Edit copy details (Beta)
This separate per-device permission downloads full condition, location, tags and private notes for offline editing. Allow edits alone does not grant it. Original and edited field values stay in the encrypted phone queue for conflict review. Receipts prevent duplicate application. Revoking access blocks future transfers but cannot erase data already downloaded on an offline phone. Review pending work before clearing offline data or forgetting the device.
Batch values and shopping checks
Fetching values sends linked release IDs or barcode searches to Discogs and keeps a resumable preview on this Mac. It does not upload private notes or the whole collection. Shopping comparisons run locally against saved record metadata; offline album checks do not send the entered artist or title to a provider.
Automatic edition preview
Opening Tracks & Connections for a copy without saved music metadata automatically sends its already-linked edition ID to one provider: the linked Discogs source when applicable, otherwise MusicBrainz when available. No private copy details are sent and other editions are not searched automatically. Saved or manually edited music data prevents this request. Closing the view cancels it; Save Changes is required to retain the response.
Music and listening
Metadata previews send the selected release ID to MusicBrainz or Discogs, and Discogs may receive its linked master ID. Bulk review sends the already-linked edition IDs for the selected scope and keeps a resumable local checkpoint. Explicit artist/label pages browse by provider ID; legacy name searches send the chosen name. Connected Records runs locally. Apple Music links send the artist and album or track title to Apple's search website.
Listening notes, dates, ratings and queue positions stay in your local collection and complete backups or optional Mac sync. Normal phone browsing excludes them. If you enable phone editing, new listening entries travel encrypted from the phone to your Mac. Ordinary exports contain listening counts and CSV last-played dates, not listening notes. Old backups and sync revisions may retain deleted entries.
Mobile access
Pairing grants one device encrypted read-only Collection and Wantlist access and optional permission to send scans. Allow edits (Beta) is a separate per-device permission, off by default. The Relay sees routing identifiers, traffic size and timing, but does not decrypt or store collection payloads. It stores short-lived authentication replay metadata. Pairing keys stay in Mac Keychain and encrypted browser storage. Normal snapshots exclude private notes, purchase prices, valuations, sales, loans and tokens. They include opaque edit fingerprints, not the private fields used to compute them. Offline snapshots can remain after revocation and may be evicted by the browser.
Queued phone edits (Beta)
Enabled phones can queue Wantlist entries, purchases, listening entries and extra photos. Entered notes, prices, captions and prepared images are encrypted in browser storage and encrypted in transit to your Mac. Phone images are prepared locally as JPEG up to 2400 pixels without source GPS metadata; original files are unchanged. The Mac validates and prepares the image again before saving.
Pending actions stay until acknowledged or explicitly discarded. Temporary Mac photo uploads expire after 15 idle minutes; the phone retains pending bytes for retry. Clearing a browsing snapshot does not clear this queue. Forget Device removes its local queue after warning, but cannot undo a Mac save. Receipts in the collection retain action/device IDs, hashes, result IDs and timestamps, not the original command text or image. They survive Undo, restore and sync to prevent replay. Saved files and sync folders remain subject to their own backup privacy limits.
Pressing identification
Photo text recognition uses Apple Vision locally. Label photos, runout inscriptions and private comparison notes are not uploaded for recognition. Explicit edition comparison sends the linked release ID or artist/catalog search to Discogs. Saved evidence and reviewed label text remain in the library, complete backups and optional Mac sync. Shared exports may include pressing observations; check them before sharing.
Complete phone backups (Beta)
Separate Mac approval grants one phone 30 minutes to download a full backup, including private notes, prices, sales and borrower details. Transfer is encrypted; the file saved to Files is not password-protected. Keep it private. This is separate from normal read-only browsing. Safari/Save to Files verification is not complete.
Multi-Mac Sync (Beta)
Connecting a folder copies your full private library and artwork to that location. iCloud or another chosen storage provider handles propagation. GrooveFile does not add file encryption. Previous revisions, old history folders and recovery archives remain until you manage them; deleting a current entry does not erase old backups. Physical multi-Mac iCloud verification is not complete. Sync does not include licensing/provider secrets, device keys, preferences or Phone Inbox.
Currency conversion
Optional conversion downloads public reference rates from the European Central Bank over HTTPS and caches them locally. The request sends no collection, amounts or currencies held. Normal network requests expose your IP address to the contacted service. No analytics or telemetry is added.
Complete backups
Settings > Backup Collection creates JSON, CSV or Markdown files with a full recovery payload and available images. These differ from ordinary sharing exports and contain private library fields. Damaged-library recovery preserves original data in a separate local archive. Backups and archives are not password-protected; choose private storage.
Extra photos
Imported and explicitly captured photos are processed locally and stored as optimized JPEGs without source EXIF/GPS metadata. Originals are unchanged. Photos and captions may reveal private details. They are excluded from providers, normal phone browsing, ordinary exports and PDF reports, but included in complete backups and optional Mac sync. Saved recovery files are not password-protected. Deletion does not erase previous backups, sync history or exported photos.
Local collection
Release metadata, copy details, tags, notes, values and automatic backups are stored in Application Support. Smart Collection names and rules are stored in the same library and its backups. Filtering and matching counts run locally. Manual backups and exports go only where you choose.
Wantlist
Wanted releases, preferred pressings, target prices and notes are stored in the same local library and backups. Searching the list and comparing owned copies happen locally. Finding or changing a wanted release uses the release lookup described below; target prices, pressing preferences and personal notes are not sent to providers. Wantlist exports are separate from owned-collection exports.
Sales
Listings, asking prices, sale prices, fees, dates, channels and sale notes are stored locally in the library and JSON backups. Sales search, totals and CSV/Markdown exports run locally. These details are not sent to metadata providers or marketplaces. GrooveFile does not process payments or contact buyers.
Loans
Borrower names, loan and return dates, optional due dates and notes are stored locally in the library and JSON backups. They are not sent to metadata providers. GrooveFile does not send reminders or contact borrowers. Remove a loan entry in Loans to delete it from the current library; existing backups may still contain it. Ordinary collection CSV and Markdown exports do not include loan history.
Collection Insights
Counts, format and location breakdowns, currency totals and recent additions are calculated locally from your owned records. Insights does not upload this information or change the collection. Cover images use the existing cover cache and may be requested from their source hosts. Opening a Discogs source link takes you to that external website.
Release lookup
A scanned barcode is sent to MusicBrainz. Find Release sends the artist, title and catalog number you enter. When you configure Discogs, the same search details and matched release IDs may also be sent to Discogs for metadata and marketplace estimates.
Collection Health
Missing-field checks and related-entry grouping run locally. Preview Metadata sends selected records' barcodes, or their artist, title and catalog number, to the same providers. Cover-link checks and image previews contact image hosts unless a cached image is available. Conditions, locations, tags, notes and purchase details are not sent in these requests. A preview does not change the library.
Cover cache
Cover images are downloaded from the provider URL and cached locally in Application Support. The cache contains image data only and retains at most 500 covers.
Camera and custom covers
Barcode scanning processes camera frames locally without saving or uploading them. Photograph Cover stores an image only when you confirm Use Photo. Imported and photographed covers are resized locally and included in backups. Optional mobile access shares thumbnails; complete backups and sync can include the images.
Import and export
CSV import reads the selected file locally. CSV and Markdown exports contain collection details but do not embed custom cover images. A Smart Collection export contains only matching records.
License activation
Activation contacts PX7 Digital with the license key, a privacy-preserving Mac identifier and the Mac display name.
Updates and feedback
The app contacts utilities.px7.digital to check an HTTPS update manifest. Feedback is sent to PX7 Digital when you choose to submit it.