Curiation · Legal
Curiation Privacy Policy
Version 1.0 · Effective July 20, 2026
The Curiation platform is operated by Haven Contemporary LLC, a Texas limited liability company doing business as Curiation ("Curiation," "we," "us"). This policy explains what we collect, why, how long we keep it, and what you can ask us to do about it. It applies to curiation.fm, library storefronts operated on the Curiation platform (including custom domains), and related services (together, the "Platform").
Questions or requests: cupchurch@curiation.fm.
1. The short version
- We do not sell personal information, and we never will.
- We run no third-party advertising or analytics trackers — no Google Analytics, no advertising pixels, no data brokers, no cross-site profiling. Nothing on the Platform reports your behavior to an outside company for marketing.
- We collect what an account, a purchase, and a working search engine require — and not much else.
- Search and playback signals are recorded against an anonymous session identifier, kept for 180 days, and then reduced to aggregate counts that identify no one.
- The briefs you search are kept separately with no identifier attached at all — no session, no account, no IP — for 24 months, so we can see what customers need and go find the music that answers it.
- Card details never reach our servers. Payments are handled by Stripe.
Everything below is the detail behind those five statements.
2. Who this covers
The Platform has three kinds of people on it, and we handle each differently:
- Visitors — anyone browsing a storefront or the marketplace without an account.
- Buyers — supervisors, producers, marketers and creators who hold accounts and license music.
- Libraries — the independent music libraries whose catalogs are listed and whose storefronts we operate.
3. What we collect
3.1 Information you give us
| Who | What | Why |
|---|---|---|
| Buyers | Name, email, password (hashed), organization | Account, authentication, order records |
| Buyers | Production/project name, use application, territory, term, paid-media tier | To price and issue your license — these become part of the license certificate |
| Buyers | Billing details, tax ID where applicable | Payment, tax compliance, invoices |
| Libraries | Legal entity name, contact details, business address, payout and tax information | Library account, Stripe Connect onboarding, payments |
| Libraries | Catalog audio, metadata, artwork, rights and composer information | To host, present, analyze and license the catalog |
| Anyone | Messages you send us | To answer you |
3.2 Information collected automatically
Search and interaction signals. To make discovery work and improve it, we record events such as searches performed, results shown and their ranking, tracks previewed, how long a preview played, shortlist and cart actions, and downloads. These are stored against a session identifier and an actor identifier that is either anonymous (for visitors) or your account ID (when signed in). Search-ranking logs specifically carry no personal identifiers at all — only the query and the ranking it produced.
Search briefs (de-identified). Separately from the events above, we keep a record of the briefs themselves — the text you searched for, the filters applied, how many results came back and how strong the best match was. These records carry no session identifier, no account identifier, no IP address and no browser user-agent: they are not linked to you, to your device, or to each other, and we cannot re-associate them with a person. We keep them for 24 months and use them for two things: improving search quality, and understanding what customers are asking for that our catalogue does not yet answer well — which is how we decide which composers, producers and libraries to bring onto the Platform next. Because these records carry no identifier of any kind, they are not affected by the session identification described in §4, and they cannot be tied back to an individual on request.
Technical data. IP address, browser and device type, and pages requested — standard server logs, used for security, abuse prevention, and diagnosing faults.
Acceptance records. When you accept the Terms of Service, a Sync License Agreement, or the Library Agreement, we record the timestamp, IP address, browser user-agent, the document version, and a cryptographic hash of the exact text you agreed to. This is evidence of contract formation and is retained for as long as the agreement matters.
3.3 What we do not collect
We do not collect precise geolocation, biometric data, contacts, or special-category personal data. We do not buy personal information from data brokers. We do not build advertising profiles, and we do not track you across other websites.
4. Cookies and similar technologies
We use cookies and equivalent browser storage only for:
- Strictly necessary functions — signing you in, keeping your session, cart and shortlist, and security.
- Preferences — remembering settings such as volume or view mode.
- Session identification for the search and interaction signals described in §3.2.
We set no advertising or cross-site tracking cookies. Blocking non-essential storage will not lock you out of the Platform, though some conveniences will reset each visit.
5. Why we process your information (legal bases)
Where the GDPR or UK GDPR applies, our bases are:
- Contract — creating your account, processing orders, issuing licenses, paying libraries.
- Legitimate interests — operating and securing the Platform, preventing fraud and abuse, and improving search and ranking quality. We use anonymous or account-level identifiers rather than tracking individuals across the web, which we consider the least intrusive way to achieve this.
- Legal obligation — tax, accounting, and responding to lawful requests.
