Artery

Privacy Policy

Updated October 1, 2026

Artery ("Artery," "we," "us") is a music-industry platform for independent artists and their managers, available at arteryhq.com. This policy explains what information we collect, how we use it, who we share it with, and the choices you have.

Questions or requests: privacy@arteryhq.com.

1. Information we collect

Information you provide

Information collected automatically

Information from public sources

Artery gathers publicly available information about artists to power its analytics: streaming statistics, playlist placements, news coverage, social-media statistics, and public fan comments (for example, comments posted publicly on YouTube or Reddit about an artist's work). Fan comments may include the commenter's public username and comment text. We use this information solely to show artists and their managers how their music is performing; we do not use it for advertising and we do not sell it. If you are a commenter and want your comment removed from Artery, contact privacy@arteryhq.com.

2. Information from connected services

Artery offers optional Google integrations. You can use Artery without connecting a Google Account — these features work only if you choose to connect one. When you connect a Google service, Artery requests only the permissions necessary to provide the features you enable, and you can review or revoke that access at any time (see Disconnecting Google below). Supported integrations include Sign in with Google, Google Calendar, Google Sheets, and other Google services you explicitly choose to connect.

Sign in with Google

If you sign in with Google, we request the openid, email, and profile scopes and receive your email address and name, which we use only to create and sign you into your Artery account. We do not retain the Google tokens from sign-in after this step.

Google Calendar

If you connect Google Calendar, Artery can read and display your calendars and events and — when you choose — create, update, delete, and synchronize events between Artery and Google Calendar. We access your calendar data only after you connect Google Calendar.

Google Sheets

If you connect Google Sheets, you can select spreadsheets with Google's file picker and link them under Catalog's Publishing Sheets or Master Sheets. Selected sheets open in Google's editor inside Artery, where Google handles changes and saves them to the original spreadsheet using your Google browser session. You can also open the file directly in Google, or preview selected tabs or ranges and import them as separate editable Artery copies. The permission Google grants allows access to and modification of files you select for Artery. Artery's API integration reads the selected files; native Artery edits do not write back to Google.

Artery stores your connected Google account identifier and email, access and refresh tokens, and selected file metadata, including identifiers, access resource keys when provided, names, modification times, edit-access status, and Catalog placement. When you choose to import, we also store the selected cell values and displayed values, basic formatting, formulas, source errors, named ranges and calculation metadata, the source identity and import time, your Artery edits, and saved revision history. Supported formulas recalculate locally in your browser; this does not send your sheet data to a separate calculation service or change the Google file. The original source snapshot is retained. A source refresh requires your confirmation and keeps the previous saved version available for restoration.

Your Google connection and linked Google files remain private to your Artery account. When a manager imports a native Artery copy for a connected artist, the import preview identifies that artist before creation, and the artist can open and edit the same copy in their own Artery account. Existing private copies are shared only when their owner chooses to share them. Other managers and teammates do not automatically receive access to a manager's copies. Copies on an artist's own account are open to the managers that artist is connected with, and their teams, who edit them together with the artist. The artist can see shared content and revisions from when sharing began, but does not receive your Google credentials or original file link. Only the copy's owner can delete it, replace its contents from Google, or change sharing. When the artist–manager connection ends, the manager's copies filed under that artist, and copies shared with the artist, are held for 30 days: the manager can view and export them, and the artist keeps editing shared copies. Reconnecting within 30 days restores them. After 30 days they move to the artist's account with their revision history but without the manager's Google file link, and the manager's Google links filed under that artist are deleted. If a manager deletes their account, these copies move to the artist straight away. Stopping sharing removes the artist's access. Sharing an Artery copy does not change Google sharing permissions. Artery does not browse your Google Drive generally. Import and refresh previews are temporarily stored for review and expire for use after ten minutes.

Disconnecting Sheets deletes its credentials and Google links without deleting original Google files or disconnecting Calendar. Native Artery copies, original source snapshots, and their saved revisions remain available after disconnect so you can continue working. Delete a native workbook separately to remove that copy and its revision history, or delete your account to remove the records you own, subject to the backup and cleanup practices in Section 9.

YouTube Analytics

If you connect YouTube from the YouTube page in Artist Tracker, Artery requests read-only channel and analytics permissions (youtube.readonly and yt-analytics.readonly), together with your Google account identity and email. We verify the channel returned by Google and retrieve performance reports, including views, watch time, subscriber gains and losses, video retention, traffic sources, content formats and audience countries. This connection does not request revenue reports or permission to upload, edit or delete videos.

