Collectery
Privacy
Terms
Impressum
Delete account
Privacy Policy - Collectery
Version 2026-09-04 · Last updated: 4 September 2026 ·
Deutsche Fassung
This policy explains what personal data the Collectery
mobile app (the "App") and the website collectery.de
collect, why, and your rights over it. It is written to meet the EU General
Data Protection Regulation (GDPR).
1. Who is responsible (Controller)
Henri Irmscher - Appentwicklung
Seckbacher Landstr. 66
60389 Frankfurt am Main, Germany
Email: privacy@collectery.de
Data protection contact: Henri Irmscher,
privacy@collectery.de.
There is no statutory obligation to appoint a data protection officer.
2. What we collect
Account and identity
- Your email address and a one-time login code, or a sign-in identifier from
Apple or Google when you use those sign-in
methods (we never receive your password).
- Profile details you choose, such as username, display name, and avatar image.
Content you create
- Photos you capture or upload, and the AI-stylized cards and 3D models
generated from them.
- Card details you add, such as title, notes, and, only if you enable it,
the place name and GPS coordinates where an item was found.
- Visibility settings (private, friends, public) you assign to your cards
and profile.
Social activity
- Who you follow and who follows you, follow requests, and the cards you
post to your feed.
- Reports you send about someone else's card, and reports other people
send about yours (see section 7).
- Your block list: the accounts you have blocked and when
you blocked them. Only you can read your own list; the blocked person is
not told and never sees it (see section 7).
Purchases
- Your Collectery Plus subscription status and related transaction
identifiers, and records of credit purchases used for 3D generation.
- Purchases are processed through RevenueCat and the
Apple App Store / Google Play. We do not
receive your full payment-card data. RevenueCat receives your Collectery
account id so a purchase can be matched to your account.
- A ledger of the credits and subscription allowances you were granted and
used, so we can show you a correct balance and refund a failed generation.
Push notifications (only if you enable them)
- A push token that identifies your device to the notification service,
the device platform, and your per-category notification preferences.
- The small amount of event data needed to compose a notification, such as
the username of a person who followed you, the status of a 3D model you
requested, or the fact that one of your cards was reported and hidden.
Notifications never contain your photos or card content.
Advertising (only with your consent)
- A device advertising identifier (Apple IDFA / Google Advertising ID) and
ad-interaction data, used to show and reward rewarded video ads. On iOS this
requires your App Tracking Transparency permission; in the EU/UK it requires
your consent via the Google consent message.
- When you finish a rewarded video, your Collectery account id is sent to
Google as part of the reward verification, so the reward can only be
credited once and to the right account.
Diagnostics (only with your consent)
- Crash reports and error logs, processed through Sentry,
and sent only if you enable crash reporting under
Settings → Send crash reports. A crash report contains the error,
the app version, and basic device and operating-system information. It is
pseudonymous, not anonymous: it can carry a device identifier and your IP
address.
- Optional product usage analytics (which features and screens you use,
funnel steps such as card creation or purchases), processed through
PostHog (EU hosting) and sent only if you opt in under
Settings → Share usage analytics. Events use a random pseudonymous
identifier stored on your device and are not linked to your account,
email, or username. They are pseudonymous, not anonymous: PostHog also
processes your IP address. We do not send your photos, card titles,
location, or other content in analytics events.
Technical data
- IP address and basic device and operating-system information, processed
as a necessary part of delivering an internet service and keeping it
secure.
- Counters we need to enforce our limits, for example how many AI cards
you created today. This counter runs on the UTC calendar
day, not your local one.
3. How AI generation works
When you choose to cut out an object or generate an AI card or 3D model,
the relevant photo is processed by our own AI models.
These models run in an isolated GPU environment that we rent from
Runpod, Inc. and pin to data centers in the EU/EEA. Processing
is transient: images are transferred through short-lived signed links, are
not kept by the infrastructure provider beyond the processing itself, and
are never used to train AI models. Free "local" looks are composed entirely
on your device and are not sent anywhere. Only the images you actively
submit for AI processing leave your device for that purpose.
You start every AI generation yourself, by tapping the button that says what
it will do and what it costs. We therefore process the photo to perform the
contract you asked for (Art. 6(1)(b) GDPR), not on the basis of consent, and
you can simply not use the feature.
