To keep the service usable and safe | Legitimate interests |
| Diagnose errors through Sentry | To fix what is broken | Legitimate interests |
| Count visits on artist sites | So the artist can see what is working | Legitimate interests |
| Product analytics on artistplus.io and the dashboard | To understand acquisition, product quality, adoption, retention, and conversion | Consent where required, otherwise legitimate interests |
| Authenticated user activity and consent audit records | To secure the service, investigate abuse and support issues, and prove product or privacy actions | Contract, legal obligation, and legitimate interests |
| First-party customer and marketing intelligence | To segment our customers and improve product and campaign decisions without cross-site advertising | Consent where required, otherwise legitimate interests |
| Send product announcements and marketing email | To tell you about what is new | Consent, withdrawable at any time |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded the processing is what a reasonable person would expect from a website host. You can object to any of it under section 9.
We do not use your data for automated decision-making that produces legal effects. We create first-party customer intelligence profiles for our own product and marketing decisions, but do not create or share cross-site advertising profiles.
5Cookies and browser storage
The full table of every cookie and storage key we set, with its purpose and lifetime, is on the Cookie Policy page. That table and this summary are generated from the same list, so they cannot disagree.
- Strictly necessary
- Needed for the site to work at all: keeping you signed in, remembering the choice you made about this banner, and stopping cross-site request forgery. These cannot be switched off, and we do not ask for consent to set them.
- Preferences
- Remember a setting you chose, like light or dark mode. They are set by your own actions and never leave your browser.
- Analytics
- Tell us which signed-in product pages, controls, and features get used so we can improve the product and understand our customers. Optional collection is off until you accept where consent is required, and stops if you decline.
On your first visit to artistplus.io from the European Economic Area, the United Kingdom, or Switzerland, analytics does not load at all until you choose. Accept and decline are presented as equal choices, and declining is a single click. Everywhere else, the banner is a notice with the same two buttons, and declining takes effect immediately. You can change your mind at any time from the Cookie settings link in the footer of every page.
Artist websites do not use cookies for analytics. They store the visitor identifier described in section 3, and nothing else.
6Who else processes your data
We share personal data with service providers who process it on our instructions and under a written contract, only for the purposes below. This list is maintained by auditing the codebase rather than by copying a template, and it is complete as of the effective date at the top of this page.
| Company | What they do for us | What they receive | Where | When |
|---|---|---|---|---|
| Clerk | Account sign-up, sign-in, and session management | Name, email address, password hash, sign-in metadata | United States | Always |
| Convex | Application database and backend functions | Account records, site content, catalog, invoices, analytics events, and connected Gmail OAuth tokens, message content, and conversation metadata | United States | Always |
| Cloudflare | File storage (R2), content delivery, and DNS for artistplus.app | Uploaded audio, video, images, documents, and press kits | Global edge network | Always |
| Vercel | Website hosting, edge routing, and TLS for custom domains | Request metadata, IP address, approximate location from edge headers, and Google OAuth callback processing including temporary authorisation codes, tokens, and connected-account identity | Global edge network | Always |
| Stripe | Subscription billing and payment processing | Billing name, email, address, card details (held by Stripe, never by us) | United States and European Union | Always |
| Resend | Transactional email delivery | Email address, name, and the contents of the message we send you | United States | Always |
| PostHog | Product analytics for artistplus.io and the dashboard | Page paths, feature events, account id, email, plan | United States | Always |
| Meta | Measures which Facebook and Instagram ads bring people to Artistplus | That a signup or subscription happened, its value, and a scrambled (hashed) email, verified phone number, name, and location used only to match an account they already hold | United States and European Union | Only if you accept advertising |
| TikTok | Measures which TikTok ads bring people to Artistplus | That a signup or subscription happened, its value, and a scrambled (hashed) email, verified phone number, name, and location used only to match an account they already hold | United States, Ireland, Singapore | Only if you accept advertising |
| Google Ads | Measures which Google ads bring people to Artistplus | That a signup or subscription happened, its value, and a scrambled (hashed) email, verified phone number, and name used only to match an account they already hold | United States | Only if you accept advertising |
