Privacy Policy·Last updated: 2026-10-03
Privacy Policy
Effective: 2026-10-03
Maor Anav ("we", "us", "our") respects your privacy. This Privacy Policy explains what data we collect, why, how we protect it, and your rights.
Plain-English summary: We collect what we need to run Queen for you — account info, the data you enter (gigs, finances, etc.), basic technical logs. We share it only with the platforms that power Queen (Supabase for storage, Vercel for hosting, etc.). We never sell your data. You can export your data or delete your account anytime — section 5 says exactly what is deleted and what is kept.
1. Information We Collect
1.1 Information you provide
- Account data: email, name, hashed password, locale, mode
- Profile data: artist/label name, country, currency, Spotify artist link (optional), tax-business type (optional)
- Business data you enter: gigs, releases, expenses, incomes, contacts, tasks, invoices, goals, notes
- Uploads: images (receipts, posters), PDF contracts
- AI chat content: messages you send to the assistant + images you attach
- Sensitive details, only if you enter them: bank account and IBAN details, tax ID or business (osek) number and tax settings, date of birth, and for travel bookings the name on your passport, passport number, expiry date and nationality
- Contracts and e-signatures: the contracts you upload or send, and the signing records described below
- People you work with: names, emails and phone numbers of contacts, crew, promoters and clients you add, and the messages you exchange with them through The Queen
1.2 Information collected automatically
- Usage data: pages viewed, features used, approximate session length
- Device data: IP address, browser, OS, screen size. IP addresses kept in security, sign-up and signing records are not anonymised automatically.
- Error reports: crash traces and stack traces (via Sentry)
- Cookies and local storage: only what sign-in and your own settings need — no advertising or tracking cookies. Page measurement (Vercel Web Analytics and Speed Insights) is cookieless. See the Cookie Policy.
1.3 Information from third parties
- Spotify: if you connect your artist account, public catalog data (album list, popularity, label name)
- Songstats (when enabled): monthly listener counts, stream totals
- Google OAuth (if used to sign in): basic profile + email
2. Why We Collect It (Legal Basis under GDPR / Israeli Privacy Law)
| Purpose | Legal Basis |
|---|---|
| Provide the Service | Contract performance |
| Account security, fraud prevention | Legitimate interest |
| Billing and tax compliance | Legal obligation |
| Product improvement, cookieless page measurement | Legitimate interest |
| Customer support | Contract performance |
| Optional emails (reminders, summaries, alerts) | Your choice in Settings → Notifications; every one has an unsubscribe link |
3. Who We Share It With
We do not sell or rent your data. We share only with:
- Supabase (database, file storage and sign-in — hosted in the United States, AWS us-east-1) — under its data processing agreement
- Vercel (web hosting; our server functions run in the United States) — under its data processing agreement; also Vercel Web Analytics and Speed Insights, which measure pages without cookies
- Google (Gemini API) — reads the documents, receipts and images you ask The Queen to read, and runs the assistant
- Anthropic (Claude API) — may run the assistant instead of Gemini (which one is a setting on our side). Whichever runs it receives the messages and images you send the assistant. Neither Google nor Anthropic uses paid API data to train its models.
- Resend (email delivery) — your email address and the content of the emails The Queen sends
- Upstash (abuse protection) — your account ID or IP address, kept for minutes to a day to count requests
- Paddle (payments for The Queen subscriptions — our merchant of record) — billing details only; we don't see your full card number
- Morning (Green Invoice) — only if you choose to connect your own Morning account: the details of each document you ask it to issue
- Wise — only if you choose to connect your own Wise account: what is needed for the payouts and balance you ask The Queen to handle
- Sentry (error monitoring) — error traces, which can include your account ID and IP address; session recording is off
- Google Places — the text you type into a venue or address search, to suggest places
- Music and event data services (Spotify, Apple Music, Deezer, YouTube, SoundCloud, Songstats, Bandsintown, Ticketmaster) — search terms and public artist or release IDs, to look up public catalogue and event information
- Google — only if you sign in with Google or connect Google Calendar or Gmail
- Meta (WhatsApp Business) — only if WhatsApp messaging is switched on for your account
We may disclose data when legally required (court order, regulator request) or to protect rights/safety (fraud, security incident).
