Privacy Policy
Last updated: 8 July 2026
Records is an app for cataloguing your CD, vinyl and cassette collection. It is offline-first: your collection lives on your device. This policy explains exactly what data the app does and does not handle.
No accounts, no advertising, no product analytics. Your collection is stored only on your device. The app reaches the internet in three cases — to look up releases in music databases, to fetch its API credentials at startup, and (only if you explicitly turn it on) to send anonymous crash reports. Nothing about your collection is ever uploaded to us.
Information stored on your device
Your collection, wishlist, scanned details, storage locations, cover images and app settings are stored locally on your device in an on-device database. We do not keep a copy of your collection on any server we operate. You can delete everything at any time from Settings → Delete All Data, or by uninstalling the app.
Camera and photos
When you scan a barcode or take a cover photo, the camera image is processed entirely on your device. Barcode detection runs locally, and cover photos you take are saved to your device only. The app does not upload your photos, and it does not send images to any cloud image-recognition or OCR service.
Release lookups (music databases)
To identify a release and fetch its details — title, artist, tracklist, cover art, catalog number — the app sends lookup queries such as a barcode, catalog number, artist or title to third-party music databases:
- Discogs
- MusicBrainz
- Cover Art Archive
These requests are necessary for the core scanning and cataloguing features. They contain only the lookup terms above — never your collection or personal identifiers. Each service handles the request under its own privacy policy.
API credentials and app verification
The Discogs API credentials are not shipped inside the app. At startup the app requests them from a small server we operate (a Cloudflare Worker). To protect that server from abuse, the request is verified with Firebase App Check, which attests that it comes from a genuine, untampered copy of the app. App Check verifies the app itself; it does not read your collection or build a profile of you.
Crash reporting (optional, off by default)
Crash reporting is disabled by default. If you turn it on in Settings, Records sends anonymous crash reports to Firebase Crashlytics (a Google service) to help us fix bugs. A report contains the error and basic diagnostics — device model, operating-system version and app version. It never includes your collection data or personal identifiers, and it is not used to track you. You can turn it off again at any time in Settings.
Links to streaming services
Album screens may show links to open a release on services such as Spotify, Apple Music or YouTube Music. These are ordinary links: nothing is shared until you tap one and your device's browser or app opens it. What happens then is governed by that service's own privacy policy.
What we do not do
- We do not sell or share your personal data.
- We do not show advertising or build advertising profiles.
- We do not use product or usage analytics.
- There is no account and no sign-in.
Permissions
The app requests only what its features need:
- Camera — to scan barcodes and take cover photos.
- Photos (when you choose to import one) — to pick an existing cover image.
- Internet & network state — for release lookups and credential fetch.
It does not request access to your location, contacts or microphone. You can manage camera and photo permissions from your device settings at any time.
Data retention
On-device data stays until you delete it or uninstall the app. Requests to third-party services (and any optional crash reports) are retained according to those services' own policies.
Children
Records is a general-purpose collection tool and is not directed at children under 13 (or the equivalent minimum age in your country). We do not knowingly collect personal data from children.
Changes to this policy
If this policy changes, the updated version will be posted at this address with a revised "last updated" date.
Contact
Questions about this policy? Contact the developer at szymonk92@gmail.com.