Last updated: 27 July 2026
WaxID identifies vinyl records from a photo of the record's label. This policy explains, in plain language, what data the app sends to our server, what happens to it, and how to get it deleted.
Photos of record labels. When you scan a record, the photo you take is sent over an encrypted connection (HTTPS) to our server, which forwards it to a third-party AI service — Google (Gemini) or Anthropic (Claude) — to read the text on the label. That text is used to find the matching release in our music database. The photo is of a record label, but a photo can incidentally capture other things; frame your scans accordingly.
We also keep a scaled-down copy of each photo you submit for scanning (long edge 1568 pixels, camera metadata such as location EXIF removed) on our server (Hetzner Object Storage, EU — Falkenstein, Germany), together with the text we read from it and the match result, to review and improve matching quality. This includes photos we could not match or that were rejected as not being a record.
Scan text and results. The text read from your photo and the release we matched it to are processed to answer your scan and stored alongside the photo copy described above. If you report a wrong match in the app, we also store which release you picked instead (or that none matched). Stored scan records carry your app identity ID (below) so we can find and delete your scans when you ask.
App identity and scan allowance. When the app registers, Apple's App Store provides a signed proof of the download; from it we derive a stable random identity ID for your Apple account's use of WaxID. We store that identity, the per-installation access token (hashed), how many scans you've used each day, and — if you subscribe — the subscription's App Store transaction identifiers, product, and expiry date so we can honor your subscription's allowance. None of this contains your name, email, or Apple ID; we cannot identify you from it, and Apple's identifiers never leave the server.
Discogs account (optional). If you connect your Discogs account, we store your Discogs username and an access token so the app can act on your Discogs account when you ask it to — adding records to your collection or wantlist, or creating marketplace listings. We never see your Discogs password. Discogs' own privacy policy applies to your Discogs account.
We do not collect your name, contacts, location, advertising identifiers, or any analytics beyond the above. We do not sell data. We do not use your data for advertising.
Photos are processed by Google Gemini or Anthropic Claude via their APIs to transcribe the label. We send only the photo (scaled down, with camera metadata such as location EXIF removed) — no account information. These providers process the image to return the transcription; their API terms state that API data is not used to train their models. Their policies: Google · Anthropic.
Email olibroughton@gmail.com and we will delete any data associated with your scans or account, normally within 7 days. Include your identity ID (shown in the app's settings) so we can find your scan records; if you connected Discogs, your Discogs username also works. Deletion covers the stored photos, scan records, outcome reports, identity, device, quota, and subscription rows, and any Discogs link.
All traffic between the app and our server uses HTTPS. Session tokens are stored hashed on the server. The server does not expose its databases to the internet.
If this policy changes in a way that affects what we collect or how long we keep it, we will update this document and the date above before the change takes effect.