LEGAL DOCUMENT
CrateCore — Privacy Policy
Effective date: August 11, 2026 (previous versions: August 7, August 6, August 4, July 30, and July 17, 2026)
Operator / data controller: the individual developer of the CrateCore service ("we", "the operator")
Data questions: legal@cratecore.app
Rights-holder complaints: legal@cratecore.app
1. In short
CrateCore is an app and website for vinyl collectors: daily music content, a personal collection catalog, a wishlist, import, push notifications, and tools.
We collect the data needed to run the app, synchronize, keep the service secure, deliver notifications, measure usage without personal content, and provide support. We do not sell personal data, do not show targeted advertising, do not collect advertising identifiers, and do not share user notes/collections for model training.
The app opens without registration: reading stories works right away. Before you register we keep none of your data on our servers (on the technical anonymous session the app may open to reach the feed, see 2.1). Feed personalization is not available in that mode — the feed is the same for everyone; app settings and read marks exist only on your device and are never sent to our servers. Collection features (scanning and searching for releases, the collection, the wishlist, import), the "liked" mark, saving stories as bookmarks, the tools, and push notifications are available only to a registered account (see 2.3). Registration erases nothing: what accumulated on the device stays yours.
Important: microphone audio is never recorded and never leaves the device. The VU meter processes the signal locally in the device's memory. Your own photos of records are stored only on the device.
2. What data we process
2.1 Account and authentication
Data: Supabase user identifier; when you register — your e-mail (code-by-email sign-in or Google) and OAuth provider identifiers; an optional profile name if you set one. Sign in with Apple will arrive with the iOS version.
Purpose: sign-in, synchronization, recovery, security.
GDPR legal basis: contract performance, Art. 6(1)(b); security — legitimate interest, Art. 6(1)(f).
Retention: while the account exists.
Note: before you register there is no account with us. If the app opens a technical anonymous session to fetch the stories, all that remains of it on the server is the session identifier itself — a random number with no name, no e-mail, no settings, no marks, and no other content of yours; opening it, like any sign-in, is recorded in the authentication service log (see 2.9). Earlier anonymous sessions, and the records they managed to create under the previous rules, were deleted from our servers on August 6, 2026 (see 2.3). The identifier of the current technical session is deleted together with the session by the "Delete this session's data" button in the app (see 9); if you simply remove the app from the device, that number stays with us unused — with none of your data attached to it. Registration deletes nothing: the data accumulated on the device stays yours.
2.2 Settings
Data: selected genres/eras/topics, drop topics, content language, notification time, timezone, quiet sound, and other settings.
Purpose: personalization of the feed, language, and notifications.
Basis: contract performance.
Retention: while the account exists.
Who: settings exist only for a registered account. Before registration feed personalization is unavailable both in the app and on the website — the feed is the general one; the app's own settings (for example, the colour theme and interface language) stay on the device and are never sent to our servers. On the website, the genres you pick are saved into your account's settings once you sign in; before sign-in the site stores them neither with us nor in your browser.
2.3 Collection, wishlist, and notes
Data: collection records, wishlist, read/saved/hidden/liked article state, grading, price, purchase date, notes.
Purpose: the app's core functionality, cross-device sync, export, recovery.
Basis: contract performance.
Retention: while the account exists; technical logs per the Retention Policy (https://cratecore.app/retention/en/).
Who: the collection, the wishlist, and server-side article states exist only for a registered account. Before registration the collection and the wishlist are unavailable, as are the "saved" bookmark (since August 3, 2026) and the "liked" mark (since August 6, 2026), while marks for read and hidden stories are kept only on the device and are never sent to our servers. Records left on our servers by unregistered sessions under the previous rules (including those created before July 30, 2026) were deleted on August 6, 2026: since that date we hold no server data of unregistered sessions.
Stylus tracker: its data (the list of styluses, hours of use, photos) is stored only on your device — it is not sent to our servers, so it is not part of the export and does not carry over to a new device. On sign-out, or when another person signs in on this device, it is deleted together with the rest of the local data.
2.4 Audio chain profile
Data: turntable, amplifier, speakers, and other setup fields, if you fill them in.
Purpose: equipment profile and app features. Available to a registered account only (as of August 3, 2026).
Basis: contract performance.
Retention: while the account exists.
2.5 Import CSV
Data: the CSV file you choose for collection import and technical data of the import job.
Purpose: one-time import. Import is available only to a registered account.
Basis: contract performance.
Retention: the file is deleted automatically after the import completes, no later than 24 hours; the import log — up to 90 days.
2.6 Push tokens
Data: the device FCM token, platform, update time.
Purpose: notification delivery, if you allowed notifications. Notifications can only be enabled in a registered account: before registration the feature is unavailable and no push token is sent to the server.
Basis: consent to notifications and performance of the chosen feature; GDPR Art. 6(1)(a)/(b) depending on jurisdiction.
