DMJ Sync Analytics (“the Service”) is operated by Nome House Studios (“we”, “us”). This policy explains what data the Service collects, why, how long we keep it, and how you can remove it.
The Service is used by musicians and their representatives to export their own social media performance data and share it with their managers, labels, and brand partners.
Who this policy covers
- Artists who create an account and connect their own social media accounts to the Service.
- Managers, labels, and brand representatives who view data an artist has explicitly chosen to share with them.
What we collect
1. Account information
When you create an account we collect your email address and a password, handled by our authentication provider (Supabase). We never see or store your password in readable form.
2. Data from connected platforms
When you connect a platform, you are shown exactly which permissions you are granting and you may decline. We only ever access data belonging to your own account.
From Instagram (via the Instagram API with Instagram Login, using the instagram_business_basic and instagram_business_manage_insights permissions):
- Your Instagram professional account’s basic profile information (account ID, username, media count)
- For each of your own posts: post ID, publication date, media type, caption text, and permalink
- Performance metrics for your own posts and account: likes, comments, reach, saves, shares, views, and total interactions
From TikTok: your own videos’ ID, publication date, title, URL, duration, views, likes, comments, and shares.
From YouTube: your own channel’s videos, including title, upload date, duration, views, watch time, average view duration, likes, comments, subscribers gained, traffic sources, viewer territories, and audience retention.
3. Access tokens
We store the access token each platform issues when you connect. It is used solely to request your own data on your behalf and is deleted when you disconnect the platform or delete your account.
What we do NOT collect
We want to be specific, because the permissions we request are narrower than people often assume:
- We do not read your direct messages on any platform.
- We do not collect your follower or following lists.
- We do not collect data about other people — only content and metrics belonging to your own account.
- We never see your social media password. You log in on Instagram’s, TikTok’s, or Google’s own website.
- We do not post, comment, message, or make any change to your accounts. Our access is read-only.
- We do not use tracking cookies, advertising pixels, or third-party analytics on the Service.
How we use your data
Only to provide the Service:
- To generate the reports and CSV exports you request.
- To calculate figures you ask for, such as cost-per-view.
- To produce a PDF summary or a shareable report link when you create one.
- To notify a webhook address you have configured yourself, if you choose to set one up.
We do not sell your data, use it for advertising, use it to train machine learning models, or share it with anyone except as described below.
Who your data is shared with
Only with people you choose. Data leaves your account in exactly three ways, all of which you initiate:
- Share links. You create a link, choose which platforms it includes, and set an expiry (up to 90 days). Anyone with the link can view a summary and download the CSVs you included. You can revoke a link at any time, which takes effect immediately.
- Manager access. You may grant a specific person read-only access to your data. They cannot modify anything, cannot connect or disconnect platforms, and cannot create share links. You can revoke this at any time, which takes effect immediately.
- Your own downloads. Files you download are yours to distribute as you see fit.
We use the following service providers to operate the Service. They process data on our behalf and are not permitted to use it for their own purposes:
| Provider | Role |
|---|---|
| Supabase | Database and authentication |
| Render | Application hosting |
| Vercel | Website hosting |
We may disclose data if required by law, but we will notify you unless legally prohibited from doing so.
How long we keep your data
- Access tokens: until you disconnect the platform or delete your account.
- Exported data: until you delete it or delete your account.
- Account information: until you delete your account.
Note that Instagram itself only makes account-level metrics available for the preceding 90 days, so data older than that may not be retrievable even where we would otherwise be able to store it.
Your rights
You can, at any time:
- Access your data — everything we hold is downloadable as CSV directly from your dashboard.
- Disconnect any platform, which immediately deletes that platform’s access token.
- Delete your data — see our Data Deletion Instructions.
- Revoke any share link or manager access, effective immediately.
If you are in the EEA or UK, you additionally have the right to object to processing, request rectification, request portability, and lodge a complaint with your local supervisory authority. If you are in California, you have the right to know what personal information is collected and to request deletion; we do not sell personal information.
Security
Data is encrypted in transit (HTTPS) and at rest. Access tokens are stored server-side and never exposed to your browser. Access to your data is checked on every single request against your identity — one artist cannot access another artist’s data.
No system is perfectly secure, and we would rather say so than imply otherwise. If you discover a security issue, please contact us at the address below.
Children
The Service is not directed to anyone under 13, and we do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
If we make a material change we will update the date at the top of this page and notify account holders by email before the change takes effect.
Contact
Nome House Studios
Email: deshawn@nomehousestudios.org
For data deletion requests, see Data Deletion Instructions.