Skip to main content

Privacy policy

Last updated: September 19, 2026

1. Who we are

Premierely is operated by Gino Gagliardi, registered at Cosijnstraat 25, 2313 NC, Leiden, the Netherlands ("Premierely", "we", "us", or "our"). Premierely is a premiere and repost booking system that connects artists and labels with music curators.

Contact: gino@premierely.io

This policy applies to the Premierely web application at app.premierely.io, the public pages it serves (curator booking pages, download gates, and link-in-bio pages, including those on a custom domain), and all associated services.

2. Data we collect

2.1 Account and profile data

When you create an account, we collect:

  • Email address and password (hashed)
  • Display name, account name, and profile details you provide
  • Whether you use Premierely as a curator or as an artist or label
  • Subscription plan and billing information
  • Account activity and usage logs

2.2 SoundCloud integration data

When you connect your SoundCloud account, we store your SoundCloud user ID, username, and encrypted OAuth access token. This token is used only to publish and manage tracks on your connected channels.

2.3 Instagram / Meta integration data

When you connect your Instagram account (available to Premierely Pro users), we request the following permissions via Meta's OAuth flow:

  • instagram_basic - your Instagram account ID and username, to identify your connected account.
  • instagram_content_publish - to post Instagram Stories on your behalf when a premiere is published on your SoundCloud channel.
  • pages_show_list - to list the Facebook Pages you manage, so we can identify the Page linked to your Instagram Business or Creator account.
  • business_management - to verify your Instagram account is connected to a Facebook Business portfolio, which is required by Meta to use the Content Publishing API.

We store:

  • Your Instagram account ID and username
  • Your connected Facebook Page ID
  • Your encrypted Meta access token and token expiry date
  • Per-channel settings for Instagram Story templates (caption text, audio clip preferences) that you configure in Premierely

We do not read your Instagram feed, access your direct messages, collect your followers, or access any Instagram data beyond what is listed above.

2.4 YouTube integration data

When you connect a YouTube channel, we ask Google for permission to upload videos (youtube.upload) and to read basic details of your channel (youtube.readonly). We store your channel ID, channel name, and thumbnail, plus your encrypted access and refresh tokens. We use them only to upload the videos and Shorts you schedule in Premierely, with the title, description, and tags you set.

Premierely's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2.5 TikTok integration data

Where TikTok posting is enabled for your account, connecting TikTok asks for your basic profile (user.info.basic), your follower and video counts (user.info.stats), and permission to post videos (video.publish). We store your TikTok user ID, display name, follower count, and encrypted tokens, and we use them only to post the videos you schedule.

2.6 Payment data

Payments are processed by Stripe. We store your Stripe customer ID and subscription status but do not store full card numbers or bank details. We do keep the card fingerprint Stripe gives us, which is a code that tells us when the same card is used twice without revealing the card itself. For payouts, Stripe Connect stores your account information in accordance with its own privacy policy.

2.7 Track and booking data

We store tracks, audio files, artwork, booking details, form answers, messages, and related metadata that you or your bookers submit through the booking system.

2.8 Security and fraud prevention data

To keep bots and fake accounts out, the login, sign-up, and password reset pages use Cloudflare Turnstile, which checks your browser and IP address. When you sign up, we store a one-way hash of your IP address and a device fingerprint. We use these, together with the card fingerprint above, only to spot people referring themselves through the partner program and other abuse.

2.9 Technical and usage data

We collect IP addresses, browser type, device type, and pages visited for security, debugging, and service improvement. Product analytics and session recording are described in sections 9 and 10.

3. How we use your data

We use your data to:

  • Provide, operate, and improve the Premierely booking system
  • Publish content to SoundCloud, YouTube, and TikTok on your behalf
  • Post Instagram Stories on your behalf when a premiere is published (only when you have connected Instagram and enabled this feature for a channel)
  • Process payments and manage subscriptions
  • Send transactional emails (login links, booking notifications, status updates)
  • Run the AI writing features you choose to use, such as rewriting a track title or drafting a description
  • Respond to support requests
  • Detect and prevent fraud or abuse
  • Comply with legal obligations under Dutch and European law

Leads pool. When a curator declines a track you submitted, that track may be shown to other curators on Premierely so it still has a chance to get booked. They see the track and its booking details, not your email address. The decline email includes a link to opt out, and you can also ask us to remove a track at any time.

