Current native Mac, iPhone and iPad apps. Reviewed 22 September 2026.
Audio CD Detection
Optional audio CD detection observes locally mounted CD volumes while GrooveFile is running. Detection does not send information online. Find CD first matches the volume name locally. If there are no local matches, choosing Find CD automatically starts a MusicBrainz lookup; Look Up on MusicBrainz also requests it explicitly. The lookup reads only macOS's small CD table of contents and sends its derived Disc ID to MusicBrainz. Cover requests use the resulting release IDs as described below. GrooveFile does not read, rip or upload audio. The CD playback buttons use local Apple Events to read Apple Music's CD playlist, track paths and playback state, and to play or pause the selected CD. macOS asks for Automation permission when a playback button is used, not during detection. While the CD banner is visible and Music is already running with that permission, GrooveFile reads the current CD track number, title, artist and playback state locally every two seconds. These display-only values are not saved or uploaded. The status check does not request permission or launch Music. The sandbox entitlement is restricted to Music's read and playback scripting groups, not library writes. Music handles audio playback and its own online requests under Apple's settings and policies. Eject uses the macOS volume API without Music automation permission; it does not force eject or stop another app. Searching your existing collection is local. Listening is recorded only after you choose Log Listening; inserting a CD does not create a listening entry. Detection can be disabled in Settings > Audio CDs. In sandboxed installations, you may need to select the mounted CD using the system folder picker.
Online Requests and Support
Local collection management does not require a PX7 account. GrooveFile contains no advertising or cross-app tracking integration. This does not mean that online services collect no data: requests disclose your IP address, User-Agent and the requested resource to their recipients. MusicBrainz/MetaBrainz logs API endpoints and query parameters and publishes aggregate traffic statistics. Authenticated Discogs requests can be associated with your Discogs account. Cover hosts and the ECB also receive technical request information. Provider retention is governed by their policies, not by deletion of your local collection or cache.
Feedback opens a separate browser page. Merely opening it does not attach your collection, tokens, photos or app logs. Submitting sends the message, chosen app and request type, and any email address you enter to PX7 Digital's support service. The service stores the support thread in Cloudflare D1 and uses Resend to deliver support emails. A private thread link grants access to that conversation: do not share it publicly. There is no automatic thread-expiry promise. Contact PX7 Digital through https://feedback.px7.digital/?app=utilities-groovefile to request access or deletion; retained emails and provider recovery copies must also be considered. Do not include license keys, provider tokens or an entire collection in feedback.
Provider policies: - https://metabrainz.org/privacy - https://support.discogs.com/hc/en-us/articles/360009334513-Privacy-Policy - https://www.ecb.europa.eu/services/data-protection/privacy-statements/html/ecb.privacy_statement_website.en.html - https://www.cloudflare.com/privacypolicy/ - https://resend.com/legal/privacy-policy
These services have their own infrastructure and may process information outside your country. Optional external links, including Apple Music and browser support, are also subject to the destination website's policies and your browser settings.
Distribution Channels
The Mac App Store edition does not contact the PX7 license server, send a Mac license identifier or display name for licensing, or use the PX7 update service. Apple manages its purchase and distribution. The license and updater description below applies only to the directly downloaded edition.
The two editions keep their local libraries and Keychain service names separate. Changing editions does not automatically copy provider tokens. Export/import of a complete collection backup transfers collection data, not those credentials. Optional metadata providers and native iCloud sync have the data flows described below.
Spotlight and Shortcuts (2.0.44)
Spotlight indexing is off by default. If enabled, GrooveFile shares owned copy IDs, artist/title/barcode, format, condition, storage status and location with the local macOS Core Spotlight index. Private notes, prices, photos and listening history are excluded. Disabling removes GrooveFile's indexed entries; an error is shown if removal fails and Remove Spotlight Data retries it.
Mac Shortcuts require local device authentication and can read owned-copy search results, open Play Next, or explicitly save a listening through the app. Search results can be passed to other actions in a shortcut you choose. macOS/Siri privacy settings and Apple's services apply when invoking actions by voice. No new GrooveFile server receives these queries. An explicit listening is collection data and follows existing backup/sync rules.
Discogs Import (2.0.43)
Import runs only when requested. Your saved token authenticates reads of your Discogs account name, Collection, folder names, custom fields and/or Wantlist. Preview pages, account data, notes, choices and the import receipt are saved in a private local .discogs-import.json file beside the library (maximum 64 MiB). This draft contains no API token and is not included in collection backups or Mac sync. New Preview asks before discarding it. Resume checks the remote account and previously downloaded pages; reopening alone does not contact Discogs. No collection or Wantlist changes are sent to Discogs. Cover requests contact the image provider; optional music review contacts the existing metadata providers. Fetching barcodes and countries sends selected release IDs to Discogs. A local copy link stores an opaque account/item-derived identifier in the library and complete backups, not your API token. Linking does not modify your Discogs account.
