Privacy Policy – Vitrio
Last updated: July 30, 2026
This Privacy Policy explains how Vitrio (“Service”) handles information when You use our application. Please read this Privacy Policy carefully. By using the Service, You agree to the practices described in this policy.
1. Developer
Developer: Frantisek Varadzin
Country: Germany
Email: email@varadzin.com
2. Introduction
Vitrio is a catalogue for physical collections — records, LEGO sets, bottles, games and anything else You collect. It has no user accounts, and the Developer operates no servers and no databases. There is nothing to sign up for and nothing to sign in to.
Your catalogue is stored on Your device and, when iCloud is enabled, synchronised through Your own private iCloud (CloudKit) database. It is never uploaded to any server controlled by the Developer, and the Developer has no way to see it. Signed out of iCloud the app still works in full — it simply keeps the catalogue on that one device.
3. Data You Store in the App
Vitrio stores what You choose to record about the things You own. All of it lives in Your private iCloud database:
- Item details — category, title, artist or set or distillery, year, edition, condition and grade (including the grading company), barcode or set number, and any photos You attach
- Value and provenance — estimated value, price paid, currency, purchase date, where You bought it, where it is stored, serial number, free-text notes, and the value history You build up over time
- Appraisals — appraised value, who appraised it, and when
- Wishlist entries — things You do not own yet
- Preferences — which categories You collect, any categories You define Yourself, Your preferred currency, and Your chosen app language
- Optional insurance details — owner name and policy number. These are used only to fill the header of an insurance PDF that You generate Yourself. They are not required, and they are not sent anywhere.
This data is stored exclusively in Your iCloud account. The Developer does not have access to Your data.
4. Catalogue Lookups — the Only Network Requests
When You scan a barcode or search by name, the app queries the public catalogue that covers that category:
- MusicBrainz and Cover Art Archive — vinyl records (metabrainz.org/privacy)
- Open Food Facts — whisky and other bottles (openfoodfacts.org/privacy)
- BoardGameGeek — board games (boardgamegeek.com/privacy)
- Rebrickable — LEGO sets, and only if You choose to add Your own free API key (rebrickable.com/privacy)
Each request contains only the barcode or the title You typed, together with a standard User-Agent header naming the app and the Developer’s contact address — MusicBrainz requires that identification. Nothing else from Your catalogue is sent: no account, no device identifier, no values, no notes, no photos.
As with any request to any website, the catalogue You query can see Your device’s IP address. Those services are independent of the Developer and their own privacy policies apply, so they are linked above.
Retro games have no open index, so for that category the app makes no request at all — You fill those in Yourself. The app also makes no request when it is offline; scans are held on the device and completed the next time You have a connection.
If You add a Rebrickable API key, it is stored in Your device’s Keychain, is sent only to Rebrickable, and only in a request You triggered. You can delete it in the app at any time.
5. Camera and Photos
Camera. The camera is used for one thing: reading barcodes. Decoding happens on the device. The camera image is never saved by the app and never leaves the device — only the decoded number is used, and only for a lookup You started. You can revoke camera access at any time in iOS Settings.
Photos. Photos You attach to an item are chosen through Apple’s photo picker, which hands the app only the picture You selected — the app has no access to the rest of Your photo library. Attached photos are stored with the item in Your private iCloud database.
6. Purchases
Vitrio Pro is sold as an Apple In-App Purchase through StoreKit. Apple handles the payment and the receipt; the Developer never sees Your payment card data. No third-party subscription or purchase service is used, so no purchase information is shared with anyone other than Apple. You can manage or cancel a subscription at any time in Your App Store account settings.
7. What We Do NOT Collect
We do not collect or store:
- Analytics or usage statistics of any kind
- Crash reports or diagnostic data
- Advertising identifiers, and there is no advertising in the app
- Cookies or similar tracking technologies
- Device location data
- Your name, email address or phone number — the app never asks for them
- Server logs, because the Developer operates no server
Vitrio contains no third-party SDKs at all. It links only Apple’s own frameworks, so there is no code inside the app capable of reporting anything to anyone.
