1. Controller and scope
The controller is Iraklii Tatoshvili, sole trader (Krat13), Wrocławska 53M/70, Kraków, Lesser Poland, Poland. Privacy requests: irakliy.tatoshvili@gmail.com. Support: support@krat13.app.
This notice covers the Krat13 app, its widgets, Live Activities, App Intents, backend-assisted features, support communications, and krat13.app. It describes current processing and reasonably foreseeable technical variants of those functions; it is not blanket permission for unrelated future purposes. If we introduce a materially new category, recipient, or incompatible purpose, we will update this notice and request consent first where the law requires it. This notice does not replace the privacy notice of Apple, Discogs, a retailer, or another service you choose to use.
2. Data that stays under your control
Your collection, want list, notes, tags, automatic daily snapshots of the library (the last three, kept on the device only), searches saved on the device, play and lending history, lender names, purchase details, storage locations, local cover/gallery photos, preferences, and imported data are stored on your device. Free-text fields and photographs can contain personal data about you or another person; do not enter information you do not have the right to store. If you enable iCloud, Apple syncs these data in your private CloudKit container. Krat13’s operator cannot browse that container. Photos selected as ordinary cover art stay on the device/iCloud; the separate Premium Scan flow is described below.
Widgets and Siri/App Intents read a limited library snapshot and cover thumbnails from the app’s shared local container. Local notifications are scheduled on the device. A “Now Spinning” Live Activity runs locally and does not use a Krat13 push server. NFC writes a Krat13 record identifier/deep link to the physical tag you choose.
Exports (including JSON backups, CSV, PDF, images, and share cards) go to the destination you select. Want-list sharing creates a compressed, not encrypted, link containing album title, artist, priority, year, genre, format, and cover-image URL where present. Anyone with the link may read and import those fields. Krat13 does not host that link, but the receiving app, person, or messaging service may keep it.
3. Backend, security, and purchases
Backend-assisted features send ordinary network and request data such as IP address, timestamp, route, response status, app/build version, device/OS class, request size, and security/error information to our Railway-hosted service and infrastructure. An IP address may reveal or be used to derive an approximate country, region, city, or network; Krat13 does not request precise GPS location for these functions. Apple App Attest also creates a pseudonymous key identifier, public key, signature counter, and registration/last-use times. We use these data to deliver requested features, verify genuine installations, enforce limits, protect provider keys, investigate abuse, and maintain security. They are not a Krat13 user account, but they remain personal data when they can be related to an installation or person.
Operational hosting, database, gateway, and provider logs may receive connection metadata even where an application payload is processed only transiently. We configure our own application logging to avoid request bodies, credentials, full pasted URLs, collection content, and search text. A provider may independently keep limited delivery, billing, fraud, safety, or abuse records under its terms and configured retention.
For a Pro-only backend request, the app sends Apple-signed transaction evidence and a StoreKit device-verification value. We verify the signature and may ask Apple for current subscription status. Apple processes payment; we do not receive your card details. Verified status may be cached in server memory for up to five minutes and is not written to our database.
4. Lookups, links, and connected services
When you search, scan a barcode, load metadata, play a preview, display remote artwork, or request market/event information, the relevant search term, barcode, catalog/matrix value, artist/title, public release identifier, or media URL goes to one or more sources listed in Service Providers & Transfers. This includes:
- Discogs
- Apple iTunes Search/media hosts
- Deezer
- Wikimedia
- Ticketmaster
- MusicBrainz
- ListenBrainz (through Krat13’s Railway backend)
A recipient and any image/audio/CDN host necessarily receives connection metadata and may derive coarse location from the IP address. Provider selection can vary by result availability, fallback order, region, and feature. MusicBrainz receives artist/title or MBID lookups for music identity and, only when Discogs is temporarily unavailable, generic release discovery. ListenBrainz receives artist MBIDs through Krat13’s Railway backend to power Fans Also Like; your library is not sent. Cover Art Archive is not an active production lookup recipient.
The optional Listen & Identify feature records a short microphone sample and uses Apple’s ShazamKit to recognize the song. Recognition is performed by Apple: Krat13 does not save the raw audio or send it to its own servers, and the microphone is active only while you run the feature. Apple receives the audio sample and connection metadata to return a match under Apple’s own privacy notice. Krat13 then uses the recognized artist, title, and track identifier (for example an ISRC) with the metadata and vinyl sources described above to find matching releases; it does not identify a specific physical pressing. Microphone access is requested only when you first start the feature and can be changed in Apple Settings.