We do not sell your data to third parties. We do not use your data for advertising purposes. We do not share your Instagram data with any third party other than Meta's own API infrastructure used to fulfill your Story posting requests.

4. Legal basis (GDPR)

We process your data on the following legal grounds:

  • Contract performance - processing necessary to deliver the services you signed up for (publishing tracks, handling bookings, posting to the channels you connect).
  • Legitimate interests - security logging, fraud prevention, service analytics, showing declined tracks in the leads pool, and contacting music curators about Premierely (see section 8).
  • Contract performance (product analytics for logged-in users) - when you are logged in to your Premierely account, we measure how the app is used so we can operate, secure, and improve the service you signed up for. This is covered by the terms and conditions you accepted at sign-up, so analytics are switched on for your account by default. You can turn them off at any time - see section 10.
  • Consent - analytics for visitors who are not logged in, and connecting third-party integrations (SoundCloud, Instagram, YouTube, TikTok). You can withdraw consent at any time by rejecting analytics or by disconnecting the integration in Settings.
  • Legal obligation - where required by Dutch or EU law.

5. Data retention

We retain your account data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where we are required to retain it longer for legal or tax purposes.

Instagram / Meta access tokens are deleted immediately when you disconnect your Instagram integration from Settings > Integrations, or when you delete your account. Expired tokens that cannot be refreshed are deleted automatically by our cleanup cron job.

6. Your rights

Under the GDPR, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request erasure of your data
  • Restrict or object to processing
  • Receive your data in a portable format
  • Withdraw consent at any time (without affecting prior processing)
  • Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl

To exercise any of these rights, including getting a copy of your data, email us at gino@premierely.io. We will respond within 30 days.

7. Data deletion

You can delete your account yourself in Settings > Account by clicking Delete account. Your account and the data linked to it are removed right away. If you can't log in, email us at gino@premierely.io and we will do it for you.

You can disconnect your Instagram integration at any time in Settings > Integrations > Instagram. This immediately deletes your stored access token and prevents future Instagram Story posts.

If you used the "Log in with Facebook" flow to connect Instagram, Meta may allow you to request deletion of your data via their own settings. See our data deletion instructions for details.

8. People who are not Premierely users

8.1 Fans on download gates and link-in-bio pages

Artists, labels, and curators use Premierely to run download gates and link-in-bio pages. When you use one as a fan, the owner of that page decides what is collected and is responsible for it. We process the data on their behalf.

  • A download gate may ask for your email address and first name, and may ask you to sign in with SoundCloud so it can follow, like, or repost for you. We then store your SoundCloud username and follower count and which steps you completed. Your SoundCloud token is kept encrypted in a cookie that expires after one hour.
  • A link-in-bio page may ask for your email address to join the owner's mailing list.
  • We count page views and link clicks with your browser type, the page that sent you, and your country.
  • Gate pages load the font the owner picked from Google Fonts, which means Google sees your IP address.

The page owner can download these details as a spreadsheet, send them automatically to a web address they choose, or read them through an AI assistant they connect to their Premierely account. To have your data removed, contact the page owner, or email us and we will pass the request on.

8.2 Music curators we contact

We look for music curators who might want to use Premierely. We use their public SoundCloud profile and contact details they publish on their profile, website, or link page, and we may use OpenAI to help draft our message. We send these emails from our own Google Workspace account. If you would rather not hear from us, reply to the email or write to gino@premierely.io and we will remove your details.

