DISCTALEBack to the record ↓

Privacy

Privacy policy

How DISCTALE handles the camera, your records, your location, the listening services and YouTube API Services during the beta.

In force for the DISCTALE beta
Version of 21 September 2026

DISCTALE is provided by Giuseppe Albrizio, independent developer, Milan, Italy, under the Formray name. He is the data controller for the beta. Privacy questions and requests: admin@formray.io. This page describes the app and website; where something is still being defined during the beta, it says so, and the date at the top changes when the page changes.

Website beta invitations and optional newsletter

When you request a beta invitation on this website, we use your email address to deliver the TestFlight link you requested, through Resend. Requesting beta access does not subscribe you to marketing emails or create an app account. Vercel hosts the form and processes technical request information, including IP addresses, to operate the site and limit abuse. The invitation can be shared and is subject to TestFlight availability; the email form is not an Apple access-control system.

Newsletter emails are optional. We subscribe you only if you select the separate newsletter checkbox and then confirm through the email link. Resend stores your address and the version and timestamps of your consent in the DISCTALE newsletter list. We use this information to send DISCTALE news, product updates and launch announcements. You can withdraw consent using the unsubscribe link in every newsletter, or by contacting disctale@formray.io, without losing beta access.

Invitation delivery records are retained according to our email provider’s service retention settings. Newsletter details are retained while you remain subscribed; limited consent and suppression records may be retained afterwards to demonstrate your choice and respect opt-outs. We do not enable email open or click tracking for this flow. Requests to access, correct or erase these details can be sent to disctale@formray.io. Our providers may process data outside the EEA under their applicable data-protection arrangements; see https://resend.com/legal/privacy-policy and https://vercel.com/legal/privacy-policy.

1. What the camera handles

DISCTALE uses the rear camera to read record barcodes, covers and centre labels. Image analysis and text recognition begin on the device. The scanner sends catalogue evidence; the separate, optional AI mode can send selected camera images only after you give its consent.

Recognition requests send catalogue evidence to the DISCTALE backend: barcode values, text read from a centre label or sleeve, and numerical descriptors of the cover. In AI mode, a useful view can be captured automatically; the Photo button is optional. The image and relevant catalogue evidence pass through our backend to OpenAI for analysis. DISCTALE does not save these images, camera text or model answers in its AI accounting records.

OpenAI states that API data is not used for model training unless explicitly opted in. Its default abuse-monitoring retention can include submitted content for up to 30 days, with longer retention for legal or safety reasons. DISCTALE requests no stored response, but does not promise zero retention by OpenAI. See https://developers.openai.com/api/docs/guides/your-data. You can close AI mode at any time and withdraw future image-analysis consent in Profile using Turn off AI photo analysis; this cannot recall an image already processed.

2. Information stored on the device

The app stores your Crate, kept records, completed dig sessions, saved places, app preferences and locally derived Taste information in the app’s storage on the device. A linked Discogs collection is also cached locally so it remains part of the Crate experience.

So that your Crate survives a reinstall or a new phone, the app keeps a copy of your Crate, saved places, imported Discogs collection and collection valuation in your own iCloud account (the private CloudKit database). That copy never passes through DISCTALE’s servers and DISCTALE cannot read it; it exists only if your phone is signed in to iCloud, and it is removed when you delete the app’s data from iCloud in iOS Settings.

Field-test builds can keep diagnostic event files in the app’s storage. Those files are designed to exclude images, raw barcode values, recognised text, audio, media addresses and secrets. They leave the phone only when you choose “Share test history” yourself.

3. Optional location and saved places

Location is optional. When you ask to save a dig place, DISCTALE uses your current location and remembers the small area around that place on the device. If you enable reminders, iOS may monitor those saved regions so the app can ask whether you are digging there.

DISCTALE does not track your route and does not send saved-place location data off the phone.