If you paste a public shop URL, the app contacts that retailer and its hosting/CDN providers. When direct extraction fails for a supported shop, Krat13 can offer the optional Jina Reader fallback. It remains off unless you choose Use Once or Always Allow; refusing does not block the rest of the app, and an ongoing permission can be withdrawn in Settings. If allowed, Krat13 removes the complete query string and fragment and sends only the public HTTPS host and path through our Railway backend. Account, login, cart, checkout, order, profile, session, and similar paths are rejected. Krat13 does not attach retailer cookies, credentials, collection data, notes, photos, name, email, Apple ID, or a Jina API key. The remaining host/path and product identifier can still reveal a browsing or purchase interest, so inspect a link before submitting it. Railway receives the device connection and security metadata described above; Jina receives the cleaned public URL and the Railway backend's connection/request metadata rather than your device's direct IP address. Krat13 uses anonymous basic Reader mode and does not request ReaderLM-v2. A successful public-page result may remain in our shared PostgreSQL cache for up to 24 hours under a URL hash, without a user/device association. Jina documents an ordinary approximately five-minute Reader cache and states that API input/output is not used for model training, but its exact anonymous-request role, processing region, security-log fields, retention, deletion, and DPA scope are not separately confirmed by the provider for anonymous free-tier requests; we have completed our internal review and proceed on the low-risk basis described here. If the provider's terms materially change this description, we will update it and request new permission where required. Retailer and media hosts are dynamic and cannot all be named in advance. If you connect Discogs, Discogs OAuth authorizes the backend to retrieve or update the collection/want-list information available through your Discogs account. If you turn on Back Up Collection Details or Back Up Want List Details in Settings, Krat13 also writes the details Discogs cannot otherwise store (prices, condition, play and lending status, lender name, disc colour, target price, store link, priority and similar) into a private custom field or private notes of your own Discogs account during sync; Discogs (US) then holds that data under its own privacy policy, and you can turn the backup off or remove the field and notes on discogs.com. Disconnecting stops future Krat13 access and deletes the local credential, but it does not delete the Discogs account or undo changes already synchronized there.
5. Sleeve photos and optional Gemini enrichment
If you use Premium Scan, the front/back sleeve photos you submit are sent through our backend to Google Cloud Vision for text recognition and matching. Images may incidentally contain a face, name, address, reflection, background, or other personal information, so frame the sleeve carefully. Krat13 does not use the images for facial recognition or biometric identification. Our backend processes them transiently and does not save a library copy. Krat13 uses Vision's synchronous online operation; Google states that image content for that operation is processed in memory and is not persisted to disk, is not used to train or improve Vision, and is covered by the Google Cloud Data Processing Addendum. Google may temporarily log request metadata, such as request time and size, for service improvement and abuse prevention. Google and hosting infrastructure also receive ordinary connection and security metadata.
Optional Google Gemini assistance is available only after you confirm you are 18+ and give permission. It is used in two places. For store-link imports it receives, through our backend, an extracted public product title and, when needed, up to 3,000 characters from a locally isolated and redacted public track-list section. For Premium Scan, when Google Cloud Vision cannot confidently identify a record, it receives a small downscaled crop of the front-cover photo you are scanning together with the text already read from that cover, so it can suggest the artist and album; that suggestion is checked against the Discogs catalogue before it is used, and Gemini is never allowed to supply a release on its own. No other photos from your library are sent, and it does not receive your collection, notes, name, email, Apple ID, pasted URL, or App Attest identifier in the prompt. Store-link import and cover scanning both work without Gemini. The production Gemini project has active Cloud billing, so Google treats it as a Paid Service and states that prompts and responses are not used to improve its products. Zero Data Retention is not enabled: Google states that prompts, supplied context, and outputs are retained for 55 days for abuse monitoring, and flagged material may be reviewed by authorized personnel for that purpose. Google may also keep project-isolated implicit cache data in memory, not at rest, for up to 24 hours. Krat13 does not use Gemini grounding, the File API, explicit context caching, the Interactions API, or Live API session resumption. Separately, a request fingerprint and generated result may remain in Krat13 backend memory for up to one hour. Withdrawing permission stops future Gemini requests but cannot recall an earlier request.