We store the connection's Google account identity and email, channel identifiers and metadata, access and refresh tokens, the OAuth client that issued the connection, a fingerprint binding it to the originally authorized channel, verification timestamps, and temporary report caches. Reports in an artist's workspace are available to that artist, their connected managers and authorized active team members. An unclaimed managed artist's reports are available to the owning manager and their authorized active team. Google credentials and the connecting account's email are not shared with these viewers. Only the owning artist or owning manager can establish or disconnect the connection. Removing a manager or team member's Artery access ends their access to these private reports.

Report caches are refreshed for use after fifteen minutes and scheduled for deletion after one day. Artery periodically rechecks connected channels even when you do not visit. Inactivity alone does not remove your connection. If Google is temporarily unavailable, we keep the connection credentials, Google account identifier and original-channel fingerprint for verification and consent withdrawal, but delete the account email, unverified channel display metadata and reports before thirty days. We verify channel access again before displaying new private data. Google may independently expire or revoke your credentials, in which case you need to reconnect. We remove stored private YouTube data when access is definitively revoked. These reports are used for the YouTube analytics feature and are not sent to an AI provider.

Use Connection → Disconnect YouTube on the YouTube page to delete the stored connection and reports and revoke access through Artery's dedicated YouTube Google project. Calendar and Sheets use a separate Google project and stay connected. Other artists using the same Google account for YouTube may need to reconnect; the confirmation explains this before disconnecting. If Google cannot confirm revocation, Artery still removes the local YouTube connection and reports and directs you to Google Account permissions to review the YouTube app's access. Connections from an earlier shared Google project are removed locally and require a new YouTube connection; Artery does not revoke those older grants automatically. Original Google files, calendar events and YouTube videos are not deleted. You can also revoke access from your Google Account permissions page, or request deletion at privacy@arteryhq.com. YouTube API Services are governed by the YouTube Terms of Service and Google Privacy Policy.

Disconnecting Google

You can disconnect Google integrations from their connection controls in Artery. Disconnecting deletes the Google access and refresh tokens Artery holds for that connection. YouTube disconnection also revokes the Google grant as described above. You can revoke Artery's access to your Google Account entirely from your Google Account permissions page.

How we handle Google data

Artery accesses Google data only from the Google services you explicitly connect, and only to provide the features you have enabled. We never use Google user data for advertising, marketing, or profiling, and we never use it to develop, improve, or train generalized or standalone artificial-intelligence or machine-learning models.

Google Limited Use disclosure: Artery's use and transfer of information received from Google APIs — across all supported Google integrations, including Sign in with Google, Google Calendar, and Google Sheets — adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, and never used to train AI or machine-learning models. We use it only to provide the user-facing features you enable, and transfer it only as necessary to provide those features (for example, the AI processing described in Section 4).

Optional Facebook and Instagram connection

When you connect Meta, we process your Facebook app-scoped identifier, connection credentials, selected Facebook Page, Instagram professional account and ad account, and granted permissions. We use the access you authorize to display account insights and post performance, identify posts and stories mentioning your connected account, and let you create and manage Meta ads when you choose. Advertising activity remains in your selected Meta ad account.

Social Listening stores tagged-post and story records, which can include the posting account's public username, caption, media, link and timestamps, in private storage for your history. Access to a workspace is governed by its artist, manager and team permissions. Story-mention notifications arrive through Meta's messaging interface; ordinary direct-message text and unrelated attachments are filtered out before storage or logging. Processed Meta delivery records become eligible for cleanup 30 days after processing. These are temporary records used to process incoming events; this cleanup does not remove saved stories, stats or milestone history. Removal happens when cleanup runs; unresolved notifications and records affected by cleanup failures may remain longer. You can request review and deletion as described below.

Retention and disconnecting. Disconnecting removes credentials and stops new collection; it does not itself delete the Social Listening archive. Existing media and records remain while your Artery account exists and they are necessary and permitted to provide that history, unless deletion is requested sooner. We also honor applicable Meta requirements and content-owner deletion requests. The archive is not displayed while disconnected. A minimal mapping between your Facebook and Artery identifiers remains while stored data needs to be located for a later deletion request; it is removed after deletion when there is no active connection.

Deleting Meta data. In Settings › Connections, choose Delete Meta data to remove stored tagged media and attributable activity. This remains available after disconnecting. If still connected, collection can resume with new activity. You may also request deletion through Facebook's Apps and websites settings or email privacy@arteryhq.com. People whose content was tagged may contact that address to request removal after we verify the request. Facebook deletion requests stop the matching connection. Historical identity conflicts require manual verification to avoid deleting another account's data.

