Catalogian ("we," "us," or "our") operates the Catalogian web application and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service.
By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our practices, please do not use the Service.
2. Information We Collect
We collect the following categories of information:
Account information: If you create an account, we collect your name and email address through our authentication provider, Clerk. Most of the Service works without an account.
Record data: The files you upload or the URLs you link, and the rows Catalogian parses from them. A record can be anonymous or kept in an account (see section 3).
Session data: For anonymous sessions, we store the session record, a cryptographic hash of the session token, creation and expiry times, ingest and query counts, and the IP address the session was created from.
Change history: For kept records that watch a source, snapshots and delta events (new, changed, and deleted rows) recorded by each check.
Billing information: Payment details are collected and processed by Stripe. We do not store your full credit card number on our servers.
Usage data: Server logs including IP addresses, request timestamps, and API usage metrics necessary for operating and securing the Service.
3. Anonymous Sessions and Share Links
The primary way to use Catalogian requires no account. When you paste a link or drop a file, Catalogian parses it into a session record: the parsed rows, the key field that identifies each row, and a snapshot you can browse and query. The record holds your full row data, and the latest snapshot stays browsable for as long as the session lives.
24-hour expiry: A session record expires 24 hours after it is created. A countdown is shown while it runs. When the clock runs out, the record, its rows, and its snapshots are deleted.
Share links: Each session gets a shareable address, /s/<token>, where the token looks like cat_eph_....
The link is a bearer credential: Anyone who has the session URL or token can read the record (and connect an LLM to it) until it expires. The link cannot be used to modify or delete the record. Treat it like a secret: share it only with people and tools you want reading your data.
A lost link is gone: We store only a cryptographic hash of the token, so if you lose the URL, the record becomes unreachable to everyone, including us, until it expires.
What "Keep" changes: Keeping a record requires an account. A kept record moves into your account intact: its rows persist, its snapshot history accumulates, and on a schedule it can watch its source for changes. A kept record stays until you delete it.
4. How We Use Your Information
We use the information we collect to:
Provide, maintain, and improve the Service.
Parse the files and URLs you submit into records and answer queries against them.
For kept records, watch configured sources for changes on their schedules and record what changed.
Process billing and manage your subscription.
Communicate with you about your account, service updates, or support requests.
Detect, prevent, and address technical issues or abuse.
5. Data Storage and Security
Your data is stored on cloud infrastructure using industry-standard services including PostgreSQL databases, Redis caches, and object storage. All data is encrypted in transit using TLS. We implement reasonable administrative, technical, and physical safeguards to protect your information from unauthorized access, alteration, disclosure, or destruction.
No method of electronic storage or transmission is completely secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
6. Records, Snapshots, and Your Content
When you turn a file or URL into a record, Catalogian parses the rows and stores them together with a snapshot, so the record stays browsable and queryable. The latest snapshot always holds the full row data. What happens next depends on the kind of record:
Anonymous session records: the record expires 24 hours after it is created unless you keep it first. At expiry, the record and its data are deleted (see section 3).
Kept records: the rows and the snapshot history are stored until you delete the record. Deleting a record removes its rows, snapshots, and change history.
You retain full ownership of your data and the content you provide to the Service. We do not sell, license, or share your data with third parties.
7. Third-Party Services
We use the following third-party services that may process your data:
Clerk: Authentication and user management. Clerk processes your email address, name, and authentication credentials. See Clerk's Privacy Policy.
Stripe: Payment processing and subscription management. Stripe processes your billing and payment information. See Stripe's Privacy Policy.
PostHog: Product analytics and session insights. PostHog may process usage events, page views, and feature interaction data. See PostHog's Privacy Policy.
We do not use advertising networks or sell your data to third parties.
8. API Access and MCP Integration
Catalogian offers programmatic access through a REST API and an MCP (Model Context Protocol) server. This section describes how data is handled when you use these interfaces.
API keys: You can generate API keys from your dashboard to access the REST API and MCP server programmatically. API keys are stored only as cryptographically hashed values; we never store them in plaintext. You can revoke any API key at any time from your dashboard.
OAuth 2.0: You can authorize third-party applications (including Claude Desktop) to access your Catalogian data via OAuth 2.0 using the Authorization Code flow with PKCE. When you authorize an application, it receives an access token scoped to the permissions you approved (e.g., catalogian:read, mcp:access). Access tokens expire after 1 hour; refresh tokens expire after 30 days. You can revoke OAuth tokens at any time from your dashboard.
Session tokens: An anonymous session can also be connected to an LLM directly, using the session token from section 3 as the credential. A session token grants the same read-only view as the share link, scoped to the one record in that session, and it stops working when the session expires.
MCP server access: When an AI agent calls the Catalogian MCP endpoint, it accesses only: (a) the records associated with your authenticated account (or, when connected with a session token, the one record in that session), and (b) snapshot data, delta events, and change history for those records. The MCP server does not access the AI client's conversation history, memory, uploaded files, or any data outside your Catalogian account or session. Each MCP tool call is individually authenticated and access-logged.
Data collected via API/MCP: We collect only the minimum data needed to fulfill each request: the identity behind the credential used, the specific record(s) queried, and server-side access logs (IP address, timestamp, and tool called). No conversation content or AI-generated content is retained by Catalogian.
Third-party AI clients: When you connect Catalogian to an AI assistant (e.g., Claude Desktop), that assistant may send your data to its own AI provider for processing. Catalogian does not control how third-party AI providers handle your data. We recommend reviewing the privacy policy of any AI assistant you connect to the Service.
9. Data Retention
Anonymous session records are deleted when they expire, 24 hours after creation, unless you keep them first (see section 3). Kept records, including their rows, snapshots, and change history, are retained until you delete them. If you delete your account, associated data is permanently removed within 30 days.
We retain your account information for as long as your account is active. Server logs and usage metrics are retained for up to 90 days for operational and security purposes.
10. Your Rights
Depending on your jurisdiction, you may have the right to:
Access the personal data we hold about you.
Request correction of inaccurate data.
Request deletion of your data.
Export your data in a portable format.
Object to or restrict certain processing of your data.
To exercise any of these rights, please contact us at the address below. We will respond to your request within 30 days.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: