Privacy Policy
Last updated: July 26, 2026
Who we are
PubSheets (“we,” “us”) provides software that helps music publishers manage catalogs, contacts, and song pitching, available at pubsheets.com. This policy explains what we collect, why, and the choices you have. Questions: privacy@pubsheets.com.
Information you give us
- Account details: your email address and organization name.
- Business content you enter: songs, lyrics, recordings, splits, contacts, notes, pitches, calendar events, and metrics. This data belongs to your organization.
- Payment details are processed by Stripe; we never see or store card numbers.
Information from Google, and how we use it
If you choose to connect Google services, we access only what the feature needs, only after you approve it on Google’s consent screen:
- Sign in with Google: your email address, to create and secure your account.
- Gmail sending: used solely to send pitch emails you compose, from your own address, when you click Send. We store an encrypted refresh token and your Gmail address. We never read, store, or analyze your inbox or any email content beyond the message you are sending.
- Google Calendar: used to display your events beside PubSheets dates and, when you ask, to create an event or invite on your calendar. We do not store your calendar events.
PubSheets’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never sell Google user data, never use it for advertising, and never let humans read it except with your consent, for security, or to comply with law.
How we protect data
- All traffic is encrypted in transit (TLS).
- Data is stored with row-level security so each organization can only ever see its own records.
- OAuth tokens are stored server-side, readable only by your own account’s session.
- Audio files are stored privately and served through expiring signed links.
Sharing
We do not sell your data, full stop. We share data only with the service providers that run PubSheets (hosting, database, storage, email delivery, payments, and AI processing of text you explicitly submit for drafting or parsing), each bound to use it only to provide their service, and when required by law.
Retention and deletion
Your organization’s data is kept while your account is active. You can disconnect Google services anytime in Settings, which deletes the stored tokens immediately. On account closure we delete your organization’s data within 30 days, except where law requires longer. Email privacy@pubsheets.com for export or deletion requests.
Changes
If this policy changes materially we will notify account owners by email before the change takes effect.