We keep deletion-status receipts containing only a random reference, status and timestamps, without Facebook or Artery account identifiers. Status is available for 90 days; expired receipts are removed during subsequent receipt requests. See Data Deletion for the full process, status explanations, and limited operational retention.

3. How we use information

When you connect a Google integration, we use the Google data you authorize only to provide the features you have enabled — displaying and synchronizing your calendar, reading selected spreadsheet ranges to create and refresh the Artery copies you choose, and similar. We never use Google data for advertising, marketing, profiling, or to train AI or machine-learning models.

We do not sell personal information, share it for advertising, or use it for third-party marketing. Artery contains no advertising and no third-party analytics or tracking SDKs.

4. AI features

Artery uses OpenAI as its AI provider to generate briefings, summarize fan comments, tidy calendar-event descriptions, produce industry-news summaries, and power the Meridian assistant. When you use one of these features, only the minimum information necessary to fulfill your request is sent to OpenAI — for example, your Meridian conversation, an artist's analytics, a calendar event description you asked to tidy, spreadsheet information you asked Artery to process, or similar content required to provide the feature.

5. Who we share information with

We use the following providers to operate Artery and share the information needed for their roles. Sharing with connected artists, managers, teams and people holding share links is described separately below:

ProviderPurposeWhat they process
NetlifyHosting and backendAll service traffic
NeonDatabaseAccount and workspace records, content metadata, and data retained from connected services
Cloudflare R2File storageUploaded files and media saved through connected services, including tagged Instagram media
OpenAIAI features (Section 4)Data sent for AI processing
ResendEmail deliveryRecipient addresses and email content
GoogleOptional integrations you connect (Section 2) — Sign in with Google, Google Calendar, Google Sheets, and other Google servicesPer the scopes you grant for each integration
Meta (Facebook and Instagram)Optional account insights, Social Listening and ad featuresAuthorized account identifiers and API requests; ad content and settings you choose to submit

Artery also pulls data in from music-data sources — Chartmetric, Spotify, YouTube, Deezer, Apple Music, X, and public web pages. These lookups are about public artist information; we do not send them your personal information.

The app loads fonts from Google Fonts and open-source libraries from the jsDelivr CDN; like any web request, those services receive your IP address when your browser fetches these assets.

We may also disclose information if required by law, or as part of a business transfer (in which case this policy continues to apply).

6. Sharing between artists and managers

Artery is built for artist–manager collaboration. If you connect your account with a manager (or join a team), that manager and team can see the data and content associated with your artist profile — analytics, calendars, tasks, catalog, and briefing notes about you. Manager briefing notes about an artist are also visible to that artist. You control these connections and can end them in the app.

7. Public share links

If you create a share link in the Demo Vault, anyone with that link can access the shared file and see its title and details — no Artery account required. A recipient can forward the link to others, so link access is not restricted to named recipients. Share links use access tokens, can be set to expire, and can be revoked in Artery. Revoking a link does not remove copies someone has already downloaded. Artery does not use share links for advertising or profiling.

8. Cookies and local storage

9. Data retention

Retention depends on the data and the feature. Account and workspace information is generally kept while needed to provide the service, subject to deletion requests, applicable requirements and the specific retention practices described in Section 2 and on our Data Deletion page.

Account deletion removes your account and the records and files owned by your account or managed workspaces. Work owned by another artist or manager is not removed merely because you contributed to it. Limited cleanup records, deletion receipts and backup copies may remain as explained on our Data Deletion page.

10. Your rights and choices

Depending on where you live (including under Canadian privacy law and the GDPR), you may have additional legal rights to access, correct, export, or erase your personal information, or to object to certain processing. Contact us and we will honor them.

11. Security

All traffic to Artery is encrypted in transit (HTTPS). Passwords are stored only as salted PBKDF2 hashes. Private-file access is controlled through authenticated requests or signed URLs. Content you publish or share can also be accessed through its public page or share link, according to the feature’s access controls. Operational access to personal information is limited to authorized personnel and the service providers that operate Artery, each only to the extent needed to run the service. User access follows the account, workspace and sharing permissions described above. Data is hosted with established infrastructure providers (Netlify, Neon, Cloudflare). No online service can guarantee absolute security, but we work to protect your information and will notify affected users of any breach as required by law.

12. Children

Artery is for users 18 and older. We do not knowingly collect information from anyone under 18; if we learn we have, we will delete it.

13. International processing

Artery is operated from Canada and our service providers process data in the United States and other countries. By using Artery you understand your information may be processed outside your own jurisdiction.

14. Changes to this policy

If we make material changes, we will update the date above and notify you in the app or by email before the changes take effect.

15. Contact

Artery — Ontario, Canada
privacy@arteryhq.com