מראה
↑↓ מעבר⏎ לבחורesc לסגור
YOIN
Privacy PolicyTerms of Service
עבריתEnglish

Privacy Policy

This document explains what information YOIN collects, why, who it is shared with, how long it is kept, and what your rights are. It describes what the system actually does today.

Last updated19 September 2026

Contents

  1. 1Who we are
  2. 2Who this covers
  3. 3What we collect
  4. 4Legal basis
  5. 5How we use information
  6. 6Artificial intelligence
  7. 7Who we share information with
  8. 8International transfers
  9. 9Security
  10. 10Security incidents
  11. 11How long we keep information
  12. 12Your rights
  13. 13If you do not provide information
  14. 14Cookies and browser storage
  15. 15Minors
  16. 16Information you enter about other people
  17. 17Changes to this document
  18. 18Contact and complaints

1Who we are#

YOIN is a management system for musicians, available at habama.shirahouminer.com. It is operated by Shira Houminer, a licensed dealer (osek murshe) in Israel. In this document, “we” means the operator of YOIN, and “the service” means the website and the system.

For any privacy question, request or complaint, write to shirahouminer@gmail.com.

For your account information, the operator is the database owner under the Israeli Privacy Protection Law, 5741-1981. For information that users enter about other people, such as their contacts, the service holds and processes it on the user’s behalf. See Information you enter about other people.

2Who this covers#

  • People who open a YOIN account: artists, managers, and anyone who works inside an artist account.
  • People who open a public page an artist sent or published: an EPK, a presave page, a Smartlink, a private listening link, or a split confirmation page.
  • People whose information a user entered, such as contacts and rights holders.

3What we collect#

Your account

  • First name, last name, email address and password. The password is stored by our sign-in provider only as a hash, and we cannot read it.
  • When you choose a password, it is checked against a database of previously leaked passwords (Have I Been Pwned). Only a short piece of a hash of the password is sent for that check, never the password itself.
  • Sign in with Google, if you choose it: the name, email address and profile picture on your Google account. We request only the three basic permissions, openid email profile. Signing in gives us no access to your Gmail, Drive, Calendar or Google contacts.
  • Connecting Google Calendar, if someone who manages the team chooses it: a separate calendar called YOIN is created in their Google account, and the events in the YOIN calendar are written to it: title, time, place and a link back to YOIN. Guests and notes are not sent. The permission is calendar.app.created, which allows creating a calendar and touching only the events in it, so your other Google calendars are not read or changed. We keep the email of the connected Google account, the calendar ID, and the token that allows writing to it, encrypted. Disconnecting deletes the YOIN calendar from Google and revokes the permission.
  • Technical sign-in data kept by our sign-in provider: IP address, browser type and sign-in times. It is used to keep your account secure.
  • Preferences: your color set (saved in your account and in a cookie), your language and territory (in cookies), and your role in each artist account (owner, manager, label, collaborator and so on).
  • Team invitations: whoever creates an invitation link can write who it is for (free text, up to 80 characters). We also keep the role, who created the link, when, until when it is valid, and who accepted it and when. The link itself is not stored, only a one-way fingerprint of it. The service does not send it: whoever created it copies it and sends it themselves.

What you enter about the artist and the work

  • The artist profile: stage name, bio, city, genre, links, photos, logo, rider and a contact email.
  • Works, recordings, releases, ISRC and UPC codes, audio versions and notes on them.
  • Credits and rights splits, including IPI numbers and memberships in societies such as ACUM.
  • Royalties, payouts, costs and partners.
  • Shows, venues, deals, guest lists, calendar, tasks and notes.
  • Files you upload: covers, photos and logos, masters and versions, and contracts.
  • The content of public pages: the EPK and press quotes, presave pages, the Smartlink, the design chosen for each page, and the social profiles and contact email the artist chose to show on them.
  • Streaming reports you import, from a distributor or from Spotify for Artists: streams, listeners and revenue by song, period, platform and country, as they appear in the file. The file name and a fingerprint of the file are kept too, so the same file is not imported twice.
  • Distribution packages, and checks of codes against stores.