8. Exports You Create
Vitrio can produce a CSV file of Your whole catalogue, an insurance PDF, and a shareable showcase image. All three are generated on Your device. They leave the device only when You send them somewhere Yourself through the iOS share sheet, and then only to the recipient You choose. In the showcase image the total value is switched off by default, so You never publish it by accident.
9. Third-Party Services
- Apple iCloud (CloudKit): all synchronisation is handled by Apple’s CloudKit service, using Your own private database. Apple’s privacy policy applies to the storage and processing of that data.
- Apple Push Notification service (APNs): CloudKit uses a silent push to tell the app that data changed on another one of Your devices. This is handled entirely by Apple. The Developer runs no push server and stores no notification tokens. The app sends You no marketing or promotional notifications.
- Apple App Store: all payment information is handled securely by the App Store. The Developer does not have access to Your payment card data.
- The public catalogues listed in section 4, each queried only with a barcode or a title, and only when You ask for a lookup.
There are no other third parties. No data is shared with anyone for advertising, profiling or analytics, because none is collected for those purposes.
10. Legal Basis for Processing (GDPR)
As the Developer is based in Germany, the General Data Protection Regulation (GDPR) applies. The legal basis for handling Your data is:
- Contract performance (Art. 6(1)(b) GDPR): processing is necessary to provide the Service You have requested — keeping Your catalogue, synchronising it between Your own devices, and performing the catalogue lookups You start.
- Consent (Art. 6(1)(a) GDPR): where applicable, such as when You grant camera access, add Your own Rebrickable API key, or share an export out of the app.
Because all data is stored in Your own private iCloud account and the Developer neither accesses nor processes it on any external server, the Developer acts as a facilitator of data storage rather than a data controller in the traditional sense. Apple Inc. acts as the data processor for iCloud-stored data under Apple’s own terms and privacy policy.
11. Data Retention
Your data is retained in Your iCloud account for as long as You use the Service. Since the Developer stores none of Your data on any external server, retention is governed by Your iCloud account settings and Apple’s data retention policies.
Deleting an item in the app deletes it, and its value history, everywhere it has synced. When You delete the app or remove its data from iCloud, Your data is deleted in accordance with Apple’s iCloud data deletion procedures. A Rebrickable API key You added is removed from the Keychain when You delete it in the app or delete the app itself.
12. Your Rights Under GDPR
Under the General Data Protection Regulation, You have the following rights:
- Right of access: You can view all Your data directly in the app and in Your iCloud account settings.
- Right to rectification: You can edit or correct any field directly in the app at any time.
- Right to erasure: You can delete individual items in the app, or remove the app and its iCloud data through iOS Settings.
- Right to data portability: the app exports Your entire catalogue as a standard CSV file, free of charge and without a subscription, at any time.
- Right to withdraw consent: You can revoke camera access in iOS Settings and delete Your API key in the app, at any time.
- Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority. The competent authority in Germany is the data protection authority of the respective federal state (Landesdatenschutzbeauftragte).
Since all data is stored in Your own private iCloud account, You have full and direct control over Your data at all times.
13. Children’s Privacy
Vitrio is not directed at children. The app requires no account and asks for no personal details, so the Developer collects no personal data from any user, of any age. We do not knowingly collect personal data from children. If You are a parent or guardian and have a question about Your child’s use of the Service, please contact us.
14. Changes to This Privacy Policy
We may update this Privacy Policy if required (e.g. if the app starts using additional services). We will notify You of any significant changes within the app or via the App Store. We will provide at least 30 days’ notice before any material changes take effect.
15. Contact Us
If you have any questions about this Privacy Policy or wish to exercise Your rights under GDPR, please contact:
📧 Email: email@varadzin.com