Privacy Statement
What TheJay records about you, what it records about the people in your network, and what it deliberately does not measure.
The Dutch text is the binding version. This translation is here so it can be read; where the two differ, the Dutch text prevails.
1. Who processes your data
- Controller
- —
- Trading as
- TheJay
- Chamber of Commerce (KvK)
- —
- VAT number
- —
- Address
- —
- —
TheJay is one service. TheJay is operated by —; where this statement says we, it means that company. Your account, your identity, your names and your address book live in TheJay's own database, and this statement is the whole statement.
2. Two roles, and here the difference matters extra
Controller — for your account
For what is yours as an artist — your profile, your music, your releases, your invoices — we (—) determine the purpose and means and are the controller under the GDPR, and this statement is the whole story.
Processor — for your network
TheJay is full of data about other people: bookers, labels, promoters, venues, fellow artists. Who they are, what you think of them, when you last spoke, and whether they listened to your demo. That is personal data, and you decide what you record about it.
For that you are the controller and we are the processor. The terms are in the Data Processing Agreement, which applies automatically — nothing to sign.
This is not a formality. A private note about a promoter is personal data, and that person has, in principle, the right to request it. Do not write anything in TheJay you would not want read aloud. We do not read your notes and give them to nobody — but the law gives the data subject a right we cannot take away.
3. What data, for what, and on what basis
| What | Why | Legal basis | How long |
|---|---|---|---|
| Account — email address, and which workspaces and brands you may see | Signing in, and knowing what you may do | Performance of the contract | As long as your account exists |
| Session | Staying signed in | Performance of the contract | 14 days |
| Which parts of TheJay your workspace used on a day — the feature, never what you did in it or who did it | Knowing which features are used, by which kind of customer, to improve TheJay and to help customers get going. Only in aggregate: a figure over fewer than five workspaces is never shown | Legitimate interest (aggregate, no individuals) | 13 months |
| If you are in touch with TheJay as a business contact — a prospect, partner, investor or journalist: your name, address, organisation and our notes about the conversation | Keeping track of the company's own relationships. Never mixed with what you keep in TheJay | Legitimate interest | Until the relationship ends, or you ask us to remove it |
| Artist profile — name, bio, photos, live set, rider, links | Your EPK and your public page | Performance of the contract | Until you delete it |
| Your library — tracks, versions, artwork, press photos | Your catalogue, your demos and your EPK | Performance of the contract | Until you delete them |
| Media on a scheduled post — the picture or video you attach | Publishing the post to the channels you choose | Performance of the contract | 72 hours after the post has finished on every channel you chose — published or permanently failed. If a channel did not work we keep the file for 30 days, so you can try again and we can find out what went wrong. A file attached to nothing goes after 7 days. See article 9. |
| Network — people and organisations, their role, notes, contact moments | Your relationship management | You decide this; we are the processor here | Until you delete it |
| Outreach and bookings | Tracking who you approached and what came of it | You decide this; we are the processor here | Until you delete it |
| Demo recipients and what they did with the link | Knowing whether your demo was listened to — see section 5 | You decide this; we are the processor here | Until you revoke or delete the link |
| Visits and clicks on a smart link | Measuring how a release is doing — see section 5 | Legitimate interest (aggregate, no individuals) | Until you delete the link |
| Content plan and posts | Planning and running your campaign | Performance of the contract | Until you delete it |
| Connected social accounts — tokens, encrypted | Posting on your behalf | Performance of the contract | Until you revoke the connection |
| Connected mailbox and calendar (Google, Microsoft) — tokens, encrypted; and of mail about your work: sender, subject, date and a short preview | Booking requests, demos and conversations in your Communication hub; what else is on a day in your calendar; and, only if you allowed it, sending what you send from TheJay from your own address | Performance of the contract | Tokens until you disconnect; mail details until you delete them or your account. See below. |
Your mailbox and calendar
If you connect a Google or Microsoft account, TheJay asks for read-only access by default: to read your mail and your calendar, and to see the names of your calendars. If you choose Read and send when connecting — or later press Allow sending from TheJay — TheJay also asks for permission to send mail (gmail.send at Google, Mail.Send at Microsoft). TheJay can never delete or change anything in your mailbox or your calendar.
Connecting an account starts reading it. From the moment you connect it, TheJay reads its mail and its calendar as described below, for the workspace you connected it to — everyone in that workspace sees what TheJay keeps — until you stop it (the mail under Manage in the Inbox, the calendar on the account in Integrations) or disconnect the account. There is no second switch to turn reading on.
