Legal
Privacy Policy
Effective October 10, 2026 · Last updated October 10, 2026
Pending final legal review. This document describes how SONRYZE Amplify works today. Sections marked for legal review may change before final adoption.
This policy explains what information SONRYZE Amplify collects, how we use and protect it, and the choices you have.
01Who we are
SONRYZE Amplify ("Amplify", "we", "us") is a software-as-a-service platform for planning and promoting music releases. Amplify is operated by Avyrox Solutions LLC, a Delaware limited liability company operating from Mentor, Ohio, United States, which is responsible for the personal information processed through the service. Amplify is offered under the SONRYZE Records brand.
Questions about this policy can be sent to socials@sonryzerecords.com.
02Information we collect
Account information. Your email address, a password (stored only as a secure hash by our authentication provider) or, if you sign in with Google, your Google account email and basic profile details. You may add a display name and profile image.
Workspace and business information. Workspace name and type, team members and their roles (owner, admin, member), and the subscription plan assigned to the workspace.
Content you provide. Artist profiles (names, genres, biographies, brand voice notes, images), releases and tracks, streaming links, campaign details, post drafts, schedules, and media files you upload (images and videos), including any rights notes you record.
Connected social account information. When an owner or admin connects a social account, we store the account's handle or name, the platform's account identifier, granted permissions, connection status, and the credentials or authorization tokens needed to publish on that account's behalf.
Publishing records. Scheduled posts, publishing attempts, outcomes, links to published posts, and an activity history of publishing actions.
Usage and technical information. Records of AI generation requests (time, workspace, type, and token counts), activity logs of changes inside a workspace, and standard server and security logs (such as IP address, browser type and request times) kept by our hosting providers.
Contact form messages. Your name, email address, and message when you use our contact form.
03How we use information
- To create and secure your account and authenticate you.
- To operate workspaces, enforce roles and plan limits, and keep each workspace's data separate.
- To generate campaign strategies and post drafts at your request using AI.
- To schedule and publish content that a workspace has approved, to the accounts it has connected and authorized.
- To store and display your media through private, time-limited links.
- To maintain security, prevent abuse, troubleshoot problems, and keep audit records.
- To respond to your messages and requests.
- To comply with legal obligations.
04AI processing
When you ask Amplify to generate a strategy or posts, we send the relevant campaign details to an AI model and return drafts to your workspace. This can include artist names and profile details, brand voice notes, release and campaign information, and your instructions. AI requests are made from our servers, never directly from your browser, and only include data from the workspace making the request.
AI requests are routed through the Lovable AI Gateway to third-party large-language-model providers (currently OpenAI models). We do not use your content to train our own models. Providers process the request to return a result under their own terms.
AI output is a draft. It may be inaccurate, and it is not published unless a workspace member approves it.
05Social platform integrations
Bluesky — operational. Workspace owners and admins can connect a Bluesky account using a Bluesky app password. Amplify uses Bluesky's official API to publish approved posts and images at their scheduled time.
Facebook Pages, Instagram professional accounts and Threads — planned, not yet available. We are preparing integrations through Meta's official APIs. They are not operational and require Meta's approval before launch. When available, an owner or admin will authorize access through Meta's own login screen, and Amplify will request only the permissions needed to list the accounts you choose to connect and to publish content you approve. We will use data received from Meta only to provide these features, will not sell it, and will not use it for advertising or for profiling.
TikTok and YouTube — planned, not yet available. These require platform approval. Reddit is supported only as drafts you copy and post yourself.
Until an integration is operational, you can still prepare posts in Amplify and publish them manually on the platform.
06Workspace separation and credential protection
- Every workspace's data is isolated. Database rules check workspace membership on each request, so members of one workspace cannot read or change another's data.
- Only workspace owners and admins can connect or disconnect social accounts, enable automatic publishing, or confirm media rights.
- Social credentials and authorization tokens are encrypted (AES-GCM) before storage, kept in a table that browsers and users cannot access, and decrypted only on our servers at the moment of publishing. They are never shown back to you or sent to your browser.
- Automatic publishing is off by default and must be explicitly enabled by a workspace owner or admin. Every post is re-checked for approval, media rights and account status immediately before it is published.
- Uploaded media is stored in private storage and shown only through short-lived signed links.
08Retention and deletion
We keep information for as long as your account or workspace is active, or as needed to provide the service, unless you ask us to delete it. We have not yet set fixed retention periods for every category of data. Specifically:
- Disconnecting a social account immediately deletes its stored credentials and cancels its queued posts. A record that the account was connected, and the history of posts already published, remain for your workspace's records.
- Deleting content such as artists, campaigns, drafts or media in the app removes it from the workspace.
- Sign-in authorization records used for connecting Meta accounts (when available) expire after at most 15 minutes and are periodically purged.
- Account or workspace deletion is currently handled on request by email to socials@sonryzerecords.com.
- Security logs and backups kept by our hosting providers follow those providers' retention schedules.
For legal review: Specific retention periods for logs, activity history and published-post records are to be defined.
09Disconnecting accounts and revoking access
Workspace owners and admins can disconnect any connected account from Social Accounts in Amplify at any time.
You can also revoke access directly with the platform: for Bluesky, delete the app password under Settings → Privacy and Security → App Passwords. When Meta integrations launch, you will be able to remove Amplify from your Facebook settings (Apps and Websites) or your Instagram and Threads app settings. When Meta notifies us that you removed Amplify or requested deletion, we will delete the related credentials, disconnect the accounts, and provide a confirmation code you can use to check the status of your request.
10Your privacy rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. You can update much of your information directly in Amplify. For any other request, email socials@sonryzerecords.com from the address on your account. We will verify your identity before acting and respond within the time required by applicable law. You may also contact your local data protection authority.
11Security
We use encryption in transit (HTTPS), encryption of stored social credentials, workspace-level access rules enforced by the database, role-based permissions, and server-side checks before publishing. No system is completely secure, and we cannot guarantee the absolute security of your information. Please use a strong password and keep your sign-in details private. If we learn of a security incident affecting your information, we will notify you as required by law.
13Children's privacy
Amplify is a business tool and is not directed to children. You must be at least 18 years old, or the age of majority where you live, to create an account. We do not knowingly collect personal information from children under 13 (or under 16 where applicable). If you believe a child has provided us information, contact socials@sonryzerecords.com and we will delete it.
14International users
Avyrox Solutions LLC is based in the United States, and our service providers may process information in the United States and other countries. Data protection laws there may differ from those where you live. Where required, we rely on appropriate safeguards offered by our providers for international transfers.
For legal review: Confirm applicable jurisdictions (e.g. GDPR/UK GDPR, CCPA/CPRA) and the transfer mechanisms to cite.
15Changes to this policy
We may update this policy as Amplify changes, including when new integrations launch. We will post the updated version on this page with a new effective date and, for material changes, notify account holders by email or in the app.
16Contact us
Avyrox Solutions LLC, operator of SONRYZE Amplify
Mentor, Ohio, United States
Email: socials@sonryzerecords.com