| Sentry | Error monitoring and crash diagnostics | Error traces, browser and request metadata, account id | United States | Always |
| Name.com (Identity Digital) | Domain registration, renewal, transfer, and DNS for domains bought with us | Registrant name, email, postal address, and phone number (WHOIS contact), plus the domain name | United States | Only if you use it |
| OpenSRS (Tucows) | Mailbox hosting for addresses on your own domain | Mailbox address, display name, and the contents of the mailbox | United States and Canada | Only if you use it |
| Gmail APIs send and read replies in an inbox you connect, and Places completes an address as you type it | Google account authorisation, connected email identity, outgoing replies and recipients, requests for linked Gmail conversations, and the partial address you type into an address field | United States | Only if you use it | |
| Apify | Reads your public Spotify discography and Instagram profile during import and on later refreshes | Your Spotify artist identifier or Instagram profile URL, and the public release and profile data they return | United States and European Union | Only if you use it |
| Spotify | Reads your public artist profile and catalog when you connect it | Your Spotify artist identifier and public release data | United States and European Union | Only if you use it |
| SoundCloud | Reads your uploads when you connect the account | OAuth tokens and your SoundCloud track metadata | United States and European Union | Only if you use it |
| Zernio | Publishes to the social accounts you connect on your behalf, and reads back how those posts performed | The connected account id, handle, display name and avatar, the access credential for that account, the captions, images, video and links we publish for you, and the counts the platform returns for your own posts | European Union, on global cloud infrastructure | Only if you connect a social account |
Rows marked "Only if you use it" are engaged when you take a specific action, such as buying a domain, connecting SoundCloud, or asking us to build a site from a link. If you never do those things, that provider never receives anything about you.
The advertising and general sharing provisions in this policy do not authorise use or transfer of data obtained through the Gmail connection. That data, including anything derived from it, is subject to the stricter rules in section 16. In particular, a merger, acquisition, or asset sale does not permit transfer of Gmail data without your explicit prior consent.
Other reasons we may share
- When the law requires it, such as a valid court order or subpoena. Where we are permitted to tell you, we will.
- To protect our rights or the safety of artists and visitors, including investigating abuse.
- In a merger, acquisition, or sale of assets, in which case the acquirer is bound by this policy until it gives you notice of any change.
We do not sell personal data, as that term is defined under the California Consumer Privacy Act. We have never received money or other value in exchange for personal information.
We do share personal data for cross-context behavioural advertising, as that term is defined under the same Act, but only for visitors who have accepted the advertising category on artistplus.io. What is shared is the fact of a signup or subscription, its value, and a hashed email, verified phone number, name, and coarse location that let Meta, TikTok, or Google match it to an account they already hold. Nothing you upload, nothing you write, no payment details, and no artist-site visitor data is ever included. You can withdraw at any time from Cookie settings in the footer, or by sending a Global Privacy Control signal, which we honour as a standing opt-out that no click on our banner can override.
7Automated import from the platforms you connect
Onboarding can build a first version of your website from a link you give us. When you do that, you instruct us to fetch publicly available information from the source you named, such as a Spotify, SoundCloud, or Instagram profile: your artist name, biography, profile and cover images, release titles and artwork, and the links listed there. Some of that fetching runs through the providers in the table in section 6, and each of them appears there with what it receives.
What happens next is ordinary automated processing rather than generation. We map the imported fields onto the template you chose, fill the gaps with that template's own placeholder wording, which we write in advance and which is the same for every artist, and save the result as a draft. Nothing specific to you is invented: it either came from the source you named or you typed it in yourself.
- We do not send your material to a third-party AI model. There is no model anywhere in this pipeline.
- We do not train any model on your content, your files, or your account data, and we do not permit anyone else to.
- We fetch only what the draft needs. Your credentials, billing data, contacts, invoices, and private files are never part of an import.
- The imported site is a draft you review and edit. Nothing is published without you.
If you would rather we read nothing from another platform, skip the link step. You can build a site from scratch instead, and everything else in the product works the same way.
