Privacy Notice

Krat13 · Effective August 1, 2026 · Last updated: August 6, 2026

Short version. Your library is local-first and Krat13 has no general user account or server-side copy of it. Optional iCloud sync is handled in your private Apple container. Network features disclose the inputs needed to provide them, and every network recipient necessarily receives technical connection data such as an IP address. Security and crash diagnostics may operate without a consent toggle; PostHog analytics and Google Gemini are optional and off until you allow them. You may delete collection records, perform a full app reset, or submit a separate privacy-rights request for identifiable historical backend/provider records.

1. Controller and scope

The controller is Iraklii Tatoshvili, sole trader (Krat13), Wrocławska 53M/70, Kraków, Lesser Poland, Poland. Privacy requests: irakliy.tatoshvili@gmail.com. Support: support@krat13.app.

This notice covers the Krat13 app, its widgets, Live Activities, App Intents, backend-assisted features, support communications, and krat13.app. It describes current processing and reasonably foreseeable technical variants of those functions; it is not blanket permission for unrelated future purposes. If we introduce a materially new category, recipient, or incompatible purpose, we will update this notice and request consent first where the law requires it. This notice does not replace the privacy notice of Apple, Discogs, a retailer, or another service you choose to use.

2. Data that stays under your control

Your collection, want list, notes, tags, searches saved on the device, play and lending history, lender names, purchase details, storage locations, local cover/gallery photos, preferences, and imported data are stored on your device. Free-text fields and photographs can contain personal data about you or another person; do not enter information you do not have the right to store. If you enable iCloud, Apple syncs these data in your private CloudKit container. Krat13’s operator cannot browse that container. Photos selected as ordinary cover art stay on the device/iCloud; the separate Premium Scan flow is described below.

Widgets and Siri/App Intents read a limited library snapshot and cover thumbnails from the app’s shared local container. Local notifications are scheduled on the device. A “Now Spinning” Live Activity runs locally and does not use a Krat13 push server. NFC writes a Krat13 record identifier/deep link to the physical tag you choose.

Exports (including JSON backups, CSV, PDF, images, and share cards) go to the destination you select. Want-list sharing creates a compressed, not encrypted, link containing album title, artist, priority, year, genre, format, and cover-image URL where present. Anyone with the link may read and import those fields. Krat13 does not host that link, but the receiving app, person, or messaging service may keep it.

3. Backend, security, and purchases

Backend-assisted features send ordinary network and request data such as IP address, timestamp, route, response status, app/build version, device/OS class, request size, and security/error information to our Railway-hosted service and infrastructure. An IP address may reveal or be used to derive an approximate country, region, city, or network; Krat13 does not request precise GPS location for these functions. Apple App Attest also creates a pseudonymous key identifier, public key, signature counter, and registration/last-use times. We use these data to deliver requested features, verify genuine installations, enforce limits, protect provider keys, investigate abuse, and maintain security. They are not a Krat13 user account, but they remain personal data when they can be related to an installation or person.

Operational hosting, database, gateway, and provider logs may receive connection metadata even where an application payload is processed only transiently. We configure our own application logging to avoid request bodies, credentials, full pasted URLs, collection content, and search text. A provider may independently keep limited delivery, billing, fraud, safety, or abuse records under its terms and configured retention.

For a Pro-only backend request, the app sends Apple-signed transaction evidence and a StoreKit device-verification value. We verify the signature and may ask Apple for current subscription status. Apple processes payment; we do not receive your card details. Verified status may be cached in server memory for up to five minutes and is not written to our database.

4. Lookups, links, and connected services

When you search, scan a barcode, load metadata, play a preview, display remote artwork, or request market/event information, the relevant search term, barcode, catalog/matrix value, artist/title, public release identifier, or media URL goes to one or more sources listed in Service Providers & Transfers. This includes Discogs, MusicBrainz/Cover Art Archive, Apple iTunes Search/media hosts, Deezer, Wikimedia, UPCitemdb, and Ticketmaster. A recipient and any image/audio/CDN host necessarily receives connection metadata and may derive coarse location from the IP address. Provider selection can vary by result availability, fallback order, region, and feature.

