← Vinyl Portfolio

Privacy Policy

Effective: April 28, 2026

Vinyl Portfolio ("we", "our", "the app") is operated by Max Rosenthal. This policy explains what information we collect, how we use it, and the choices you have. We treat your data with care because building tools collectors trust starts with respecting their privacy.

Quick summary: We collect what we need to run the app (sign-in info, your collection data, photos you upload, optional purchase locations). We do not sell your data. We do not use advertising networks. We do not track you across other apps or websites.

1. Information We Collect

1.1 Account information

When you sign in via Apple, Google, or email, we receive your email address and (for OAuth providers) a unique provider-issued user ID. If you choose Apple's Hide My Email option, we receive Apple's relay address instead of your real one. We use this only to authenticate you and to send essential account-related communications.

1.2 Profile information

During profile setup you provide a display name (required) and may optionally provide a bio, a location string (e.g. "Los Angeles, CA"), and a profile photo. Your display name is visible to other Vinyl Portfolio users; your bio, location, and photo are visible to users who can view your collection.

1.3 Collection and wishlist data

Information about records you add to your collection or wishlist — including artist, title, label, catalog number, purchase price, purchase date, condition, personal notes, and any photos you upload of your records. This data is private to your account by default. You may optionally make your collection visible to other Vinyl Portfolio users via your privacy settings.

1.4 Camera and photos

The app uses your device camera to scan record barcodes and capture record cover or label images. Images are processed to identify the record (via our AI identification service) and stored with the corresponding record entry. You may delete any uploaded photo at any time from the record's detail view.

1.5 Location data (optional)

If you choose to add a purchase location to a record, the app may use your device's location services or accept a location you type in manually. Locations are stored with that record only and are visible only to you (and to viewers of your collection if you've made it visible). The app does not track your location continuously.

1.6 Usage and diagnostic data

We collect basic diagnostic information to keep the app working: error reports, performance metrics, and feature interaction events. This data is associated with your user ID but is not used for advertising or cross-app tracking.

2. How We Use Your Information

3. Third-Party Services

We use the following third-party services to provide the app. Each receives only the minimum data needed for the integration described.

3.1 Supabase

Hosts our authentication, database, and file storage backend. Supabase processes account credentials, profile data, collection data, and uploaded images on our behalf. See supabase.com/privacy.

3.2 Discogs

Provides record metadata (artist, title, year, pressing details) and marketplace pricing reference data. We send Discogs anonymous catalog numbers, barcodes, and search queries — no personal information. See discogs.com/help/privacy.

3.3 eBay

Provides current marketplace listing data used to compute pricing estimates and "standout listings" for wishlist items. We send eBay anonymous search queries and catalog numbers — no personal information. See ebay.com privacy policy.

3.4 Anthropic

Powers the AI Curated recommendations feature (a Pro tier feature). When you use AI Curated, we send Anthropic an anonymized prompt containing your collection's pricing summary and curatorial preferences — no email, name, or personally identifying details. See anthropic.com/legal/privacy.

3.5 Mapbox

Renders the purchase location maps shown on individual record details. Mapbox receives the latitude/longitude coordinates being rendered (which you provided to the app). See mapbox.com/legal/privacy.

3.6 Netlify

Hosts our website and serves the web application. Netlify processes standard web request data (IP address, user agent) when you visit vinylportfolio.com. See netlify.com/privacy.

4. What We Do NOT Do

5. Data Storage and Security

Data is stored on Supabase's infrastructure (US region) and protected by industry-standard encryption in transit (TLS) and at rest. Account credentials are never stored in plaintext. Authentication tokens use short-lived JWTs that automatically expire.

No security measure is perfect, and no online service can guarantee absolute security. We commit to notifying affected users without undue delay if we ever discover a data breach affecting their information.

6. Your Rights and Choices

6.1 Account access

You can view and edit your profile information, collection data, and privacy settings from inside the app at any time.

6.2 Data export

You can request a JSON export of your collection and profile data by emailing support@vinylportfolio.com. We respond to export requests within 30 days.

6.3 Account deletion

You can delete your account from the Profile section of the app. Deletion removes your collection, wishlist, profile data, and uploaded images from our active database immediately. Backups are retained for up to 30 days for disaster recovery, after which all your data is purged permanently.

6.4 Email contact for privacy questions

For any privacy-related questions, requests, or concerns, email support@vinylportfolio.com.

7. Children's Privacy

Vinyl Portfolio is rated 4+ and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us so we can delete it.

8. International Users

The app is operated from the United States. If you use the app from outside the US, you understand that your information will be transferred to and processed in the US, where data protection laws may differ from those in your country.

9. California Privacy Rights (CCPA)

If you are a California resident, you have the right to know what personal information we collect, the right to request deletion of your information, the right to opt out of the sale of personal information (we do not sell), and the right to non-discrimination for exercising these rights. To exercise any of these rights, email support@vinylportfolio.com.

10. Changes to This Policy

We may update this policy as the app evolves. When we make a change that meaningfully affects how we handle your data, we'll post the updated policy here with a new effective date and notify users via the app or email when material changes occur.

11. Contact

Vinyl Portfolio
Operator: Max Rosenthal
Email: support@vinylportfolio.com
Website: vinylportfolio.com