8How long we keep things
| Data | Kept for |
|---|---|
| Account and profile data | While your account is open |
| Site content and uploaded files | While your account is open |
| Files you delete | Trash for 3 to 30 days depending on plan, then permanently removed |
| Raw analytics events | 400 days (about 13 months) |
| Signed-in user activity and first-party marketing events | While the account is open, plus the 30-day deleted-account recovery window |
| Encrypted raw IP for signed-in product activity | 30 days |
| Keyed IP hash for signed-in product activity | 24 months |
| Signed-in consent history | While the account is open, plus the 30-day deleted-account recovery window |
| Daily analytics totals | While the account is open. They contain no visitor identifiers |
| Support messages | Three years from the last message on the ticket |
| Billing and invoice records | Seven years, to satisfy tax and accounting law |
| Purchase acknowledgments for non-refundable orders | Seven years, alongside the billing record they defend |
| Error reports in Sentry | 90 days |
| A closed account | Recoverable for 30 days, then permanently deleted |
Connected social accounts have their own retention windows in section 15. Gmail connection credentials and conversation history are covered separately in section 16, including what remains after disconnecting.
Closing your account marks it deleted and takes your published site offline immediately. For 30 days after that we can still restore it or export your content for you. After that window the content is permanently removed, apart from the billing records above and aggregate statistics that no longer identify you.
9Your rights, and how to use them
Depending on where you live, you have some or all of the following rights. We honour them for everyone, not only where the law compels it.
- Access
- Ask what we hold about you and get a copy of it.
- Correction
- Have inaccurate data fixed. Most of it you can edit yourself in settings.
- Deletion
- Have your data erased, subject to records we must keep by law.
- Portability
- Get your data in a machine-readable format, or ask us to send it to someone else.
- Objection
- Object to processing we base on legitimate interests, including analytics.
- Restriction
- Ask us to pause processing while a dispute about accuracy or grounds is resolved.
- Withdraw consent
- Where we rely on consent, take it back at any time. Doing so does not undo processing that already happened lawfully.
- Non-discrimination
- Using any of these rights never costs you service, features, or a worse price.
How to make a request
Email privacy@artistplus.io from the address on your account, or write to support@artistplus.io if that is easier, and say what you want. If we cannot tell that the request comes from you, we will ask one verification question rather than a form.
We acknowledge requests within 5 business days and complete them within 30 days. If a request is genuinely complex we may extend that by up to 60 days and will tell you why before we do. There is no charge, unless a request is repetitive or excessive, in which case we will tell you the cost before doing anything.
An authorised agent may make a request on your behalf where the law allows it. We will ask for proof of the authorisation.
If you are in the EEA or the UK and you think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first, but the right is yours either way.
10Where your data is processed
We are based in the United States and most of our providers process data there. Files and pages are served from a global edge network, so a copy may be cached near the visitor requesting it.
Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision where one applies, together with the technical measures described in section 11.
11How we protect it
- Everything travels over HTTPS. Certificates for custom domains are issued and renewed automatically.
- Files at rest in object storage and records in our database are encrypted by the provider.
- Every backend function checks who is asking before it returns anything. Authorisation is enforced on the server, never in the browser.
- Share links use unguessable tokens, and can carry a password and an expiry you set.
- Stored third-party access tokens are protected by our database provider’s encryption at rest. Gmail storage and access controls are described in section 16.
- Raw signed-in product IP addresses are isolated from event and marketing tables, encrypted with AES-256-GCM, and automatically redacted after 30 days. The marketing projection never contains IP values or hashes.
- Access to production data by our team is limited to the people who need it to do their job, and administrative actions are logged.
No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant authority without undue delay, and within 72 hours of becoming aware of it where the law requires that.
12Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from them. Artists between 13 and 18 need a parent or guardian to accept the Terms of Service on their behalf.
If you believe a child under 13 has given us personal data, write to privacy@artistplus.io and we will delete the account and its content promptly.
Websites published by artists are public and may be visited by anyone. Artists are responsible for what they publish and for any collection their own site performs.