Retention: while the token is valid or while the account exists; deleted when you sign out, delete the account, disable notifications, or when the server cleans up an invalid token.
2.7 Analytics and crash reports
Data: usage events without personal content, e.g. onboarding_completed, article_opened, article_saved, article_liked, share_clicked, collection_add, import_started/completed, drop_preorder_click, push_opt_in; crash reports (Crashlytics); Firebase technical identifiers. The device advertising identifier (AAID/IDFA) is not collected. The user identifier is not sent to analytics.
Purpose: product metrics, bug fixing, stability.
Basis: legitimate interest, Art. 6(1)(f); consent where required. Analytics and crash reporting can be turned off in the app: Account → Privacy & Data.
Retention: Firebase Analytics — user/event-level data up to 2 months (default setting), aggregate reports longer; Crashlytics — 90 days.
Restriction: event parameters never include e-mail, user identifier, note texts, barcodes, CSV contents, search queries, or other personal fields.
2.8 Purchases
There are no paid features at the moment and no purchase data is processed. If paid features appear, purchases will be handled by the App Store / Google Play and a payment provider, and this Policy will be updated before they are enabled.
2.9 Technical logs and security
Data: user identifier, request type, result, response time, rate-limit and app attestation events. Barcodes are not stored in security logs. A request for stories made before registration also lands in the technical log on the same terms — but it carries none of your settings, marks, or other content. Beyond our own logs, our infrastructure providers process the technical data of the connection (IP address, request headers) — without it a server response cannot be delivered and abuse cannot be blocked — and the authentication service keeps its own service log of sign-ins, including the opening of a technical anonymous session. None of your content is in those logs.
Purpose: security, abuse prevention, diagnostics.
Basis: legitimate interest.
Retention: 30 days (request log); sync log — 90 days; the service logs of our infrastructure and authentication providers — for the periods set by those providers (list: https://cratecore.app/subprocessors/); longer only if needed to investigate a specific incident or required by law.
2.10 Messages sent through the site contact form
Data: the subject, the text of the message, the language of the page it was sent from, your e-mail address — if you gave one — and a pseudonymized fingerprint of your IP address (a sha256 hash with a secret salt), used only to protect the form from spam; the IP address itself is not stored.
Purpose: answering the message and protecting the form from spam.
Basis: legitimate interest, Art. 6(1)(f) GDPR.
Retention: 12 months; write to legal@cratecore.app to have a message deleted earlier.
A notification about a new message (its text and the sender's address, if given) is delivered to the editorial team in Telegram; the IP fingerprint is not sent there (service list: https://cratecore.app/subprocessors/en/).
3. Device permissions
- Camera: scanning record barcodes and, at your choice, taking your own photos of a record or cartridge. Photos are saved only on the device and are not uploaded to servers. These are collection features — they become available after free registration; before registration the camera is not requested for them. If you decline the camera, you can enter and search for releases manually.
- Microphone: local sound visualization only (Visualizer). Audio is not recorded, not sent, and not stored. The feature is available after free registration; before registration the microphone is never requested.
- Notifications: daily stories, drops, and wishlist alerts, if you allow them (available to a registered account).
- Gyroscope/motion sensors: the on-device speed check (RPM) only; sensor data is not sent to the server. The feature is available after free registration.
- Local storage: local database and cache for offline use.
4. What we do not do
- We do not sell personal data.
- We do not use targeted advertising and do not collect advertising identifiers.
- We do not share user notes, collections, CSV, photos, or audio for model training.
- We do not record or transmit sound.
- We do not upload user photos to servers.
- We do not request, store, or display Discogs images.
- We do not use the live public MusicBrainz API in the production path.
5. Processors and third-party services
We use third-party services to run the app. The current list with details: https://cratecore.app/subprocessors/en/.
Main services:
- Supabase — database, authentication, file storage, server functions. Region: EU (Frankfurt, eu-central-1).
- Google Firebase — push notifications (FCM), analytics, crash reports, app attestation.
- Resend — delivery of service e-mails (sign-in codes).
- Cloudflare — hosting of cratecore.app, CDN, cookieless web analytics for the site, bot protection for the sign-in page (Turnstile), AI illustration generation for stories, inbound e-mail routing for legal@cratecore.app.
- Google Analytics 4 — traffic statistics for the website; runs only with your consent (section 10).
- Google / Apple — account sign-in and app stores.
- OpenRouter + DeepSeek — generation of editorial content from public facts; no user data is sent.
- Contabo — VPS for the content pipeline (n8n); no user data is sent.
Story images and release covers may be loaded by your device directly from Wikimedia and Cover Art Archive / Internet Archive servers — those servers see your IP address, as with any image on the internet.
6. International transfers
The main database is hosted in the EU (Frankfurt). Some providers (Google, Resend, Cloudflare, Apple) may process data outside your country or the EEA, including in the US. Contractual and technical safeguards are used for such transfers, including Standard Contractual Clauses where applicable.
