Privacy Policy — Metal Vault
Last updated: May 2, 2026
Metal Vault ("we", "our", "the app") is operated by SkuDev, a Poland-based independent developer (Mateusz Skura). This policy explains what data we collect, why we collect it, and how we keep it safe.
1. Information We Collect
Account information
- Email address — for sign-in via email magic link or OAuth
- Display name and avatar — optional, only if you set them
- Discogs username and OAuth access token — only if you connect your Discogs account; the token is encrypted at rest and used only to read your own Discogs collection and wantlist
Collection data
- Vinyl records you add — including release information, purchase price, condition grading, personal notes
- Photos you upload — sleeve and condition photos for your collection (Pro tier)
- Watchlist items — albums you want to buy
- Followed artists — for release notifications
Usage data
- Page views and interactions — to improve the app
- Device location — only if you grant permission, for "concerts near me" feature; coordinates only, never your address. Reverse-geocoded via OpenStreetMap Nominatim
- Device information — browser type, operating system, screen size
- IP address — used only at request time for abuse-prevention rate limiting; not persisted to long-term storage
- Push notification subscription endpoint — only if you enable push; this is a vendor-supplied URL (Apple/Google/Mozilla) used to deliver notifications you've opted into
Payment data
If you subscribe to Metal Vault Pro:
- Payments are processed by Google Play Billing (Android) or Stripe (web). We never see or store your full card number.
- We store: subscription status, plan type, renewal date, and a customer ID provided by the payment processor.
2. How We Use Your Data
- To provide the core service: tracking your vinyl collection, syncing with Discogs, generating insurance reports, sending price alerts
- To send notifications you've opted into (concert alerts, price alerts, weekly digest)
- To improve the app — fix bugs, understand which features people use
- To process payments and manage subscriptions
- We never sell your data to third parties
- We never use your data for advertising profiles
3. Third-Party Services
We share limited data with these services to make the app work:
- Supabase — database and authentication (data stored in EU)
- Discogs — to look up release info and prices (we send only the queries needed)
- Ticketmaster Discovery API — for upcoming concert events lookup
- Setlist.fm — for past concert setlists
- OpenStreetMap Nominatim — for reverse geocoding ("concerts near me")
- Stripe — payment processing on the web
- Google Play Billing — payment processing inside the Android app
- RevenueCat — subscription state management on top of Play Billing / Stripe
- Resend — email delivery (weekly digest, account emails)
- Spotify API — optional, only used for share images and the persona widget
- eBay Browse API — optional, used to show "available now" prices in the album view
- Sentry — error reporting (request bodies and headers are stripped before transmission)
- Vercel — hosting and content delivery
Each of these providers has their own privacy policy and security practices. We choose providers that offer GDPR-compliant infrastructure.
4. Data Storage and Security
- All data is stored on secured servers in the European Union (Supabase EU region)
- All connections use HTTPS encryption
- Photos are stored in private cloud storage; only you can access yours
- Database access uses row-level security — your data is isolated from other users
5. Your Rights (GDPR)
If you're in the EU/UK, you have these rights:
- Access — request a copy of all data we have about you
- Correction — fix wrong data
- Deletion — delete your account and all associated data
- Portability — export your collection in CSV format (available in Profile → Export)
- Objection — opt out of certain data processing
- Complaint — file a complaint with your data protection authority
To exercise any right, email us at the address below. We respond within 30 days.
6. Data Retention
- Active accounts: we keep your data as long as your account exists
- Deleted accounts: data is removed within 30 days of account deletion
- Payment records: retained 7 years (legal requirement)
- Backups: may exist for up to 90 days after deletion before final purge
7. Cookies and Local Storage
We use:
- Authentication cookies — to keep you logged in
- Local storage — for offline features and your preferences
We do not use third-party tracking cookies, analytics tags, or advertising pixels.
8. Children's Privacy
Metal Vault is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has signed up, contact us and we will delete the account.
9. Changes to This Policy
If we make material changes, we'll notify you in-app and via email at least 30 days before the change takes effect.