Get Heard is operated by Get Heard (CVR 46673425), Milnersvej 13A, 3400, Hillerød, Denmark. Write to hello@getheard.now.
This policy covers Get Heard, the service a musician uses to get a song heard: finding outlets, writing and sending pitches, tracking the replies, and publishing a press kit, a smart link and a link-in-bio page.
Three kinds of people appear in it and they have different rights, so they are separated below: the musicians who sign up, the people they write to, and the people who visit a published page.
We store your email address, your name if you give one, and either a password hash or the fact that you sign in with Google. We store the sessions your browser holds so you can be signed in, and the plan you are on together with the Stripe customer that pays for it.
For each of those sessions we also store what your browser says it is - the line every browser sends with every request, naming itself and the system it runs on. We keep it so the Devices list in your settings can tell you which sign-in is which, and so you can end one you do not recognize. Signing that device out deletes it.
We store everything you put into the service, because that is the service: your artists, releases, audio, artwork, lyrics, the video clips it renders, the outlets you have written to and what you sent them, the replies you recorded, and the numbers it reads back from your connected accounts.
When you connect an account (Gmail, Instagram, Facebook, TikTok or YouTube), we hold the access token that account issued, per artist, so the service can act as you asked. Disconnecting removes it.
We record what each request to an AI vendor cost, so your plan's included budget can be enforced. That record is a model name, a token count and a cost, not the text.
Staff at Get Heard can open your account in an internal tool. They do this to answer a support request, to keep the service running, or to act on something you have asked for. What they see there is your account: the plan you are on, what the service has cost to run for you, how far you have got with a release, whether anything is stuck, and the titles of any releases that are set to post by themselves. They do not read your pitches, the replies you received, your audio or your artwork from that tool.
Some of them can also act on your account on your behalf. They can extend a trial, add credit, resend your sign-in link, stop a release from posting by itself, and close or reopen the account. At your request they can also export or delete it. Deleting is limited to the smallest number of people who need it.
Every time a member of staff opens your account, and every change they make, is recorded: who, when, and what. That record is kept for 24 months. Looking at totals across all accounts is not recorded, because those numbers describe no one in particular. You can ask us who has looked at your account and we will tell you.
When you send us a message from Help inside the app, we store what you wrote, any screenshots you attach to it, and three facts about the app itself: which edition it is, which version, and the page you were on. We store our replies in the same conversation.
We answer inside the app rather than by email, so we do not ask you for an address and we do not keep one for this. The reply appears in the same conversation and the app tells you it is there.
A screenshot is a picture of your own screen and we store it exactly as you sent it, so whatever happened to be visible when you took it is in our hands too. It is kept with the message it came with, deleted when that conversation is, and shown only to the staff described above.
We do not attach your account to our technical fault reports, and those reports carry nothing that points back at you (see section 7). Answering your message and closing the conversation are recorded in the staff record described above, by ticket number, not by what you wrote.
A closed conversation is deleted 12 months after it is closed. One that is still open is kept until it is finished, however long that takes. Everything goes when the account does.
The service holds contact details for music blogs, playlist curators and writers: a name, a public contact address, the publication, and what they cover. This comes from those outlets' own public pages, which is where they publish it in order to be written to.
A pitch sent through the service carries a small invisible image and rewritten links, so the sender can see whether their message was opened and whether a link was followed. We keep those events for 24 months. They are a rough signal, not a certainty: mail apps that pre-load images make an opened message look read when nobody read it.
When a musician drafts a pitch to you, your name, publication and beat are sent to an AI vendor as part of the prompt that writes it. See the list in section 5.
If you would rather not be in the service at all, write to us and we will remove you, and we will not need you to have an account to do it.
Pages published by this service count their own visits. When a page is opened we record the time, which page, which link led there, the browser and system name, the country and city suggested by the network address, and a short scrambled form of that address so a second visit from the same network is not counted twice. The address itself is never stored and the scrambled form cannot be turned back into one. No cookies are set and nothing is shared with an advertising network. These records are kept for 24 months.