Google Calendar Data
The Queen connects to Google Calendar (using the Google Calendar API) to provide calendar synchronization. With your permission, we read your existing calendar events to show your availability inside the app, and we create or update events that correspond to bookings (gigs) you add in The Queen. We access calendar event data only — we never access, modify, or delete your calendars themselves, their settings, or their sharing permissions.
The Queen's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
We do not sell Google user data and we do not use it for advertising. It is used solely to provide the calendar features described above. You can disconnect your Google account at any time from Settings, which immediately revokes access to your calendar data.
Gmail data and AI processing
If — and only if — you switch on receipt auto-import, The Queen reads Gmail messages that match a receipt or invoice search and downloads their attachments, so it can turn them into expense records for you. This feature is off by default and you can turn it off at any time in Settings.
To read those attachments we send them to Google's Gemini API — and to no other AI provider. We do not send Gmail messages or attachments to any third-party AI provider, and we do not use it — raw, aggregated, anonymised or derived — to create, train, or improve any AI or machine-learning model, our own or anyone else's.
We do not use Gmail data for any purpose other than producing the expense records you asked for, and we do not retain the message content beyond the extracted receipt fields.
Electronic Signature Data
When you send a contract for electronic signing through The Queen, or when you sign a contract sent to you (whether you are a registered user or signing as an external party through a signing link), we collect and retain the following information for each signer to establish the legal validity of the signature and to provide an audit trail:
- Full name and email address of each signer
- IP address and user agent (browser / device fingerprint) at the moment of each material action (opening the signing link, viewing the document, agreeing to the electronic-signing consent, signing, or declining)
- UTC timestamps for each of those events
- A cryptographic hash of the document that was signed, so the integrity of the signed document can be proven later
This information is collected from ALL signers, including external signers who do NOT have a Queen account, because it is required to comply with electronic signature laws (such as the U.S. ESIGN Act and the EU eIDAS Regulation) and to make the resulting document admissible as evidence. Signer information is retained for as long as the contract remains in our records or as required by applicable law, whichever is longer. External signers can request a copy of their data or its deletion (subject to legal-retention obligations) by emailing thequeenappinfo@gmail.com.
4. International Transfers
Your data is stored in the United States (Supabase, AWS us-east-1) and processed there by our hosting (Vercel), and by the other providers in section 3, some of which process data in the United States or the European Union.
- Israeli law: we transfer data abroad under the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 2001, on the basis of our providers' written commitments to protect it (their data processing agreements).
- Users in the EU/EEA: the European Commission recognises Israel as ensuring an adequate level of protection. For providers in the United States we rely on the EU–U.S. Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses.
5. Data Retention
| Data | Retention |
|---|---|
| Account + business data | Until you delete your account |
| Assistant conversations | Kept in your account until you delete the account — there is no automatic deletion |
| Items you delete inside the app | Some are hidden rather than erased at once, and are erased when you delete the account |
| Invoices and tax records | Kept after your account is deleted, no longer linked to you — tax law requires a business to keep its records |
| Error reports (Sentry) | Sentry's retention period for our plan — at most 90 days |
| Your email choices (Settings → Notifications) | Until you change them or delete the account |
| Addresses of people without an account who unsubscribed | Kept, so we keep honouring the request |
| A short record of each account deletion (see below) | No end date |
| Files you uploaded | Until you delete them or your account (the files in your own storage folder are deleted with the account) |
When you delete your account, this is exactly what happens today.
What is deleted, at once
There is no waiting period, and it cannot be undone. If you have a paid subscription, it is cancelled first; if the cancellation cannot be confirmed, nothing is deleted and you are told why.