On-device cutout (Google ML Kit). The free cutout runs
entirely on your phone. To do that, your device downloads a segmentation
model from Google once. Google can see that a device asked for the model,
together with the technical data any download involves, such as your IP
address. Your photo never leaves your device for this.
Labelling. AI-generated card images carry a visible label
in the App and, in the shared image file, the same information in the
metadata (XMP/IPTC). Photos, on-device cutouts, and the free local looks
are not AI-generated and are not labelled.
4. Sharing a card by link
You can create a share link for one of your cards. The link looks like
collectery.de/c/<token> and opens a public page.
- No account is needed to open it. Anyone who has the
link can see the card, and can pass the link on.
- The page shows the card image, the 3D model if the card has one, the
title, the creation date, and, from your profile, your display name, your
username, and your avatar.
- We count how often the page was opened, so we can show you that number.
We do not build a visitor profile and the page is set to
noindex, so it should not turn up in search engines.
- Turning the link off. You can switch a share link off at
any time in the App. The page then stops working immediately. The image
and model files themselves are delivered through signed links that stay
valid for up to 30 minutes, so a copy someone already
loaded can still be reachable for that long. Plan for that: a link you
have handed out cannot be un-handed-out.
- Legal basis: performance of the contract (Art. 6(1)(b) GDPR). You choose
to create the link.
5. Your profile, visibility, and search
Please read this carefully, because "private" does less than the word
suggests.
- Your username, display name, and profile picture are visible to
every signed-in Collectery user, and they can be found through
the in-app search. This is also true when your account is set to
private.
- A private account limits your cards and
your follower and following counts. It does not hide your
profile itself.
- If you do not want to be findable under your real name, choose a
username and display name that do not contain it, and do not use a photo
of yourself as your avatar. You can change all three at any time in the
App.
- Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Collectery
is a social app; being findable is how following works.
6. Location and place names
- Location is off unless you turn it on for a card.
- If you use "use my location", your device's coordinates are sent to
Apple (on iOS) or Google (on Android) to
be turned into a readable place name. If you type an address instead, the
text you typed is sent to the same service to be turned into coordinates.
Apple and Google are independent controllers for that lookup and apply
their own privacy policies.
- The resulting place name is shown with the card to everyone who
is allowed to see the card, including anyone with a share link.
Coordinates are stored with the card but are not displayed.
- You can remove the place from a card at any time by editing it.
- Legal basis: performance of the contract (Art. 6(1)(b) GDPR), triggered
by you.
7. Reports and moderation
Anyone using the App can report a card. This is the notice-and-action
mechanism required by the EU Digital Services Act, and it involves personal
data on both sides.
- What we store for a report: the account id of the person
reporting, the reported card, the reason chosen, the free text added, and
the time.
- Automatic hiding. The first report
hides the reported card automatically, before any human has looked at it.
This is an automated step to limit harm quickly. It is not an automated
decision with legal effect in the sense of Art. 22 GDPR, because a person
reviews every case afterwards and the card comes back if the report was
unfounded.
- The owner is told. The person whose card was hidden
receives a push notification, if they have notifications enabled, and can
appeal (see the Terms).
- Where the report goes. To review reports quickly, each
report is also forwarded to a private moderation channel we run on
Discord. The message contains the card title, the
username of the card owner, the card id, the reason, and the free text.
It does not contain the reporter's identity or the card image.
- Blocking. You can also block another person from their
profile. We store one row per block: who blocked whom, and when. A block
only affects the two of you, and it removes any follow between you: you
stop seeing each other's cards, profile details, and follower counts. The
blocked person is not told and cannot see that they were blocked, not even
in a data export. You can see and lift your blocks under
Settings, Blocked people; lifting one deletes the row. Legal
basis: performance of a contract (Art. 6(1)(b) GDPR) and our legitimate
interest in a safe service (Art. 6(1)(f) GDPR).
- Legal basis: compliance with a legal obligation
(Art. 6(1)(c) GDPR together with the Digital Services Act) and our
legitimate interest in a safe service (Art. 6(1)(f) GDPR).
