Privacy policy.
Last updated: 11 August 2026
1. Introduction
Total Audio Promo Ltd (“TAP”, “we”, “us”, or “our”) operates totalaudiopromo.com and related services. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.
Data Controller: Total Audio Promo Ltd
Contact: [email protected]
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name, email address, and authentication credentials (managed by our authentication provider, Supabase).
2.2 Workspace Data
Data you create within TAP, including releases, artist rosters, contact lists, pitch drafts, and outreach records. This data is stored in your workspace and accessible only to workspace members.
2.3 Usage Data
We collect anonymised usage data to improve the service, including page visits, feature usage, and performance metrics. We use consent-based analytics only.
3. How We Use Your Data
- Providing and maintaining the TAP service
- Processing your payments (via Stripe)
- Sending essential service communications
- Improving the service based on anonymised usage patterns
- Responding to support requests
4. Data Storage and Security
Your data is stored securely using Supabase (hosted on AWS in the EU region). Payment information is processed by Stripe and never stored on our servers. We implement row-level security policies to ensure workspace data isolation.
5. Third-Party Services
- Supabase: Authentication and database hosting
- Stripe: Payment processing
- Vercel: Application hosting
- OpenRouter: Routes our AI requests to the model provider below. Prompt content passes through OpenRouter in transit and is not retained beyond the request.
- Anthropic (Claude): AI features including contact enrichment, pitch drafting, and Newsjack social drafts. News article titles and descriptions sent for draft generation are processed by Anthropic and not retained beyond the request.
- Google: Your Gmail mailbox (via IMAP and SMTP), Google Calendar, and Google Drive, each only when you connect them (see Section 5.1 below)
5.1 Google API Services Disclosure
TAP’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your mailbox: app password, not a Gmail API scope
We do not request any Gmail OAuth scope. TAP reaches your mailbox using an app password that you generate in your own Google account and paste into TAP, over the standard IMAP and SMTP protocols. That credential is stored encrypted against your workspace and is used for exactly two things:
- Reading, to match replies: We read message metadata (sender, recipient, subject line, timestamp, thread ID) to detect replies to your pitches and track release outcomes. We do not store the full body of your emails.
- Writing, only what you approve: We save drafts into your mailbox and send messages from your own address. Every send requires a named person in your workspace to approve that specific message first. There is no automated send, no bulk send, and no scheduled send that skips approval.
You can revoke this at any time by deleting the app password from your Google account, or by disconnecting from Settings > Integrations. Either takes effect immediately.
What we do request through Google sign-in
When you connect Google, TAP asks for three scopes and no others:
calendar.events: to put your release dates and pitch deadlines in your calendar.drive.file: access limited to the specific Drive files and folders you choose to link to a release. This scope gives us no visibility of anything else in your Drive. We read file metadata (name, type, size, thumbnail) and do not download or store file contents.userinfo.email: to know which Google account you connected.
Data storage and retention
Email metadata and Drive file metadata are stored in your workspace database, protected by row-level security policies. Only members of your workspace can access this data. App passwords and OAuth tokens are encrypted at rest. We do not share, sell, or transfer Google user data to third parties, except as necessary to provide the service.
Revoking access
You can disconnect your Google account at any time from Settings > Integrations. This immediately revokes our access. You can also revoke the calendar and Drive scopes directly from your Google Account permissions page, and the mailbox app password from the link above.
5.2 Send-on-Behalf-Of
TAP can send pitch emails on your behalf using credentials you connect to your workspace (Gmail via IMAP today, additional providers planned). When you signed up, you authorised TAP to do this. The timestamp of that authorisation is stored on your workspace as send_consent_at. Without that timestamp, the sending settings page is gated and the send endpoint refuses any proposed send.
Per-message approval is required. Every send, on every channel, requires a named human in your workspace to approve the specific message before TAP dispatches it. There is no batch send without per-message review, no agent-only send without a human approver, and no scheduled send that skips the approval queue. Approval is the safeguard, not the channel. See the Data Processing Addendum for the contractual detail. You can review and revoke send permission from Settings > Sending at any time; revocation takes effect immediately and cancels any pending approvals.
TAP refuses to send from a domain that publishes p=reject if the message would fail DMARC alignment. We do not silently fall back to a TAP-branded address. Recipients always see your real address.
6. Your Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request erasure of your data
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
To exercise these rights, contact [email protected].
7. International Users
We serve users globally and comply with applicable data protection laws in the territories where we operate, including:
- California (CCPA/CPRA): California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell personal information.
- Canada (PIPEDA): Canadian users have the right to access and correct their personal information. We obtain meaningful consent for the collection, use, and disclosure of personal data.
- Australia (APPs): Australian users are protected under the Australian Privacy Principles. We take reasonable steps to protect personal information from misuse, interference, and loss.
We do not sell your personal information to any third party, regardless of your location.
8. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or an in-app notification.