# Privacy Policy
Effective: 2026-06-04
Queen Music Tech Ltd. ("we", "us", "our") respects your privacy. This Privacy Policy explains what data we collect, why, how we protect it, and your rights.
> Plain-English summary: We collect what we need to run Queen for you — account info, the data you enter (gigs, finances, etc.), basic technical logs. We share it only with the platforms that power Queen (Supabase for storage, Vercel for hosting, etc.). We never sell your data. You can export or delete everything anytime.
## 1. Information We Collect
### 1.1 Information you provide
- Account data: email, name, hashed password, locale, mode
- Profile data: artist/label name, country, currency, Spotify artist link (optional), tax-business type (optional)
- Business data you enter: gigs, releases, expenses, incomes, contacts, tasks, invoices, goals, notes
- Uploads: images (receipts, posters), PDF contracts
- AI chat content: messages you send to the assistant + images you attach
### 1.2 Information collected automatically
- Usage data: pages viewed, features used, approximate session length
- Device data: IP address (anonymized after 30 days), browser, OS, screen size
- Error reports: crash traces and stack traces (via Sentry)
- Cookies: session cookies (required) + analytics cookies (with consent)
### 1.3 Information from third parties
- Spotify: if you connect your artist account, public catalog data (album list, popularity, label name)
- Songstats (when enabled): monthly listener counts, stream totals
- Google OAuth (if used to sign in): basic profile + email
## 2. Why We Collect It (Legal Basis under GDPR / Israeli Privacy Law)
| Purpose | Legal Basis |
|---|---|
| Provide the Service | Contract performance |
| Account security, fraud prevention | Legitimate interest |
| Billing and tax compliance | Legal obligation |
| Product improvement, analytics | Legitimate interest (or consent for granular tracking) |
| Customer support | Contract performance |
| Marketing emails | Consent (opt-in) — separate from transactional |
## 3. Who We Share It With
We do not sell or rent your data. We share only with:
- Supabase (database hosting, US/EU regions) — DPA signed
- Vercel (web hosting, edge global) — DPA signed
- Anthropic (AI assistant, US) — your chat messages + uploaded images are sent for processing. Anthropic does not train on your data.
- Stripe (payments) — billing info only; we don't see your full card number
- iCount / Greeninvoice (Israeli invoicing) — name + email + amount for invoice generation
- Sentry (error monitoring) — error traces, no personal data fields
- Spotify, Songstats — only public artist IDs you opt to link
- Google — only if you use Google OAuth to sign in
We may disclose data when legally required (court order, regulator request) or to protect rights/safety (fraud, security incident).
## Google Calendar Data
The Queen connects to Google Calendar (using the Google Calendar API) to provide calendar synchronization. With your permission, we read your existing calendar events to show your availability inside the app, and we create or update events that correspond to bookings (gigs) you add in The Queen. We access calendar event data only — we never access, modify, or delete your calendars themselves, their settings, or their sharing permissions.
The Queen's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
We do not sell Google user data and we do not use it for advertising. It is used solely to provide the calendar features described above. You can disconnect your Google account at any time from Settings, which immediately revokes access to your calendar data.
## Electronic Signature Data
When you send a contract for electronic signing through The Queen, or when you sign a contract sent to you (whether you are a registered user or signing as an external party through a signing link), we collect and retain the following information for each signer to establish the legal validity of the signature and to provide an audit trail:
- Full name and email address of each signer
- IP address and user agent (browser / device fingerprint) at the moment of each material action (opening the signing link, viewing the document, agreeing to the electronic-signing consent, signing, or declining)
- UTC timestamps for each of those events
- A cryptographic hash of the document that was signed, so the integrity of the signed document can be proven later
This information is collected from ALL signers, including external signers who do NOT have a Queen account, because it is required to comply with electronic signature laws (such as the U.S. ESIGN Act and the EU eIDAS Regulation) and to make the resulting document admissible as evidence. Signer information is retained for as long as the contract remains in our records or as required by applicable law, whichever is longer. External signers can request a copy of their data or its deletion (subject to legal-retention obligations) by emailing privacy@thequeen.app.
## 4. International Transfers
Data may be processed in the United States, European Union, or Israel. We rely on:
- Standard Contractual Clauses (SCCs) for EU↔US transfers
- Israeli Privacy Protection Authority adequacy
## 5. Data Retention
| Data | Retention |
|---|---|
| Account + business data | Until you delete your account |
| AI chat logs | 90 days (auto-redacted PII) |
| Deleted data (soft-deleted, "Trash") | 30 days, then permanently deleted |
| Invoices and tax records | 7 years (Israeli tax law) |
| Sentry error logs | 30 days |
| Marketing consent records | Until withdrawn |
## 6. Your Rights
### Under Israeli Privacy Protection Law and GDPR you have the right to:
- Access — request a copy of your data → /settings/data → "Export"
- Rectification — correct inaccurate data → edit in app, or email privacy@thequeen.app
- Erasure ("right to be forgotten") → /settings/data → "Delete account"
- Restriction — pause processing → email privacy@thequeen.app
- Portability — receive your data in JSON format → /settings/data → "Export"
- Object — opt out of marketing, profiling → unsubscribe link or settings
- Lodge a complaint with the Israeli Privacy Protection Authority (https://www.gov.il/he/Departments/the_privacy_protection_authority) or your local supervisory authority
We respond to verified requests within 30 days.
## 7. Security
We protect your data with industry-standard measures:
- Encryption in transit: HTTPS (TLS 1.3) on all connections
- Encryption at rest: AES-256 on Supabase storage
- Access control: Row Level Security on all user-data tables enforcing
auth.uid() = user_id - Application filtering: every database query manually scoped to your user_id
- Authentication: Supabase Auth, hashed passwords (bcrypt), optional 2FA (coming soon)
- Monitoring: rate limiting, anomaly detection, audit logs
- Backups: daily, encrypted, point-in-time recovery
In the unlikely event of a data breach, we will notify affected users within 72 hours (per Israeli Privacy Law Amendment 13 and GDPR Article 33).
## 8. Children
The Service is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us data, email privacy@thequeen.app and we will delete it.
## 9. Cookies
See our separate Cookie Policy at /legal/cookies.
## 10. AI / Automated Decision-Making
The Queen Assistant uses Claude (by Anthropic) to process your queries and tool requests. It is a decision-support tool, not an autonomous decision maker. You always confirm destructive actions. AI outputs are not professional advice — see Section 7 of the Terms of Service.
We do not use your data for any automated decision that has legal or significant effects on you (per GDPR Article 22).
## 11. Changes to this Policy
We may update this Policy. Material changes will be announced via email or in-app notice. Continued use after the effective date constitutes acceptance.
## 12. Contact
Privacy questions: privacy@thequeen.app
Security issues: security@thequeen.app
For Israeli users — Data Protection Officer:
Queen Music Tech Ltd., [Address], privacy@thequeen.app
EU representative (if applicable): TBD when we enter EU markets at scale.
> REVIEW WITH LAWYER: before production launch. This Policy is a starting point — your tech lawyer must validate it against Amendment 13 implementation details, confirm DPO/EU rep requirements, and customize the retention table to your actual setup.