If you paste a public shop URL, the app contacts that retailer and its hosting/CDN providers. The Jina Reader fallback is currently disabled. If it is activated after commercial-use and processing review, Krat13 may send the cleaned URL for a supported site to Jina Reader through our Railway backend when direct extraction fails. Known tracking parameters are removed and credential/identifier-like query names are rejected, but the host, path, product identifier, and remaining query values may reveal browsing choices or contain information; inspect a link before submitting it. Jina would receive the backend's connection/request metadata rather than your device's direct IP address. Krat13 would use anonymous basic Reader mode and send no Jina API key. A successful public-page result could remain in our shared PostgreSQL cache for up to 24 hours under a URL hash, without a user/device association. Retailer and media hosts are dynamic and cannot all be named in advance. If you connect Discogs, Discogs OAuth authorizes the backend to retrieve or update the collection/want-list information available through your Discogs account. Disconnecting stops future Krat13 access and deletes the local credential, but it does not delete the Discogs account or undo changes already synchronized there.

5. Sleeve photos and optional Gemini enrichment

If you use Premium Scan, the front/back sleeve photos you submit are sent through our backend to Google Cloud Vision for text recognition and matching. Images may incidentally contain a face, name, address, reflection, background, or other personal information, so frame the sleeve carefully. Krat13 does not use the images for facial recognition or biometric identification. Our backend processes them transiently and does not save a library copy. Krat13 uses Vision's synchronous online operation; Google states that image content for that operation is processed in memory and is not persisted to disk, is not used to train or improve Vision, and is covered by the Google Cloud Data Processing Addendum. Google may temporarily log request metadata, such as request time and size, for service improvement and abuse prevention. Google and hosting infrastructure also receive ordinary connection and security metadata.

Optional Google Gemini enrichment is available only after you confirm you are 18+ and give permission. It receives, through our backend, an extracted public product title and, when needed, up to 3,000 characters from a locally isolated and redacted public track-list section. It does not receive your collection, notes, photos, name, email, Apple ID, pasted URL, or App Attest identifier in the prompt. Import works without Gemini. The production Gemini project has active Cloud billing, so Google treats it as a Paid Service and states that prompts and responses are not used to improve its products. Zero Data Retention is not enabled: Google states that prompts, supplied context, and outputs are retained for 55 days for abuse monitoring, and flagged material may be reviewed by authorized personnel for that purpose. Google may also keep project-isolated implicit cache data in memory, not at rest, for up to 24 hours. Krat13 does not use Gemini grounding, the File API, explicit context caching, the Interactions API, or Live API session resumption. Separately, a request fingerprint and generated result may remain in Krat13 backend memory for up to one hour. Withdrawing permission stops future Gemini requests but cannot recall an earlier request.

6. Analytics and crash diagnostics

PostHog analytics is off by default. If you opt in, PostHog receives an app-generated random privacy-request/installation reference, SDK-generated identifiers, lifecycle and screen/event names, timestamps, and coarse non-content properties such as counts, duration, success/failure, feature entry point, and provider source. The SDK or ingestion service may also receive app/build version, OS/device class, language/locale, time zone, IP address, and an approximate country/region/city derived from IP, depending on SDK and project configuration. We may disable storage or display of selected properties, but the network service still receives the IP address long enough to accept, route, secure, and process the request. These data are pseudonymous, not anonymous. Krat13 event properties are designed not to include record titles, artist names, search text, notes, pasted URLs, or photos.

Turning analytics off calls the SDK opt-out and stops future Krat13 capture. It does not automatically recall events already delivered or necessarily remove a queued event created while consent was active. Use Request My Data or Erasure if you want identifiable historical analytics located and erased where applicable.

When configured, Sentry receives sanitized crash and non-fatal diagnostics such as timestamp, app/build environment, device/OS class, stack trace, and a coarse error category. Sentry’s network edge necessarily receives the IP address and may process coarse geography or security metadata even if default PII storage is disabled. Raw response bodies, model identifiers, request URLs, library content, screenshots, view hierarchy, user account, and custom user ID are removed or disabled by Krat13 before submission. Unexpected SDK/platform fields or data embedded by the operating system in a low-level crash may still occur, so reports are treated as personal data rather than promised anonymous. Crash reporting has no in-app opt-out because we rely on it for reliability and security; you may object where applicable.

