CatalogArmor LogoCatalogArmor
TermsPrivacy← Home

Privacy Policy

Version 1.0 · Last updated 30 September 2026

CatalogArmor is in a free, invitation-only beta. We will email you before any change to this document takes effect.

The short version

  • We collect what we need to run your account, monitor your artists and deliver your alerts, and nothing more.
  • We do not sell personal data, show ads, or use analytics or tracking cookies.
  • Artist and release data comes from public streaming-platform data.
  • Payments are handled by Paddle, and we never see your card details.
  • You can access, correct, export or delete your data. Email [email protected].

Contents

  1. 1. Who is responsible
  2. 2. Data about our users
  3. 3. Data about people who are not our users
  4. 4. Where the data comes from
  5. 5. Cookies
  6. 6. Who receives personal data
  7. 7. Transfers outside the EEA
  8. 8. Deletion and backups
  9. 9. Security
  10. 10. Your rights
  11. 11. Complaints
  12. 12. Automated decisions
  13. 13. YouTube API Services and Google
  14. 14. Changes to this policy

1. Who is responsible

The controller of your personal data under the EU General Data Protection Regulation (“GDPR”) is the provider of CatalogArmor:

Provider
The operator of CatalogArmor, a Hungarian sole trader (egyéni vállalkozó). Registration in progress — published here before paid plans launch.
Registered seat
Registration in progress — published here before paid plans launch
Registration
Registration in progress — published here before paid plans launch
Email
[email protected]

CatalogArmor is in a free, invitation-only beta. The full legal details above will be completed as soon as registration is finished, and before any paid plan is sold.

We have not appointed a data protection officer, because the law does not require one for our activities. For any privacy question or request, email [email protected].

We plan to transfer the Service to a Hungarian company (Kft.) controlled by the same person (see Terms, section 20). If that happens, the company becomes the controller. We will update this section on the day of the transfer and tell existing users by email in advance.

2. Data about our users

This section covers people who have a CatalogArmor account, or who have been invited to one. Giving us your name, email address and a password (or signing in with Google) is necessary to create an account. Everything else is optional or depends on the features you use.

Your account

What
Name, email address, password (stored only as a salted hash), profile picture, and, if you sign in with Google, your Google account ID.
Why
Create and run your account, let you sign in, and send you essential service emails such as password resets and account notices.
Legal basis
Performance of our contract with you (GDPR Art. 6(1)(b))
How long
While your account exists. See section 8 for what happens after you delete it.

Sign-in security

What
IP address and browser user agent of active sessions; IP address at registration and at your last sign-in; the result of the bot check at sign-up and sign-in; two-factor secrets and backup codes (encrypted).
Why
Keep your account secure, detect account takeover and abuse, and run two-factor authentication.
Legal basis
Our legitimate interest in keeping the Service and accounts secure (GDPR Art. 6(1)(f)); for two-factor authentication, performance of our contract with you (GDPR Art. 6(1)(b))
How long
Sessions expire after 7 days. Registration and last sign-in IP addresses are kept while your account exists. Two-factor data is kept until you turn it off.

Activity log

What
Records of actions in your account and team, such as sign-ins (with IP address and browser), changes to alert settings, whitelist and artist changes, team changes, alert status changes, and your acceptance of these documents. Actions our staff take on your account, such as a password reset they trigger, are also logged.
Why
Show you and your team what happened and when, investigate security incidents, and document how takedown-related features were used.
Legal basis
Performance of our contract with you (GDPR Art. 6(1)(b)) and our legitimate interest in accountability and abuse prevention (GDPR Art. 6(1)(f))
How long
While your account (or, for entries about shared artists, your team) exists. Sign-in and security entries are deleted after 12 months.

Monitoring data

What
The artist profiles you add, your whitelist (release titles, UPCs, notes, dates), alerts (threats) raised for your artists, and the status you give them (for example “whitelisted” or “takedown requested”).
Why
Provide monitoring, alerts, distributor detection and the takedown wizard. Takedown drafts are generated in your browser. We do not store them, and we do not know whether you send them.
Legal basis
Performance of our contract with you (GDPR Art. 6(1)(b))
How long
While your account exists, or until you remove the item.

Alert channels

What
The alert email address, SMS or WhatsApp phone number, Telegram chat ID, Discord webhook URL, and Slack workspace, channel and access token (encrypted) that you set up, plus the content of the alerts we send.
Why
Deliver alerts to the destinations you chose.
Legal basis
Performance of our contract with you (GDPR Art. 6(1)(b))
How long
Until you remove the channel or delete your account. Earlier values stay in the activity log (see above).

Teams

What
Team membership, roles, per-artist access, and invitations (the invitee’s email address and who sent the invitation).
Why
Let teams share artists and control who can see and do what.
Legal basis
Performance of our contract with you (GDPR Art. 6(1)(b)); for invitees who are not yet users, the legitimate interest of the team owner and us in enabling collaboration (GDPR Art. 6(1)(f))
How long
Membership lasts as long as the team relationship. Invitations are deleted within 30 days after they are accepted, revoked or expired.