The intake interview

The first time you sign in, the system asks a few questions. You can type or speak, and typed answers are saved as text.

If you choose to speak, transcription is done by your browser’s own speech recognition. In Chrome, the browser sends the audio to Google’s servers to transcribe it, and the screen says so next to the record button. We save the transcribed text. The recording itself is not saved on our servers today.

Information about other people

Users can enter information about other people: contacts (radio editors, journalists, DJs, venue and booking contacts), rights holders and payees, guests and partners. It can include name, organization, role, email, phone, website, IPI number, payment details the user entered, notes and a history of outreach. See Information you enter about other people.

People who open a public page

  • That the page was opened, what was clicked, how many seconds the page stayed open or the audio played, and the type of device (phone or computer).
  • A rough browser signature: a short code computed from the browser language, screen size and time zone. Its only purpose is to keep a refresh from counting as a new visit. It is not unique to a person and does not identify anyone. No IP address is stored with this data.
  • On a presave page: an email address, if you choose to leave it with the artist. It is kept in the artist’s account and is not passed to anyone else. The service does not send emails to it today.
  • On a private listening link: comments on the song and the name written next to them. If the link is password protected, a correct password places a cookie in your browser for twelve hours.
  • A file downloaded from a private link or a promo link can carry an identifier in its file name and in the data inside it (a watermark). The identifier ties that copy to the link or the recipient, so a leaked copy can be traced.
  • On a split confirmation page: the name you typed, when you approved or declined, and anything you wrote when declining.

Security and abuse prevention

To stop repeated attempts, such as many sign-ups or guessing a link password, we keep a counter keyed by a one-way hash of the IP address, made with a secret key. The IP address itself is not stored in the counter. Our hosting and database providers record IP addresses in their server logs for operations and security.

Public information about the artist

When you ask for a scan or a catalog import, the system looks up public information in open music databases (MusicBrainz, Deezer and Apple): release titles, dates, codes, cover art and links. The findings are shown to you for approval before they enter the account.

What we do not collect

There are no payments in the service today, so we do not collect credit card or bank account details, other than payment details a user chooses to enter about royalty payees. There are no advertising cookies, no third-party analytics tools and no social media pixels.

4Legal basis#

  • Consent: opening an account, leaving an email on a presave page, writing a comment or approving a split. You can withdraw consent at any time, from that moment on.
  • Providing the service: storing, showing and processing what you entered, so we can give you the service you signed up for.
  • Legitimate interest: security, preventing abuse, basic open counts for the artist, and improving the service, in a reasonable and proportionate way.
  • Legal obligation: when the law, a competent authority or a court order requires it.

You are under no legal obligation to give us information. Providing it is up to you and depends on your consent. What happens if you do not provide it is set out in If you do not provide information.

5How we use information#

  • To provide the service: show your screens, work out the next step, prepare documents (such as a split sheet or a CWR file) and serve your public pages.
  • To show the artist who opened their pages and what was clicked, without identifying the person.
  • To draft text with AI, only when you ask. See Artificial intelligence.
  • To look up public information in music databases, only when you ask.
  • To secure the service and prevent abuse.
  • To answer requests and give support.
  • To meet our legal obligations.

We do not sell personal information, we do not use it for advertising, and we do not build marketing profiles from it. Information received from your Google account is used only to sign you in, identify your account, and, if you connected Google Calendar, write the YOIN calendar there. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6Artificial intelligence#

Some tools use Anthropic’s Claude model: for example, drafting a bio from your interview answers, tidying a transcript, explaining why a venue was suggested, or drafting a pitch to radio or press. This happens only when you ask.

Only what the task needs is sent to the model: the relevant text, and facts the system already holds (such as the venue name, city, capacity and distance). What the model writes comes back as a draft, and it is saved only after you approve it. Read every draft, because it can be wrong.

For a pitch draft, the song details and your short bio are sent, and if you chose a recipient, their name and organisation as stored in your contacts, so the pitch can address them. Contacts’ email addresses and phone numbers are not sent.

For each request we log the task type and the number of tokens used, without the content. Under Anthropic’s commercial terms, data sent through its API is not used to train its models.