7. Retention and deletion
Detailed table: https://cratecore.app/retention/en/.
In short:
- data before registration (app settings, read marks): on the device only — we hold none of it on our servers;
- account, settings, collection, wishlist, notes: while the account exists;
- import CSV: deleted after import, no later than 24 hours;
- request and security logs: 30 days;
- sync log: 90 days;
- import log: 90 days;
- push tokens: while valid or until account deletion;
- Firebase Analytics: up to 2 months (user/event-level data); Crashlytics: 90 days;
- database backups (when enabled): up to 30 days.
8. Your rights
Depending on applicable law, you may have the right to:
- access your data;
- receive a copy of your data / export;
- correct your data;
- delete your account and data;
- restrict processing;
- object to processing based on legitimate interest;
- withdraw consent where processing is based on consent;
- lodge a complaint with a supervisory authority.
Export and data deletion are available in the app (Account → Privacy & Data), as is turning analytics off. The export returns the account's server data and therefore works after free registration: before registration we hold no server data, and what is on the device stays with you. You can also write to legal@cratecore.app.
9. Deleting your data and account
Deletion is available in the app in any state.
- For a registered account, the "Delete my data and account" button triggers cascading deletion of server data: the authentication account, settings, collection, wishlist, article states, audio chain profile, push tokens, and import files — those of them that exist for you; the app's local data on the device is wiped along with them.
- Before registration the same button is called "Delete this session's data" and wipes the app's local data on this device (settings, read marks, the story cache). There is nothing to delete on the servers: none of your data is there. If a technical anonymous session was opened for reading, it ends together with that data.
Data may temporarily persist in backups (when enabled — up to 30 days) and in technical logs until their retention expires, where necessary for security and audit.
10. Cookies, site analytics, and the website
The cratecore.app website has two cookies of its own, both technical: your colour theme (cc_theme) and your answer to the consent banner (cc_consent, 180 days). Both appear only after an action of yours and hold no identifier. Site features (code sign-in and the read counter behind the one-off invitation to sign in) use the browser's localStorage. Genres picked on the site are not stored in the browser: they go into your account's settings, and only after you sign in. The sign-in page is protected from bots by Cloudflare Turnstile: its script loads only on /login and /ru/login as a strictly necessary security measure (legitimate interest, Art. 6(1)(f) GDPR), needs no consent, and sets no advertising cookies (see the Cookie Policy, section 4.3).
We measure site traffic with two tools. Cloudflare Web Analytics counts page views without cookies: it stores nothing in your browser, does no "fingerprinting", and singles out no individual visitor; the basis is legitimate interest, Art. 6(1)(f) GDPR. Google Analytics 4 sets cookies (_ga, _ga_…), so its script loads ONLY after you press "Accept" in the consent banner: before that, and after "Decline", not a single request goes from the page to Google and no Google cookies appear. The basis is your consent, Art. 6(1)(a) GDPR, and you can withdraw it at any time. Google Analytics advertising features (Google Signals, a Google Ads link, remarketing) are not enabled, and your e-mail and account identifier are never sent to site analytics. Google bases transfers to the US (Google LLC) on the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses. The full cookie list, lifetimes, and how to withdraw consent: https://cratecore.app/cookies/en/.
The CrateCore publication is registered in Google Publisher Center, and pages of the site may appear in Google Search, Google News, and Discover. That is ordinary indexing of an open website: we send Google no data about you, and the Subscribe with Google / Reader Revenue Manager script is not present on the site's pages. If it, or any other third-party script, is ever added, the Cookie Policy will be updated before it is enabled and the script itself will run only after your consent.
11. Content, images, and rights-holder complaints
Editorial images are used under permissible licenses and with attribution. If you are a rights holder and believe content violates your rights, file a complaint under the Copyright Policy: https://cratecore.app/copyright/en/.
Disputed images are taken down no later than 72 hours after the complaint is confirmed.
12. Children
CrateCore is not intended for children under 16 in the EU/EEA or under 13 in the US. We do not knowingly collect children's data. If you believe a child has provided us data, contact us: legal@cratecore.app.
13. Automated decisions
CrateCore may use algorithms for feed personalization, choosing the story for a notification, and abuse protection. These decisions have no legal or similarly significant effect on the user. If paid limits appear, server-side decisions about them can be appealed via legal@cratecore.app.
14. California and other US state rights
CrateCore does not sell or "share" personal data for cross-context behavioral advertising. You can request access, correction, or deletion using the methods in section 8; we do not discriminate for exercising these rights.
15. Changes to this policy
We may update this Policy. We will announce material changes in the app or on the website before they take effect, where required by law.
16. Contact
Data questions and subject rights: legal@cratecore.app
Rights-holder complaints: legal@cratecore.app