Imported account names, notes and custom fields become collection data and may be included in backups, exports, sync and native iCloud sync. Keep backups private. Provider tokens remain in Keychain and are not imported into the collection or its backups. No new telemetry or cloud service is added.
Local Backup Images (2.0.32)
Automatic image snapshots share a separate Artwork folder inside the local Backups folder. These files are not encrypted and can include private photos. Deleting a record or rotating snapshot metadata does not erase retained image files. Keep the whole folder private. No service or telemetry is added.
Storage Status (2.0.25)
Each owned copy can be Active or In Storage. This is a view preference, not a privacy boundary: stored copies remain in whole-library backups and native iCloud sync. Their status appears in exports and barcode matches. No new service, permission or telemetry is added.
Artist and Label Pages (2.0.14)
Owned-record pages compare saved source IDs locally. Opening a page does not request a discography. Explicit online browsing sends the provider artist or label ID and pagination cursor; opening a Discogs edition list sends its master ID. No owned collection, listening log or personal notes accompany these requests. Label links are stored with music metadata and included in complete backups, Mac sync and ordinary CSV sharing. Online result lists are temporary previews.
Pressing Evidence (2.0.14)
Label-photo text recognition uses Apple Vision locally on the Mac. No photo, recognized text, observed runout or physical comparison note is sent to a metadata provider. Loading identifiers sends the chosen Discogs release ID; an explicit edition search sends the entered artist/catalog text and page.
Saved observations, reviewed text and your confirmation are stored in the collection. Complete backups and optional native iCloud sync preserve them. Ordinary CSV sharing includes the evidence; Markdown sharing includes observations and comparison notes. Keep these exports private when they contain personal notes. Removing evidence does not erase historical backups or sync revisions.
Physical Storage and Inventory
Storage addresses and inventory checks are stored locally in the collection. Checks retain expected copy IDs and historical artist/title/format/barcode/location labels, observed copy IDs or unregistered barcodes, dates and completion/cancellation status. They do not retain extra copies of artwork. Complete backups and optional native iCloud sync preserve this history. Removing a saved box does not erase its inventory history or copies in older backups/sync revisions.
Inventory barcode matching and manual identification use the local collection; they do not submit scans to metadata providers. The native app stores the complete collection, including storage addresses, positions and inventory history. QR labels contain the box-name filter, not its hierarchy, inventory or pairing key. Locally saved addresses remain available offline.
Music Metadata and Listening
Opening Tracks & Connections automatically requests a preview when that copy has no saved music metadata. It sends an already-linked edition ID, preferring the linked Discogs source when applicable, otherwise MusicBrainz when available. It does not search other editions, submit private copy details, or save the response without Save Changes. Saved or manually edited music data prevents automatic lookup. Closing the view cancels the request.
Preview Source Metadata also sends the chosen release ID to MusicBrainz or Discogs; Discogs may also receive the linked master ID. Explicit online discovery sends the displayed artist or label name and page number to the chosen provider. Connected Records is computed locally. Opening Apple Music search sends the artist and album or track title to Apple's website; no music account integration or playback tracking is added.
Listening dates, ratings, notes and queue positions are entered by you and stored locally. They are not sent to music metadata providers. Complete backups and optional native iCloud sync include them. Ordinary exports include listening counts and CSV last-played dates, but not listening notes. Deleting an entry does not erase earlier backups or sync revisions. Keep those files private.
Extra Photos
Photos imported or explicitly captured for an owned copy are processed locally and stored as optimized JPEGs, without the source EXIF/GPS metadata. Original files are unchanged. Photos and captions may themselves reveal private details. They are not sent to metadata providers or included in ordinary CSV/Markdown exports or PDF collection reports. Explicit sale advertisement exports can include photos chosen by you.
Stored copy photos are included in complete backups and optional native iCloud sync. Exported backup files are not password-protected. Deleting a photo does not erase previous backups, sync revisions or exported copies. Keep documentation and recovery files private.
Version 2.0.30 (library format 13) also retains local checksum-addressed image files beside the collection JSON. Removing a photo or record does not erase these files. Automatic cleanup is not enabled, to avoid breaking older references. Explicit recovery archives damaged image bytes before replacing them from a backup.
The Archive backup format contains the same private library data and available images as complete backups. It is not encrypted or password-protected. Its checksums detect corruption; they do not authenticate the person who supplied an archive. Temporary restore files are removed after processing.