7. Website and email communications

krat13.app does not use advertising cookies, analytics cookies, pixels, or behavioural tracking. Cloudflare Web Analytics is not enabled, and the site has no forms, user accounts, uploads, Pages Functions, advertising integrations, or third-party analytics embeds. The site may store only a theme or language preference in your browser. Cloudflare hosts and delivers the site and necessarily receives ordinary request data, including IP address, approximate location derivable from IP, user agent, requested URL and referrer where supplied, timestamp, TLS/network information, and security or diagnostic data. Cloudflare may process this information across its global network for delivery, caching, security, abuse prevention, service operation, and legal compliance. If a Cloudflare security, traffic-management, or load-balancing feature requires a cookie, it is used as strictly necessary infrastructure rather than for advertising or cross-site behavioural tracking. We do not configure Logpush or another external website-log export. Cloudflare may still create customer-visible aggregate analytics and provider-side network, security, system, billing, or legal records under its active terms and configuration.

Porkbun remains the domain registrar and provides inbound forwarding for addresses such as support@krat13.app; Cloudflare provides authoritative DNS. Messages sent to a forwarded Krat13 address pass through Porkbun and are delivered to a Google Gmail mailbox. Porkbun and Google may therefore receive the sender and recipient addresses, subject, message body, attachments, mail headers, IP or routing information, spam/security signals, timestamps, and our reply. A message sent directly to the published Gmail privacy address bypasses Porkbun but is still handled by Google. We use correspondence only to answer the request, operate support, prevent abuse, comply with law, and establish or defend claims. Please do not include passwords, payment-card details, health information, government identifiers, or other sensitive data unless strictly necessary. Provider delivery, security, backup, and legally required records may follow their own retention rules. If we introduce non-essential website analytics, advertising, tracking, forms, accounts, or uploads, we will update this notice and provide any legally required consent control before enabling them.

8. Why we process data

Where GDPR/UK GDPR applies, our bases are: contract or steps you request for lookup, scan, sync, export, purchase verification, and support; consent for Gemini and opt-in analytics; legitimate interests for proportionate security, abuse/fraud prevention, service delivery, crash diagnosis, defence of legal claims, and website operation; and legal obligation where law requires processing. You may withdraw consent for future processing in Settings without affecting earlier lawful processing. We do not make decisions producing legal or similarly significant effects solely by automated means.

You can use local cataloguing without enabling PostHog or Gemini. You can avoid a particular metadata, retailer, scan, event, Discogs, or preview transfer by not invoking that network feature. Core security/transport processing is required when a backend or website request is made. If you do not want that necessary processing, do not use the corresponding network feature or website; you may stop using or uninstall the app, but uninstalling is not a waiver or substitute for your privacy rights.

9. Retention

DataTypical retention or rule
Local/iCloud libraryUntil you delete it from the relevant device/iCloud location.
App Attest recordUntil a successful revocation request, or 180 days after last verified use.
Rate-limit/security stateRate-limit windows up to 24 hours; operational logs for the configured security period.
Purchase verificationTransient; verified status may remain in memory for up to five minutes.
Vision photosTransient at our backend. For the synchronous operation Krat13 uses, Google states that image content is processed in memory and not persisted to disk; request metadata may be logged temporarily.
Gemini prompt/output and result cacheGoogle abuse-monitoring retention: 55 days because ZDR is not enabled; project-isolated implicit memory cache may last up to 24 hours. Krat13 backend result/fingerprint memory: up to one hour.
PostHog and SentryAccording to the configured project retention; opt-out does not itself erase historical events.
Search/feature/provider requestsPayloads are generally transient at Krat13 except stated caches. Successful Jina public-page output and shared Discogs public metadata expire within 24 hours and are not stored with a user/device reference. Provider delivery, safety, billing, security, or abuse records follow the provider’s active terms/settings.
Website/hosting recordsKrat13 keeps no website-user database and configures no Cloudflare Logpush export. Customer-visible aggregate analytics and Cloudflare network, cache, security, system, account, billing, backup, or legally required records follow Cloudflare's active service configuration, DPA where applicable, and retention criteria; some may be retained longer for security incidents, legal duties, or claims.
Support and privacy emailMessages and attachments remain in the destination Gmail mailbox until they are deleted under our support practice, except where a longer record is reasonably required for the request, security, a legal duty, or a claim. Deletion from the mailbox is subject to Google's deletion and backup cycle. Porkbun forwarding data and provider delivery, spam, security, and legally required logs follow the providers' active terms and retention criteria.