Your own mailbox is yours. In a workspace with colleagues you can connect an account as your own mailbox instead. Then only you see what TheJay keeps from it; an administrator sees that it is connected, never its mail. A conversation from it reaches your colleagues only when you link it to a booking, a contact or another record, or share it with the team. Its calendar is not read. When you leave the workspace, it is disconnected and the conversations only you could see are deleted.
- Mail you work with. From the moment your mailbox is connected until you stop reading it or disconnect it, TheJay reads it in the background every few minutes, and again when you open the Communication hub. It looks at your inbox, at your Sent folder, and at your other folders — from those it keeps only replies to conversations in TheJay — and at delivery reports (a bounce), to see which message could not be delivered. It keeps only the messages about your work — from people in your People list, booking requests, demos, answers to what you sent from TheJay. Of those it stores the sender, the recipients, the subject, the date and a short preview. The full text and the attachments are fetched when you open a message and are not stored.
- Mail you send from TheJay. Only with the send permission, and only from your own mailbox: a reply, a message, a link you share, and the reminders about your bookings you leave switched on leave through Google or Microsoft from your own address, and appear in your own Sent folder. Without the send permission TheJay sends none of it — you get a link to send yourself. TheJay never sends what you write from its own address.
- Your whole inbox. Under Mailbox you can see every message in your inbox. That view is read live from Google or Microsoft each time you look, and none of it is stored or logged. Add a sender to your People and from then on their mail is kept as above.
- Calendar. From the moment you connect, when your workspace has not chosen a calendar yet, until you switch Show what else is in it off on the account in Integrations or disconnect: TheJay reads the events around a date to show you whether that date is busy. Events are not stored. Putting your bookings into your calendar is a separate switch, off until you turn it on.
- AI. Only when you ask TheJay to read a message for you is that one message sent to the AI provider (section 8) — never automatically, and it is not used to train any model.
- Tokens are stored encrypted (AES-256-GCM). Disconnecting deletes them and, for Google, revokes them at Google. You can also withdraw access yourself at myaccount.google.com/permissions or account.live.com/consent/Manage. Mail details already in your hub stay until you delete them or your account.
- Never sold, never used for advertising, never passed to anyone but the sub-processors in section 7, and never read by people at TheJay — unless you ask us to for support, it is needed for security, or the law requires it.
People you are in touch with through TheJay
For these you are the controller and we are the processor (section 2).
- Their messages on a TheJay page — a guest page, a booking page, a signing page — and their email answers to what you sent are kept in the conversation with them, so both of you see one history. Every email about a conversation carries a Stop emails about this link; the conversation stays readable on their page.
- A booking request sent through your public booking form is kept in your workspace as a contact and a conversation.
- An answer to a demo — a reply by email, or a message on the demo page — is recorded against that recipient on your list, beside the listening described in section 5.
- When somebody you work with joins TheJay, TheJay shows them — and only them, once they have proved their address — the public names of workspaces that hold that address and have worked with them. Nothing is linked, and no workspace is told anything, unless they choose to link it. Once they link a workspace, its messages to them arrive in TheJay, with an email copy according to their own notification preference.
- After somebody answers on a TheJay page (and never before), the page may suggest once what TheJay would do for them. We record that it was shown or dismissed, and whether an account followed, on that link's own record. Where a proved address holds live links from more than one workspace, the suggestion may say how many — a number, counted from a salted hash of the address, never a name. Pressing Ask … to add you to their team tells the sender in the conversation; it gives nobody access.
Mail TheJay sends itself
TheJay's own mail relay (section 7) sends only TheJay's own mail: sign-in and confirmation codes, receipts for something a person did on TheJay, invitations to join TheJay ("Luc invited you…"), account, billing and security mail, and notices to members about their own workspace. Nothing a member writes, and no reminder or change notice about a member's business, goes through it.
TheJay's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. What is deliberately not recorded
This describes the code as it runs, not an intention:
- No IP addresses. Anywhere. Not on a smart link visit, not on a demo page.
- No user agents. Which browser, device or operating system someone arrived with is not recorded.
- No location. Not even a country, not even approximate.
- No cookies on your public pages. Your release link, your demo link and your artist page set no cookie at all and use no browser storage. A fan who clicks your smart link picks up nothing.
- No third-party trackers or pixels. No Google Analytics, no Meta pixel, no ad network.
- No selling of data, and no training of AI models on your music, your network or your writing.
5. Measuring people — demo links and smart links
Two features in TheJay measure what other people do. That is what they exist for, so it gets its own section, in plain words.
Demo links
When you send a demo, TheJay records per link: when it was opened, whether it was played, whether someone reached halfway, whether they finished it, and whether it was downloaded — nothing finer than that. If you attached the link to a specific recipient, those events hang off that person. That is exactly what the product promises — "who listened and how far" — and it is at the same time the measuring of someone else's behaviour. An answer — a reply to your email, or a message on the demo page — is recorded against that person too.
