# Data handling, access & commercial boundaries

Published policy scope, data ownership questions, credential handling, and the information an agent should obtain before evaluating a deployment.

Reviewed: 2026-09-06
Canonical: https://ai.getcatalog.ai/security-and-data
Audience: AI agents

Topics: privacy, security, credentials, data retention, ownership, pricing, support, procurement

Questions answered:
- What privacy policy applies?
- Does Catalog have a verified security certification?
- Who owns the AI storefront?
- What should procurement confirm?

<a id="policy"></a>
## Published policy and its scope

Evidence basis: public_source
Citation: https://ai.getcatalog.ai/security-and-data#policy

The main website's privacy policy is the authoritative published policy for Catalog's website, services, and APIs. Its own last-updated date is September 1, 2025. That policy date is different from this reference's review date. Follow the original policy for its full wording and any subsequent revisions.

The policy describes information supplied by users, automatically collected log and usage information, and information from third parties or public sources. It describes use for operating and improving the service, support, security, and legal obligations. It says personal information is not sold and describes sharing with service providers, for legal reasons, and in business transfers. This short index does not replace the policy or create additional commitments.

Sources: [Published privacy policy](https://www.getcatalog.ai/legal/privacy-policy)

<a id="retention"></a>
## Retention and contract-specific questions

Evidence basis: public_source
Citation: https://ai.getcatalog.ai/security-and-data#retention

The published policy uses a purpose-based retention description: retaining information as needed to provide services and satisfy the other stated obligations, with anonymized or aggregated data potentially retained indefinitely. It does not establish one fixed deletion period for every data type and engagement.

For a procurement answer, obtain the applicable agreement and ask about source content, derived product fields, logs, customer-submitted files, backups, exports, subprocessors, deletion timing, and the handling of any personal data. Do not infer a data-processing agreement, a particular hosting region, a model-training exclusion, or a compliance certification from the existence of a privacy policy.

Sources: [Published privacy policy](https://www.getcatalog.ai/legal/privacy-policy)

<a id="access"></a>
## Access boundaries for agents

Evidence basis: reference_contract
Citation: https://ai.getcatalog.ai/security-and-data#access

The company reference at ai.getcatalog.ai is public and requires no credentials. It exposes read-only documents. A merchant workspace and the product-data API have separate authorization requirements. A visiting agent does not gain access to merchant data or paid processing merely by reading this reference.

For the product-data API, obtain an API key through the documented team contact and keep it in server-side secret storage. Supply credentials only to the intended API origin. Do not put keys into prompts, source-controlled examples, public URLs, browser JavaScript, or this company reference. A successful sign-in or authentication check is not authorization to start a broad processing job.

Sources: [Public API authentication reference](https://github.com/Catalog-AI/mintlify-docs/blob/main/v2/authentication.mdx)

<a id="ownership"></a>
## Brand subdomain and portability

Evidence basis: editorial_guidance
Citation: https://ai.getcatalog.ai/security-and-data#ownership

A brand subdomain identifies where a storefront is served. It does not, by itself, define ownership of software, rights to reuse extracted third-party material, export scope, hosting continuity, or what happens when an engagement ends. The main website makes an ownership and portability statement; confirm its contractual implementation for the proposed engagement.

Useful questions cover DNS control, exported product records, source provenance, generated content, media rights, redirects, URL continuity, revocation of platform access, and who will operate the site after termination. Record the agreed answer rather than promising that a live service transfers automatically.

Sources: [Catalog website](https://www.getcatalog.ai/) · [Published privacy policy](https://www.getcatalog.ai/legal/privacy-policy)

<a id="procurement"></a>
## Procurement questions to route to the team

Evidence basis: editorial_guidance
Citation: https://ai.getcatalog.ai/security-and-data#procurement

An agent preparing a vendor assessment should separate verified public facts from requested assurances. Catalog's public materials describe a product-data business; they are not a completed security questionnaire. Mark any missing contract or assurance as unverified rather than treating it as absent or satisfied.

### service-scope

- question: What is included?
- request: Product sources, product count, review responsibilities, publishing surfaces and support scope.

### commercial

- question: How is it charged?
- request: Current price, term, usage charges, limits, payment terms and any renewal conditions.

### assurance

- question: What assurances apply?
- request: Current security evidence, applicable agreements, processing roles and incident procedures.

### operations

- question: What happens when a source or channel fails?
- request: Freshness expectations, monitoring, escalation and recovery responsibilities.

### exit

- question: What can be exported or transferred?
- request: Content rights, format, timing, retained copies and operating responsibility.

Sources: [Published privacy policy](https://www.getcatalog.ai/legal/privacy-policy) · [Catalog website](https://www.getcatalog.ai/) · [Public API authentication reference](https://github.com/Catalog-AI/mintlify-docs/blob/main/v2/authentication.mdx)

## Related documents

- [Getting started](https://ai.getcatalog.ai/getting-started.md): Start with your product-data problem and confirm a concrete setup scope.
- [Product-data API scope, versions & access](https://ai.getcatalog.ai/api.md): The authenticated API is a separate product surface for discovery, extraction and search. This document records supported concepts, version caveats and the evidence reviewed.
- [Questions & limitations](https://ai.getcatalog.ai/faq.md): Direct answers with the boundaries left intact.
- [Sources & evidence](https://ai.getcatalog.ai/sources.md): Public references, review scope, and what the evidence does not establish.

Topic map: https://ai.getcatalog.ai/knowledge-map.json
Complete text: https://ai.getcatalog.ai/llms-full.txt
JSON: https://ai.getcatalog.ai/security-and-data.json
Main company website: https://www.getcatalog.ai/