7Who we share information with#

Inside the artist account

Everyone added to an artist account sees what their role allows. For example, a royalties-only role sees only its own share of the royalties: its shares in works and recordings, the statements for those songs and its own payments, and not other people’s shares. The owner or management links that person to their name in the split. Contracts are kept in a vault that only the owner and management can open. The owner and management also see the name and email address of everyone on the team, and the invitations that were created. Anyone who can see the tasks also sees the names of the rest of the team, so tasks can be assigned to them, and where there is no name, the part of the email address before the @.

On public pages

Whatever an artist chooses to publish on an EPK, a presave page, a Smartlink or a listening link is visible to anyone who has the link. On a split confirmation page, the person who received the link sees the title of the work, the names of the rights holders and each one’s percentage. Emails and contact details are not shown there.

Service providers

We rely on providers that process information for us, only to run the service:

  • Supabase: the database, file storage and sign-in. Servers in the European Union (Frankfurt, Germany).
  • Vercel: website hosting, running the code and scheduled tasks. The code runs in the European Union (Frankfurt, Germany), and the network that delivers the pages is in the United States and other locations worldwide.
  • Anthropic: the Claude AI model, only when you ask for a draft. United States.
  • Google: Sign in with Google and Google Calendar, if you choose them. United States.
  • Public music databases (Apple, Deezer and MusicBrainz), and link previews from Spotify and YouTube: only release titles, codes and links are sent to them, when you ask for a scan, an import or a code check.

Built but not active

Connections to Spotify and YouTube accounts exist in the code but are not available today. Sending email from the system (for example, pitches to radio through the email provider Resend) is not active either, and no email is sent on behalf of users today. Before we turn any of these on, we will update this document.

When the law requires it

We will disclose information if the law, a competent authority or a court order requires it, or when it is needed to protect rights, safety or property.

If the service moves to another entity, for example in a sale or a merger, the information will move with it under the same commitments, and we will give notice in advance.

8International transfers#

Information is stored and processed outside Israel: the database is in the European Union, and some providers are in the United States. Transfers to the European Union go to countries whose data protection law is recognized in Israel. Transfers to the United States rely on the providers’ contractual commitments to protect and secure the data, in line with the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001.

9Security#

  • All traffic is encrypted (HTTPS).
  • Row-level permissions in the database: each user sees only the artist accounts they belong to, and only what their role allows.
  • Audio files and contracts sit in private storage and open through signed links that expire after a short time.
  • Images for public pages (covers, photos, logos and riders) sit in storage that anyone with the exact file address can open. The address contains a random part, and the files cannot be listed. So do not upload anything there that needs to stay secret.
  • Tokens for external connections are encrypted (AES-256-GCM), and the key is kept separately from the database.
  • Passwords for private listening links are stored only as a hash (bcrypt).
  • Rate limits on sign-up, on password guessing and on actions on public pages, and security headers on every page.

No system is completely secure. We follow the Privacy Protection (Data Security) Regulations, 5777-2017, and review our security periodically.

10Security incidents#

If a security incident affects personal information, we will act at once to stop it and limit the harm. We will report to the Privacy Protection Authority as the regulations require, and email the people affected when the law requires it or the Authority instructs us to. The notice will explain what happened, what information was exposed and what was done.

11How long we keep information#

An automatic cleanup runs once a day and removes whatever has passed its period. Until 18 September 2026 it did not run, and the rows below were kept without limit.

  • The account, artist data and files: while the account is active. Deleting from settings removes them immediately, and a request by email is handled within 30 days.
  • Opens, clicks and seconds listened on public pages: 24 months, and sooner if the link or the artist account is deleted.
  • Emails left on presave pages, and comments on listening links: while the page, the work or the artist account exists.
  • The results of background jobs, including the export file behind "download a copy of everything": 30 days after the job finished.
  • The AI usage log (task type and token count, no content): one year.
  • Rate limit counters: a hash only, not linked to an account or a person, and deleted after one day.
  • A record of an account deletion: the date, the internal identifiers, and how many rows and files were deleted. No name, no email and no content. It is kept so we can show the deletion was carried out, and it is not deleted with the account.
  • Team invitations, including what was written on them: as long as the artist account exists. An invitation is also deleted when whoever created it deletes their own account. An invitation link expires after 7 days, and its row stays as a record of what happened.
  • Backups: our database provider keeps automatic backups for a limited period. Deleted information can remain in a backup until that backup is replaced.
  • Information the law requires us to keep is kept for the period the law sets.
  • Server logs and sign-in logs at our providers: according to each provider’s retention policy.

