1. Introduction
ReleaseLab ("we", "our", "the Service") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your personal information. ReleaseLab is operated from the Netherlands and complies with the EU General Data Protection Regulation (GDPR).
2. Data We Collect
Account Information
- Name and email address (required for account creation)
- Label name and business details you provide
- Password (stored as a secure hash, never in plain text)
Content You Upload
- Audio files (WAV, FLAC, AIFF)
- Artwork and press photos (JPG, PNG)
- Documents (contracts, press kits, EPK assets)
- Release metadata (titles, ISRCs, UPCs, credits)
Business Data
- Artist profiles and contact information
- Contract terms and deal structures
- Revenue and cost records
- Pipeline task data and activity logs
Automatically Collected
- Browser type and version
- IP address (for security and rate limiting)
- Pages visited and actions taken within the Service
- Error reports (via Sentry, for debugging and reliability)
3. How We Use Your Data
- Providing the Service — storing and displaying your content, managing releases, generating task portal links, and processing pipeline workflows
- Communication — sending email notifications about task updates, release milestones, and team activity (using your label's notification email or personal email)
- Security — protecting against unauthorized access, detecting abuse, and maintaining data integrity
- Improvement — analyzing usage patterns to improve the Service (aggregated and anonymized)
We do not sell your personal data or content to third parties. We do not use your content for advertising purposes.
4. Data Storage and Security
Your data is stored on secure cloud infrastructure:
- Application data — hosted on servers within the EU
- Files and media — stored on Cloudflare R2 object storage with encryption at rest and signed URL access controls
- Backups — automated daily backups retained for disaster recovery
All connections to ReleaseLab are encrypted via TLS/HTTPS. Access to production systems is restricted to authorized personnel.
5. Data Sharing
We share data only with the following categories of service providers, solely as necessary to operate the Service:
- Cloudflare — file storage and content delivery
- Resend — transactional email delivery
- Sentry — error monitoring and reliability (receives error context, not your content)
We do not share your data with advertisers, data brokers, or any other third parties.
6. Multi-Tenancy
ReleaseLab is a multi-tenant platform where each label operates in strict isolation. Technical controls ensure that data belonging to one label cannot be accessed by users of another label. This isolation applies to all data including releases, artists, contracts, financial records, and uploaded files.
7. Task Portal
The task portal allows external collaborators to view task details and upload files via secure, time-limited token links. Portal visitors are not required to create an account. We log portal page views for activity tracking (visible to the label manager). Portal tokens expire automatically.
8. Your Rights (GDPR)
As a data subject under the GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate personal data
- Erasure — request deletion of your personal data ("right to be forgotten")
- Portability — receive your data in a structured, commonly used format
- Restriction — request that we limit processing of your data
- Objection — object to processing based on legitimate interests
To exercise any of these rights, contact us at privacy@releaselab.app. We will respond within 30 days.
9. Data Retention
We retain your data for as long as your account is active. Upon account deletion:
- Personal data is deleted within 30 days
- Uploaded files are permanently removed from storage
- Backups containing your data are purged within 90 days
10. Cookies
ReleaseLab uses only essential cookies required for the Service to function (session management, CSRF protection). We do not use tracking cookies, analytics cookies, or advertising cookies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The "Last updated" date at the top reflects the most recent revision.
12. Contact
For privacy-related questions or to exercise your rights: