Privacy Policy

Spinventory Privacy Policy

Effective date: 2026-06-03 Last updated: 2026-06-03

This Privacy Policy explains how the Spinventory mobile application (“Spinventory,” “the app,” “we,” “us”) handles your information. Spinventory is operated by Joshua Campbell, an individual developer based in the United States.

If you have questions about this policy, contact: [email protected]


Summary, in plain English

Spinventory is a tool for managing your personal vinyl record collection. We’ve designed it to keep your data on your device by default. We don’t sell your data. We don’t run ads. We don’t share your collection with anyone. The only information that leaves your device is what’s needed for the app to work — primarily, communicating with Discogs to sync your collection — plus optional, anonymous crash reports you can turn off in Settings.


1. Information we collect

Information stored only on your device

The following information is stored locally on your phone using Android’s secure storage and standard app storage. It is not transmitted to us or to any Spinventory-controlled server:

  • Your record collection — titles, artists, labels, years, formats, conditions, notes, play counts, prices, locations within your home, custom groups, scan history, and any other metadata you record about your records.
  • Your Discogs OAuth access tokens — these are stored in the Android Keystore via Expo SecureStore and are used solely to authenticate requests you initiate to the Discogs API.
  • Your app preferences — sort order, display settings, dark/light mode, and similar.
  • Cached metadata — album artwork URLs, tracklists, and release details retrieved from Discogs to display while you browse.

Information transmitted to third parties when you use specific features

  • Discogs API (https://www.discogs.com): When you sign in with Discogs, sync your collection, fetch pricing, add or remove records, or update your wantlist, the app communicates directly with Discogs’s servers on your behalf. Spinventory uses Discogs’s official OAuth 1.0a authentication, and the requests are signed with credentials stored only on your device. Your interaction with Discogs is governed by Discogs’s own privacy policy. We do not see or store this traffic.
  • MusicBrainz API (https://musicbrainz.org): When the “surname-style” artist sorting feature is enabled, the app sends artist names to MusicBrainz to look up their canonical sort form (e.g. “Davis, Miles” instead of “Miles Davis”). Only the artist name is sent. No personal information is included. MusicBrainz’s privacy policy applies to this lookup.

Information collected via crash reporting (optional, opt-out available)

If you leave the “Send crash reports” setting enabled (it is on by default), the app uses Sentry (operated by Functional Software, Inc.) to report unhandled errors and crashes. Crash reports include:

  • The error message and stack trace
  • The app version and device model (e.g. “Pixel 8”)
  • The operating system version (e.g. “Android 14”)
  • Anonymous identifiers used solely to group reports from the same installation
  • A trail of recent in-app actions (“breadcrumbs”) leading up to the crash, with sensitive values scrubbed

Crash reports do not include your collection data, your Discogs username, your real name, your location, or your API tokens. Reports are automatically discarded if Sentry’s filter detects content that looks like a token or key.

You can turn crash reporting off any time in Settings → Privacy → Send crash reports.

Information collected through Google Play

Google Play Services collects standard installation and crash diagnostic data when you install or use the app, including approximate install counts, device type, and crash logs. This is controlled by Google’s own privacy policy and is independent of Spinventory.


2. Information we do NOT collect

We want to be explicit about what Spinventory does not do:

  • No advertising. Spinventory shows no ads and does not include any advertising or analytics SDKs.
  • No location tracking. The app does not request, collect, or use your geographic location.
  • No contacts, calendar, photos, or microphone access. The app does not read your contacts, calendar, photo library, or microphone, even if Android lists these as available permissions to the app.
  • No data sale. We do not sell, rent, or share your information with data brokers, marketers, or any third party for monetary or non-monetary consideration.
  • No profile-building. We do not build advertising profiles or behavioral profiles of you.
  • No account on our servers in v1.0. Spinventory v1.0 does not include any Spinventory-operated user account, login, or cloud storage. Your collection lives only on your device unless and until you choose to enable the cloud sync feature described below.

