Records Legal Privacy

Privacy Policy

Last updated: 8 July 2026

Records is an app for cataloguing your CD, vinyl and cassette collection. It is offline-first: your collection lives on your device. This policy explains exactly what data the app does and does not handle.

The short version

No accounts, no advertising, no product analytics. Your collection is stored only on your device. The app reaches the internet in three cases — to look up releases in music databases, to fetch its API credentials at startup, and (only if you explicitly turn it on) to send anonymous crash reports. Nothing about your collection is ever uploaded to us.

01 — On device

Information stored on your device

Your collection, wishlist, scanned details, storage locations, cover images and app settings are stored locally on your device in an on-device database. We do not keep a copy of your collection on any server we operate. You can delete everything at any time from Settings → Delete All Data, or by uninstalling the app.

02 — Camera

Camera and photos

When you scan a barcode or take a cover photo, the camera image is processed entirely on your device. Barcode detection runs locally, and cover photos you take are saved to your device only. The app does not upload your photos, and it does not send images to any cloud image-recognition or OCR service.

03 — Lookups

Release lookups (music databases)

To identify a release and fetch its details — title, artist, tracklist, cover art, catalog number — the app sends lookup queries such as a barcode, catalog number, artist or title to third-party music databases:

These requests are necessary for the core scanning and cataloguing features. They contain only the lookup terms above — never your collection or personal identifiers. Each service handles the request under its own privacy policy.

04 — Credentials

API credentials and app verification

The Discogs API credentials are not shipped inside the app. At startup the app requests them from a small server we operate (a Cloudflare Worker). To protect that server from abuse, the request is verified with Firebase App Check, which attests that it comes from a genuine, untampered copy of the app. App Check verifies the app itself; it does not read your collection or build a profile of you.

05 — Crashes

Crash reporting (optional, off by default)

Crash reporting is disabled by default. If you turn it on in Settings, Records sends anonymous crash reports to Firebase Crashlytics (a Google service) to help us fix bugs. A report contains the error and basic diagnostics — device model, operating-system version and app version. It never includes your collection data or personal identifiers, and it is not used to track you. You can turn it off again at any time in Settings.

06 — Links

Links to streaming services

Album screens may show links to open a release on services such as Spotify, Apple Music or YouTube Music. These are ordinary links: nothing is shared until you tap one and your device's browser or app opens it. What happens then is governed by that service's own privacy policy.

07 — Not done

What we do not do

08 — Permissions

Permissions

The app requests only what its features need:

It does not request access to your location, contacts or microphone. You can manage camera and photo permissions from your device settings at any time.

09 — Retention

Data retention

On-device data stays until you delete it or uninstall the app. Requests to third-party services (and any optional crash reports) are retained according to those services' own policies.

10 — Children

Children

Records is a general-purpose collection tool and is not directed at children under 13 (or the equivalent minimum age in your country). We do not knowingly collect personal data from children.

11 — Changes

Changes to this policy

If this policy changes, the updated version will be posted at this address with a revised "last updated" date.

12 — Contact

Contact

Questions about this policy? Contact the developer at szymonk92@gmail.com.