Waxwall Privacy Policy
Effective: October 5, 2026
Who we are: Waxwall is operated by John Rivera ("we", "us"), New York, United States.
Contact: support@waxwall.app
Waxwall is an app for cataloguing your vinyl records and sharing your record wall with other collectors. This policy explains what we collect, why, who processes it for us, how long we keep it, and how to delete it.
What we collect
Account information
- Your email address and password. The password is stored by our authentication provider as a one-way hash; we never see it.
- An internal account ID.
Profile information you choose to add
- Display name, handle, bio and location (free text you type; we do not use your device's location).
- Your record wall and room layout.
- Profile photo, if you add one.
- Your profile is public: other people, including people without an account, can see your display name, handle, bio, location, wall, lists and posts.
Your records
- Your crate (the records you own and the pressing of each copy).
- Your wishlist, lists and favorites.
- Collector notes, which only you can see.
Photos you take with "Scan your copy"
- A photo of the front of a record you own, taken with the camera.
- We remove location and camera details (EXIF) and keep the photo with your copy.
- If it passes our safety check and matches the album, it becomes a community jacket that other collectors can see and choose as artwork. You can delete it at any time in Settings → My jacket photos.
Social activity
- Posts and their captions, comments, likes, who you follow and who follows you, and accounts you block.
- Posts, comments and likes are visible to other users, except people you have blocked or who have blocked you.
Reports
- If you report a post, comment or profile, we keep the report, the reason and any details you add.
- The person you report is not told who reported them.
Discogs connection (optional)
- If you connect Discogs, we store an access token (encrypted) and your Discogs username.
- We copy your Discogs collection and wantlist into your Waxwall crate and wishlist.
- You can disconnect at any time.
Activity needed to run the service
- To keep catalog lookups within the limits our data providers set, we record per account:
- how many searches you make each minute
- which albums and artists you searched for or opened, by day
- We also keep standard server logs (IP address, time, request) for security and debugging.
What we do not collect
- No advertising identifiers.
- No contacts.
- No precise or background location.
- No health or financial data.
- No browsing history outside Waxwall.
- We do not track you across other companies' apps or websites, sell your data, or use it for advertising.
How we use it
- To run Waxwall: your account, crate, wall, posts and the social features you use.
- To keep the community safe:
- checking jacket photos for unsafe content
- reviewing reports
- enforcing blocks and our Terms
- To keep the service working: respecting data-provider rate limits, preventing abuse and fixing problems.
- To contact you about your account: sign-in emails, password resets and replies to your support requests.
Who processes your data for us
We share data only with the service providers below, and only so they can provide their service to us. We require each to protect it at least as well as this policy does.
| Provider | What they do | What they receive |
|---|---|---|
| Supabase, Inc. | Hosts our database, authentication, file storage and server functions (servers in the United States, AWS us-west-2) | All the account, profile, record, photo and social data above, plus server logs |
| OpenAI, L.L.C. (third-party AI) | Checks jacket photos for unsafe content (OpenAI moderation API) | A 320-pixel copy of each jacket photo you save, with no name, email or other account details. Waxwall asks for your permission before the first photo. Under OpenAI's API data policy, API inputs are not used to train its models by default and may be retained for up to 30 days for abuse monitoring. |
| Discogs (Zink Media, LLC) | Only if you connect it: provides your collection and wantlist; provides public release data for everyone | Your Discogs authorization, plus the catalog lookups you trigger. Waxwall uses Discogs' API but is not affiliated with, sponsored or endorsed by Discogs. |
| Apple | App Store distribution. Your device also fetches 30-second song previews from Apple's iTunes service. | Preview requests include the album or artist name and your IP address, not your Waxwall account |
| MusicBrainz / Cover Art Archive (MetaBrainz Foundation, Internet Archive) and Wikimedia / Wikidata | Public album data, cover images and artist photos | Your device or our server requests public catalog data and images. These requests include an IP address and the album or artist name, never your account details. |
| Spotify | Album links only; our server looks up public album links | No personal data |
| Resend | Delivers account emails (sign-up confirmation, password reset) | Your email address and the email's contents |
| Cloudflare | Hosts our website and our domain's DNS | Standard request data (IP address, browser) when you visit waxwall.app |
| Expo (650 Industries) | Tools we use to build the app | The app does not send your data to Expo |
We may disclose information if the law requires it, to protect people's safety, or as part of a sale or merger of the service. In a sale or merger, this policy will continue to apply to your data.
How long we keep it
- Account, profile, records, photos and social activity: until you delete them or delete your account.
- When you delete your account: we delete the account and the data above, including stored photos, as soon as you confirm. If a step has to be retried, it finishes within 7 days. Our provider is configured to keep daily database backups for seven days, so deleted data may remain in those backups until the provider removes them through its normal backup rotation. Public images may stay in internet caches for up to an hour.
- Reports you sent about others: kept without your account attached until they are resolved, then deleted within 1 year.
- Searches and daily lookup records: deleted after 30 days.
- Server logs: kept by our provider for 7 days.
Your choices and rights
- Edit your profile in Settings at any time.
- Delete photos: Settings → My jacket photos.
- Disconnect Discogs: Settings → Discogs. To also revoke access on Discogs' side, open Discogs → Settings → Applications.
- Block anyone from their profile, post or comment, and manage blocks in Settings → Privacy & safety → Blocked accounts.
- Delete your account in the app: Settings → Account → Delete account. This deletes your account and the data described above.
- Withdraw photo-check permission: stop using "Scan your copy". We only send photos you choose to save.
- Access, correction, export or other requests: email support@waxwall.app. We answer within 30 days. Depending on where you live (for example, the EU/UK under the GDPR or California under the CCPA/CPRA), you may have the right to:
- access your data, correct it, delete it, port it, or object to or restrict its use
- complain to your local data protection authority
We do not sell or "share" personal information for cross-context behavioral advertising.
- Legal basis (EU/UK): we process your data to perform our contract with you (running Waxwall), with your consent (jacket photo checks; you can stop at any time), and for our legitimate interests (safety, security and keeping the service running).
Children
Waxwall is not for children under 13, and you must be at least 13 to create an account (or older if your country requires it). If we learn that a child under 13 has an account, we delete it.
Security
Data travels over HTTPS. Discogs tokens are encrypted at rest. Access to production data is limited to the operator. No system is perfectly secure; tell us at support@waxwall.app if you find a problem.
Changes
If we make a material change, we will update this page and its effective date and tell you in the app.
Contact
John Rivera · support@waxwall.app