4. Listening and catalogue services

The DISCTALE backend uses Discogs catalogue data to identify releases. When you have connected your Discogs account, the app reads your collection, your wantlist and record prices directly from the Discogs API on your own device, under your own authorization: the DISCTALE backend signs each of those requests with the application credential it alone holds. Normally it does not receive their content. If direct access is unavailable, the app may use the backend to relay those reads; this fallback is not used when Discogs reports a rate limit. For those reads Discogs receives your device’s IP address, under the Discogs privacy policy. The app streams a short preview when one exists (Apple, through the iTunes catalogue, or Deezer), opens Spotify for playback through your own account, or shows a visible official YouTube player with playback controlled by your autoplay preference.

Those services receive requests under their own terms and privacy policies. DISCTALE does not promise that every recognised release has playable audio. Preview audio is streamed and never stored for offline playback.

5. Accounts and collection linking

You can scan records, use the manual search tools and Try harder and listen through YouTube without a DISCTALE account. An account is required for personal AI investigations and purchases. You can create it with Sign in with Apple or with your Google account; the two work the same way and an account belongs to the sign-in that created it (the same email through Apple and through Google is two separate accounts). We verify the identity token Apple or Google issues and retain a digest of that provider’s identifier, device-bound sessions, the name you share and the email the provider has verified, including a private relay address if you choose Hide My Email with Apple. With Google, the app opens Google’s own sign-in page in the system browser and reads only the identity token; DISCTALE never receives access to your Google account or its data, and stores no Google token. Completing sign-in requires a name and a verified email. If the provider does not supply a name, the app asks you to enter it before continuing. An older account with missing details must complete its profile by signing in again. These details identify your account in your profile and our restricted dashboard, where the sign-in provider is also shown; they are not used for advertising. The device Keychain temporarily retains a name awaiting confirmation so a failed first login does not lose it.

Apple handles payment details. DISCTALE receives and verifies transaction identifiers, product, renewal, expiry and refund status, and associates the purchase with your DISCTALE account. It does not receive your card number or bank details. Restoring a purchase requires the account it belongs to; it does not transfer the purchase to another account.

You can sign out or delete your account inside the app. Deletion clears name, email, the Apple or Google identifier digest and active access, removes linked shared digs, and detaches AI and purchase records from the account. Minimal transaction identifiers and accounting evidence remain to prevent reuse of deleted purchases and reconcile costs; they are not a personal profile. Account deletion does not cancel an Apple subscription: manage it in your Apple subscription settings. Your Crate remains on the phone and in your own iCloud.

Connecting Discogs and importing your collection are optional: the Discogs authorization token is kept in the iOS Keychain on your device and is removed when you unlink from the app. Reads made with that token normally leave from your device; when the connection fallback described above is needed, they pass through the backend. The backend signs requests and stores neither the token nor your collection nor the prices. Price information is shown for at most six hours after it was read.

Beta builds hold an individual access credential in the iOS Keychain. New installations use Apple App Attest to obtain it automatically, without an invitation or Apple account sign-in. Apple verifies the app installation; DISCTALE retains its public key, Apple’s attestation receipt, app version and installation identifier to verify access and prevent replay or abuse. The private key stays on the device. These security records are separate from your DISCTALE account and are not used for advertising or tracking. Short-lived verification challenges expire after five minutes.

6. Shared digs (optional)

Off by default. In Settings → Account you can switch on “Share your digs with DISCTALE”. With it on, when you finish a dig the app sends that dig’s document to the DISCTALE backend: the dig’s identifier, its title if you gave one, the name of the shop if you linked one, when it started and ended, and for each record found its catalogue identity (title, artists, release and master identifiers, year, country, label, format), how it was recognised, whether it played and whether a preview existed. The document also records when you gave consent and which build you were using.

The shared-dig document never contains photos or camera frames, text read by the camera, barcode values, coordinates of saved places, contacts, name or email, preview addresses, tracklists, or the recognition register. The register leaves the phone only through Share test history. A shared dig uses a random device code, and the backend attaches your account if you are signed in. Separate account and AI requests described above can contain other data.