3. Camera and storage permissions

Spinventory requests these Android permissions:

  • Camera. Used to scan record barcodes and location QR codes. Camera frames are processed entirely on your device and are not stored, transmitted, or retained.
  • Storage. Used to read and write CSV exports, PDF labels, and JSON backups when you initiate an export from the app. Files are written to your device’s local storage and are only shared if you explicitly share them through the system share sheet.

You can revoke these permissions at any time in Android’s system settings.


4. Cloud sync (coming soon)

A future version of Spinventory will offer an optional cloud sync feature so you can keep your collection in sync across multiple devices and protect against device loss. This feature is not enabled in v1.0.

When cloud sync becomes available, it will:

  • Sign you in to a Spinventory-operated server using your existing Discogs OAuth login (you will not need a separate password or account).
  • Sync the same collection data described in Section 1 to a server operated by Joshua Campbell on shared hosting infrastructure based in the United States.
  • Never store your Discogs OAuth tokens on the server. Tokens are used once to verify your identity and discarded.
  • Issue a per-device API key (stored in your device’s secure storage) so you can revoke any single device without affecting the others.
  • Allow you to view and revoke any signed-in device from within the app.
  • Automatically revoke API keys that haven’t been used in 6 months as a security measure.
  • Provide an explicit option to delete all your synced data from the server.

When this feature ships, this policy will be updated with the precise data flows, server location, and retention details. You will be notified of the update before the feature is enabled.


5. How long we keep your information

  • Data on your device is retained for as long as Spinventory is installed. Uninstalling the app removes all locally stored data, including your collection, your Discogs tokens, and your preferences.
  • Crash reports sent to Sentry are retained per Sentry’s standard retention schedule (currently 90 days for most plans).
  • Cloud sync data (when enabled in a future version) will be retained as long as your account is active. You will be able to delete it on demand.

6. Children’s privacy

Spinventory is not directed to children under 13 and we do not knowingly collect information from children under 13. If you believe a child has provided us with information, please contact us at [email protected] and we will take appropriate action.


7. Security

We use industry-standard practices to protect the information Spinventory handles:

  • OAuth tokens are stored in Android’s hardware-backed Keystore via Expo SecureStore.
  • Network requests to Discogs, MusicBrainz, Sentry, and (in the future) Spinventory cloud sync are made over HTTPS.
  • API keys (when cloud sync is enabled in the future) will be stored on the server as SHA-256 hashes; the plaintext is never persisted server-side after issuance.

No method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.


8. Your rights and choices

Because v1.0 stores your data only on your device, most of your rights are exercised through the app itself:

  • Access: Open the app to view your data at any time.
  • Export: Use the export options in Settings to download your collection as CSV, JSON, or PDF.
  • Correction: Edit any record, location, or setting directly in the app.
  • Deletion: Uninstalling the app deletes all local data. You can also clear individual sections from Settings.
  • Opt out of crash reporting: Settings → Privacy → Send crash reports.
  • Revoke Discogs access: Visit https://www.discogs.com/settings/applications and revoke the Spinventory authorization. The next time you launch the app, you can sign in again or stay signed out.

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to request information about the personal data we hold about you, to request its deletion, and to opt out of the sale of personal information. Spinventory does not sell personal information. To make a CCPA request, contact us at [YOUR_CONTACT_EMAIL].

If you are in the European Economic Area, the United Kingdom, or another region with applicable data protection laws, you may have additional rights under those laws. Contact us to exercise them.


9. Third-party links

The app may display content fetched from Discogs that includes external links (for example, to album marketplace pages). When you tap an external link, you leave the app and your interaction with the linked site is governed by that site’s policies, not this one.


10. Changes to this policy

We may update this Privacy Policy from time to time. When we make a material change — for example, when cloud sync launches — we will update the “Effective date” at the top, post the new policy at this URL, and notify users of significant changes through an in-app notice or release notes.

Continued use of the app after a policy update constitutes acceptance of the revised terms.


11. Contact

Spinventory is an independent app developed by Foobar Studios.

For privacy questions, data requests, security reports, or general concerns:

Email: [email protected]


Spinventory is not affiliated with, endorsed by, or sponsored by Discogs or MusicBrainz. “Discogs” and “MusicBrainz” are trademarks of their respective owners and are used here only to describe the integrations the app provides.

Scroll to Top