- Consent — where we ask for it, such as optional marketing email. You may withdraw consent at any time.
6. How we share information
We share personal information only in these situations:
- With the library you buy from. Completing a purchase means the library receives what it needs to fulfill and stand behind the license: your name or organization, your production details, and the license scope. The library is the licensor; it needs to know who it licensed to.
- With service providers who run parts of the Platform under contract and may not use your data for their own purposes: Stripe (payments and payouts), Supabase (database and authentication), and our hosting and content-delivery providers. Payment card details go directly to Stripe; we never receive or store full card numbers.
- When the law requires it, or to protect rights and safety — including responding to a valid DMCA notice, in which case a takedown notice and its contents may be forwarded to the party who uploaded the material.
- In a business transfer — if the business is acquired or merged, information transfers with it, subject to this policy.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
7. Catalog audio and AI
This deserves its own section, because it is the question we get asked most.
Curiation does not operate or build any model that generates or outputs audio, and does not use Platform content to train generative AI systems. We analyze catalog audio to power search, tagging, similarity and ranking — analysis that produces search results, never audio. We do not license, sell, or share catalog content with any third party as training data.
For libraries, the full scope of permitted analysis and the restrictions we are bound by is set out in Section 3A of the Library Agreement, with a plain-English explanation at /legal/how-we-use-your-music.
To be explicit about what survives a departure: when a library leaves, its recordings are removed from our storage and its catalog leaves the searchable marketplace, but the derived representations may be retained. They are one-way and non-reversible, they are never used to train anything that outputs audio, and they are never sold, licensed, or shared as training data — but we retain them rather than delete them, and we would rather say so than imply otherwise.
8. How long we keep things
| Data | Retention |
|---|---|
| Account records | While your account is open, then as needed for legal and tax purposes |
| Order, license and payment records | Retained as business and tax records (generally at least 7 years) — a license is evidence and must outlive the account |
| Acceptance records | For as long as the agreement remains relevant |
| Search and interaction events (session- and account-linked) | 180 days, then folded into monthly aggregate counts that identify no individual |
| De-identified search briefs (the brief text, filters and result quality — no session, account, IP or user-agent) | 24 months, then deleted |
| Server logs | Short-term, for security and diagnostics |
| Library recordings (audio and stems) | For the term of the Library Agreement; removed from storage on termination, and the catalog is removed from the searchable marketplace (Library Agreement §3.7) |
| Derived representations (embeddings, feature vectors, tags, usage signals) | May be retained after termination. They are one-way and non-reversible — no audio can be reconstructed from them — are never used to train any model that outputs audio, and are never sold, licensed, or shared with any third party as training data (Library Agreement §§3.5, 3.7) |
9. Your rights
Wherever you are, you may ask us to:
- Access the personal information we hold about you
- Correct anything inaccurate
- Delete your information, subject to records we must keep for legal, tax, or license-evidence reasons
- Export your information in a portable format
- Object to or restrict certain processing
- Withdraw consent where processing is based on it
- Opt out of marketing — every marketing email has an unsubscribe link, and transactional messages about your orders are not marketing
We will not discriminate against you for exercising any of these rights.
Email cupchurch@curiation.fm. We will verify your identity (usually by confirming control of the account email) and respond within 30 days, or tell you if we need longer. If you are in the EU, UK, or Switzerland, you also have the right to complain to your local data protection authority.
Libraries: your catalog data and transaction history are exportable at any time under Library Agreement §9.1 — you do not need to make a privacy request to get your own data out.
10. Security
We use encryption in transit, hashed passwords, access controls, signed time-limited download URLs, and least-privilege access to production systems. No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal information, we will notify you and any required authority as the law directs.
11. International transfers
We operate from the United States, and our service providers may process data in the US and elsewhere. If you are in the EU, UK, or Switzerland, your information will be transferred to the US. Where required, these transfers rely on Standard Contractual Clauses or another lawful transfer mechanism through our providers' terms.
12. Children
The Platform is a business-to-business service, is not directed to children, and we do not knowingly collect information from anyone under 18. If we learn we have, we will delete it.
13. Changes
We may update this policy. Material changes will be notified by email or Platform notice at least 14 days before taking effect, and the version and effective date at the top of this page will change. We will not retroactively reduce the protections that applied to information collected under an earlier version.
14. Contact
Haven Contemporary LLC, d/b/a Curiation
Email: cupchurch@curiation.fm
Copyright and DMCA notices go to our designated agent instead — see /legal/dmca.
© 2026 Haven Contemporary LLC, d/b/a Curiation. Version 1.0, effective July 20, 2026.