Shared digs are stored in DISCTALE’s own storage in the European Union (Google Cloud, europe-west1) and read only by the DISCTALE dashboard, to see how recognition and listening go dig by dig. They are not shared with third parties and not used for advertising. They are kept until you withdraw consent, and in any case deleted automatically 400 days after they were written. Switching sharing off deletes every dig your phone sent; deleting your account deletes the digs that carried it; you can also write to admin@formray.io.

7. Retention, deletion and requests

In the app you can remove Crate items, kept records, saved sessions, saved places and local diagnostic events. Unlinking Discogs removes the connection and its token from the app. Deleting the app deletes everything it stored on the device; the copy in your iCloud stays until you remove it from iCloud.

The backend keeps recognition evidence and operational logs to diagnose catalogue recognition. Personal AI accounting separately records your account, investigation identifiers, time, status and allowance consumption, without storing the image or the model answer. Provider costs are recorded even when an investigation fails or is cancelled; the restricted dashboard separates those costs from your personal allowance. These account links remain until account deletion; the monthly allowance reset does not erase the history.

Crash and performance reports (see section 9) are kept on the backend for ninety days and then deleted automatically.

Listening recognition (ShazamKit)

Listen is optional and starts only when you open it. With microphone permission, Apple ShazamKit recognizes nearby music using an audio signature. DISCTALE does not save microphone audio or add matches to your Shazam library. Listening stops when a result is obtained, you close the view or you leave the app. ShazamKit is provided by Apple under its privacy policy (https://www.apple.com/legal/privacy/).

After recognition, the artist and song title are sent through the DISCTALE backend to Discogs to find possible vinyl releases. Audio identifies a recording, not a physical pressing. The result and an available Apple Music link are shown in the listening view. Closing Listen does not add a record to your Crate.

8. YouTube API Services

DISCTALE uses YouTube API Services to find the official upload of a recording when no licensed preview exists, and to show it in the official embedded YouTube player. Autoplay YouTube is off by default. When enabled in Settings, every YouTube player opened by DISCTALE starts the video when it appears, including a single result selected by the resolver. When disabled, playback waits for your tap. The player connects to YouTube when it opens; with autoplay enabled, YouTube collects playback data when the player loads, without further interaction. By using these features you agree to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms). Google’s handling of data is described in the Google Privacy Policy (https://policies.google.com/privacy).

What is sent to YouTube: the artist and title of the recording being searched, through the DISCTALE backend. The YouTube feature does not sign you in to YouTube, does not request access to your YouTube account, and therefore holds no YouTube user data; there is nothing to revoke. Playback happens inside the YouTube player under YouTube’s own terms and privacy policy.

What is stored: the public identifiers of the matching videos, with their YouTube title, channel, thumbnail address and length, associated with the catalogue release on the DISCTALE backend so that a record already searched is not searched again. A match is kept for at most 7 days and a “no match” for 24 hours; expired rows are deleted, which keeps every stored item inside the 30-day limit set by the YouTube API Services Developer Policies. On your device, the row you chose for a record stays until you change or reject it, and it is checked against a fresh answer before it is reused. Thumbnails and the player itself are loaded on your device directly from YouTube, under the Google Privacy Policy. The cached catalogue matches do not contain your YouTube account details.

9. Analytics and tracking

DISCTALE contains no analytics or advertising SDK and does not track you across apps or websites. Its privacy manifest declares name, email, user identifiers, purchase history, optional AI photos, feedback, diagnostics, product interaction and coarse location (a shop name in a shared dig). These are declared linked to you, never for tracking. Account, purchase and AI data support app functionality; shared digs also support analysis of recognition and listening.

From version 0.7.7 the app receives Apple’s MetricKit reports about itself: crashes, hangs, launch time, memory and battery-related measurements iOS aggregates about a day at a time. The app sends them to the DISCTALE backend with the app version, iOS version and device model, never with your name, account or any image. They are used only to find and fix defects, are not linked to you, and are deleted after ninety days. You can turn this off in Settings, under “Share diagnostics”.