Privacy Policy

Last updated: October 1, 2026

This policy describes how RSD Tracker handles information when you browse releases, maintain a Want List, enable notifications, or use optional social features.

Information we handle

Browsing does not require an account. If you enable push notifications, the service stores an app installation identifier, APNs device token, bundle identifier, and app version so it can deliver updates.

If you choose to sign in, the service may store a stable account identifier supplied by Apple, your verified email address and display name, an Argon2id password hash, and passkey public credentials (including credential identifiers, counters, device/backup state, and authenticator model identifiers). RSD Tracker never receives the biometric or device PIN used to unlock a passkey. Apple account-change notices are signature-verified; only one-way hashes of their opaque identifiers and payload are retained for replay prevention and lifecycle processing. The service also stores your hosted Want List, crews, memberships, assignments, shopping status, selected price limits, activity, notifications, and sharing preferences.

If you choose to submit app feedback, the service receives your selected report type, title, description, app version/build, iOS version, a random submission identifier, and a random installation identifier. The network request also exposes an IP address to the service. Feedback does not require an account and does not automatically include account details, device model, location, logs, or attachments. Avoid including personal or sensitive information in your text.

How information is used

Information is used to operate release tracking, verify and recover accounts, synchronize your account, process Apple authorization, relay, and account-deletion changes, coordinate shopping crews, show shared lists you create, prevent abuse, secure sessions, and send requested notifications. Private notes are not included in public shared-list responses. Price limits are shared only when you explicitly choose to include them.

Sharing and service providers

Crew information is visible to members of that crew. A shared-list link is visible to anyone who receives it until it expires or is revoked, subject to the options you chose. Infrastructure, email-delivery, Apple authentication, and analytics providers process data only as needed to provide their configured service. RSD Tracker does not sell personal information.

The website may use Plausible Analytics to collect aggregate usage information, such as page views and selected feature interactions. The tracker is configured not to send search terms, query strings, precise location, release or crew identifiers, invitation tokens, notes, email addresses, or account handles. Analytics can be disabled by the operator without rebuilding the website.

When you explicitly submit feedback, its type, title, description, app version/build, iOS version, and a random receipt are sent to a private GitHub issue tracker for support. Repository collaborators can read those reports. Your IP address, installation identifier, submission identifier, and account identity are not included in the GitHub issue. Bugs and feature requests go to the app tracker; data issues go to the server tracker.

Storage, retention, and security

Data may be stored on your device, in your private iCloud account when enabled, and on RSD Tracker servers for hosted social features. Session, verification, password-reset, passkey-challenge, invite, and share tokens are stored in hashed form on the server. Verification, reset, and passkey challenges expire and are single-use. An unverified password-only signup may be removed after seven days when it has no live verification link. Other data is retained while your account or feature remains active and for a limited period needed for security, backups, and legal obligations.

The feedback service does not keep a separate copy of report text in its database. It retains submission digests and keyed hashes of installation identifiers, a report digest, a random receipt, the configured destination, delivery state, and timestamps long term to prevent duplicate tickets. These minimal records do not automatically expire. Short-lived hashed rate-limit records expire after their abuse-limit window or an upstream cooldown. Submitted text remains in GitHub according to our support-retention policy; deleting your app account does not automatically delete account-free feedback reports. Contact support with your receipt to request review, redaction, or removal. Infrastructure access logs and backups follow their respective retention policies.

Your choices

You can use core browsing without an account, disable notifications in system settings, control whether crew members may assign releases directly to you, and revoke active shared links. You can permanently delete your account from Profile in the RSD Tracker app. Deletion revokes active sessions and public links, removes your profile, authentication credentials, hosted Want List, memberships, requests, and other private account data, and deletes every crew you own, including its shared plan and member content; crews are not automatically transferred. For an Apple-linked account, RSD Tracker first uses a fresh Sign in with Apple authorization to revoke the Apple grant. Limited one-way hashes may be retained for security, replay prevention, and provider account-change processing, together with records required by law.

Children

The hosted social service is not directed to children under 13, and RSD Tracker does not knowingly collect their personal information.

Contact

Questions, access requests, account export, or account deletion requests can be sent to support@austinh.net.

RSD Tracker is not affiliated with or endorsed by Record Store Day.