Privacy policy.
Last updated 4 Jul 2026
Mutism is an audience-intelligence tool for booking agents and the artists they represent. This policy explains what data we collect, why we collect it, and the rights you have over it. We have tried to write it the way we would want to read it.
Who we are
The data controller is Mutism, operated by Jack Murphy as a sole proprietor in the United States. The fastest way to reach us about anything in this policy is x@mutism.us — it reaches a human. A postal address is available on request.
What we collect
Account data. Your email address (used for magic-link sign-in), an optional display name, and session cookies that keep you signed in.
Connected accounts.If you or your artist connect SoundCloud or Instagram, we store the account identifier and access tokens needed to read from those services. SoundCloud verifies an artist's identity when they claim their profile, and is then read periodically for the account's own profile and track statistics. Instagram is used to read aggregated audience insights.
Artist performance data. Public event history (dates, venues, cities, lineups) from sources such as Resident Advisor. This is information about public professional activity.
Audience statistics.City-level, aggregated audience numbers — from our licensed data partner Chartmetric, and, where an artist connects their own Instagram, from Meta's Instagram API (which only ever provides aggregates). For a connected SoundCloud account, we read the account's public follower list to count followers per city, then keep only those aggregated counts — we do not store profiles of, or any other information about, individual followers or listeners.
Billing data. Payments are handled by Stripe. We store your subscription status and Stripe customer reference; we never see or store card numbers.
Usage data. Product events (pages viewed, features used) via OpenPanel, and error reports via Sentry, so we can fix what breaks.
Why we collect it, and on what legal basis
To provide the service — accounts, rosters, artist data, billing. Basis: performance of a contract (GDPR Art. 6(1)(b)).
To verify artist consent.An artist's data is only unlocked after the artist themselves connects their SoundCloud to confirm the claim. Basis: consent (Art. 6(1)(a)), which can be withdrawn at any time by disconnecting or contacting us.
To read Instagram audience insights— only for accounts that explicitly connect via Instagram's own authorisation flow. Basis: consent (Art. 6(1)(a)).
To improve the product and keep it secure — usage analytics, error monitoring, abuse prevention. Basis: legitimate interests (Art. 6(1)(f)); we use aggregated views wherever possible.
To meet legal obligations — tax and accounting records tied to billing. Basis: legal obligation (Art. 6(1)(c)).
We do not sell personal data, run advertising, or use automated decision-making that produces legal or similarly significant effects about you.
If you're an artist
Mutism processes information about your public professional life — where you have played, and aggregated statistics about where your audience is. Your agent can request to add you, but nothing about you is shown to them until you confirm the claim yourself. You can ask us at any time what we hold about you, ask us to correct it, or ask us to remove you entirely — see your rights below.
Who we share data with
We use a small set of service providers to run Mutism, each bound by a data-processing agreement: Vercel (hosting), Neon (database), Stripe (payments), Resend (transactional email), Mapbox (geocoding — city names only, never personal data), Chartmetric (licensed audience statistics), Meta (Instagram API, for accounts you connect), OpenPanel (product analytics), and Sentry (error monitoring). We share only what each provider needs to do its job. We never sell or rent personal data.
International transfers
Some of our providers process data in the United States. Where data leaves the EU/EEA or UK, transfers rely on the EU–US Data Privacy Framework or Standard Contractual Clauses, as applicable to each provider.
How long we keep things
Account and roster data: for as long as your account is active, and deleted on request. Access tokens: until you disconnect the account or your account is deleted. Billing records: as long as tax law requires. Aggregated audience statistics tied to an artist are deleted when the artist is removed. Error logs and analytics events age out on short rolling windows.
Your rights
Under the GDPR you can ask us for access to your data, correction, deletion, a portable copy, restriction of processing, or object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time without affecting prior processing. Email x@mutism.us and we will respond within one month. You also have the right to lodge a complaint with your local supervisory authority.
Deleting your data
To delete your account and everything tied to it, email x@mutism.us from your account address with the subject “Delete my account”. We will remove your account, connected-service tokens, roster links, and any audience data derived from accounts you connected, within 30 days, and confirm when it is done.
To disconnect Instagram specifically without deleting your account, you can also remove Mutism from your Instagram account's Apps and websites settings; we stop syncing immediately and delete the stored token on our next sync attempt, or on request.
Children
Mutism is a professional tool and not directed at children. We do not knowingly process data of anyone under 16.
Changes to this policy
If we change this policy in a way that matters, we will update the date at the top and, for significant changes, tell account holders by email before the change takes effect.