Plan and billing

What
Your plan, billing period, subscription status, allowances, and the customer and subscription IDs that Paddle gives us. We never receive your full card details.
Why
Provide the plan you bought and keep it in sync with Paddle.
Legal basis
Performance of our contract with you (GDPR Art. 6(1)(b)); for records we must keep, compliance with a legal obligation (GDPR Art. 6(1)(c))
How long
While your account exists. Records that tax and accounting law requires us to keep are retained for the statutory period, generally up to 8 years.

Support and other communication

What
What you write to us and our replies, including your email address and any details you share.
Why
Answer your questions and handle requests, including data-protection requests.
Legal basis
Performance of our contract with you (GDPR Art. 6(1)(b)) or our legitimate interest in responding to enquiries (GDPR Art. 6(1)(f))
How long
Up to 2 years after the conversation ends, unless we need the messages longer to establish or defend legal claims.

Beta invitations and waitlist

What
The email addresses invited to the closed beta, and email addresses submitted to our waitlist.
Why
Control who can register during the beta and tell waitlist members when the Service opens.
Legal basis
Beta invitations: our legitimate interest in running an invitation-only beta (GDPR Art. 6(1)(f)). Waitlist: your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time
How long
Beta invitations are kept until the beta ends. Waitlist entries are kept until you ask us to remove them, and at the latest 12 months after the public launch.

Technical logs

What
Web server and application logs, which contain IP addresses, requested URLs, timestamps, browser information and error details.
Why
Operate the Service, fix errors, and detect and investigate attacks.
Legal basis
Our legitimate interest in operating a secure and reliable service (GDPR Art. 6(1)(f))
How long
Up to 90 days, or longer only where needed to investigate a specific incident.

We do not use your data for advertising, we do not sell it, and we do not build marketing profiles. We send service emails (for example about security, billing or changes to our terms). We will only send marketing emails if you opt in, and every such email will include an unsubscribe link.

3. Data about people who are not our users

To work, the Service also processes limited data about people who do not have an account with us. We rely on legitimate interests (GDPR Art. 6(1)(f)): our customers’ interest, and ours, in protecting music catalogs against fraudulent and unauthorised releases. We have balanced these interests against the rights of the people concerned. The data is already public and professional in nature, we use only what is needed, and no one is subject to automated decisions with legal effect.

  • Artists and other people in release metadata. Artist names and platform IDs, public profile images, public social-media handles shown on artist profiles, release titles, and names that appear in label or ℗/© lines. This data comes from the public data of Spotify, Apple Music, Deezer and YouTube. We keep artist profile details while at least one customer monitors the artist, and delete or anonymise them within 12 months after that. We keep release metadata for as long as it is useful for detection, and review it at least once a year.
  • Distributor contacts. Names of distributors and the business contact details and takedown channels they publish. We use them to point our customers to the right place to report an unauthorised release. We keep them until they are out of date or until the person concerned objects.
  • Team invitees and alert recipients. Email addresses and phone numbers that a customer enters for a colleague. These are covered in section 2 and are only used for the invitation or the alerts.

You can object to this processing at any time by emailing [email protected]. We will stop unless we have compelling legitimate grounds, for example keeping a record needed to protect a catalog against a proven fraudulent release.

4. Where the data comes from

We get personal data:

  • from you, when you sign up, configure the Service or contact us;
  • from your team owner or team admins, when they invite you or give you access;
  • from Google, when you sign in with Google (your name, email address, Google account ID and profile picture);
  • from Paddle, about your subscription status once you buy a plan;
  • from public streaming-platform data (Spotify, Apple Music, Deezer, YouTube) and from information that distributors publish themselves.

5. Cookies

We use only cookies that are strictly necessary to provide the Service. We do not use analytics, advertising or tracking cookies, so we do not ask for cookie consent. First-party cookies:

CookiePurposeExpires
authKeeps you signed in7 days
auth_challengeCarries you through the two-factor step of sign-in5 minutes
google_oauth_state, google_oauth_redirect, google_oauth_termsProtect Sign in with Google against forgery, return you to the right page, and record that you accepted the Terms before continuing with Google10 minutes
slack_oauth_stateProtects the Slack connection flow against forgery5 minutes

Cloudflare Turnstile runs a bot check on our sign-up and sign-in forms. To tell people from bots, it processes technical signals from your browser and device, such as your IP address and browser characteristics. Cloudflare may also set strictly necessary security cookies (such as __cf_bm) when protecting our site. Once paid plans launch, Paddle’s checkout sets its own cookies needed for payment and fraud prevention when you open it. If you signed in with Google, your profile picture loads from Google’s servers, which lets Google see your IP address.

