Last updated: 29 September 2026
Royalti is operated by AJL Technologies Ltd, a company registered in England and Wales ("Royalti", "we", "our", "us"). This policy explains what data we collect, how we use it, how long we keep it, and what rights you have. If anything is unclear, email support@royaltiapp.com.
When you create an account: your name, email address, and role (artist or manager). Authentication is handled by Clerk; we never see or store your password. If you sign in with Apple or Google, we receive only your name and email.
The core of the product. This includes:
Statement files you import in the Catalogue are read on your own device. The file itself is not uploaded — only a per-song summary is: song titles, industry codes (ISWC, ISRC, tunecodes), writer and publisher names, ownership shares, amounts, the statement period, and your society member / CAE number. Statements forwarded by email are read on our servers and produce the same summary.
Song and release details you add, or that we fill in for you: titles, industry codes, credits and splits, versions, release and label details, links and notes. Contacts you add to a song (names, roles, companies, email addresses and phone numbers). Documents you upload (contracts, split sheets, agreements) and media files (masters, stems, artwork, press photos and video).
If the app hits an error, a technical report (the error, the screen it happened on, browser/device type and app version) is sent to Sentry so we can fix it. Collection of personal data is switched off: reports don't include your email, royalty figures or login tokens.
Whether you have an active subscription or trial, refreshed on each app open from Apple's StoreKit. We never see your credit card; Apple handles all billing.
We collect anonymous usage events (e.g. "a user opened the app", "a user confirmed a parsed statement"). These events contain no user identifier — they are stored as aggregate counters only. They cannot be linked back to your account.
We apply automatic expiry timers to anything sensitive that isn't part of your active product data. After the timer runs out, the data is permanently deleted by our database — we do not need to take any action for this to happen.
| Data | Retention |
|---|---|
| Source PDFs / images / raw email bodies | 30 days, then auto-deleted |
| Parsed but unconfirmed statements | 90 days, then auto-deleted |
| Confirmed deals (your dashboard) and contracts | Until you delete them or close your account |
| Catalogue song summaries | Until you remove the import or close your account |
| Vault details, documents and media | Until you delete them or close your account |
| Learned statement layouts (column headings and file name only — no rows or amounts) | 365 days |
| Song lookup and artwork caches | 3–30 days |
| Crash reports | Up to 90 days |
| Bank link tokens | Until you disconnect the bank |
| Subscription state | 90 days, refreshed on each app open |
| Anonymous aggregate counters | Indefinite (no identity attached) |
We compute industry-level statistics — for example, the median payment from a major royalty source, or the distribution of deal types across users. This dataset is built from fully anonymised counters stored in a separate database namespace that has never seen and never will see a user identifier. It cannot be reverse-engineered to reveal individual users or accounts.
We may publish or share these aggregate insights as part of industry reports, blog posts, or commercial partnerships. If you would prefer your account's confirmed deals not to contribute even to anonymised aggregate counters, email us and we'll exclude you.
We use these vendors to operate the product. Each receives only the minimum data needed for its role.
The Royalti Statement Fetch extension for desktop Chrome reads your statements from the royalty portals you sign into yourself (currently PRS for Music, PPL, SoundExchange, Believe Backstage and The Orchard), and statements a payer shares with you as a Google Drive folder (currently Roc Nation Publishing). For a Drive folder it reads only the folder you open and the folders inside it, using your own Google sign-in, and downloads only the statement files and summaries it needs. It never reads the rest of your Drive or changes anything in it. It uses your own logged-in browser session — including, where a portal needs them, the request headers the portal's own page uses — only inside that portal's tab, to list your statements, read the balances the portal shows for them (advances, recoupment and payments — so Royalti can tell money earned from money paid), and download the statement files the portal already offers you. It reads those files in your browser and sends parsed summaries to your own Royalti account. Raw statement files and your portal session never leave your browser. The extension doesn't change anything in your portal account, with one exception: some portals only produce older statements when you ask for them. Some portals only hand out newer statements through their own Download button. For those, the extension also asks once, and after you agree it presses that button in a hidden tab and reads the file instead of saving it to your computer. It never touches your other downloads. In both cases the extension asks your permission once, and only after you agree does it press that portal's own "generate report" or "Download" option for you. You can withdraw that permission at any time in the extension's settings. It never accepts terms, changes settings, or touches payments or payout details on your behalf.
The extension stores only these items, and only in your browser's local storage: your Royalti link token, an activity log of what it has done, sync progress (including reports it asked a portal to build), the portal member each of your Royalti accounts is linked to, any portal permissions you have granted, and your extension settings. On Royalti's own website it runs a small script so the Statements page can show its status and start a sync; that script never receives your link token.
The extension never reads or stores your portal passwords, never tracks your browsing outside the portals it syncs and Royalti's own site, and sends no data to anyone other than your own Royalti account.
We do not sell, rent, or trade your personal information. We do not share your individual royalty figures with labels, publishers, PROs, distributors, or any third party.
Data flows only to:
All connections to Royalti are encrypted in transit (HTTPS / TLS). API endpoints require authenticated sessions, are rate-limited per user, and validate every input. Bank credentials are never transmitted to or stored on our servers — Plaid and Yapily handle authentication directly via OAuth flows. Internal admin access is restricted by an explicit email allow-list.
Contracts and Vault documents are encrypted (AES-256) before they are stored. Vault media files are encrypted in your browser before upload. The keys for all of these are held by Royalti, themselves encrypted under a master key, so that you and the people you share with (such as your manager) can open them on any device. This means files are not end-to-end encrypted: we decrypt them only to show them to you or people you've shared with, when you ask Rex to read one, or if compelled by valid legal process.
Regardless of where you live, you can:
Users in the EU, UK, or California have additional rights under GDPR / UK-GDPR / CCPA, including the right to data portability and to lodge a complaint with a supervisory authority. We honour all such requests.
Royalti is not directed at and not intended for use by anyone under 18. We do not knowingly collect data from minors.
We will update this page if our data practices change. The "Last updated" date at the top will reflect the latest revision. Material changes will be communicated in-app.
Questions, requests, complaints: support@royaltiapp.com. We aim to respond within 7 days.