Privacy Policy
The short version: DIG processes the Discogs account and music-library data needed to answer your requests. It is read-only, does not sell personal data, and does not use advertising or behavioral analytics.
Last updated: 25 July 2026 · Applies to DIG for Discogs (the MCP server and REST API at discogs-mcp.woiii.workers.dev, the Chrome side panel extension, and supported AI-assistant integrations) and to this website.
Data DIG processes
- Account and authorization data. DIG processes your Discogs username, numeric Discogs user ID, OAuth access token, and related authorization metadata to connect requests to your account. OAuth credentials are protected server-side and used only for authorized Discogs API requests. DIG does not receive your Discogs password.
- Collection and wantlist data. Depending on the tool you request, DIG processes release identifiers, artists, titles, formats, labels, genres, styles, personal ratings, wantlist entries, and dates added. It also computes collection summaries, taste profiles, ownership signals, comparisons, and recommendations.
- Catalogue and marketplace data. DIG processes Discogs catalogue metadata, community ratings and counts, user-contributed release information, and—where available and permitted—dynamic marketplace fields needed for pressing analysis.
- Tool requests and responses. DIG receives the task-specific arguments sent by your browser extension, MCP client, or AI assistant and returns the corresponding result. It does not ask for a complete chat transcript.
Why this data is used
- Authenticate you and maintain the connection you requested.
- Search, filter, compare, summarize, and recommend music.
- Respect Discogs rate limits, prevent abuse, and keep the service reliable.
- Respond to support, privacy, and security requests.
Who receives or processes data
- Discogs. DIG sends the API requests needed to retrieve the catalogue or account data you asked for. Discogs handles that activity under its own terms and privacy practices.
- Cloudflare. The MCP server, OAuth service, cache, and related infrastructure run on Cloudflare. Cloudflare processes service traffic and stored values as an infrastructure provider.
- Your selected AI provider. When you use DIG through ChatGPT, Claude, Codex, or another supported client, that provider processes your conversation, tool request, and returned result under its own privacy policy. For ChatGPT and Codex, that provider is OpenAI.
- Support services you choose. Information you place in an email or public GitHub issue is processed by the corresponding email or GitHub service. Do not include passwords, access tokens, private collection exports, or other secrets in support messages.
DIG does not sell personal data or share it for targeted advertising.
Storage and retention
- OAuth grants are retained while the connection is active or until they expire, are revoked, or are deleted as part of a valid account or privacy request.
- Cached Discogs responses expire automatically: releases and masters after 24 hours, version lists after 12 hours, searches after 6 hours, and collections and wantlists after 4 hours. These are current operational limits and may be shortened where required by Discogs or the final integration contract.
- Support correspondence is retained only as long as reasonably needed to resolve the request, maintain security records, or meet applicable legal obligations.
Chrome extension and website
The side panel runs locally in your browser and talks only to the DIG server described above. It stores your sign-in session in your browser's extension storage, on your machine. It does not read your browsing history and has no access to pages outside discogs.com.
This website uses static pages and self-hosted fonts. WOIII.me does not add analytics, advertising trackers, or marketing cookies to the site. Hosting providers may still process ordinary network and security data such as IP addresses and request timestamps to deliver and protect it.
Your choices and controls
- Revoke DIG's access to your Discogs account at any time from your Discogs settings, under Applications. This immediately invalidates DIG's token.
- Sign out from the extension to end its session on your machine.
- Remove the connector from your AI client to stop it from calling DIG.
- Contact us to ask about access, correction, deletion, restriction, or another privacy right that applies where you live. We may need enough information to verify the request and locate the relevant account.
Data we do not request
Do not send payment-card information, health information, government identifiers, passwords, API keys, OAuth tokens, MFA codes, or other authentication secrets through DIG inputs or support channels.
Changes
We may update this policy when DIG's functionality, providers, or legal obligations change. The date above identifies the current version.
Contact
Questions about privacy: help@woiii.me or GitHub Issues.