6. Who receives personal data

Service providers (processors). These providers process personal data only on our instructions and under data processing terms that meet GDPR Art. 28:

ProviderWhat forWhere
netcup GmbH (Germany)Server hosting for the application, database and backupsEU
Cloudflare, Inc.Network, DNS and security services; Turnstile bot check; storage of uploaded profile pictures (Cloudflare R2, EU jurisdiction)Global network; EU storage for R2
Twilio Inc. (SendGrid)Account emails such as password resets, team invitations and account noticesUSA
Zoho Corporation B.V. (ZeptoMail)Alert emailsEU data centre
Twilio Inc.SMS alertsUSA
Meta Platforms Ireland Ltd. (WhatsApp Business Platform)WhatsApp alertsEU / USA

Independent recipients. These parties receive data and process it under their own terms and privacy policies:

  • Paddle (Paddle.com Market Ltd. and its affiliates) is our reseller and Merchant of Record. When you buy a plan, Paddle collects your billing details and payment data directly, under its own privacy notice.
  • Google provides Sign in with Google under the Google Privacy Policy.
  • Slack, Discord and Telegram receive the content of your alerts when you connect them as alert channels. They deliver it to the workspace, server or chat you chose.
  • Streaming platforms (Spotify, Apple, Deezer and Google/YouTube) receive only public artist and release identifiers in our requests to their interfaces, never personal data about you.
  • Authorities, courts and advisers. We share data with authorities and courts where the law requires it, and with our lawyers and accountants, who are bound by confidentiality, where needed.
  • A successor company, if the Service is transferred as described in section 1.

When you send a takedown email that you drafted with the Service, you send it yourself, from your own mailbox or account. It does not pass through CatalogArmor.

7. Transfers outside the EEA

Some providers are based in, or access data from, countries outside the European Economic Area, in particular the United States. We rely on the EU–U.S. Data Privacy Framework where the recipient is certified under it, and otherwise on the European Commission’s Standard Contractual Clauses (GDPR Art. 46). Telegram, Slack and Discord receive alert content because you asked us to deliver alerts to them (GDPR Art. 49(1)(b)). You can ask us for a copy of the relevant safeguards at [email protected].

8. Deletion and backups

How long we keep each type of data is listed in sections 2 and 3. In addition:

  • Deleting your account. When you delete your account in your settings, we sign you out everywhere and schedule the deletion for 14 days later. This lets us reverse accidental or unauthorised deletions if you contact us. After that, we permanently delete or anonymise your account data within 30 days. The exceptions are records we must keep by law, and data about shared artists that belongs to your team.
  • Backups. Deleted data can remain in our encrypted backups for up to 30 days, until those backups are overwritten.
  • Legal claims. If data is needed to establish, exercise or defend a specific legal claim, we may keep it until that matter is resolved.

9. Security

We protect personal data with measures that fit the risk. These include encryption in transit (TLS), hashed passwords, encrypted two-factor secrets and third-party access tokens, optional two-factor authentication, server-side session revocation, bot checks, least-privilege access to production systems, and a staff panel reachable only over a private VPN. If a personal data breach occurs, we will notify the NAIH within 72 hours unless it is unlikely to put anyone’s rights at risk, and we will inform you directly if it is likely to result in a high risk to you.

10. Your rights

Under the GDPR you have the right to:

  • access your personal data and receive a copy (Art. 15);
  • rectify inaccurate data (Art. 16);
  • erasure of your data (Art. 17);
  • restrict processing in certain cases (Art. 18);
  • data portability, meaning your data in a structured, machine-readable format (Art. 20);
  • object at any time to processing based on legitimate interests (Art. 21); and
  • withdraw your consent at any time, where we rely on consent, without affecting processing that has already taken place (Art. 7(3)).

You can change most of your data yourself in your dashboard, including your profile, alert channels and team, and you can delete your account in your settings. For anything else, email [email protected]. We may ask you to confirm your identity. We reply within one month, which can be extended by two further months for complex requests, in which case we will tell you why. Requests are free of charge.

11. Complaints

If you think we have not handled your data lawfully, please contact us first. We will try to put it right. You also have the right to lodge a complaint with the Hungarian supervisory authority:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)

1055 Budapest, Falk Miksa utca 9–11.

Postal address: 1363 Budapest, Pf. 9.

Phone: +36 1 391 1400 · Email: [email protected] · Web: naih.hu

You can also complain to the supervisory authority in the EU country where you live or work, or go to court. In Hungary, such cases are heard by the regional court (törvényszék), and you may choose the court for the place where you live.

12. Automated decisions

Alerts are produced automatically by comparing releases with your whitelist. They are signals for a human to review, not decisions. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (GDPR Art. 22). What to do about an alert is always your decision.

13. YouTube API Services and Google

CatalogArmor uses YouTube API Services to monitor public YouTube channels and uploads for the artists you add. We use them only with our own API key, to read public data. We do not access your YouTube or Google account through them. For how Google handles data, see the Google Privacy Policy. The YouTube Terms of Service also apply.

If you use Sign in with Google, you can revoke CatalogArmor’s access to your Google account at any time on Google’s security settings page. We receive only your name, email address, Google account ID and profile picture (scopes: openid, email, profile).

14. Changes to this policy

We will update this policy when our processing changes. For material changes, we will email you before they take effect. The version and date at the top of this page show which version is current. Previous versions are available on request.

Questions about this document? Email [email protected].