6. Analytics and crash diagnostics
PostHog analytics is off by default. If you opt in, PostHog receives an app-generated random privacy-request/installation reference, SDK-generated identifiers, lifecycle and screen/event names, timestamps, and coarse non-content properties such as counts, duration, success/failure, feature entry point, and provider source. The SDK or ingestion service may also receive app/build version, OS/device class, language/locale, time zone, IP address, and an approximate country/region/city derived from IP, depending on SDK and project configuration. We may disable storage or display of selected properties, but the network service still receives the IP address long enough to accept, route, secure, and process the request. These data are pseudonymous, not anonymous. Krat13 event properties are designed not to include record titles, artist names, search text, notes, pasted URLs, or photos.
Turning analytics off calls the SDK opt-out and stops future Krat13 capture. It does not automatically recall events already delivered or necessarily remove a queued event created while consent was active. Use Request My Data or Erasure if you want identifiable historical analytics located and erased where applicable.
When configured, Sentry receives sanitized crash and non-fatal diagnostics such as timestamp, app/build environment, device/OS class, stack trace, and a coarse error category. Sentry’s network edge necessarily receives the IP address and may process coarse geography or security metadata even if default PII storage is disabled. Raw response bodies, model identifiers, request URLs, library content, screenshots, view hierarchy, user account, and custom user ID are removed or disabled by Krat13 before submission. Unexpected SDK/platform fields or data embedded by the operating system in a low-level crash may still occur, so reports are treated as personal data rather than promised anonymous. Crash reporting is on by default because we rely on it for reliability and security, and you can turn it off at any time in Settings → Privacy & Data → Share Crash Reports. Turning it off stops future reports; it does not recall a report already sent.
7. Website and email communications
krat13.app does not use advertising cookies, analytics cookies, pixels, or behavioural tracking. Cloudflare Web Analytics is not enabled, and the site has no forms, user accounts, uploads, Pages Functions, advertising integrations, or third-party analytics embeds. The site may store only a theme or language preference in your browser. Cloudflare hosts and delivers the site and necessarily receives ordinary request data, including IP address, approximate location derivable from IP, user agent, requested URL and referrer where supplied, timestamp, TLS/network information, and security or diagnostic data. Cloudflare may process this information across its global network for delivery, caching, security, abuse prevention, service operation, and legal compliance. If a Cloudflare security, traffic-management, or load-balancing feature requires a cookie, it is used as strictly necessary infrastructure rather than for advertising or cross-site behavioural tracking. We do not configure Logpush or another external website-log export. Cloudflare may still create customer-visible aggregate analytics and provider-side network, security, system, billing, or legal records under its active terms and configuration.
Porkbun remains the domain registrar and provides inbound forwarding for addresses such as support@krat13.app; Cloudflare provides authoritative DNS. Messages sent to a forwarded Krat13 address pass through Porkbun and are delivered to a Google Gmail mailbox. Porkbun and Google may therefore receive the sender and recipient addresses, subject, message body, attachments, mail headers, IP or routing information, spam/security signals, timestamps, and our reply. A message sent directly to the published Gmail privacy address bypasses Porkbun but is still handled by Google. We use correspondence only to answer the request, operate support, prevent abuse, comply with law, and establish or defend claims. Please do not include passwords, payment-card details, health information, government identifiers, or other sensitive data unless strictly necessary. Provider delivery, security, backup, and legally required records may follow their own retention rules. If we introduce non-essential website analytics, advertising, tracking, forms, accounts, or uploads, we will update this notice and provide any legally required consent control before enabling them.
8. Why we process data
Where GDPR/UK GDPR applies, our bases are: contract or steps you request for lookup, scan, sync, export, purchase verification, and support; consent for the Jina fallback, Gemini, and opt-in analytics; legitimate interests for proportionate security, abuse/fraud prevention, service delivery, crash diagnosis, defence of legal claims, and website operation; and legal obligation where law requires processing. You may withdraw consent for future processing in Settings without affecting earlier lawful processing. We do not make decisions producing legal or similarly significant effects solely by automated means.
