Privacy policy
Last updated: August 9, 2026
1. Who we are
Premierely is operated by Premierely, registered at Cosijnstraat 25, 2313 NC, Leiden, the Netherlands (“Premierely”, “we”, “us”, or “our”). Premierely is a SoundCloud premiere and repost booking platform that connects artists and labels with SoundCloud channel owners.
Contact: [email protected]
This policy applies to the Premierely web application available at app.premierely.io, our free tools at premierely.io/tools/, and all associated services.
2. Data we collect
2.1 Account and profile data
When you create an account, we collect:
- Email address and password (hashed)
- Display name and profile details you provide
- Subscription plan and billing information
- Account activity and usage logs
2.2 SoundCloud integration data
When you connect your SoundCloud account, we store your SoundCloud user ID, username, and encrypted OAuth access token. This token is used only to publish and manage tracks on your connected channels.
2.3 Instagram / Meta integration data
When you connect your Instagram account (available to Premierely Pro users), we request the following permissions via Meta’s OAuth flow:
- instagram_basic – your Instagram account ID and username, to identify your connected account.
- instagram_content_publish – to post Instagram Stories on your behalf when a premiere is published on your SoundCloud channel.
- pages_show_list – to list the Facebook Pages you manage, so we can identify the Page linked to your Instagram Business or Creator account.
- business_management – to verify your Instagram account is connected to a Facebook Business portfolio, which is required by Meta to use the Content Publishing API.
We store:
- Your Instagram account ID and username
- Your connected Facebook Page ID
- Your encrypted Meta access token and token expiry date
- Per-channel settings for Instagram Story templates that you configure in Premierely
We do not read your Instagram feed, access your direct messages, collect your followers, or access any Instagram data beyond what is listed above.
2.4 Payment data
Payments are processed by Stripe. We store your Stripe customer ID and subscription status but do not store full card numbers or bank details. For payouts, Stripe Connect stores your account information in accordance with their own privacy policy.
2.5 Track and booking data
We store tracks, audio files, booking details, messages, and related metadata that you or your bookers submit through the platform.
2.6 Technical and usage data
We collect technical log data and device information from visitors to our websites and users of the platform:
- Full IP addresses – the complete, unmasked IP address your device uses to connect, as recorded in our server and application logs
- Browser type and version, operating system, and device type
- Pages visited, referring URL, and timestamps
We use this data for security, debugging, and service improvement. We use Vercel (hosting) and Supabase (database), which may process this data on our behalf. On our public site and free tools at premierely.io/tools/, full IP addresses are also shared with advertising partners – see Section 9.1.
2.7 YouTube / Google integration
When you connect your YouTube channel (available to Premierely Pro users), we request the following permissions via Google’s OAuth flow:
- youtube.upload – to upload a video of your track to your own YouTube channel when you publish a track in Premierely and have enabled auto-upload.
- youtube.readonly – to read your own channel’s ID, title, and thumbnail so we can show your connected channel in Settings and set it as the upload target.
We store your YouTube channel ID, title, and thumbnail, and your encrypted Google OAuth access and refresh tokens.
We access only your own channel. We do not read, modify, or access other users’ channels, videos, playlists, or analytics. Tokens are encrypted at rest using AES-256-GCM and are never exposed to your browser or any third party.
Premierely’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we share Google user data: we do not share, transfer, or disclose your Google user data to any third party. The only exceptions are our infrastructure processors – Supabase (encrypted database hosting) and Vercel (application hosting) – which store or process this data solely so we can run the Premierely service, and disclosure where required by law. We never sell Google user data, never share it with advertisers or data brokers, and never use it for credit or lending decisions.
We use your Google user data only to provide the user-facing features described above: connecting your YouTube channel and uploading the videos you schedule. We do not use it for advertising, for analytics unrelated to these features, or to develop, improve, or train generalized AI or machine learning models. In plain terms: this data is only used to make the YouTube features you asked for work – nothing else.
