Privacy Policy
This Privacy Policy explains, in plain language, what data StreamRev collects, how we use it, and the choices and rights you have. By using StreamRev you agree to the practices described here.
What we collect
- Account info: the email address you sign in with. Sign-in is handled by Supabase Auth - we never see or store your password.
- Statements you upload: the contents of the royalty files you choose to upload - things like song titles, artist names, ISRCs, territories, unit/stream counts, and earnings amounts.
- Connected-account data: if you connect a third-party account (for example, your Genius profile), we retrieve and store the catalog data that account exposes about your work - song titles, the credits and roles associated with each song, artist/profile details, and public engagement metrics such as page views. We only pull this after you explicitly authorize the connection, and only to build your catalog.
- Public performance metrics: to estimate reach, we collect publicly available stream and play counts for your tracks from public sources and associate them with your catalog.
- Collaborator metadata: catalog and statement data often names other people who worked on your songs (co-writers, producers, publishers). We store this to attribute income correctly. If you are a collaborator named in someone's catalog and want your information removed, email us (see Your rights).
- Basic operational logs: standard request and error logs needed to run and debug the service.
We do not ask for, and you should not upload, bank account numbers, government IDs, or other sensitive identifiers - StreamRev doesn't need them.
What we do with it
We use your data only to operate StreamRev for you: to parse your statements, match and normalize the line items, and show you your coverage and earnings. We do not sell your data, and we do not use it for advertising.
What happens to an uploaded file
When you upload a statement we parse it into normalized line items, and we keep your original file, encrypted with a key unique to your account. We keep it for two reasons: so every figure we show you can be traced back to the exact document you gave us, and so we can fix a parsing mistake without asking you to find the file again. We also store a one-way fingerprint (hash) of it so we can spot duplicate uploads.
Sources we don't read automatically yet: if you upload a statement from a platform we haven't added support for, we store your file - encrypted the same way - until we can add support, then process it. Either way, the file is encrypted at rest with your account's own key, and you can ask us to delete your data at any time (see Your rights below).
Where it's stored
Your data is stored in a managed PostgreSQL database hosted by Supabase in the United States. Each user's data is scoped to their own account in our application code, so other users cannot see your catalog, statements, or earnings.
Security
- Sign-in and password handling are delegated to Supabase Auth; we store no passwords.
- All traffic to the site and API is served over HTTPS.
- Access to your data is restricted to your authenticated account; we enforce per-user scoping in code and test for it.
- Your original uploaded files are encrypted at rest with a key unique to your account (see above).
- This is beta software - we work to keep it secure but cannot guarantee perfect security. Please don't upload anything you couldn't tolerate being exposed in the unlikely event of a breach.
Third parties we rely on
- Supabase - authentication and database hosting (United States).
- Render - hosting for our application and API (United States).
- Genius - when you choose to connect your Genius account, we access your catalog data through Genius's API.
- Sentry - crash/error reporting, configured to not send personal information.
These providers process data only to help us run the service.
YouTube API Services
StreamRev uses YouTube API Services to show you public performance data for your own songs. By using StreamRev, you also agree to the YouTube Terms of Service, and Google's handling of data is described in the Google Privacy Policy.
What this means in practice:
- What we access: we search YouTube for videos matching songs in your catalog and retrieve public video information only - titles, channel names, and public view counts. This is read-only. We never upload, edit, comment, or interact with YouTube content on your behalf.
- No access to your YouTube account: StreamRev does not ask you to sign in with Google or YouTube, and we never access private YouTube account data, subscriptions, watch history, or any authorized user data. We do not use YouTube's OAuth scopes at all.
- What we store: the public view counts and video identifiers for videos matched to your songs, so your dashboard can show how your catalog is performing over time. Stored counts are refreshed on an ongoing nightly basis, so nothing we display is more than 30 days old.
- Deletion: if you delete your StreamRev account (see Your rights below), the stored YouTube-derived data for your account is deleted with it, within 30 days. You can also contact us at any time to have it removed sooner.
- No sharing: we do not sell or share YouTube-derived data with third parties; it exists solely to render your own dashboard.
Cookies & tracking
We don't use third-party advertising or tracking cookies. Your login session is held in your browser's sessionStorage and is cleared when you sign out or your session expires.
Your rights
You control your data. At any time you can ask us to:
- Access and download it - get a copy of the data we hold about you in a portable format.
- Correct it - fix anything that's inaccurate.
- Delete it - remove your account and your stored catalog, statement, and connected-account data.
To exercise any of these, email streamrevmusic@gmail.com. We'll respond within 30 days. Depending on where you live, you may have additional rights under laws such as the GDPR or the California Consumer Privacy Act (CCPA); we honor those requests the same way. We do not sell or share your personal information, so there is nothing to opt out of on that front.
How long we keep it
We keep your data for as long as your account is active so we can provide the service. If you ask us to delete your account, we remove your personal data from our live systems within 30 days, except where we're required to keep certain records to comply with law. Backups are purged on our normal rotation.
Children
StreamRev is a financial tool intended for adults. You must be at least 18 years old to use it. StreamRev is not directed to children, and we do not knowingly collect personal information from anyone under 13. If we learn that we have collected information from a child under 13, we will delete it promptly.
If there's a data breach
If a security incident affects your personal data, we will notify you and the appropriate authorities as required by applicable law, and tell you what happened and what we're doing about it.
Changes
If we change how we handle data in a material way, we'll make a reasonable effort to notify beta participants. Continued use after a change means you accept the updated policy.
Contact
Questions about privacy? Email streamrevmusic@gmail.com. StreamRev is operated out of Miami, Florida, USA.
