Privacy Policy - Collectery

Version 2026-09-04 · Last updated: 4 September 2026 · Deutsche Fassung

This policy explains what personal data the Collectery mobile app (the "App") and the website collectery.de collect, why, and your rights over it. It is written to meet the EU General Data Protection Regulation (GDPR).

1. Who is responsible (Controller)

Henri Irmscher - Appentwicklung
Seckbacher Landstr. 66
60389 Frankfurt am Main, Germany
Email: privacy@collectery.de

Data protection contact: Henri Irmscher, privacy@collectery.de. There is no statutory obligation to appoint a data protection officer.

2. What we collect

Account and identity

Content you create

Social activity

Purchases

Push notifications (only if you enable them)

Advertising (only with your consent)

Diagnostics (only with your consent)

Technical data

3. How AI generation works

When you choose to cut out an object or generate an AI card or 3D model, the relevant photo is processed by our own AI models. These models run in an isolated GPU environment that we rent from Runpod, Inc. and pin to data centers in the EU/EEA. Processing is transient: images are transferred through short-lived signed links, are not kept by the infrastructure provider beyond the processing itself, and are never used to train AI models. Free "local" looks are composed entirely on your device and are not sent anywhere. Only the images you actively submit for AI processing leave your device for that purpose.

You start every AI generation yourself, by tapping the button that says what it will do and what it costs. We therefore process the photo to perform the contract you asked for (Art. 6(1)(b) GDPR), not on the basis of consent, and you can simply not use the feature.

On-device cutout (Google ML Kit). The free cutout runs entirely on your phone. To do that, your device downloads a segmentation model from Google once. Google can see that a device asked for the model, together with the technical data any download involves, such as your IP address. Your photo never leaves your device for this.

Labelling. AI-generated card images carry a visible label in the App and, in the shared image file, the same information in the metadata (XMP/IPTC). Photos, on-device cutouts, and the free local looks are not AI-generated and are not labelled.

4. Sharing a card by link

You can create a share link for one of your cards. The link looks like collectery.de/c/<token> and opens a public page.

5. Your profile, visibility, and search

Please read this carefully, because "private" does less than the word suggests.

6. Location and place names

7. Reports and moderation

Anyone using the App can report a card. This is the notice-and-action mechanism required by the EU Digital Services Act, and it involves personal data on both sides.

8. Why we use your data and the legal basis

PurposeLegal basis (GDPR Art. 6)
Create your account and provide the App's core featuresPerformance of a contract (Art. 6(1)(b))
Process AI cutouts, cards, and 3D models you requestPerformance of a contract (Art. 6(1)(b))
Show your profile to other users and make it findable in searchPerformance of a contract (Art. 6(1)(b))
Publish a card on a public share page you createdPerformance of a contract (Art. 6(1)(b))
Turn coordinates or a typed address into a place namePerformance of a contract (Art. 6(1)(b))
Notify you when a 3D model you requested is ready or has failedPerformance of a contract (Art. 6(1)(b))
Notify you that one of your cards was reported and hiddenLegal obligation (Art. 6(1)(c)) with the Digital Services Act
Notify you about social activity, such as new followers and follow requests, if you enable these notificationsLegitimate interests (Art. 6(1)(f)) - you can turn them off at any time
Process subscriptions and credit purchases and unlock paid featuresPerformance of a contract (Art. 6(1)(b))
Handle content reports, hide reported cards, and review appealsLegal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))
Keep tax and accounting records for purchasesLegal obligation (Art. 6(1)(c))
Show and reward advertising; use advertising identifiersConsent (Art. 6(1)(a))
Crash and error diagnosticsConsent (Art. 6(1)(a))
Optional product usage analytics (feature and funnel events)Consent (Art. 6(1)(a))
Security, abuse, and fraud prevention, including daily generation limits and rewarded-ad verificationLegitimate interests (Art. 6(1)(f))
Run the website collectery.de and keep it availableLegitimate interests (Art. 6(1)(f))

9. Who receives your data

We do not sell your data. Two different kinds of recipient exist, and the difference matters for your rights.

9.1 Processors (they act only on our instructions)

These providers process data on our behalf under a data processing agreement (Art. 28 GDPR). They may not use it for their own purposes.

ProviderWhat it doesWhereBasis for any transfer outside the EU/EEA
Supabase, Inc. Authentication, database, and file storage: your account, cards, images, and 3D models Data stored in the EU, region Frankfurt (Germany). Company seat in the USA. Standard Contractual Clauses (Art. 46(2)(c)) for any support access from the USA
Brevo Delivery of sign-in and account emails EU (France) No transfer outside the EU/EEA
Runpod, Inc. GPU infrastructure on which we run our own AI models for cutouts, stylized cards, and 3D models Processing pinned to data centers in the EU/EEA. Company seat in the USA. Signed data processing agreement with Standard Contractual Clauses (Art. 46(2)(c))
RevenueCat, Inc. Subscription and in-app purchase management; receives your Collectery account id USA Standard Contractual Clauses (Art. 46(2)(c))
Google Ireland Ltd. (Firebase Cloud Messaging) Delivery of the push notifications you enable EU (Ireland), with Google LLC in the USA involved in delivery EU-US Data Privacy Framework, otherwise Standard Contractual Clauses
Sentry (Functional Software, Inc.) Crash and error reporting. Only if you switch crash reporting on. EU instance (Frankfurt). Company seat in the USA. Standard Contractual Clauses (Art. 46(2)(c))
PostHog, Inc. Optional product usage analytics. Only if you opt in. EU Cloud (Frankfurt). Company seat in the USA. Signed data processing agreement with Standard Contractual Clauses (Art. 46(2)(c))
Hostinger Hosting of the website collectery.de, including the public card pages, and its access logs EU/EEA No transfer outside the EU/EEA for the hosting itself

9.2 Independent controllers (they decide for themselves)

These companies receive data because a feature you use runs through them. They act as their own controller, under their own privacy policy, and we cannot instruct them. Exercise your rights against them directly.