3. How we use your data
We use your data to:
- Provide, operate, and improve the Premierely platform
- Publish content to SoundCloud on your behalf
- Post Instagram Stories on your behalf when a premiere is published (only when you have connected Instagram and enabled this feature for a channel)
- Upload a video of your track to your own YouTube channel when you publish it (only when you have connected YouTube and enabled auto-upload for a channel)
- Process payments and manage subscriptions
- Send transactional emails (booking notifications, status updates)
- Respond to support requests
- Detect and prevent fraud or abuse
- Comply with legal obligations under Dutch and European law
We do not sell your data to third parties. The Premierely application (app.premierely.io) does not use your account or product data for advertising. Our free tools at premierely.io/tools/ display ads served by Google AdSense – see Section 9.1 and Section 10.1 for details. We do not share your Instagram data with any third party other than Meta’s own API infrastructure used to fulfill your Story posting requests.
4. Legal basis (GDPR)
We process your data on the following legal grounds:
- Contract performance – processing necessary to deliver the services you signed up for (publishing tracks, handling bookings, posting Instagram Stories).
- Legitimate interests – security logging, fraud prevention, and service analytics.
- Contract performance (product analytics for logged-in users) – when you are logged in to your Premierely account at app.premierely.io, we measure how the app is used so we can operate, secure, and improve the service you signed up for. This is covered by the terms and conditions you accepted at sign-up, so product analytics are switched on for your account by default. You can turn them off at any time – see section 10.
- Consent – connecting third-party integrations (SoundCloud, Instagram). You can withdraw consent at any time by disconnecting the integration in Settings.
- Legal obligation – where required by Dutch or EU law.
5. Data retention
We retain your account data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where we are required to retain it longer for legal or tax purposes.
Instagram / Meta access tokens are deleted immediately when you disconnect your Instagram integration from Settings > Integrations, or when you delete your account. Expired tokens that cannot be refreshed are deleted automatically by our cleanup cron job.
Google / YouTube access and refresh tokens are deleted immediately when you disconnect your YouTube integration from Settings > Integrations, or within 30 days of account deletion.
6. How we protect your data
We use the following safeguards to protect your data, including sensitive data such as OAuth tokens and personal details:
- Encryption in transit – all traffic between your browser, our servers, and third-party APIs uses TLS (HTTPS).
- Encryption at rest – OAuth access and refresh tokens (Google, SoundCloud, Meta) are encrypted with AES-256-GCM before they are stored. Tokens are only handled on our servers and are never sent to your browser.
- Access controls – every database query is checked against your account’s ownership in our service layer, and our database enforces row-level security.
- Payment security – payments are processed by Stripe; we never store your card number.
- Limited internal access – access to personal data is limited to what is needed to run and support the service.
7. Your rights
Under the GDPR, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request erasure of your data
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent at any time (without affecting prior processing)
- Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
8. Data deletion
You can disconnect your Instagram integration at any time in Settings > Integrations > Instagram. This immediately deletes your stored access token and prevents future Instagram Story posts.
You can disconnect your YouTube integration at any time in Settings > Integrations > YouTube. This immediately deletes your stored Google access and refresh tokens and prevents future YouTube uploads.
To delete your entire account and all associated data, contact us at [email protected].
For step-by-step data deletion instructions, see our data deletion page.
9. Third-party services
We use the following processors, each with their own privacy policies:
- Supabase – database hosting (EU region)
- Vercel – application hosting and edge functions
- Stripe – payment processing and Stripe Connect for payouts
- Meta (Facebook / Instagram) – Instagram Content Publishing API
- SoundCloud – SoundCloud API for track publishing
- Google / YouTube – YouTube Data API for uploading videos to your connected channel
- OpenAI – AI-assisted title and description rewrite (Pro feature); track metadata is sent to OpenAI for this purpose only
- Google Tag Manager and Google Analytics 4 – product analytics for the Premierely app (app.premierely.io): which pages you visit and which actions you take (sign-up, login, booking, purchase, download gate, publish). We run Google Consent Mode v2 with advertising storage, ad user data, and ad personalisation set to denied at all times, so this data is not used for advertising or ad profiling.
