Core app, website, and security
| Recipient | Purpose and data | When / location |
|---|---|---|
| Apple | App distribution and StoreKit payment; private iCloud/CloudKit sync; App Attest; subscription verification through the App Store Server API. Apple processes your Apple account/payment data. Krat13 sends signed StoreKit transaction/device evidence for Pro backend requests and a pseudonymous attestation key for security. | App use; iCloud only if enabled. Apple operates globally, including EU and US. |
| Railway | Hosts the Krat13 backend, PostgreSQL database and, if enabled, Redis abuse-control store. Receives transient feature requests, IP/connection and security data, App Attest records, short caches, StoreKit proof, and Discogs OAuth data in transit. Infrastructure may derive coarse location from IP. | Only backend-assisted features. Configured US West (San Francisco); support/resilience may involve other locations. |
| Cloudflare | Authoritative DNS, CDN, security, and Cloudflare Pages hosting for krat13.app. Receives IP address, IP-derived approximate location, user agent, requested URL/referrer where supplied, timestamp, TLS/network data, and security/diagnostic information. Web Analytics, Logpush, forms, accounts, uploads, and Pages Functions are not enabled. Cloudflare's self-serve terms incorporate its DPA where it processes covered personal data as our processor. | Website visits. Global network; Cloudflare is US-based and may process in the EU, US, and other locations. |
| Porkbun | Domain registrar and provider of inbound forwarding for addresses such as support@krat13.app; Cloudflare provides authoritative DNS. For forwarded mail Porkbun may process sender/recipient addresses, subject, body, attachments, mail headers, IP/routing information, timestamps, and spam/security signals. It also processes the operator's domain-account and registration information. | Domain registration, and only when an email is sent to a forwarded Krat13 address. US-based; service providers may operate elsewhere. |
| Google Gmail | Destination mailbox for forwarded support mail and the directly published privacy address. Processes and stores sender/recipient addresses, subject, message, attachments, mail headers, routing/security metadata, timestamps, and replies. This consumer mailbox is governed by Google's applicable account terms and privacy policy; this register does not assert that every such activity is processor-only. | Only when you email us or we reply. Google operates globally, including the EU and US. |
Features you request
| Recipient | Purpose and data | When / location |
|---|---|---|
| Google Cloud Vision | Text recognition and matching from front/back sleeve photos. Synchronous image content is processed in memory without disk persistence; temporary request-metadata logs may remain. | Premium Scan only; Google Cloud DPA; global API, no fixed processing region confirmed. |
| Google Gemini API | Optional. For store links: cleanup of a public product title or redacted track-list excerpt. For Premium Scan: when Google Cloud Vision cannot confidently identify a record, a small downscaled crop of the front-cover photo plus the text already read from it, to suggest the artist and album (checked against Discogs before use); no other library photos are sent. Generated result only. Paid service: no product-improvement training use. ZDR is not enabled; Google abuse-monitoring retention is 55 days. Krat13 backend cache is up to one hour. | Only after 18+ confirmation and permission; Google Cloud DPA; global API, no fixed processing region confirmed. |
| Discogs (Zink Media) | Release/marketplace lookup and optional OAuth import or sync. Receives search terms or the Discogs account data/actions you authorize. | Lookup or connected Discogs feature; US. |
| MusicBrainz (MetaBrainz Foundation) | Music identity and artist MBID lookup using artist/title or MBID terms; generic release discovery only after a qualifying temporary Discogs availability failure. Results are not presented as confirmed Discogs pressings. | Relevant identity lookup or failure-only fallback; public read API, global network. |
| ListenBrainz (MetaBrainz Foundation) | Fans Also Like artist similarity using artist MBIDs. Requests pass through Railway with Krat13’s server-side service token; the library and a user ListenBrainz account are not sent. | When Fans Also Like loads; public service through the Railway backend, global network. |
| Apple ShazamKit | Song recognition for the optional Listen & Identify feature. Apple receives the short microphone sample and connection metadata and returns a match under Apple’s own privacy notice; Krat13 keeps only the recognized artist, title, and track identifier (for example an ISRC) and never stores or forwards the raw audio. | Only while you run Listen & Identify; Apple operates globally, including EU and US. |
| Apple iTunes Search | Public music metadata, artwork, and audio-preview lookup using artist/title/track terms; image/media hosts receive ordinary request data. | Relevant lookup or playback; global. |
