What we store
Account identity, provided by Clerk: your user id, email address, name and avatar URL. Passwords and authentication factors are held by Clerk and never reach TasteLab.
Workspace and project records you create, including project names and descriptions.
Catalog data you import: item ids, titles, creators, categories, tags, descriptions, popularity values, dates, durations, prices and any metadata column you map.
Behavioural event data you import: the subject identifier, item identifier, event type, timestamp, value and session identifier exactly as supplied in your file.
Audience segment definitions, recommendation strategies, simulation configurations, seeds, results, metrics, generated reports and share links.
An activity log of significant workspace actions, used to populate the dashboard.
Behavioural event identifiers
TasteLab treats the subject identifier in an event file as an opaque string. It is used only to group events into sessions and to compute item-to-item co-occurrence.
Do not upload direct identifiers. Pseudonymise user identifiers before importing them. TasteLab has no feature that requires a real identifier and no feature that will resolve one.
If you upload data describing identifiable people, you remain the controller of that data and are responsible for having a lawful basis to process it.
What we do not do
We do not sell data, and we do not share imported catalog or event data with third parties beyond the sub-processors listed below.
We do not use your catalog or event data to train any model.
We do not build profiles of identifiable individuals. Audience segments are behavioural constructs you define; they are never derived from an individual person.
We do not perform psychological profiling or infer protected characteristics.
AI processing
When an Anthropic API key is configured, TasteLab sends the following to the Anthropic API in order to produce written interpretation: strategy names and weights, calculated metric values, audience segment names and descriptions, the project name and use case, and up to ten example item titles from a run.
It does not send behavioural event rows, subject identifiers, or the full catalog.
Every AI feature is optional. With no key configured, simulations, metrics, comparisons and the calculated sections of every report continue to work in full.
Sub-processors
Clerk — authentication and user identity.
Anthropic — AI interpretation, only when an API key is configured, and only with the fields listed above.
Your chosen PostgreSQL host and application host. TasteLab is self-hostable; where you deploy it determines where your data resides.
Retention and deletion
Deleting a project makes it and all of its contents inaccessible and stops its share links resolving.
To delete your account and all associated workspace data, contact the operator of the TasteLab deployment you are using.
Last updated when this deployment was built. TasteLab is an independent product and is not affiliated with any music, media or streaming company.