8. Why we use your data and the legal basis
| Purpose | Legal basis (GDPR Art. 6) |
| Create your account and provide the App's core features | Performance of a contract (Art. 6(1)(b)) |
| Process AI cutouts, cards, and 3D models you request | Performance of a contract (Art. 6(1)(b)) |
| Show your profile to other users and make it findable in search | Performance of a contract (Art. 6(1)(b)) |
| Publish a card on a public share page you created | Performance of a contract (Art. 6(1)(b)) |
| Turn coordinates or a typed address into a place name | Performance of a contract (Art. 6(1)(b)) |
| Notify you when a 3D model you requested is ready or has failed | Performance of a contract (Art. 6(1)(b)) |
| Notify you that one of your cards was reported and hidden | Legal obligation (Art. 6(1)(c)) with the Digital Services Act |
| Notify you about social activity, such as new followers and follow requests, if you enable these notifications | Legitimate interests (Art. 6(1)(f)) - you can turn them off at any time |
| Process subscriptions and credit purchases and unlock paid features | Performance of a contract (Art. 6(1)(b)) |
| Handle content reports, hide reported cards, and review appeals | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
| Keep tax and accounting records for purchases | Legal obligation (Art. 6(1)(c)) |
| Show and reward advertising; use advertising identifiers | Consent (Art. 6(1)(a)) |
| Crash and error diagnostics | Consent (Art. 6(1)(a)) |
| Optional product usage analytics (feature and funnel events) | Consent (Art. 6(1)(a)) |
| Security, abuse, and fraud prevention, including daily generation limits and rewarded-ad verification | Legitimate interests (Art. 6(1)(f)) |
| Run the website collectery.de and keep it available | Legitimate interests (Art. 6(1)(f)) |
9. Who receives your data
We do not sell your data. Two different kinds of recipient exist, and the
difference matters for your rights.
9.1 Processors (they act only on our instructions)
These providers process data on our behalf under a data
processing agreement (Art. 28 GDPR). They may not use it for their own
purposes.
| Provider | What it does | Where | Basis for any transfer outside the EU/EEA |
| Supabase, Inc. |
Authentication, database, and file storage: your account, cards, images, and 3D models |
Data stored in the EU, region Frankfurt (Germany). Company seat in the USA. |
Standard Contractual Clauses (Art. 46(2)(c)) for any support access from the USA |
| Brevo |
Delivery of sign-in and account emails |
EU (France) |
No transfer outside the EU/EEA |
| Runpod, Inc. |
GPU infrastructure on which we run our own AI models for cutouts, stylized cards, and 3D models |
Processing pinned to data centers in the EU/EEA. Company seat in the USA. |
Signed data processing agreement with Standard Contractual Clauses (Art. 46(2)(c)) |
| RevenueCat, Inc. |
Subscription and in-app purchase management; receives your Collectery account id |
USA |
Standard Contractual Clauses (Art. 46(2)(c)) |
| Google Ireland Ltd. (Firebase Cloud Messaging) |
Delivery of the push notifications you enable |
EU (Ireland), with Google LLC in the USA involved in delivery |
EU-US Data Privacy Framework, otherwise Standard Contractual Clauses |
| Sentry (Functional Software, Inc.) |
Crash and error reporting. Only if you switch crash reporting on. |
EU instance (Frankfurt). Company seat in the USA. |
Standard Contractual Clauses (Art. 46(2)(c)) |
| PostHog, Inc. |
Optional product usage analytics. Only if you opt in. |
EU Cloud (Frankfurt). Company seat in the USA. |
Signed data processing agreement with Standard Contractual Clauses (Art. 46(2)(c)) |
| Hostinger |
Hosting of the website collectery.de, including the public card pages, and its access logs |
EU/EEA |
No transfer outside the EU/EEA for the hosting itself |
9.2 Independent controllers (they decide for themselves)
These companies receive data because a feature you use runs through them.
