Pacer is an AI-native operating system for artists, labels and music teams. This policy explains what we collect when you use Pacer at pacermusic.co, why we collect it, who we share it with, and what you can ask us to do about it.
For the personal data described here, Pacer is the controller. There is one important exception, covered in section 8: for the contact details you upload or collect about fans, curators and creators, you are the controller and we act as your processor.
Account details. Depending on how you sign in, this is your email address, name, profile image, a KOR-ID identifier, or a wallet address. If you sign in with an email and password, we store a hash of that password, never the password itself.
How you found us. When you first arrive we read the UTM parameters, referrer and landing path from the URL, and store them against your account once you sign up. This is used only for our own aggregate reporting on where sign-ups come from. It is never shown to you, to other users, or to anyone outside Pacer.
Connected accounts. If you connect Spotify, TikTok or Instagram, we store the access and refresh tokens those platforms issue, encrypted at rest, along with the account identifier, username and granted scopes. We use them to read the metrics and catalogue data the platform exposes. Disconnecting an account in Settings deletes the stored tokens.
What you create in Pacer. Goals, tasks, releases, content drafts, schedules, creative assets, your context files, your persona, retrospectives, notes and chat messages with the agents.
Audit data before you have an account. The free release audit runs without sign-up. When it does, we store the profile links you entered and the report we generated, so that the report still exists if you come back or decide to create an account and claim it. Until it is claimed, that record is not linked to any user.
Contacts you bring with you. Fans, outreach contacts, curators and the creators surfaced by Repost Radar: names, email addresses, phone numbers, social handles, and any notes you add. See section 8.
Usage. A throttled last-active timestamp (updated at most once an hour), product events describing which features are used, and standard server logs. We use these to understand whether the product works, not to build a profile of you for anyone else.
Billing. Your subscription status and the Stripe customer and subscription identifiers. Card details are entered on Stripe's own checkout and never reach Pacer's servers.
Telegram. If you link Telegram for alerts, we store the chat identifier and an encrypted bot token.
- To run the product: generate your audit, plan your week, draft content and outreach, and keep your numbers current.
- To give the agents the context they plan from. Your context files, goals and metrics are deliberately fed into agent prompts; that is the feature.
- To send you the emails the service depends on: verification, password resets, alerts you have turned on.
- To take payment and manage your subscription.
- To keep the service secure, debug failures, and enforce rate limits and abuse controls.
- To understand, in aggregate, which parts of Pacer are used and which are not.
Pacer's agents run on large language models operated by third-party AI providers. To answer a request, the relevant slice of your data (your context files, goals, recent metrics, the release you are working on, the message you typed) is sent to one of those providers as part of the prompt.
We use the commercial API tiers of these services, under which the provider does not use inputs or outputs to train its models. We do not sell your data, and we do not use your content to train models of our own.
Model output is generated text. It can be wrong, out of date, or confidently mistaken, and it is not professional advice. What you do with it is your decision; see the Terms of Service.
When you send outreach from Pacer, the message can include a tracking pixel that records when it is opened, and links that pass through our server so we can record a click before redirecting to the destination. That is how the reply and engagement figures on the Outreach pages are produced.
You are the sender of that email. You are responsible for having a lawful basis to contact the recipient, for honouring unsubscribe and suppression requests, and for complying with the anti-spam and data protection law that applies to you.
The Fan CRM, Outreach and Repost Radar features hold personal data about third parties: fans who signed up to your list, playlist curators, and TikTok creators who used your sound, including contact email addresses found from public sources.
For that data you are the controller and Pacer is your processor. We process it on your instructions, to provide the features you are using. You are responsible for having a lawful basis to hold and use it, and for responding to requests from those people. If one of them contacts us directly, we will refer them to you and help you respond.
Deleting a contact in Pacer deletes it from our database. Deleting your account deletes the whole set.
- Account and product data: for as long as your account exists.
- Unclaimed audits: kept so you can come back to the report; delete on request.
- Sessions: seven days, then expired and cleared.
- OAuth tokens: until you disconnect the account or delete your account.
- Billing records: retained as long as tax and accounting law requires, which is longer than your account.
- Server logs: a short operational window, then rotated out.
Traffic is served over TLS. Platform access tokens and Telegram bot tokens are encrypted at rest with a key held outside the database. Passwords, where used, are stored only as hashes. Publicly shareable links (release asset kits, outreach tracking) are signed so they cannot be guessed or altered.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as the law requires.
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to how we use it, take it elsewhere in a portable format, and withdraw consent you have given.
Much of this you can do yourself: your context, persona, goals, contacts and content are all editable and deletable in the app, and connected accounts can be disconnected in Settings.
Account deletion is not yet self-serve. Email hello@pacermusic.co and we will delete your account and its data. We aim to respond to any request within 30 days. If you think we have handled your data badly, you may also complain to your local data protection authority.
Pacer and the providers listed in section 5 operate in several countries, so your data may be processed outside the country you live in. Where that happens we rely on the transfer safeguards those providers offer, such as standard contractual clauses.
Pacer is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, email hello@pacermusic.co and we will delete it.
We will update this page when what we do changes, and move the "last updated" date at the top. If a change materially affects your rights, we will tell you in the app or by email rather than relying on you noticing.
Privacy questions and data requests: hello@pacermusic.co. Anything else: hello@pacermusic.co.