You can use local cataloguing without enabling Jina Reader, PostHog, or Gemini. You can avoid a particular metadata, retailer, scan, event, Discogs, or preview transfer by not invoking that network feature. Core security/transport processing is required when a backend or website request is made. Refusing an optional feature does not require uninstalling and does not remove your privacy rights.
9. Retention
| Data | Typical retention or rule |
|---|---|
| Local/iCloud library | Until you delete it from the relevant device/iCloud location. |
| App Attest record | Until a successful revocation request, or 180 days after last verified use. |
| Rate-limit/security state | Rate-limit windows up to 24 hours; de-duplication records for a Discogs write (so a retried request is not applied twice) up to 24 hours; operational logs for the configured security period. |
| Purchase verification | Transient; verified status may remain in memory for up to five minutes. |
| Vision photos | Transient at our backend. For the synchronous operation Krat13 uses, Google states that image content is processed in memory and not persisted to disk; request metadata may be logged temporarily. |
| Gemini prompt/output and result cache | Google abuse-monitoring retention: 55 days because ZDR is not enabled; project-isolated implicit memory cache may last up to 24 hours. Krat13 backend result/fingerprint memory: up to one hour. |
| PostHog and Sentry | According to the configured project retention; opt-out does not itself erase historical events. |
| Search/feature/provider requests | Payloads are generally transient at Krat13 except stated caches. Successful Jina public-page output expires within 24 hours. Shared Discogs API response caches expire within one hour for search results, two hours for marketplace/pricing results, and five hours for other public Discogs response data; they are not stored with a user/device reference. These response-cache limits do not shorten catalogue metadata saved in a user’s local/iCloud library. Provider delivery, safety, billing, security, or abuse records follow the provider’s active terms/settings. |
| Website/hosting records | Krat13 keeps no website-user database and configures no Cloudflare Logpush export. Customer-visible aggregate analytics and Cloudflare network, cache, security, system, account, billing, backup, or legally required records follow Cloudflare's active service configuration, DPA where applicable, and retention criteria; some may be retained longer for security incidents, legal duties, or claims. |
| Support and privacy email | Messages and attachments remain in the destination Gmail mailbox until they are deleted under our support practice, except where a longer record is reasonably required for the request, security, a legal duty, or a claim. Deletion from the mailbox is subject to Google's deletion and backup cycle. Porkbun forwarding data and provider delivery, spam, security, and legally required logs follow the providers' active terms and retention criteria. |
Where an exact provider or log period is not stated above, we keep data no longer than reasonably needed for the listed purpose and applicable legal obligations. You may ask for the current configured period.
10. Providers and international transfers
Our provider register identifies known recipients, purposes, and locations. Some recipients are in the United States or operate globally, so data may leave the EEA/UK. For a transfer to one of our service providers, we rely on an appropriate safeguard — the European Commission's Standard Contractual Clauses, an adequacy decision (including the EU-US Data Privacy Framework where the recipient is certified), or another mechanism permitted by law, set out in that provider's data processing agreement. Independent sources and platforms you choose to use, such as Discogs or Apple, act under their own terms. Contact us to obtain a copy of a safeguard relevant to your request.
11. Your rights and complaints
Subject to applicable law, you may request information and access, a copy, correction, deletion, restriction, portability, or objection and may withdraw consent. Use Settings → Request My Data or Erasure or email the privacy address below. The app prepares an email with available pseudonymous analytics, backend-security, and Discogs references so we can search without making your name or email an analytics identifier. We may request only additional information reasonably necessary to verify identity or locate records.
We will acknowledge and respond without undue delay and normally within one month, subject to lawful extensions. Requests are normally free. Erasure is not absolute: we may retain data that must be kept for legal obligations, legal claims, security evidence, freedom of expression, or another applicable exception; we will explain a refusal or limitation and the available complaint route. If we cannot reasonably identify data as yours—especially anonymous or deliberately unlinked diagnostics—we cannot safely disclose or erase it as your record. EU/EEA and UK users may complain to their local supervisory authority; in Poland this is the President of the Personal Data Protection Office (UODO).
