Core app, website, and security
| Recipient | Purpose and data | When / location |
|---|---|---|
| Apple | App distribution and StoreKit payment; private iCloud/CloudKit sync; App Attest; subscription verification. Apple processes your Apple account/payment data. Krat13 sends signed StoreKit transaction/device evidence for Pro backend requests and a pseudonymous attestation key for security. | App use; iCloud only if enabled. Apple operates globally, including EU and US. |
| Railway | Hosts the Krat13 backend, PostgreSQL database and, if enabled, Redis abuse-control store. Receives transient feature requests, IP/connection and security data, App Attest records, short caches, StoreKit proof, and Discogs OAuth data in transit. Infrastructure may derive coarse location from IP. | Only backend-assisted features. Configured US West (San Francisco); support/resilience may involve other locations. |
| Cloudflare | Authoritative DNS, CDN, security, and Cloudflare Pages hosting for krat13.app. Receives IP address, IP-derived approximate location, user agent, requested URL/referrer where supplied, timestamp, TLS/network data, and security/diagnostic information. Web Analytics, Logpush, forms, accounts, uploads, and Pages Functions are not enabled. Cloudflare's self-serve terms incorporate its DPA where it processes covered personal data as our processor. | Website visits. Global network; Cloudflare is US-based and may process in the EU, US, and other locations. |
| Porkbun | Domain registrar and provider of inbound forwarding for addresses such as support@krat13.app; Cloudflare provides authoritative DNS. For forwarded mail Porkbun may process sender/recipient addresses, subject, body, attachments, mail headers, IP/routing information, timestamps, and spam/security signals. It also processes the operator's domain-account and registration information. | Domain registration, and only when an email is sent to a forwarded Krat13 address. US-based; service providers may operate elsewhere. |
| Google Gmail | Destination mailbox for forwarded support mail and the directly published privacy address. Processes and stores sender/recipient addresses, subject, message, attachments, mail headers, routing/security metadata, timestamps, and replies. This consumer mailbox is governed by Google's applicable account terms and privacy policy; this register does not assert that every such activity is processor-only. | Only when you email us or we reply. Google operates globally, including the EU and US. |
Features you request
| Recipient | Purpose and data | When / location |
|---|---|---|
| Google Cloud Vision | Text recognition and matching from front/back sleeve photos. Synchronous image content is processed in memory without disk persistence; temporary request-metadata logs may remain. | Premium Scan only; Google Cloud DPA; global API, no fixed processing region confirmed. |
| Google Gemini API | Optional cleanup of a public product title or redacted track-list excerpt; generated result. Paid service: no product-improvement training use. ZDR is not enabled; Google abuse-monitoring retention is 55 days. Krat13 backend cache is up to one hour. | Only after 18+ confirmation and permission; Google Cloud DPA; global API, no fixed processing region confirmed. |
| Discogs (Zink Media) | Release/marketplace lookup and optional OAuth import or sync. Receives search terms or the Discogs account data/actions you authorize. | Lookup or connected Discogs feature; US. |
| MusicBrainz / Cover Art Archive (MetaBrainz) | Music metadata and cover-art lookup using barcode, artist, title, or release identifier. | Scan, search, repair, or add; EU/US-facing infrastructure. |
| UPCitemdb | Product lookup using the scanned/entered barcode. | Barcode lookup when this fallback source is used; US/global service. |
| Apple iTunes Search | Public music metadata, artwork, and audio-preview lookup using artist/title/track terms; image/media hosts receive ordinary request data. | Relevant lookup or playback; global. |
| Deezer | Album metadata and cover-art lookup using artist/title terms. | Fallback lookup; EU/global. |
| Wikipedia / Wikimedia | Fallback public metadata or imagery using artist/title terms; image hosts receive ordinary request data. | Fallback lookup; US/global. |
| Ticketmaster | Public upcoming-event search using the record artist’s name. | Only if you enable/request Upcoming Shows; US/global. |
| Jina Reader (Jina AI / Elastic) | Optional, currently disabled fallback for a supported store page that blocks direct extraction. If activated under approved terms, receives the cleaned pasted URL and Railway backend connection/request metadata—not the device’s direct IP. Krat13 uses anonymous basic Reader mode and sends no Jina API key; remaining path/query data may still contain information. | Only after commercial/processing approval and only for the supported store-link fallback; provider region remains under review. |
| User-selected retailers, websites, image/audio hosts, and CDNs | The app may contact the public URL you submit and hosts returned by metadata results. They receive the requested URL/resource, IP address, user agent or transport metadata, and may set or read storage within a system web view under their own rules. Examples include Amazon, eBay, Bandcamp, Empik, Vinyla, HHV, JPC, Muziker, Shopify/IdoSell/Shoper stores, and artwork/audio CDNs. The category is dynamic and cannot be exhaustively named in advance. | Only when you submit/open a link or load remote media; location follows the selected recipient. |
Analytics and diagnostics
| Recipient | Purpose and data | When / location |
|---|---|---|
| PostHog | Pseudonymous product analytics: app-generated privacy-request reference, SDK identifiers, timestamps, lifecycle/event/screen name, coarse non-content properties, app/build, OS/device class, locale/time zone, IP/connection metadata, and possible approximate geography derived from IP. Krat13 does not intentionally send library content, search text, or pasted URLs as event properties. | Only if you opt in. Configured EU cloud (Frankfurt); transport/support/onward infrastructure may operate elsewhere. |
| Sentry | Sanitized crash/non-fatal diagnostics: timestamp, app/build, device/OS class, stack trace, coarse category, and IP/security metadata at ingestion. Krat13 disables default PII, user context, screenshots, view hierarchy, network tracking, raw bodies, URLs, and library/model identifiers, but treats reports as personal data because low-level or provider-generated fields may still occur. | When crash reporting is configured. Configured EU ingest (Germany); provider operations/support may involve other locations. |
Roles, retention, and transfers
Apple, Discogs, public metadata/content services, Porkbun, and Google may determine some processing under their own platform or account terms. Railway, Cloudflare, PostHog, Sentry, and feature API providers process limited data to provide contracted technical functions, subject to the actual account and contract configuration. A provider can act as our processor for some data and as an independent controller for other account, security, network, legal, or service data. This description does not turn an independent recipient into our processor.
Our backend does not retain a general copy of your library. Known Krat13 retention is in the Privacy Notice; a provider may keep delivery, billing, request, safety, fraud, or security data under its active configuration and terms. A stated region describes the configured primary project or ingest endpoint, not a promise that network transit, support, resilience, subprocessors, or legally required access never occurs elsewhere.
Some routes may transfer personal data outside the EEA/UK. The applicable legal route must be confirmed for each active provider and may include regional processing, adequacy, contractual safeguards, or another lawful mechanism. This register does not assert an unconfirmed DPA, Standard Contractual Clause, or zero-retention setting. For current information relevant to a request, email irakliy.tatoshvili@gmail.com.