House Label

Last updated: April 2026

PRIVACY POLICY

House Label is a beta platform for independent musicians. This policy explains what we collect, why, and your rights. We try to keep it short, plain, and accurate — if anything is unclear, write to contact@houselabel.ai.

1. Who we are

House Label is a beta platform that helps independent musicians manage funding, royalties, presskits, and promotion. This policy describes what we collect, why, and what your rights are. For any privacy question, write to contact@houselabel.ai.

2. Information we collect

We collect only what is needed to run the service: - Account: email and authentication credentials (handled by Supabase Auth). - Artist profile: name, location, genre, career stage, disciplines, citizenship, languages, project description, and any links you add. - Service data: grants you track, draft answers, presskit content, songs and releases you log. - Uploaded files: photos and media you upload to your presskit (stored in Supabase Storage). - Linked accounts: when you connect a streaming or social account, we store read-only stats and the access tokens needed to refresh them. You can disconnect at any time. - Usage: basic request logs and IP addresses for rate limiting and abuse prevention. We do not collect analytics, advertising identifiers, or device fingerprints.

3. How we use it

Your data is used to: - Operate the platform features you choose to use. - Send your profile context to Anthropic’s Claude API so the AI agents can draft grant answers, bios, and presskit text. - Send transactional emails through Resend (invitations, password resets). - Render your presskit through our Presenton service (hosted on Railway). - Enforce rate limits and prevent abuse. We do not sell, rent, or share your personal data with advertisers or data brokers.

4. Sub-processors

House Label relies on the following service providers: - Supabase — database, authentication, file storage. (supabase.com) - Vercel — application hosting. (vercel.com) - Anthropic — AI text generation via the Claude API (used by the Grant Redactor and the presskit Q&A agent). Per Anthropic’s commercial terms, data sent through the API is not used to train their models. - OpenAI — AI used by our presskit slide-rendering service to lay out generated slides. Per OpenAI’s API data usage policies, data sent through their API is not used to train their models, and we have disabled any optional data-sharing in our account. - ElevenLabs — voice AI used by the optional voice-session feature in the marketing agent (text-to-speech plus speech-to-text). Data retention is disabled on our account, so conversation transcripts and audio are not retained for training. - Resend — transactional email delivery. (resend.com) - Railway — hosting for our presskit rendering service (an open-source renderer we deploy ourselves; no third-party operator processes that data). - TinyFish — browser automation used by the Grant Redactor to fill grant portals on your behalf when you trigger it. Each provider processes data only to deliver its part of the service, under its own privacy terms. Where a provider offers a setting to opt out of model training, we have turned it off.

5. Storage and security

- All traffic is served over HTTPS. - The database uses row-level security: each user can only read or write their own rows. - File uploads are scoped to your account through Supabase Storage policies. - Authentication is managed by Supabase Auth with secure session cookies. - We are a small team and do not yet have a formal SOC 2 / ISO certification. We rely on our infrastructure providers’ security posture and follow standard practices (least-privilege access, no plaintext secrets in code, environment-scoped credentials). If you discover a security issue, please email contact@houselabel.ai so we can address it quickly.

6. Your rights

You can: - Access all your stored data directly inside the platform. - Edit or update your profile, grants, drafts, and presskit at any time. - Delete your account by emailing contact@houselabel.ai. We remove your profile data, tracked grants, drafts, presskit content, uploaded files, and linked-account tokens within 30 days. - Export a copy of your data on request. Depending on where you live (e.g. Quebec — Law 25, EU — GDPR), you may have additional rights such as data portability or filing a complaint with your local privacy regulator.

7. Cookies

We use only the cookies needed for authentication and session management (set by Supabase Auth). No analytics cookies, no advertising trackers, no third-party tracking scripts.

8. Data retention

Account and service data is kept while your account is active. After deletion, data is removed within 30 days. Rate-limiting data lives in memory only and clears on server restart.

9. Changes

We may revise this policy as the product evolves. The “last updated” date at the top reflects the current version. Material changes will be announced inside the app or by email.