If California privacy law applies to us and your data, you may request access/knowledge, correction, or deletion and receive equal service. We do not sell personal information or share it for cross-context behavioural advertising. These California statements are conditional and do not claim that every CCPA threshold applies to Krat13.
12. Deletion controls and their limits
Settings → Delete All Records deletes owned collection records and their record-linked local covers, lending/daily record reminders, widget snapshot, Live Activities, and related caches, and requests corresponding private CloudKit deletion. It keeps the want list, preferences, subscription, analytics/AI choices, and Discogs connection. It does not delete the collection at Discogs or copies already exported or shared.
Settings → Delete All App Data performs the full reset: collection, want list, local cover files, automatic daily snapshots, widget snapshot, caches, local notifications/Live Activities, connected Discogs credential, optional analytics/AI choices, and most app preferences, then attempts to revoke this installation’s App Attest record. CloudKit deletion may be queued while offline. It does not cancel an Apple subscription, erase Apple purchase history, guarantee deletion from another device before iCloud sync completes, delete data already exported/shared or written to a physical NFC tag, or automatically erase historical records already held by PostHog, Sentry, Google, support email, Apple, Discogs, a retailer, or another recipient.
After a full reset, the app offers a pre-filled historical provider erasure request using the lookup references captured before local deletion. You may make the same request at any time without deleting the app. We will erase or instruct processors to erase identifiable data where required, and will explain data we cannot identify, control, or lawfully delete. Independent services such as Apple or Discogs may require a direct request through their own account controls.
Uninstalling removes the app and local container under Apple’s platform rules, but may not remove iCloud data, subscriptions, backups, exported/shared copies, provider records, or support correspondence. Delete iCloud data separately in Apple’s iCloud storage settings and manage subscriptions in Apple settings. Uninstalling is optional and does not replace a privacy request.
13. Information about artists, labels, and companies
Krat13’s Catalog Policy is a registry of artists, groups, record labels, and companies regarding Russia’s war against Ukraine. For the people it names it holds: the stage or public name and common aliases, Discogs and MusicBrainz identifiers, the type of classification (an official designation by a government body such as a sanctions listing, or Krat13’s own editorial classification), a short factual basis (for example a public statement, participation in a state event, fundraising for armed forces, or a commercial performance in the Russian Federation after 24 February 2022), the source it rests on, and review dates. Because some of these facts concern political positions, we treat them as special-category data.
We process this information under our legitimate interest in operating an editorial catalog policy and informing our users (Art. 6(1)(f) GDPR), and, for the political facts, because the persons concerned made them public themselves through public statements, official-event appearances, and commercial performances (Art. 9(2)(e) GDPR). Only publicly documented conduct of public figures is recorded; identification is by exact match; a classification takes effect only at high or medium confidence; and the app’s wording never accuses. A performance-only classification records a commercial activity, not an opinion, and is never described as support for the war. The registry is delivered only to verified Krat13 installations and is not published as a public list; it is hosted with our backend provider named in the provider register. An entry stays while its classification is active; an official designation that ends is deactivated.
Because notifying each person individually would be disproportionate, this section is the notice to them. Anyone named in the registry may ask us to correct, restrict, or erase their entry, object to the processing, or request access, by emailing irakliy.tatoshvili@gmail.com or support@krat13.app. We review every request against the recorded sources and answer within one month; where we keep an entry, we explain why and how to complain to the supervisory authority named in section 11.
14. Age, security, and changes
Krat13 is not directed to children. Where a minor may use the general app, a parent or guardian should supervise and provide any consent required by local law. The optional Google Gemini feature is available only after the user confirms they are at least 18. The other optional features that rely on your consent — usage analytics and the external store-page reader — should be enabled only by someone who can give valid consent under their local law, which in some countries is 16; where a minor uses Krat13, a parent or guardian should make that choice. We use proportionate safeguards but no network or device is perfectly secure. Keep your device, Apple ID, backups, and connected Discogs account secure.
We may change vendors, SDK versions, infrastructure, fields, or retention settings as the service evolves, but only for the purposes and categories described here or another compatible lawful purpose. We will update the date above and the provider register when material facts change, provide additional notice where required, and obtain fresh consent before a new consent-based purpose. A new version applies prospectively from its stated date; it does not retroactively legalise earlier processing.
15. Contact
The controller’s contact details are provided in section 1 above.