13United States state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, you have rights to know, access, correct, delete, and port your personal information, to opt out of sale or sharing, and not to be discriminated against for using them.
We do not sell personal information. We do share it for cross-context behavioural advertising, but only if you accepted the advertising category on artistplus.io. To opt out, open Cookie settings in the footer and switch Advertising off; it stops immediately and for good.
Your browser can also opt out for you. We treat a Global Privacy Control signal as a binding opt-out of advertising that no choice on our banner can override, so if your browser sends one you do not need to do anything else. We honour it for optional analytics too.
The categories of personal information we collect, the purposes, and the parties we disclose to are set out in sections 2, 4, and 6. Use the process in section 9 to exercise any of these rights.
14Changes to this policy
We update this policy when what we do changes. For material changes, including adding a subprocessor that receives content or account data, we will give at least 30 days notice by email or an in-product notice before the change takes effect.
Before accessing new types of Google data or using Google data for a new purpose, we will explain the change and obtain your affirmative consent. Continued use of Artistplus or acceptance of advertising cookies does not authorise a new use of Gmail data.
The effective date at the top of this page always reflects the current policy.
15Connected social accounts
Connecting a social account is optional, and this section applies only if you do it. The feature may not be switched on for your account yet, in which case nothing here applies to you at all.
What we hold
- Account identity
- The platform's identifier for the account you connected, its handle, display name, profile picture, and the account type the platform reports, such as an Instagram Business or Creator account.
- The access credential
- The token that lets us publish on your behalf. It is issued by the platform when you approve the connection and is held by our publishing provider, which is named in the table in section 6. It is never stored as readable text in our own database.
- What we publish for you
- The caption, images, video and links of each post, the schedule you set, and whether the platform accepted it, including the reason it gave if it did not.
- Post records
- The platform's identifier for each published post and its permalink, so we can link you to the live post and read its numbers.
- Per-post metrics
- The counts the platform returns for your own posts, such as impressions, reach, likes, comments, shares, saves and clicks, where the platform provides them.
We do not read your direct messages. We do not download your followers, their handles, or their contact details. We do not collect anything that identifies the individual people who see or interact with your posts: metrics reach us as counts.
Why we hold it
- To publish the posts you schedule, which is the service you asked for.
- To show you what was published, when, and to which account.
- To show you how a post performed, using the counts the platform returns.
- To keep a record of what we published on your behalf, which we need if you or a platform ever asks.
The legal basis is the contract between us: you connected the account so that we would post to it. Where we rely on legitimate interests instead, such as keeping a record of what was published, you can object under section 9.
What we do not do with it
Data we receive from Meta, TikTok, Google or X is used only to provide and improve the features you connected the account for. We do not sell it, we do not share it with advertising networks, we do not combine it with data about other artists, and we do not use it to train any model. Where a platform imposes a limited use requirement on the data its interfaces return, we hold ourselves to it for every platform, not only the one that asks.
How long we keep it
| Data | Kept for |
|---|---|
| The connection and its credential | While the account stays connected. Disconnecting revokes the credential with the platform and deletes both |
| Per-post metrics | 13 months, the same window as the rest of our analytics |
| The record of a published post | While your Artistplus account is open. It outlives the connection, because it is the record of something we did on your behalf, and it holds no credential |
How to disconnect
Disconnect an account from your dashboard at any time. We revoke the credential with the platform, delete the connection, and stop publishing to it immediately, including anything already scheduled. You can also remove our access from the platform's own connected-apps settings, and we treat that as a disconnection when the platform tells us about it.
Disconnecting does not remove posts that were already published. They live on the platform and only you can take them down there. Closing your Artistplus account disconnects every connected account and deletes the connections, on the timetable in section 8.
16Connected Gmail and Google user data
Google sign-in and the optional Gmail connection
Signing into Artistplus with Google uses the identity information described in section 2. It does not by itself connect your mailbox to Messages. When you separately connect Gmail, Google asks you to authorise access. We receive the connected email address and basic account identity through the openid and email permissions. We never receive your Google password.