Where an exact provider or log period is not stated above, we keep data no longer than reasonably needed for the listed purpose and applicable legal obligations. You may ask for the current configured period.

10. Providers and international transfers

Our provider register identifies known recipients, purposes, and locations. Some recipients are in the United States or operate globally, so data may leave the EEA/UK. Depending on the provider and route, the lawful mechanism may be regional processing, an adequacy framework, contractual safeguards, or another mechanism permitted by law. We do not claim that a particular provider is covered by Standard Contractual Clauses until that arrangement is confirmed. Contact us for current safeguard information relevant to your request.

11. Your rights and complaints

Subject to applicable law, you may request information and access, a copy, correction, deletion, restriction, portability, or objection and may withdraw consent. Use Settings → Request My Data or Erasure or email the privacy address below. The app prepares an email with available pseudonymous analytics, backend-security, and Discogs references so we can search without making your name or email an analytics identifier. We may request only additional information reasonably necessary to verify identity or locate records.

We will acknowledge and respond without undue delay and normally within one month, subject to lawful extensions. Requests are normally free. Erasure is not absolute: we may retain data that must be kept for legal obligations, legal claims, security evidence, freedom of expression, or another applicable exception; we will explain a refusal or limitation and the available complaint route. If we cannot reasonably identify data as yours—especially anonymous or deliberately unlinked diagnostics—we cannot safely disclose or erase it as your record. EU/EEA and UK users may complain to their local supervisory authority; in Poland this is the President of the Personal Data Protection Office (UODO).

If California privacy law applies to us and your data, you may request access/knowledge, correction, or deletion and receive equal service. We do not sell personal information or share it for cross-context behavioural advertising. These California statements are conditional and do not claim that every CCPA threshold applies to Krat13.

12. Deletion controls and their limits

Settings → Delete All Records deletes owned collection records and their record-linked local covers, lending/daily record reminders, widget snapshot, Live Activities, and related caches, and requests corresponding private CloudKit deletion. It keeps the want list, preferences, subscription, analytics/AI choices, and Discogs connection. It does not delete the collection at Discogs or copies already exported or shared.

Settings → Delete All App Data performs the full reset: collection, want list, local cover files, widget snapshot, caches, local notifications/Live Activities, connected Discogs credential, optional analytics/AI choices, and most app preferences, then attempts to revoke this installation’s App Attest record. CloudKit deletion may be queued while offline. It does not cancel an Apple subscription, erase Apple purchase history, guarantee deletion from another device before iCloud sync completes, delete data already exported/shared or written to a physical NFC tag, or automatically erase historical records already held by PostHog, Sentry, Google, support email, Apple, Discogs, a retailer, or another recipient.

After a full reset, the app offers a pre-filled historical provider erasure request using the lookup references captured before local deletion. You may make the same request at any time without deleting the app. We will erase or instruct processors to erase identifiable data where required, and will explain data we cannot identify, control, or lawfully delete. Independent services such as Apple or Discogs may require a direct request through their own account controls.

Uninstalling removes the app and local container under Apple’s platform rules, but may not remove iCloud data, subscriptions, backups, exported/shared copies, provider records, or support correspondence. Delete iCloud data separately in Apple’s iCloud storage settings and manage subscriptions in Apple settings. Uninstalling is optional and does not replace a privacy request.

13. Age, security, and changes

Krat13 is not directed to children. Where a minor may use the general app, a parent or guardian should supervise and provide any consent required by local law. The optional Google Gemini feature is available only after the user confirms they are at least 18. We use proportionate safeguards but no network or device is perfectly secure. Keep your device, Apple ID, backups, and connected Discogs account secure.

We may change vendors, SDK versions, infrastructure, fields, or retention settings as the service evolves, but only for the purposes and categories described here or another compatible lawful purpose. We will update the date above and the provider register when material facts change, provide additional notice where required, and obtain fresh consent before a new consent-based purpose. A new version applies prospectively from its stated date; it does not retroactively legalise earlier processing.

14. Contact

Privacy requests: irakliy.tatoshvili@gmail.com
General support: support@krat13.app
Postal address: Iraklii Tatoshvili, Wrocławska 53M/70, Kraków, Lesser Poland, Poland