9. Third-party services

We use the following processors, each with their own privacy policies:

  • Supabase - database, login, and file storage (EU region)
  • Vercel - application hosting; our server code runs in Frankfurt
  • Hetzner (Nuremberg, Germany) - our own server that renders videos and Stories and uploads them to YouTube, TikTok, and Instagram. It handles your audio, artwork, and encrypted tokens for that purpose only
  • Postmark - sends all emails from the app, including login links, booking notifications, and invoices
  • Cloudflare Turnstile - bot check on login, sign-up, and password reset
  • Stripe - payment processing and Stripe Connect for payouts
  • Meta (Facebook / Instagram) - Instagram Content Publishing API
  • SoundCloud - SoundCloud API for track publishing and download gate actions
  • Google (YouTube Data API) - uploading videos and Shorts to the YouTube channel you connect
  • TikTok - posting videos to the TikTok account you connect, where enabled
  • OpenAI - the AI writing features (title rewrite, description drafting, and template suggestions, some of them Pro only) receive the track details and form answers needed for the text. Importing brand colours from a website sends that public website. We also use it to draft emails to music curators (see section 8). Under OpenAI's API terms, this data is not used to train its models
  • Google (Google Tag Manager and Google Analytics 4) - product analytics: which pages you visit and which actions you take in the app (sign-up, login, booking, purchase, download gate, publish). We run Google Consent Mode v2 with advertising storage, ad user data, and ad personalisation set to denied at all times, so this data is not used for advertising or ad profiling
  • PostHog (EU, hosted in Frankfurt) - product analytics and session recording: which pages you visit, which actions you take, and a replay of how the screen was used so we can find and fix problems. Anything you type is always masked. Invoice, billing and payout details are blanked in recordings. Not used for advertising
  • Microsoft Clarity - heatmaps and screen replays that show where people click and scroll, so we can find confusing parts of the app. Loaded through Google Tag Manager, only once analytics consent is recorded. Anything you type is masked. Not used for advertising
  • Google Workspace - our own email, including replies to support requests and messages to music curators

10. Cookies and local storage

Needed to run the app. These are always on, because login and security break without them.

  • Login cookies (Supabase, sb-*) - keep you logged in. The sb-accounts cookie remembers which accounts you switch between on this browser, for 30 days.
  • OAuth state cookies - short-lived protection tokens used while you connect SoundCloud, Instagram, YouTube, or TikTok.
  • Download gate cookies - on gate pages, including custom domains, these hold your sign-in while you complete the steps. They expire after one hour.
  • Cookie consent cookie - stores your analytics preference. If you are logged in and have not made a choice yet, we set this to "accepted" on the basis of the terms and conditions you agreed to at sign-up (see section 4). If you have already chosen to reject analytics, that choice is never overridden.

Our own counters. These are first-party, never shared, and hold a random ID only.

  • Booking form visitor ID (prem_vid) - set when you open a booking form on a curator's page, so the curator can see how many forms were opened and how many were sent.
  • Partner referral (premierely_ref) - set when you arrive through a partner's link, for 30 days, so the partner gets credit if you sign up.
  • Visitor session cookie - groups a browsing session for analytics. It is only set once analytics consent is recorded.

Analytics. These only load once analytics consent is recorded, and they are never used for advertising.

  • Google Analytics 4 via Google Tag Manager (_ga*) - used to measure page views and product usage.
  • Analytics storage (PostHog) - ph_* cookie and local storage keys that group a browsing session for analytics and screen replay. Cleared when you reject analytics.
  • Microsoft Clarity (_clck, _clsk) - group page views and screen replays into one visit.

Local storage. The app also saves a few settings in your browser, such as whether the sidebar is open, and a draft of a booking form you have not sent yet so you don't lose it. This stays on your device.

How to turn analytics off. Reject analytics in the cookie banner, or clear the premierely_analytics_consent cookie and choose "reject" when the banner reappears. Analytics cookies stop loading immediately and Consent Mode is set to denied.

We do not use third-party advertising cookies, ad pixels, or cross-site ad profiling. Vercel may collect anonymous performance metrics without cookies.

11. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or via an in-app notice. The date at the top of this page shows when it was last updated.

12. Contact

Questions or concerns? Email gino@premierely.io or write to: Gino Gagliardi, Cosijnstraat 25, 2313 NC, Leiden, the Netherlands.