Optional Native iCloud Sync (Beta)
Mac 2.0.85 and iPhone/iPad build 8 offer an explicit Connect iCloud action. Installing or opening the app does not consent to sync. Connecting sends the complete collection, private notes, purchase prices, photos, sales, loans and storage information to the private CloudKit database of your Apple iCloud account. Devices connected to that account can merge changes and deletions without a running Mac or PX7 Relay. Apple processes this data under its iCloud terms. Provider credentials, license keys and unsaved scan queues are not uploaded.
Recovery checkpoints retain earlier collection data, including deleted entries. Pausing or disconnecting sync does not erase these checkpoints or copies on other devices. Keep an independent exported backup: sync replicates deletions and is not a replacement for backup. Read-only recovery access asks for separate consent and does not enable uploads. Physical multi-device acceptance remains in progress.
Backups and Currency Rates
Explicit complete backups contain private library recovery data and available images. Keep them private. Their checksum detects corruption, not the trustworthiness of whoever supplies a backup. Ordinary sharing exports differ from complete recovery backups. Provider tokens and license keys are excluded.
From Mac 2.0.86, the browser companion and GrooveFile relay access are retired. The current Mac app does not start a relay connection or resume folder sync. Previous exports, browser storage and shared folders are not remotely erased by upgrading or disconnecting. A record deletion does not erase older backups. The former companion domain serves only native app links and setup information; it does not receive collection edits or scans. Box labels contain a box name, not a pairing key. Standard web hosting receives ordinary request information.
Optional currency conversion downloads public reference rates from the European Central Bank over HTTPS. It sends no record names, prices or collection data. The ECB can observe the network request and IP address. Rates are cached locally; conversion is calculated on the device.
Local Collection and Providers
Collection Insights computes counts, amounts and recent additions locally from owned records. It does not upload collection statistics, prices or locations, and does not save a separate analytics dataset. Recent cover thumbnails use the existing cover cache and image hosts; opening a Discogs source link contacts Discogs.
Loan borrower names, dates, deadlines and notes are stored locally in the library and JSON backups. Loan history retains basic release details when a returned copy is later sold or deleted. Loan search and overdue checks run locally. Borrower details are not sent to metadata providers, included in ordinary collection exports, or used to contact anyone. You can remove a loan entry in Loans; existing backups may still contain it.
Sales listings, asking prices, sale prices, fees, dates, channels and sale notes are stored locally in the collection and JSON backups. Sales search, totals and CSV/Markdown exports run locally. These details are not sent to metadata providers or marketplaces. GrooveFile does not process payments or contact buyers.
PX7 GrooveFile stores your collection locally on your Mac as a versioned JSON document in Application Support. Collection data leaves this device through optional iCloud sync and explicit export/backup workflows. Choosing a cloud-backed destination for an export or backup also lets that storage service upload it.
Smart Collection names, filters and sorting rules are stored in the same local library and its JSON backups. Matching counts and filtering run locally; saving or opening a Smart Collection does not send its rules to metadata providers. Smart Collection exports contain only matching records.
Wantlist entries, preferred pressings, target prices and notes are stored in the same local library and backups. Search and owned-copy comparisons run locally. Finding or changing a wanted release uses the same provider lookup described below; target prices, pressing preferences and personal notes are not sent to providers. Wantlist CSV and Markdown exports are separate from owned-collection exports.
Barcode lookup sends scanned barcodes to MusicBrainz. If you add a Discogs personal access token, GrooveFile also sends barcode lookup requests to Discogs and may request marketplace statistics and price suggestions for matched releases.
Find Release sends the artist, title and catalog number you enter to MusicBrainz and, when a token is configured, Discogs. These search terms are used to find matching releases.
Collection Health checks missing fields and related entries locally. Preview Metadata sends the selected records' barcodes (or artist, title and catalog number when no barcode is available) to the same providers. Checking cover links and previewing proposed images contacts their image hosts unless a cached image is available. Conditions, locations, tags, notes and purchase details are not sent in Health lookup requests. Running a preview does not change your library.
Album covers returned by those providers are downloaded from the cover URL and cached in Application Support so they remain available in Shelf View. The cache contains image data only and is limited to 500 covers.
When you use camera scanning, the live image is processed locally on your Mac. Barcode scanning does not save or upload camera frames. Only the detected barcode is used for the lookup described above.
When you choose Photograph Cover and confirm Use Photo, the selected image is stored in your collection. Imported and photographed covers are resized locally and included in collection backups. They are not uploaded to providers; complete backups and optional native iCloud sync include stored originals. CSV import reads the selected file locally; ordinary CSV and Markdown exports do not embed custom cover images, but explicitly selected complete backup formats do.
The app connects to PX7 Digital when you activate or deactivate a license and when it checks for updates. License activation sends the license key, a privacy-preserving Mac identifier and the Mac's display name.
Discogs data is identified in the app and linked to the corresponding Discogs release. GrooveFile is not affiliated with or endorsed by Discogs.