| Deezer | Album metadata and cover-art lookup using artist/title terms. | Fallback lookup; EU/global. |
| Wikipedia / Wikimedia / Wikidata | Fallback public metadata (release year) using artist/title terms; cover imagery is no longer taken from Wikipedia. Wikidata is queried through Krat13’s backend by Discogs artist identifier for public artist facts. | Fallback lookup; US/global. |
| Ticketmaster | Public upcoming-event search using the record artist’s name. | Only if you enable/request Upcoming Shows; US/global. |
| Jina Reader (Jina AI / Elastic) | Optional, permission-controlled fallback after direct extraction fails for a supported store. Receives the public HTTPS host/path after the complete query and fragment are removed, plus Railway backend connection/request metadata—not the device’s direct IP. Krat13 sends no cookies, credentials, user/library fields, Jina API key, or ReaderLM-v2 request. Refusal and withdrawal are available in-app. | Anonymous Basic Reader; Jina documents an ordinary ~5-minute cache and no model training from API input/output. Exact role, region, security-log retention/deletion, and DPA scope for anonymous requests are not separately provider-confirmed for free-tier use; our internal review is complete and the transfer is low-risk (cleaned public URL only, backend-shielded, no user or library data). |
| Krat13 sample-content image host (base44.app) | Cover images for the optional demo records offered on first launch (“Load samples”) are served from a file store operated by Krat13 on the base44.app platform. The host receives the image request, IP address, and user agent. No account or library data is sent. | Only if you choose to load the sample records; US/global platform. |
| User-selected retailers, websites, image/audio hosts, and CDNs | The app may contact the public URL you submit and hosts returned by metadata results. They receive the requested URL/resource, IP address, user agent or transport metadata, and may set or read storage within a system web view under their own rules. Examples include Amazon, eBay, Bandcamp, Empik, Vinyla, HHV, JPC, Muziker, Shopify/IdoSell/Shoper stores, and artwork/audio CDNs. The category is dynamic and cannot be exhaustively named in advance. | Only when you submit/open a link or load remote media; location follows the selected recipient. |
Analytics and diagnostics
| Recipient | Purpose and data | When / location |
|---|---|---|
| PostHog | Pseudonymous product analytics: app-generated privacy-request reference, SDK identifiers, timestamps, lifecycle/event/screen name, coarse non-content properties, app/build, OS/device class, locale/time zone, IP/connection metadata, and possible approximate geography derived from IP. Krat13 does not intentionally send library content, search text, or pasted URLs as event properties. | Only if you opt in. Configured EU cloud (Frankfurt); transport/support/onward infrastructure may operate elsewhere. |
| Sentry | Sanitized crash/non-fatal diagnostics: timestamp, app/build, device/OS class, stack trace, coarse category, and IP/security metadata at ingestion. Krat13 disables default PII, user context, screenshots, view hierarchy, network tracking, raw bodies, URLs, and library/model identifiers, but treats reports as personal data because low-level or provider-generated fields may still occur. | Unless you turn off Share Crash Reports in Settings → Privacy & Data. Configured EU ingest (Germany); provider operations/support may involve other locations. |
Roles, retention, and transfers
Apple, Discogs, public metadata/content services, Porkbun, and Google may determine some processing under their own platform or account terms. Railway, Cloudflare, PostHog, Sentry, and feature API providers process limited data to provide contracted technical functions, subject to the actual account and contract configuration. A provider can act as our processor for some data and as an independent controller for other account, security, network, legal, or service data. This description does not turn an independent recipient into our processor.
Our backend does not retain a general copy of your library. Known Krat13 retention is in the Privacy Notice; a provider may keep delivery, billing, request, safety, fraud, or security data under its active configuration and terms. A stated region describes the configured primary project or ingest endpoint, not a promise that network transit, support, resilience, subprocessors, or legally required access never occurs elsewhere.
Some routes may transfer personal data outside the EEA/UK. For a transfer to one of our service providers we rely on an appropriate safeguard — the European Commission's Standard Contractual Clauses, an adequacy decision (including the EU-US Data Privacy Framework where the recipient is certified), or another lawful mechanism, set out in that provider's data processing agreement; independent recipients act under their own terms. This register still does not assert a fixed processing region or a zero-retention setting. To obtain a copy of a safeguard relevant to a request, email irakliy.tatoshvili@gmail.com.