Last updated: 30 April 2026
Royalti is operated by AJL Technologies Ltd, a company registered in England and Wales ("Royalti", "we", "our", "us"). This policy explains what data we collect, how we use it, how long we keep it, and what rights you have. If anything is unclear, email support@royaltiapp.com.
When you create an account: your name, email address, and role (artist or manager). Authentication is handled by Clerk; we never see or store your password. If you sign in with Apple or Google, we receive only your name and email.
The core of the product. This includes:
Whether you have an active subscription or trial, refreshed on each app open from Apple's StoreKit. We never see your credit card; Apple handles all billing.
We collect anonymous usage events (e.g. "a user opened the app", "a user confirmed a parsed statement"). These events contain no user identifier — they are stored as aggregate counters only. They cannot be linked back to your account.
We apply automatic expiry timers to anything sensitive that isn't part of your active product data. After the timer runs out, the data is permanently deleted by our database — we do not need to take any action for this to happen.
| Data | Retention |
|---|---|
| Source PDFs / images / raw email bodies | 30 days, then auto-deleted |
| Parsed but unconfirmed statements | 90 days, then auto-deleted |
| Confirmed deals (your dashboard) | Until you delete them or close your account |
| Bank link tokens | Until you disconnect the bank |
| Subscription state | 90 days, refreshed on each app open |
| Anonymous aggregate counters | Indefinite (no identity attached) |
We compute industry-level statistics — for example, the median payment from a major royalty source, or the distribution of deal types across users. This dataset is built from fully anonymised counters stored in a separate database namespace that has never seen and never will see a user identifier. It cannot be reverse-engineered to reveal individual users or accounts.
We may publish or share these aggregate insights as part of industry reports, blog posts, or commercial partnerships. If you would prefer your account's confirmed deals not to contribute even to anonymised aggregate counters, email us and we'll exclude you.
We use these vendors to operate the product. Each receives only the minimum data needed for its role.
We do not sell, rent, or trade your personal information. We do not share your individual royalty figures with labels, publishers, PROs, distributors, or any third party.
Data flows only to:
All connections to Royalti are encrypted in transit (HTTPS / TLS). API endpoints require authenticated sessions, are rate-limited per user, and validate every input. Bank credentials are never transmitted to or stored on our servers — Plaid and Yapily handle authentication directly via OAuth flows. Internal admin access is restricted by an explicit email allow-list.
Regardless of where you live, you can:
Users in the EU, UK, or California have additional rights under GDPR / UK-GDPR / CCPA, including the right to data portability and to lodge a complaint with a supervisory authority. We honour all such requests.
Royalti is not directed at and not intended for use by anyone under 18. We do not knowingly collect data from minors.
We will update this page if our data practices change. The "Last updated" date at the top will reflect the latest revision. Material changes will be communicated in-app.
Questions, requests, complaints: support@royaltiapp.com. We aim to respond within 7 days.