They act as their own controller, under their own privacy
policy, and we cannot instruct them. Exercise your rights against them
directly.
| Recipient | What it receives, and when | Where | Basis for any transfer outside the EU/EEA |
| Google Ireland Ltd. (AdMob and the UMP consent message) |
Advertising identifier, ad interactions, and, when you finish a rewarded video, your Collectery account id for reward verification. Only with your consent. |
EU (Ireland) and USA |
EU-US Data Privacy Framework, otherwise Standard Contractual Clauses |
| Apple Distribution International Ltd. and Google Ireland Ltd. (Sign in with Apple, Google Sign-In) |
The fact that you signed in to Collectery, and the identifier they hand us |
EU (Ireland) and USA |
EU-US Data Privacy Framework or Standard Contractual Clauses |
| Apple (App Store) and Google (Google Play) |
App download and every in-app purchase. They are the seller of the purchase. |
EU (Ireland) and USA |
EU-US Data Privacy Framework or Standard Contractual Clauses |
| Apple (iOS) and Google (Android) geocoding |
Coordinates or the address you typed, when you add a place to a card |
EU (Ireland) and USA |
EU-US Data Privacy Framework or Standard Contractual Clauses |
| Google (ML Kit model download) |
The technical data of a model download from your device, such as your IP address. Never your photo. |
EU (Ireland) and USA |
EU-US Data Privacy Framework or Standard Contractual Clauses |
| Apple (Apple Push Notification service) |
Delivery of push notifications on iOS |
EU (Ireland) and USA |
Standard Contractual Clauses |
| Discord Netherlands B.V. / Discord Inc. |
Our private moderation channel receives each content report: card title, owner username, card id, reason, free text. |
EU (Netherlands) and USA |
Standard Contractual Clauses (Art. 46(2)(c)) |
We may also disclose data where the law requires it, for example to law
enforcement on a valid legal basis.
10. The website collectery.de
The website, the public card pages under /c/<token>, the
download page, and these legal pages are hosted by
Hostinger on shared hosting in the EU/EEA.
- When you open a page, the server writes an access log
entry containing your IP address, the time, the page requested, the
referrer, and your browser's user agent. This is the technical minimum
for delivering a web page and defending against attacks.
- The website uses no cookies, no tracking, and no third-party
resources. Fonts are served from our own domain, and the 3D
viewer used on card pages is served from our own domain as well, so
opening a page does not tell anyone but our host that you were there.
There is no consent banner because there is nothing to consent to.
- Card pages send a
no-referrer header and are marked
noindex.
- Legal basis: legitimate interests in a working, secure website
(Art. 6(1)(f) GDPR).
11. Advertising and Collectery Plus
The App shows rewarded video ads through Google AdMob. Before serving ads in
the EU/UK we ask for your consent through Google's consent message, and on
iOS we ask for App Tracking Transparency permission. You can review or
withdraw your ad consent at any time in the App under
Account → Manage ad consent.
One rewarded video unlocks two AI cutouts, or one AI card
generation, depending on where you started it.
Collectery Plus does not make the App ad-free forever.
A subscription includes a set amount of AI cards, AI cutouts, and 3D models
per billing period, and while that amount lasts you create without ads.
Once it is used up, AI card generation continues the free way, with a
rewarded video, unless you buy credits. The included amount expires at the
end of each period and does not carry over.
More on how Google uses data:
policies.google.com/technologies/partner-sites.
12. International transfers
Some recipients (for example Google, Apple, RevenueCat, Discord) may process
data on servers outside the EU/EEA, including the United States. Where that
happens, the transfer is safeguarded by an EU adequacy decision where the
provider is certified under the EU-US Data Privacy Framework and, where
needed, by the European Commission's Standard Contractual Clauses together
with additional safeguards where appropriate. Section 9 names the basis for
each recipient.
Our AI processing runs on infrastructure rented from Runpod, Inc., a US
company. We pin this processing to data centers in the EU/EEA, transfer content
only through short-lived signed links, and do not have it retained after
processing. For any residual access from outside the EU/EEA, Runpod's Data
Processing Agreement with the European Commission's Standard Contractual
Clauses applies.
13. How long we keep it
We keep personal data only as long as necessary for the purposes above:
- Account and content (profile, cards, photos, 3D
models): for as long as your account exists. You can delete your account
and all associated data, or export your data, at any time in the App under
Settings → Account.
- Share links: the token and its view count live as long
as the link does. Turning the link off deletes the token; already signed
media links keep working for up to 30 minutes.
- Content reports and moderation decisions: up to
12 months after the case is closed, so we can answer an
appeal (possible for six months) and recognise repeat abuse. Reports that
lead to a legal case are kept until it ends.
- Push notifications: your push token is deleted when you
sign out or delete your account, and tokens that have been inactive for
about 9 months are deleted automatically. Your notification preferences
are kept for as long as your account exists.
