Privacy Policy
Last updated: 20 September 2026
Artist Build Pty Ltd (ABN 66 701 987 895) operates artist.build. This policy explains how we handle personal information when you visit the website, use a workspace or access an artist portal. Contact us at luke@belikechildren.com about privacy, access, correction or a complaint.
Information we handle
We collect account and workspace details such as names, email addresses, roles and membership information. Customers may upload artist and business contact details, deals, contracts, invoices, statements, payment information, messages and files. We also process support correspondence, subscription and transaction references, usage records and technical information about the website and service.
Information comes from you, your workspace administrators and authorised users, connected services you choose to enable, and research sources used by enabled features. A workspace administrator controls which internal users and artists can access its records. If an agency gives us your information, you can contact that agency or contact us for help identifying the relevant workspace.
Why we use it
We use information to provide and secure the service, manage access and subscriptions, run features and automations requested by customers, respond to support requests, diagnose problems, understand service usage and meet applicable obligations. We do not sell customer personal information.
You can choose not to provide optional information or connect an external service. Features that need that information may then be unavailable. Account and payment details needed to supply a paid service cannot be omitted.
AI and connected services
When you use Scooter or another AI feature, relevant prompts and workspace material may be sent to the AI provider needed to perform that task. This can include text from selected contracts, messages or records. AI results can be inaccurate; check them before relying on them or sending them to someone else. Do not upload information you are not authorised to share.
Optional connections, such as Gmail and Xero, process information needed for the connection's enabled functions. Disconnecting a service stops future use of that connection. For most connections, records already imported into your workspace are not automatically erased. Google connections are different and are described in the next section. Research features may query external search services. Lusha contact enrichment is currently disabled.
Google user data
If you connect a Google account, we request only the access the connected feature needs:
- Gmail read access (
gmail.readonly), so Scooter can read messages in the mailbox you connect and identify briefs, replies and payment evidence relating to your deals. - Gmail send access (
gmail.send), so outreach and replies you approve are sent from your own mailbox rather than from us. - Your Google email address (
userinfo.email), so we can show which mailbox is connected.
If we add a calendar connection, this section will be updated before it is switched on, and we will request read-only access to calendar events only.
Limited Use. artist.build's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We use Google user data only to provide and improve the features described above, which you can see in the product.
- We do not sell Google user data, and we do not use it for advertising.
- We do not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models. Message and calendar text is sent to our AI provider to perform the specific task you asked for, under terms that do not permit training on it, and is not used to train any model of ours or theirs.
- Human access is restricted. Our staff do not read your mail or calendar, except where you have given specific permission, where it is necessary to investigate a fault or a security incident you or we have identified, or where the law requires it.
Disconnecting in artist.build. Disconnecting deletes our stored Google credentials, unaccepted mailbox suggestions, their notifications and evidence links, mailbox scan state, and thread follow-up tracking. For accepted suggestions, we redact the message content and message identifiers held on the suggestion itself. We also clear mailbox and message identifiers on linked agreement artefact records. If another team member or a separate delegated connection still authorises the same mailbox, that connection can continue processing new messages.
Disconnecting does not erase every copy of information obtained from Google. Information retained in workspace records can include email bodies, subjects, senders and message identifiers copied into inbound email logs, contract text and agreement documents when a suggestion was accepted, as well as related assistant conversations, proposals and activity records. These records remain subject to the Google API Services User Data Policy, including Limited Use; accepting a suggestion does not remove those obligations. Contact us to request deletion of Google-derived information retained in those records. We will verify the scope of the request and explain any retention obligations.
You can also revoke access through your Google account permissions. Google then prevents further access under that grant. Revoking at Google does not notify artist.build to delete previously stored information. To initiate the in-app cleanup, also disconnect in artist.build; contact us for deletion of retained workspace copies. A connection error or an expired token does not trigger deletion, because it does not establish that you asked us to delete your records.
Backup copies may retain deleted information until the relevant backup retention period ends.
Who receives information
We use service providers for hosting and storage (including Vercel and Neon), authentication (Clerk), subscription payments (Stripe), transactional email (Resend), AI processing (including Anthropic), search (Brave) error diagnostics (Sentry) and product analytics (PostHog). Payment card details entered into Stripe are handled by Stripe; we store subscription and payment references rather than full card numbers.
We may disclose information to people you authorise, to professional advisers where necessary, or where required or permitted by law. Shared company reviews are intended to be visible across the artist.build network. Review comments should not contain confidential deal details or personal information you do not have permission to publish. Private agency notes, billing preferences, deals and contacts are not part of that shared review display.
Overseas processing
Some providers process or store information outside Australia, including in the United States. Our current database region is Northern Virginia, United States. Other processing locations depend on the provider and connection you use. Contact us if you need to assess a particular data-location requirement before uploading information.
Cookies and analytics
We use cookies and similar technologies for sign-in, security and product analytics. Analytics may include account identifiers, workspace information, pages visited and feature events. Session recording is disabled in our application. Error diagnostics are filtered to omit request bodies, credentials, AI prompts and personal details. You can manage cookies in your browser, although blocking authentication cookies may prevent sign-in.
Storage and retention
We use access controls and operational safeguards to protect information, but no online service is completely secure. We retain workspace records while needed to provide the service and handle support, legal, accounting and security needs. Cancelling a subscription does not itself delete the workspace. Contact us to request an export or deletion; we will explain any information we need to retain and the practical effect on shared workspace records. Backup copies may remain until the relevant backup retention period ends.
Access, correction and complaints
Contact luke@belikechildren.com to request access or correction, ask about a deletion request or raise a privacy concern. We may need to verify your identity and authority before changing or disclosing workspace information. We will acknowledge your request and explain the next steps. If we cannot resolve a privacy complaint, you may contact the Office of the Australian Information Commissioner.
Changes
We may update this policy as the service changes. The current version and its date will appear here. We will communicate material changes affecting how customer information is handled.