- Google AdSense – serves advertisements on our free tools at premierely.io/tools/ (not on app.premierely.io). Google and its advertising partners may use cookies to serve ads based on your visits to this and other sites. You can opt out of personalized advertising via Google Ad Settings or aboutads.info.
9.1 Advertising data sharing
On our public marketing site and our free tools at premierely.io/tools/, we share your full, unmasked IP address with third-party advertising partners, programmatic ad buyers, and demand-side platforms – including Google AdSense and Google Authorized Buyers – as part of each ad request.
We share IP addresses with these partners for the following purposes:
- Geographic ad targeting – determining your location with enough precision to serve ads relevant to your country, region, or city.
- Ad fraud detection and traffic validation – identifying invalid traffic, bots, and click fraud.
- Ad frequency capping and campaign delivery measurement – limiting how often you are shown the same ad, and measuring ad delivery and campaign performance.
This sharing applies only to our public marketing site and free tools. The Premierely application (app.premierely.io) does not serve ads and does not share your IP address, account data, or product data with any advertising partner.
10. Cookies
We use the following cookies:
- Session cookie – required to keep you logged in. This is a functional cookie; it cannot be disabled without breaking authentication.
- OAuth state cookies – short-lived CSRF protection tokens used during SoundCloud, Instagram, and YouTube OAuth flows.
- Cookie consent cookie – stores your analytics preference. In the app (app.premierely.io), if you are logged in and have not made a choice yet, we set this to “accepted” on the basis of the terms and conditions you agreed to at sign-up (see section 4). If you have already chosen to reject analytics, that choice is never overridden.
- Product analytics cookies (Google Analytics 4 via Google Tag Manager) – used in the app to measure page views and product usage. They only load once analytics consent is recorded, and they are never used for advertising.
- Visitor session cookie – our own first-party cookie that groups a browsing session for analytics. It is only set once analytics consent is recorded.
How to turn product analytics off. Reject analytics in the cookie banner, or clear the premierely_analytics_consent cookie and choose “reject” when the banner reappears. Analytics cookies stop loading immediately and Consent Mode is set to denied.
On our free tools (premierely.io/tools/), Google AdSense and its advertising partners may set cookies to serve and measure ads, including personalized ads where you have consented via the cookie/consent banner shown to visitors in the EEA, UK, and Switzerland. You can opt out of personalized ads at any time via Google Ad Settings or aboutads.info. The core Premierely application (app.premierely.io) does not use advertising cookies. Vercel may collect anonymous performance metrics.
10.1 Consent and regional privacy rights
Sharing your IP address for personalized advertising is governed by the consent preferences you set in our Consent Management Platform (CMP), the cookie banner shown on premierely.io. You can review, change, or withdraw those preferences at any time by reopening the banner.
If you are in a jurisdiction with applicable privacy laws – including the EEA, the UK, Switzerland, and US states with comprehensive consumer privacy laws – and you withhold consent or opt out of personalized advertising, that signal is transmitted with the ad request. Your IP address is then masked, truncated, or otherwise restricted before it is made available to advertising buyers, and it is not used to build an advertising profile or to serve you personalized ads. Non-personalized ads may still be shown, and a limited amount of technical data – including a coarse, non-precise location derived from your IP address – may still be processed for ad delivery, fraud detection, and frequency capping.
11. Fraud prevention data
When you sign up or log in, we record your IP address and basic device characteristics (browser type, operating system). We use this only to detect and prevent fraud and abuse, based on our legitimate interest in keeping the platform safe. We keep this data for 180 days and then delete it automatically.
12. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or via an in-app notice. The date at the top of this page shows when it was last updated.
13. Contact
Questions or concerns? Email [email protected] or write to: Premierely, Cosijnstraat 25, 2313 NC, Leiden, the Netherlands.