Spinbund

Privacy Policy

Last updated: August 19, 2026

Spinbound helps you track the vinyl records you've pre-ordered — what's on order, where it is, and when it's coming. This policy explains what we collect, why, who processes it, and the choices you have. Spinbound is operated by Lane Becker.

We built Spinbound to do one job well, not to profile you. We do not sell your data, we do not show ads, and we do not track you across other apps or websites.

What we collect and why

Account information. When you create an account with Sign in with Apple or an email and password, we store the email address associated with your account and a user identifier. If you use Sign in with Apple's "Hide My Email," we only ever see Apple's private relay address. This authenticates you and keeps your data yours.

Your records and order details. We store the artist, album, edition, shop, order number, tracking number, expected, ordered, and arrived dates, and any notes you add for each record you're tracking.

Forwarded order emails (optional). If you set up email forwarding, order receipts you forward to your personal Spinbound address (<handle>@in.spinbound.app; a generated u_<random> handle is the default) are received and processed to extract order details. Alongside the extracted details, we keep the email's subject line, sender address, and a message identifier so you can confirm what was added and see it in your activity history. Because the store writes the subject line, it may include your name. We may also save a product image from the email to use as provisional album artwork until official cover art is found. Spinbound processes the message body transiently but does not retain the full raw body. If the built-in parser cannot read a receipt, a bounded excerpt may be sent to Anthropic as described below. We do not intentionally extract or store shipping or billing addresses or payment details as Spinbound fields, but forwarded receipt text may contain them while it is being processed. We only process mail you send to your Spinbound address; we do not read your inbox.

Push notification token. If you enable notifications, we store the Apple Push Notification service (APNs) device token so we can tell you when a record ships, is out for delivery, arrives, or needs your attention.

Operational metadata and diagnostics. We keep minimal records needed to run the service reliably, including inbound-email events, de-duplication keys, and internal usage counters that enforce cost and rate limits. The app also files diagnostic reports when something fails, such as repeated save conflicts or a tap that produces no response. These reports can include error stack traces, a short buffer of the app's recent internal operations, a structural description of the control you tapped (never the words displayed on screen), the app version, and your device's browser user-agent string. They are filed only after a failure, are rate limited, are read only by us, and are deleted after 180 days or when you delete your account.

Recognition signals (how Spinbound gets smarter). So that receipts from a store one person has taught Spinbound to read can be recognized automatically for everyone, we keep an account-linked server-side log of structural signals about how order emails are processed: which store's domain an email came from, the shape of its layout (format markers, never the email text), whether our reading was confirmed or corrected, and coarse timing such as the number of days between ordering and shipping. When you confirm or correct an album's artist, that album-and-artist name pair may join a shared catalog used to identify the same release for other users. The raw log is otherwise deleted after 180 days, and when you delete your account it is purged immediately. Shared catalog facts describe stores and releases and do not contain your name, email address, order numbers, or collection. When you delete your account, any opaque former-account identifier attached to candidate-store trust metadata is also scrubbed at deletion.

We do not collect location, contacts, browsing or search history, or advertising identifiers. We do not build an analytics profile of how you use the app. The failure-only diagnostic reports described above exist solely so we can identify and fix faults.

Who processes your data

Spinbound relies on a few services to operate. We share only what each needs to do its job:

We do not use advertising networks or third-party analytics SDKs, and we do not share your data with data brokers.

The website

The Spinbound website at spinbound.app has a waitlist form. When you submit it, we store the email address you enter, a source label identifying which form you used, and your browser's user-agent string. We use these only to email you about the TestFlight launch and to detect abuse of the form. We do not add you to another list or share the entry. The site uses no third-party analytics, advertising, or trackers, and its fonts are served from our own domain. To leave the waitlist, email privacy@spinbound.app and we will delete your entry.

Data retention and deletion

We keep your records while your account is active. Arrived records are archived as collection history rather than automatically deleted.

You can delete your account from within the app at Settings → Delete account. This permanently removes the account and its tenant-scoped database data — including your records, forwarding address, device tokens, inbound event history, and diagnostic reports — and also purges your raw recognition signals, scrubs any former-account identifier from candidate-store trust metadata, and removes the receipt-derived cover images tied to your account. Shared store/release facts (which contain no account, name, order, or collection data) may remain. One known minor gap remains: a receipt-derived cover image can be left orphaned in file storage when you delete an individual record (rather than your whole account); it contains no account email, name, order number, or collection link, and we are addressing it. You can contact privacy@spinbound.app to request deletion of any residual artifact.

Security

Data is transmitted over encrypted connections using HTTPS/TLS. A correctly configured native build stores your login session in the iOS Keychain; a native build that cannot access secure storage is treated as a release failure. Access to your database records is restricted by per-account row-level security, and server-side keys that can bypass those restrictions are never included in the app.

Children

Spinbound is not directed to children under 13, or under 16 where applicable, and we do not knowingly collect data from them.

Changes to this policy

If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app.

Contact

Questions or requests about your privacy: privacy@spinbound.app.