- Your login and your profile
- Everything stored under your account — for example gigs, releases, income and expenses, contacts, tasks and contracts
- Your connections with other users, and your place on other people's teams and rosters
- Files you uploaded — for example your profile photo, contract PDFs you uploaded or sent, cover art, imports, press-kit files and receipt images
- Messages you sent in chats, and signatures you saved for reuse
- Stored connections to outside services, such as Google Calendar — and we ask Google to withdraw the access you gave The Queen
- Your pages on The Queen's label site, if you have any
What is kept, and why
- Invoices you issued through The Queen. Tax law requires a business to keep its records, so invoices are kept, no longer linked to your account.
- A short record of every deletion: the date, the account's internal ID, the reason you typed (if you gave one), the IP address the request came from, and a one-way code (SHA-256) made from your email address. The code cannot be turned back into the address; it only lets us see that an address already had its free trial, so the trial stays one per person — our legitimate interest in preventing repeated free trials. This record has no end date. To have the email code removed too, email thequeenappinfo@gmail.com.
- Signed contracts are also the other party's document. A contract someone else sent you — its file and its signing record, including your signature — stays in their account. A contract you sent is deleted from your account, but a signed copy the other side already downloaded stays with them.
- Messages other people sent you in a chat stay in their account.
- Payments are processed by Paddle, our merchant of record, which keeps its own records of them.
- Backups: copies of deleted data in our database backups are gone within 8 days, when those backups expire.
Signing up again with the same address is always allowed; it simply starts on the free Starter plan. Step by step, with the Settings path: Data deletion.
6. Your Rights
Under Israeli Privacy Protection Law and GDPR you have the right to:
- Access — request a copy of your data → /settings/data → "Export"
- Rectification — correct inaccurate data → edit in app, or email thequeenappinfo@gmail.com
- Erasure ("right to be forgotten") → /settings/data → "Delete account". What is deleted and what is kept: Data deletion
- Restriction — pause processing → email thequeenappinfo@gmail.com
- Portability — receive your data in JSON format → /settings/data → "Export"
- Object — opt out of marketing, profiling → unsubscribe link or settings
- Lodge a complaint with the Israeli Privacy Protection Authority (https://www.gov.il/he/Departments/the_privacy_protection_authority) or your local supervisory authority
We respond to verified requests within 30 days.
7. Security
We protect your data with industry-standard measures:
- Encryption in transit: HTTPS (TLS 1.3) on all connections
- Encryption at rest: AES-256 on Supabase storage
- Access control: Row Level Security on all user-data tables enforcing
auth.uid() = user_id - Application filtering: every database query manually scoped to your user_id
- Authentication: Supabase Auth, hashed passwords (bcrypt), optional two-factor sign-in (2FA)
- Monitoring: rate limiting, anomaly detection, audit logs
- Backups: daily, encrypted, kept for 7 days
In the unlikely event of a data breach, we will notify affected users within 72 hours (per Israeli Privacy Law Amendment 13 and GDPR Article 33).
8. Children
The Service is for people aged 18 and over (Terms of Service, section 1.1). We do not knowingly collect data from anyone under 18. If you believe a child has provided us data, email thequeenappinfo@gmail.com and we will delete it.
9. Cookies
See our separate Cookie Policy at /legal/cookies.
10. AI / Automated Decision-Making
The Queen Assistant runs on Google's Gemini API or Anthropic's Claude API (section 3) to process your questions and tool requests. It is an AI and can make mistakes. It is a decision-support tool, not an autonomous decision maker. You always confirm destructive actions. AI outputs are not professional advice — see Section 7 of the Terms of Service.
We do not use your data for any automated decision that has legal or significant effects on you (per GDPR Article 22).
11. Changes to this Policy
We may update this Policy. Material changes will be announced via email or in-app notice. Continued use after the effective date constitutes acceptance.
12. Contact
Privacy questions: thequeenappinfo@gmail.com
Security issues: thequeenappinfo@gmail.com