What this asks of you. You are the controller here. Tell the recipient that you can see whether they listened. One sentence in your message is enough. If you do not, you are measuring someone without their knowledge, and that is your responsibility and not ours.
What is not recorded on a demo visit: no IP address, no device, no location. If the link is not attached to a recipient, there is no way at all to know who was there.
Smart links
For a release link TheJay counts how many visits there were and which service was clicked. Nothing more: no visitor id, no cookie, no IP address, no session. Two visits from the same person are indistinguishable, and that is deliberate. You get a campaign count, not an audience.
6. Cookies
| Name | Purpose | Lifetime | Properties |
|---|---|---|---|
| thejay_session | Remembering that you are signed in | 14 days | HttpOnly, Secure, SameSite=Lax |
That is the only cookie, it is strictly necessary, and it is set only when you sign in. On the public pages — /r/, /d/ and /a/ — it is not set and nothing else happens. Hence no cookie banner.
7. Who else sees your data
The full list is on the sub-processors page, which forms part of this statement. In short: the hosting provider, the language-model provider for your AI text, and the mail relay, which carries only TheJay's own mail (section 3). Mollie handles payment once paid plans open; during early access nothing is paid through TheJay and nothing goes to Mollie.
Social platforms
If you connect Instagram, TikTok, YouTube or LinkedIn, what you post goes straight to that platform on your instruction. What they do with it falls under their own terms. We store the access tokens encrypted (AES-256-GCM), and without the key they are useless.
Publishing is switched off today. No key is configured in production, so no social account can currently be connected and nothing goes to a platform. You can still plan and write. If this changes, it will appear on the sub-processors page before it works.
Your own public pages
Your EPK, your release link and your demo link exist to be shared. What you put on them is public to anyone holding the link — that is the point, but worth realising before you put a phone number in your rider. A link can be revoked; what someone has already seen cannot.
8. Transfers outside the EEA
The application and database run inside the EU. If you use an AI feature — have a text written, ask the assistant, have a contract read, or record a voice note, or have a message from your mailbox read — that request goes to the AI provider, today OpenAI in the United States. OpenAI does not train its models on it and keeps it for up to 30 days to detect abuse; a contract you have had read stays stored there until it is deleted. The European Commission's Standard Contractual Clauses apply. Without the AI features, nothing leaves the EU by this route.
9. How long we keep things
- The periods per category are in the table under section 3.
- We delete media on a post ourselves, and that is deliberate. TheJay is a scheduling tool, not a storage service. Once your video is on Instagram or TikTok there is little reason for us to hold the original — and an archive of unreleased work sitting here for years is a risk we do not want to put on you. The clock only starts once every channel you chose has finished; never because the scheduled time went by. If a channel fails at 10:01, the file stays.
- The post itself stays. Title, caption, hashtags, the scheduled and the actual time, the channels, the status, the link to what was posted, the original filename, its type, dimensions, duration and size, and what went wrong — plus a small thumbnail. So your calendar stays readable without us keeping hundreds of megabytes.
- We do not touch your library. Tracks, artwork and press photos stay until you delete them. The period above applies only to the file attached to a scheduled post.
- Revoke a demo link or a smart link and it is dead immediately. Delete it and the associated events go with it.
- Delete your account and we delete your data within 30 days, except what we must keep by law — in practice payment records, for 7 years, once there are any.
10. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection. Most of it you can do yourself: every record in TheJay can be viewed, changed and deleted.
If someone in your network asks for their data, that is your request to answer — you are the controller there. If it reaches us, we forward it to you and help.
What you cannot do yourself yet. There is no button today that deletes your account with everything in it, and none that exports everything. That is a shortcoming, not a choice. Until then: email — and we do it by hand, within 30 days, with confirmation.
You can complain to the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).
11. Security
- Your password is stored as a salted bcrypt hash, never in the clear, and a sign-in that fails costs the same time whether the address, the password or the code was wrong.
- Every row belongs to one workspace and nothing is readable across that boundary.
- Social account tokens are stored encrypted with AES-256-GCM, with a key that exists only in the runtime environment.
- Files are reachable only through a token, not through a guessable URL.
- A demo link is addressed to one person, expires, and can be revoked at any moment — every recipient of the same demo has an address of their own, so one can be taken back without touching the others. A download can be locked behind a code sent to the address the link was sent to.
- Everything runs over HTTPS; the session cookie is HttpOnly and Secure.
In the event of a data breach posing a risk to those affected, we report it to the Dutch Data Protection Authority within 72 hours and inform you without undue delay.
12. Changes
If this statement changes substantively, we raise the version number and email you before it takes effect.