What we access and why
- Send email (gmail.send)
- Sends the replies you compose and choose to send from your connected Gmail account to people who contacted you through your artist website.
- Read email (gmail.readonly)
- Retrieves messages in Gmail conversations linked to your Artistplus inquiries, including incoming replies and responses you send from Gmail itself, so you can see the conversation in Messages. The Google permission covers the mailbox, but our implementation fetches linked conversations rather than importing your entire inbox. It does not modify or delete messages in Gmail.
Synchronisation can happen when you open or refresh a conversation and through background checks while the connection remains active. Reading message bodies is necessary to display replies; permission to send email alone does not provide that access.
What we store and how we protect it
We store the connected email address, granted permissions, OAuth access and refresh tokens, and token expiry time in our Convex backend. For linked conversations we store message text, subject, sender and recipient email addresses, timestamps, message and thread identifiers, direction, and synchronisation metadata. We also store replies composed in Artistplus. This is server-side storage, not storage limited to your browser.
Data travels over HTTPS and is encrypted at rest by our database provider. Application access to conversations is checked against the signed-in artist. Tokens are used by server-side code to communicate with Google. Administrative access to message content is restricted by role and requires a recorded reason and an audit entry. These safeguards do not make the stored messages end-to-end encrypted.
Limited Use, sharing, and human access
Artistplus complies with the Google API Services User Data Policy, including its Limited Use requirements, when handling information received from Google APIs. Gmail data is also subject to the Google Workspace user data and developer policy.
We use Gmail data only to provide the connected messaging features you authorise. Google processes the authorisation and email delivery, Convex processes and stores the connection and conversation records, and Vercel hosts the application and OAuth callback. These existing providers are listed in section 6. Sending a reply discloses its content and sender details to the recipients you choose and their email providers.
- We do not sell Gmail data or transfer it to data brokers or information resellers.
- We do not use Gmail data, including derived data, for advertising, ad targeting, retargeting, marketing profiles, or credit and lending decisions. Accepting advertising cookies does not change this.
- We do not send Gmail data to AI providers or use it to create, train, or improve AI or machine-learning models.
- Transfers of Gmail data are limited to providing the messaging features you authorise, necessary security purposes, legal obligations, or a merger, acquisition, or asset sale with your explicit prior consent.
- Our personnel and service providers may read Gmail data only with your documented, affirmative permission to view specific data, when necessary for security purposes such as investigating abuse, or when required by law. A general support request does not by itself grant permission to read your messages.
| Data | Kept for |
|---|---|
| Connection tokens and connected-account details | While connected. Disconnect removes them from the live database |
| Conversation content and metadata | Retained for your Messages history until deletion is processed. Disconnecting alone does not erase it |
Disconnect, revoke access, or request deletion
To disconnect, open Settings, then Integrations, then Email and choose Disconnect beside the connected Gmail address. This removes the stored Gmail tokens, granted permissions, expiry, and connected address from our live database and prevents new sending and syncing through that connection. An operation already in progress may finish. Disconnecting does not erase conversation history already stored in Artistplus or delete anything from Gmail.
Disconnecting in Artistplus does not call Google to revoke the authorisation. You can separately remove Artistplus access from your Google Account connections. Google sign-in and the Gmail connection may share an OAuth client, so removing the Google authorisation may also require you to authorise Google sign-in again.
Stored conversation history has no separate automatic expiry when you disconnect: it remains available in Messages until deletion is processed. To request deletion of Gmail-derived messages, metadata, and connection details without closing your Artistplus account, email support@artistplus.io from your account address and ask to delete your connected Gmail data. Disconnect first to stop further synchronisation. You may also request a copy of that data. The identity checks and response periods in section 9 apply, and account closure follows section 8. Deleting our copies does not delete the emails held by Google or your recipients.
Removing records from the live database does not instantly erase older backup copies. Backups and any records that must be retained by law remain subject to the same access and Limited Use restrictions. Contact support@artistplus.io for the status and scope of your deletion request, including retained copies.