Privacy Policy — Catalog
Last updated: September 23, 2026 Service: Catalog, available at catalog.rawexplicit.com Operator: Jose Miguel Lopez, an individual doing business as Raw Explicit, Miami, Florida, USA ("we," "us," "Raw Explicit")
This Policy explains what personal data Catalog collects, why, and what happens to it — including when you delete something.
1. What we collect
Account data: your email address and, if you provide it, your name. If you sign in with Google, we receive your name, email address, and profile picture from your Google account; we do not receive your Google password or access to anything else in your Google account. If you sign in with an email and password, your password is stored only in hashed form by our authentication provider and is never visible to us.
Content you upload: audio files, cover art, and any notes, titles, or metadata you attach to them (release names, stages, scores, comments).
Portfolio activity: the links you create, their expiration and password settings, and whether download is allowed. We do not currently track who opens a Portfolio link beyond what is needed to enforce its password or expiration.
Usage data: basic technical logs (timestamps, IP addresses, error reports) used to operate and secure the Service.
We do not collect more than the Service needs to function, and we do not sell personal data.
2. Who else touches your data (subprocessors)
To run Catalog, we use the following service providers, each processing data only to provide their part of the Service:
- Vercel — hosting of the Catalog application, including technical request logs.
- Supabase — authentication and database (account records, metadata, permissions), and storage for some uploaded files.
- Cloudflare R2 — file storage for audio, artwork, and other uploaded media.
- Resend — transactional email (account confirmation, password resets, invitations, notifications), sent from mail.rawexplicit.com.
- Google — only if you choose to sign in with Google, to confirm your identity.
These providers do not have independent rights to use your content; they store or transmit it on our behalf.
3. Why we process this data
- To provide the Service you signed up for (storing, organizing, and playing your music; running Portfolios).
- To secure accounts, confirm email addresses, and enforce the access permissions you set.
- To communicate with you about your account (confirmations, invitations, password resets, service notices).
- To fix bugs and improve the Service, using aggregated or technical data where possible.
We do not use your content to train any model, and we do not use it for advertising.
4. Confidentiality of unreleased material
Unreleased music you store in Catalog is treated as confidential. We do not listen to, review, or share it except to operate the Service, investigate a security or abuse report, comply with a legal obligation, or with your permission. See our Terms of Service, Section 6, for detail.
5. Deletion — what actually happens
This is the part that matters most, so we are specific about it.
- Deleting a song or a version, or choosing to delete a release together with its songs, removes the associated audio files from storage. This cannot be undone. We do not keep a separate backup copy of deleted audio.
- Deleting a release on its own does not delete its songs: by default they stay in the artist's catalog.
- Database backups may preserve metadata (a song's title, notes) for disaster-recovery purposes, but not the audio file itself. A restored record without its audio is not usable.
- If a workspace is deleted, all content in that workspace is deleted, including material uploaded by other members or belonging to artists they manage — unless a future feature changes this and we update this Policy accordingly.
- Removing a person's access to a workspace or an artist stops their ability to see the content; it does not delete the content itself.
If you are storing someone else's unreleased work, make sure they understand this deletion behavior — it is part of what you are agreeing to on their behalf when you upload it.
6. How long we keep data
We keep account and content data for as long as the account is active. If your account is deleted, associated data is deleted as described in Section 5, except where we are required to retain limited records (e.g., for legal or security purposes) for a defined period.
7. Your rights
Depending on your location, you may have the right to access, correct, export, or request deletion of your personal data. You can delete content directly in the Service, and deletion there is immediate and permanent (Section 5). To delete your account or make any other request, contact us at rawexplicit95@gmail.com.
8. Security
We rely on our providers' security measures (encryption in transit, access controls) and our own permission system, which restricts what each workspace member can see based on their role, down to the level of a single artist. Accounts created with a password must confirm their email address before they can access any workspace. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify affected workspace Owners within a reasonable time and as required by applicable law.
9. International transfer
Our infrastructure providers may process or store data outside your country. By using the Service, you consent to this transfer, which is necessary to provide it.
10. Children
Catalog is not directed at children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect data from them.
11. Changes to this Policy
We will update this Policy as the Service changes, particularly around billing and any future analytics on Portfolio views. We will post the updated version here and, for material changes, make a reasonable effort to notify workspace Owners.
12. Contact
Questions about this Policy or a data request: rawexplicit95@gmail.com.