Privacy Policy
What we collect, and why.
Teca is operated by LOUIE & TODD INC. ("we", "our"). This policy covers both the Teca iOS app and the teca.wtf landing page.
Data we collect
- Account identifier. When you sign in with Apple, we receive an Apple-issued user ID and, if you choose to share it, your name and a relay email. We use this to identify your account and sync your collection across devices.
- Your collection & wantlist. Records, crates, wantlists, setlists, and notes you add to Teca, including albums you import from Discogs, Spotify, or Apple Music, are stored on our server so they follow you between devices. You can delete any of this at any time from inside the app.
- Discogs link (optional). You can import by entering your public Discogs username, or sign in on Discogs' own site. When you sign in, we store the access token Discogs issues, never your Discogs password, and use it to read your Discogs collection and wantlist. If you turn on "Send changes back to Discogs" (off by default), we also use it to add the records and wants you add in Teca to Discogs, and to remove only the ones Teca added. Disconnect anytime from Discogs settings.
- Spotify link (optional). Spotify access is by request. To ask, you enter the email you use for Spotify. We store it with your request and add it by hand in Spotify's developer dashboard so Spotify lets your account connect. Once you're added, you sign in on Spotify's own site. We store the access token Spotify issues, never your Spotify password, and use it to read your saved albums, tracks, playlists, and top tracks, so Teca can suggest records and you can import them into your wantlist or collection. Imported records are stored like any other entry in your account. Disconnect anytime from the Account screen in the app or from Spotify's app settings.
- Apple Music link (optional). If you connect Apple Music, iOS asks your permission first. Teca then reads your Apple Music library (albums, songs, and playlists) and your recently played songs, to suggest records you might want on vinyl and let you import them. We store the access token Apple issues for Teca and your Apple Music country, and the albums you choose to import are stored like any other entry in your account. Our server does not store your listening history. Disconnect anytime from the Account screen in the app.
- Notifications (optional). Teca asks to send notifications only after you tap "Notify me", for example to hear when Spotify access opens or when Teca has record stores near you. If you allow them, we store the push token Apple or Google issues for your phone (with the phone's platform and Teca's build number) and the topics you asked for. A record-store reminder stores only the first 3 digits of the ZIP code you typed (the postal region), never the full ZIP. The token is used only to deliver those notifications, through Apple (iPhone) or Google Firebase Cloud Messaging (Android). We also note which of our notifications reached your account, so none is sent to you twice. Turn topics off in Account > Notifications and nothing more is sent about them; signing out removes your phone, and deleting your account removes the phone, the topics and that record.
- Scan photos and videos. When you use AI Scan, the sleeve photo or a short scan video (up to about 10 seconds) is sent through our server to Google Gemini, a third-party AI service, for identification. Photos and videos are processed per request only and are not retained on our server.
- Feedback you send. When you use Share feedback (or answer the one time Teca asks), your star rating and anything you type go to PostHog, with your phone model, its system version and the app version, so we can reproduce a problem. Screenshots you choose to attach (up to three) are stored on our server with your account, re-saved without their location or other photo metadata, seen only by the Teca team, and deleted when you delete your account. Teca also keeps a count of records you add by hand and whether it has asked you, so it asks at most once.
- Product analytics, error reports and logs in the app. Release builds of the Teca app send usage events to PostHog, our product-analytics processor. They cover which screens you open and what you tap (for example scan started, record added, crate created, a filter or sort changed, how far down a list you scrolled); what you type into Teca's search and filter fields, sent once you stop typing; the artists and titles of records you add, scan or import (a Discogs, Spotify or Apple Music sync is sent as one summary listing up to 100 records); error messages you see; crash reports, sent the next time you open the app; and warning or error log lines such as a failed request. Our server sends PostHog the same kind of summary for the Discogs syncs it runs for you, plus its own error reports. When you are signed in all of this is identified by your Apple-issued Teca user ID so we can see how the app is used across sessions. We may occasionally ask a short in-app survey; answering is optional, and your answers go to PostHog too. No advertising identifiers, no ad networks, and no tracking across other companies' apps or websites. Development and test builds send nothing.
- Waitlist signups. On the landing page we store your email and (optionally) phone number, plus the page that referred you, your browser's user-agent string, and a salted one-way hash of your IP address (we don't keep the raw IP) used to block abuse. Only used to email or text one note when early access opens. We keep waitlist entries until the app ships or you ask us to delete yours, whichever comes first.
- Product analytics on this website. The landing page and the support pages load PostHog, a product-analytics tool, which sets a first-party cookie holding a random visitor ID and records page views, clicks and other interactions, the referring page, and coarse technical details (browser, operating system, and an approximate city/country derived from your IP). We use it to see how many people reach the page and how many finish signing up. When you successfully join the waitlist, we pass your email to PostHog as the identifier for your visitor profile, so those events are linked to you. If you send a report or feedback from the support page, your answers go to PostHog too, with your email only if you add one so we can reply. Links from the app to this website carry a pseudonymous ID, so support can connect your web visit to your app account; it is not your name or email. PostHog processes this data on servers in the United States, and can also record a replay of your visit to this page if we switch that feature on. Analytics are not loaded when the page is opened on localhost, and we don't run ad networks, ad SDKs, or cross-site advertising trackers. These events live in PostHog under our plan's retention settings; we don't keep a separate copy.
- Basic request logs. Standard server access logs (request time, path, status, hashed IP) retained ≤ 30 days for abuse prevention and debugging.
What we don't collect
- No ad SDKs, ad networks, or cross-site advertising trackers.
- No advertising identifiers (IDFA) and no tracking of you across other companies' apps or websites.
- No selling or renting of your data. We share it only with the processors listed below.
- No precise location, contacts, microphone, or health data.
- No camera feed from the AR crate view. It stays on your device.
Who processes your data
- Railway: application hosting + Postgres database.
- Apple: Sign in with Apple, Apple Music if you connect it, and notifications to iPhones if you turn them on.
- Google Firebase Cloud Messaging: notifications to Android phones, only if you turn them on.
- Discogs: only if you connect your account.
- Spotify: only if you request access (we add your email in Spotify's dashboard) or connect your account.
- Google Gemini: only for the sleeve photos and scan videos you submit.
- PostHog: product analytics, error reports, logs and surveys for the app, our server and this website (US-hosted).
Opting out of analytics
On this website, any browser tracking-protection or content blocker
that blocks us.i.posthog.com stops analytics from
loading; the page works fine without it. In the iOS app, release
builds always send the events listed above: with a random identifier
kept on your device while you are signed out, and tied to your user
ID once you sign in. There is no in-app analytics toggle today. You can email
us and we'll delete the analytics profile tied to your account or
address, along with any waitlist entry.
Your rights
You can delete your account directly in the app: Account, then Delete account. This removes your collection, wantlist, crates, setlists, and Discogs, Spotify, and Apple Music links, signs you out everywhere, and asks Apple to revoke Teca's Sign in with Apple access. We keep an archived copy and your account email for up to 30 days, so a mistaken deletion can be undone on request. Then both are deleted for good. If you sign in again later with the same Apple ID, you start over with a clean, empty account. You can also request access, export, correction, or deletion of your data at any time by emailing 32_false.ascot@icloud.com from the address tied to your account.
Children
Teca is not directed at children under 13 and we do not knowingly collect data from them.
Changes
If this policy changes in a material way, we'll update the "last updated" date above and email waitlist and account holders.
Contact
LOUIE & TODD INC.
Questions or data requests:
32_false.ascot@icloud.com