Privacy Policy

Last Updated: March 2026

Introduction

catalog.fm ("we," "us," or "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our music streaming platform and services.

Information We Collect

Account Information:

  • Email address (required)
  • Display name
  • Password (encrypted)
  • Profile customization preferences including avatar and biography

Usage Information:

  • Listening history and play counts
  • Playlists created and followed
  • Search queries and browsing behavior
  • Device information and IP address

Cookies We Use:

  • Session cookies for authentication
  • Analytics cookies to understand usage patterns
  • Preference cookies to remember your settings

How We Use Your Information

Core Platform Services:

  • Provide and maintain our streaming service
  • Process your subscription and calculate artist payouts
  • Enable personalized recommendations

Analytics and Improvement:

  • Analyze usage patterns to improve our service
  • Develop new features based on user behavior
  • Optimize platform performance and reliability

Artist Transparency:

  • Calculate fair payment distribution to artists
  • Provide artists with aggregated listening data
  • Share individual user payout breakdown (anonymized where appropriate)

Music Recommendations

We use your listening history, preferences, and behavior to provide personalized music recommendations. This includes:

  • Algorithmic suggestions based on your listening patterns
  • Editorial playlists curated by our team
  • Artist and genre discovery features

You have the option to disable recommendations or reset your listening history at any time via your account settings.

Information Sharing

With Artists and Labels:

We share aggregated listening data with artists and labels to calculate payouts. Individual user data is anonymized unless required for payment transparency under our fair payment model.

Service Providers:

  • Payment processing providers (for subscriptions)
  • Cloud hosting and infrastructure providers
  • Analytics and performance monitoring services

Legal Requirements:

We may disclose your information if required by law, court order, or to protect our rights, property, or safety.

Data Security

We implement industry-standard security measures to protect your personal information, including:

  • Encryption of data in transit and at rest
  • Regular security audits and updates
  • Secure authentication protocols
  • Limited employee access to personal data

Your Rights and Choices

Account Management:

  • Access and update your profile information
  • Download your listening data and history
  • Delete your account and associated data

Cookie Settings:

  • Manage cookie preferences through your browser
  • Opt out of non-essential cookies

Privacy Center:

  • Control who can see your listening activity
  • Adjust recommendation settings
  • Manage marketing communications preferences

Your Rights Under GDPR (European Economic Area)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):

Your Rights:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — request correction of inaccurate or incomplete data
  • Right to erasure — request deletion of your personal data ("right to be forgotten")
  • Right to restrict processing — request that we limit how we use your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consent — withdraw consent at any time where processing is based on consent

Lawful Basis for Processing:

  • Contract performance — to provide our streaming service and process your subscription
  • Legitimate interests — to improve our platform, prevent fraud, and ensure security
  • Consent — for optional features such as personalized recommendations and marketing communications
  • Legal obligation — to comply with applicable laws and regulations

To exercise any of these rights, please contact us at privacy@catalog.fm. We will respond to your request within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

Your Rights Under CCPA (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with the following rights:

Your Rights:

  • Right to know — request details about the categories and specific pieces of personal information we have collected about you
  • Right to delete — request deletion of your personal information, subject to certain exceptions
  • Right to correct — request correction of inaccurate personal information
  • Right to opt out — opt out of the sale or sharing of your personal information
  • Right to non-discrimination — we will not discriminate against you for exercising any of these rights

Do Not Sell or Share My Personal Information:

catalog.fm does not sell your personal information to third parties. We do not share your personal information for cross-context behavioral advertising. If our practices change in the future, we will update this policy and provide you with an opt-out mechanism.

Categories of Information Collected:

  • Identifiers (e.g., email address, display name, IP address)
  • Internet or other electronic network activity (e.g., listening history, browsing behavior)
  • Commercial information (e.g., subscription details, payment history)
  • Inferences drawn from the above (e.g., music preferences, recommendations)

To exercise any of these rights, please contact us at privacy@catalog.fm. You may also designate an authorized agent to make a request on your behalf. We will verify your identity before processing your request and respond within 45 days.

Data Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy. When you delete your account, we will remove your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes. Aggregated and anonymized data may be retained for analytics and reporting purposes.

International Users

catalog.fm is operated in the United States. If you are accessing our services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.

Where required by law, we rely on appropriate data transfer mechanisms to ensure your personal data is protected, including Standard Contractual Clauses (SCCs) approved by the European Commission and other safeguards as required by applicable data protection laws. By using our services, you acknowledge that your data may be processed in jurisdictions with different data protection laws than your own.

Children's Privacy

Our services are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately so we can delete it.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of our services after any changes indicates your acceptance of the updated policy.

Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

  • Email: privacy@catalog.fm
  • Privacy Team: catalog.fm Privacy Department

We are committed to resolving complaints about our collection or use of your personal information and will respond to your inquiry within 30 days.