Skip to content

    Trust & Security

    Last updated June 21, 2026

    This page is maintained by the Never Mentioned team to answer common security and privacy questions about how we run the site. It describes our current practices and the platform capabilities we use — it is editable project content, not an independent certification or third-party audit.

    Shared Responsibility

    Never Mentioned is built on the Lovable Cloud platform (backend hosted by Supabase). Platform security — infrastructure, managed Postgres, authentication primitives, and storage — is provided by those vendors. Application-level decisions (what data we collect, who can access it, how long we keep it) are owned by the Never Mentioned team.

    Account holders are responsible for keeping their login credentials safe and for the content they post in community areas.

    Access & Authentication

    • Sign-in is available via email/password and Google OAuth.
    • Passwords are hashed and managed by our auth provider — we never see plaintext passwords.
    • Password reset is performed via a signed email link.
    • Admin tools are gated by a server-side role check and Row-Level Security policies; admin status cannot be granted from the client.
    • Sessions can be ended at any time by signing out, which clears local auth state.

    Data We Collect & How It's Used

    We collect only what's needed to run the site:

    • Account data: email, display name, and (optional) avatar/profile fields you provide.
    • Activity: saved artists/playlists, heat reactions, comments, and community posts you create.
    • Artist submissions: information you submit through the artist intake forms.
    • Email preferences: newsletter subscription state and unsubscribe tokens.
    • Aggregate analytics: page-view counts used to understand what content resonates.

    Database access is protected by Row-Level Security: users can only read/write their own private records, and admin-only tables (outreach CRM, ops tasks, internal events) are restricted to verified admin accounts.

    Third-Party Services We Use

    • Lovable Cloud / Supabase — database, auth, storage, edge functions.
    • Google OAuth — optional sign-in.
    • Spotify — embedded players and public artist metadata (monthly listeners, album art).
    • Email delivery provider — transactional emails (welcome, password reset, contact replies) and newsletter sends.
    • Lovable AI Gateway — AI assistance used in editorial/admin tooling only.

    We do not sell personal data. We do not share account-level data with advertisers.

    Cookies & Analytics

    We use cookies and local storage strictly for sign-in sessions, remembering your preferences, and basic anti-spam rate limiting. Our analytics are aggregate page-view counts stored in our own database — we do not run third-party advertising trackers.

    Retention & Deletion

    Account and content data are retained while your account is active. You can request account deletion at any time by emailing the address below; we will remove your profile and personal records and anonymize any content that needs to be retained for moderation history.

    You can unsubscribe from any email at any time using the link in the email footer or by visiting /unsubscribe.

    Vulnerability Reporting

    If you believe you've found a security issue, please email nevermntd@gmail.com with the subject line "Security Report". Please give us a reasonable window to investigate and remediate before any public disclosure. We appreciate responsible reporting.

    Privacy Requests & Contact

    For privacy questions, data access, correction, or deletion requests, contact nevermntd@gmail.com. We aim to respond within a reasonable timeframe.

    This page is app-owned editable content. It is not a certification or independent audit.