- Server and access logs (Supabase, Hostinger): up to
30 days, then deleted or overwritten. Kept longer only
for a specific security incident, and only for that incident.
- Backups: database backups are kept for up to
30 days on a rolling basis and are then overwritten.
Content you deleted therefore disappears from the backups within 30 days
at the latest. Backups are only ever restored as a whole, after a
failure.
- Proof of a deletion: when you delete your account we
keep a minimal record that a deletion happened, with the internal account
id and the date and no content, for up to 3 years. We
need it to show a supervisory authority that we acted on your request
(Art. 5(2) GDPR).
- Consent records (which version of these documents you
accepted, and when; your analytics, crash, and advertising choices): for
as long as your account exists and up to 3 years
afterwards, so we can demonstrate the consent was given.
- Crash and error diagnostics (Sentry): up to 90 days,
and only if you enabled crash reporting.
- Product usage analytics (PostHog): up to
12 months, and only if you opted in. You can withdraw
consent at any time under Settings → Share usage analytics; this
stops further collection immediately.
- Advertising: advertising identifiers are used only
transiently to serve ads; a record of your consent choices is kept for as
long as needed to demonstrate compliance.
- Purchases: kept while your account is active. Where the
law requires us to retain transaction records, for example under German
tax and commercial law (§ 147 AO, § 257 HGB), we keep the necessary
records for the statutory period of up to 10 years. Those
records survive a deletion of your account, because we are not allowed to
erase them.
14. Deleting your account
- Deleting removes your profile, your cards, your photos, your 3D models,
your share links, your follows, and your push tokens.
- A running Collectery Plus subscription is not cancelled by
this. It is a contract with Apple or Google, and only you can
cancel it, in your App Store or Google Play account. Cancel it
before you delete the account, or you keep paying for a
service you can no longer reach.
- Unused credits and any remaining subscription allowance expire
without compensation.
- What we must keep is listed in section 13: accounting records and the
minimal proof that the deletion happened.
15. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17, also directly in the App);
- receive your data in a portable format (Art. 20, also directly in the App);
- restrict processing (Art. 18);
- object to processing based on our legitimate interests
(Art. 21), including the social notifications;
- withdraw any consent at any time, without affecting prior processing
(Art. 7(3));
- lodge a complaint with a supervisory authority. Ours is
Der Hessische Beauftragte für Datenschutz und
Informationsfreiheit (HBDI), Gustav-Stresemann-Ring 1,
65189 Wiesbaden, Germany.
To exercise these rights, contact
privacy@collectery.de.
We answer within one month of receiving your request. If a
request is complex or you send several, we may extend this by up to two
further months and will tell you why within the first month
(Art. 12(3) GDPR).
Checking who you are. If we have reasonable doubt that a
request really comes from you, we may ask for information that lets us
confirm it, usually a message from the email address on the account
(Art. 12(6) GDPR). We ask for the least we can, never for a copy of an
identity document, and we use what you send only for that check.
What the in-app export contains. The export includes your
profile, your cards and their images and 3D models, your card details and
places, your purchase and credit history, your consent records, and your
social graph. The social graph contains
the usernames of the people who follow you and the people you
follow. Those usernames are other people's personal data: you may
keep them for yourself, but please do not publish or otherwise re-use them.
You can turn push notifications on or off per category at any time in the
App under Settings → Notifications, or disable them entirely in
your device's system settings. Disabling notifications does not limit any
other App feature.
You can turn optional usage analytics on or off at any time under
Settings → Share usage analytics. Crash reporting can be toggled
separately under Settings → Send crash reports.
16. Children
The App is not directed to children under 16. We do not knowingly collect
personal data from children under 16; if you believe a child has provided us
data, contact us and we will delete it.
17. Automated decisions
We do not use your data for profiling or for automated decisions that
produce legal effects for you within the meaning of Art. 22 GDPR. The
automatic hiding of a reported card described in section 7 is a temporary
protective measure, and a person reviews every case.
18. Changes to this policy
We may update this policy as the App evolves. Each version carries a version
number, shown at the top. When we change something that matters, we ask you
to look at the new version in the App before you carry on.
19. Contact
Questions about this policy or your data:
privacy@collectery.de.