Our own website is counted the same way and more sparingly. When you open one of our public pages we record the date, which of our pages it was, the site that linked you to it - its name only, never the full address you came from - any campaign tag on the link, the browser and system name, the country the network suggests, and a scrambled form of your network address. That scrambling uses a random key that is replaced every night and thrown away with the visits it was used on, so it can tell that one person opened two pages today and cannot tell that the same person came back tomorrow. The address itself is never stored. There is no cookie, no script from another company, and nothing is shared with an advertising network. We keep these visits for 60 days and then delete them together with the keys that scrambled them. What is left afterwards is a daily count that names nobody.
If you then create an account, we note that the account came from that day's visit, so we can tell which of our own links and campaigns bring people here. That connection can only be made on the day itself, for the reason above, and what it records is the campaign, not you.
If you leave your email on an artist's page, it is kept for that artist, who can use it to tell you when they release new music. We store the address and the language your browser asked for, so each message arrives in a language you read. Every message carries an unsubscribe link, and your address is removed when you unsubscribe or when the artist's account is closed. An address left before this list existed was used for a single release-day message and is removed within 30 days of it being sent.
Where an artist has featured a public post that mentions them, we store what that platform published: the author's handle, the text, and a link back to the original. Only already-public posts, and only ones the platform's own interface surfaces.
We do not sell personal data, we do not share it with advertising networks, and we do not build profiles across sites. The counting described above happens on pages published by this service and on our own website, and nowhere else - it does not follow you between them, and it cannot follow you beyond them.
Running this service means other companies process some of the data above on our behalf:
You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. Account holders can do the first and the last from inside the service. Everyone else (an editor we hold an address for, a fan who signed up to be told about a release) can write to us and we will act on the address itself, without needing you to have an account.
Deleting an account removes what is described in section 1, including any support conversations. Pages already published stay reachable for 90 days afterwards, for the reason set out in the terms, and then come down.
Three things survive it.
The first: once a day we write down how the service as a whole is doing, meaning how many accounts there are, how many were used that day, how many are paying, what the AI bills came to, and how many people visited our own website and which sites and campaigns sent them. Those rows are counts and amounts for a date. They carry no account, no name and no address, nothing that could be traced back to you, and nothing is added to them after an account is deleted.
The second: the record of which member of staff opened or changed your account, described in section 1. It outlives the account on purpose. "Who at Get Heard saw my data" is a question people ask after they have left, and a record that deleted itself on the way out could not answer it. Those rows name the employee and the date, not you. What is left of your account on them is a number that no longer points at anything. They are kept for 24 months and then removed.
The third: the record of a fault in the software, described in section 7. It carries no account and nothing that points at one, and it is removed 30 days after the fault last happened.
When something in this service breaks, it writes down what broke, so the fault can be found and fixed. That record says which kind of failure it was, which part of the service it happened in, the error message, and the position in our own code that produced it. If the app running in your browser is what failed, the browser sends the same three things.
These records are not attached to an account. There is no account number and no user in them, and the part that says where it happened is the shape of the address rather than the address itself, so it cannot be traced to one release, one page or one person. The message is cleaned before it is stored: email addresses, access tokens, file paths, web addresses and long numbers are replaced with markers first.
One record covers every occurrence of the same fault, with a count. It is removed 30 days after the last time that fault happened. Because these records name nobody, deleting an account does not change them, and nothing in them described you in the first place.
A request we refuse is not a failure and is not recorded. Asking for a release that does not exist, or running out of the AI budget your plan includes, is the service working.
Sometimes a police force, a court or a government body asks a company for data about the people who use it.
We check that it is lawful before we answer it: that it comes from an authority entitled to make it, that it was served the way the law requires, and that what it asks for is something that law actually reaches. A request that fails those tests is refused, and one we believe to be unlawful is challenged rather than quietly complied with.
Where we do have to answer, we give the least that answers it. A request naming one account gets that account and not the workspace around it; a question that one record answers gets that record and not the account.
We write down every request: who asked, what they asked for, the legal basis they gave, what we decided and why, who decided it, and what we handed over. That record exists so we can account for what we did.
Unless the law forbids us from saying so, we will tell you that your data was asked for.
If this policy changes, the new version appears here with a new effective date, and account holders are told before a change that materially affects them takes effect.