12Your rights#

  • Access: receive the information held about you.
  • Correction: ask to correct information that is wrong, incomplete or out of date. You can correct most of it yourself in the screens.
  • Deletion: in settings, under "My data", you can delete the account yourself, and the deletion happens straight away. An account that owns no artist, such as that of someone who joined a team by invitation, is deleted there by itself too, and other people’s artists stay. You can also ask for any deletion by email, and we will handle it within 30 days.
  • Portability: in settings you can download a JSON file with your works, splits, contacts, calendar, pitches and royalties. For a fuller copy, write to us.
  • Objection: object to a particular use of your information, and ask not to receive marketing messages. We send no marketing messages at all today.
  • Withdrawing consent: at any time, from that moment on.

To use any of these rights, write to shirahouminer@gmail.com from the address on your account, or with details that let us find the information. We will reply within 30 days. If we refuse a request, we will explain why, and you may turn to the court under the Privacy Protection Law.

Deletion removes the artist, everything that hangs off it and every file uploaded, and the sign-in account too once you own no artist. What someone already downloaded, a watermarked copy already handed out, and an automatic provider backup until it rolls over, are not in our control. The screen says so before you press.

If an artist entered your information (for example as a contact, a rights holder, or someone who left an email on a presave page), you can contact the artist directly, or contact us and we will help with the request.

13If you do not provide information#

  • Without a name, an email and a password (or Sign in with Google), an account cannot be opened.
  • Everything else is optional. Without it some screens stay empty, and the system says what is missing.
  • Without the sign-in cookies you cannot stay signed in.
  • On a public page, leaving an email, a name or a comment is never required.

14Cookies and browser storage#

The service uses only the cookies and storage it needs to work. There are no advertising cookies, no analytics cookies and no third-party cookies.

CookiePurposeDuration
sb-…-auth-tokenKeeps you signed in. The sb- prefix marks all the sign-in cookies.Until you sign out, and at most 400 days
yoin.themeThe color set you chose.One year
habama.langThe language of the system.One year
habama.territoryYour territory, which sets dates and currency.One year
yoin_pass_…Set after a correct password on a private listening link. Scripts on the page cannot read it.12 hours
oauth_state oauth_verifier oauth_backOnly while connecting an external account, such as Google Calendar.10 minutes

Local storage in your browser

KeyPurposeDuration
habama.coached.…That you have already seen the short guide on a given screen.Until you clear your browser
yoin.noteNameThe name you wrote next to a comment on a private listening link, so you do not have to type it again.Until you clear your browser

You can delete cookies and local storage in your browser settings. Deleting the sign-in cookies signs you out.

15Minors#

The service is meant for people aged 16 and over. People between 16 and 18 need the consent of a parent or guardian. We do not knowingly collect information about anyone under 16, and if we learn that we have, we will delete it.

16Information you enter about other people#

If you enter information about other people (contacts, rights holders, payees, guests and partners), you are responsible for it. That means you have a lawful basis to hold it, for example professional contact details that were published or given to you; it is accurate; it is deleted once it is no longer needed; and people are notified when the law requires it.

For this information we act on your behalf: we store and display it, and we do not use it for any purpose of our own. We do not contact these people, and we do not sell or pass on their details.

17Changes to this document#

When the service changes, this document is updated and the date at the top changes. We will give advance notice of any material change, in the system or by email, before it takes effect.

18Contact and complaints#

For any question, request or complaint: shirahouminer@gmail.com.

If your request is not resolved, you can contact the Privacy Protection Authority at Israel’s Ministry of Justice.

Questions about this document, or a request about your information: shirahouminer@gmail.com

Terms of Service

This document is reviewed periodically and updated when the service changes.