RecipientWhat it receives, and whenWhereBasis for any transfer outside the EU/EEA
Google Ireland Ltd. (AdMob and the UMP consent message) Advertising identifier, ad interactions, and, when you finish a rewarded video, your Collectery account id for reward verification. Only with your consent. EU (Ireland) and USA EU-US Data Privacy Framework, otherwise Standard Contractual Clauses
Apple Distribution International Ltd. and Google Ireland Ltd. (Sign in with Apple, Google Sign-In) The fact that you signed in to Collectery, and the identifier they hand us EU (Ireland) and USA EU-US Data Privacy Framework or Standard Contractual Clauses
Apple (App Store) and Google (Google Play) App download and every in-app purchase. They are the seller of the purchase. EU (Ireland) and USA EU-US Data Privacy Framework or Standard Contractual Clauses
Apple (iOS) and Google (Android) geocoding Coordinates or the address you typed, when you add a place to a card EU (Ireland) and USA EU-US Data Privacy Framework or Standard Contractual Clauses
Google (ML Kit model download) The technical data of a model download from your device, such as your IP address. Never your photo. EU (Ireland) and USA EU-US Data Privacy Framework or Standard Contractual Clauses
Apple (Apple Push Notification service) Delivery of push notifications on iOS EU (Ireland) and USA Standard Contractual Clauses
Discord Netherlands B.V. / Discord Inc. Our private moderation channel receives each content report: card title, owner username, card id, reason, free text. EU (Netherlands) and USA Standard Contractual Clauses (Art. 46(2)(c))

We may also disclose data where the law requires it, for example to law enforcement on a valid legal basis.

10. The website collectery.de

The website, the public card pages under /c/<token>, the download page, and these legal pages are hosted by Hostinger on shared hosting in the EU/EEA.

11. Advertising and Collectery Plus

The App shows rewarded video ads through Google AdMob. Before serving ads in the EU/UK we ask for your consent through Google's consent message, and on iOS we ask for App Tracking Transparency permission. You can review or withdraw your ad consent at any time in the App under Account → Manage ad consent.

One rewarded video unlocks two AI cutouts, or one AI card generation, depending on where you started it.

Collectery Plus does not make the App ad-free forever. A subscription includes a set amount of AI cards, AI cutouts, and 3D models per billing period, and while that amount lasts you create without ads. Once it is used up, AI card generation continues the free way, with a rewarded video, unless you buy credits. The included amount expires at the end of each period and does not carry over.

More on how Google uses data: policies.google.com/technologies/partner-sites.

12. International transfers

Some recipients (for example Google, Apple, RevenueCat, Discord) may process data on servers outside the EU/EEA, including the United States. Where that happens, the transfer is safeguarded by an EU adequacy decision where the provider is certified under the EU-US Data Privacy Framework and, where needed, by the European Commission's Standard Contractual Clauses together with additional safeguards where appropriate. Section 9 names the basis for each recipient.

Our AI processing runs on infrastructure rented from Runpod, Inc., a US company. We pin this processing to data centers in the EU/EEA, transfer content only through short-lived signed links, and do not have it retained after processing. For any residual access from outside the EU/EEA, Runpod's Data Processing Agreement with the European Commission's Standard Contractual Clauses applies.

13. How long we keep it

We keep personal data only as long as necessary for the purposes above:

14. Deleting your account

15. Your rights

Under the GDPR you have the right to:

To exercise these rights, contact privacy@collectery.de. We answer within one month of receiving your request. If a request is complex or you send several, we may extend this by up to two further months and will tell you why within the first month (Art. 12(3) GDPR).

Checking who you are. If we have reasonable doubt that a request really comes from you, we may ask for information that lets us confirm it, usually a message from the email address on the account (Art. 12(6) GDPR). We ask for the least we can, never for a copy of an identity document, and we use what you send only for that check.

What the in-app export contains. The export includes your profile, your cards and their images and 3D models, your card details and places, your purchase and credit history, your consent records, and your social graph. The social graph contains the usernames of the people who follow you and the people you follow. Those usernames are other people's personal data: you may keep them for yourself, but please do not publish or otherwise re-use them.

You can turn push notifications on or off per category at any time in the App under Settings → Notifications, or disable them entirely in your device's system settings. Disabling notifications does not limit any other App feature.

You can turn optional usage analytics on or off at any time under Settings → Share usage analytics. Crash reporting can be toggled separately under Settings → Send crash reports.

16. Children

The App is not directed to children under 16. We do not knowingly collect personal data from children under 16; if you believe a child has provided us data, contact us and we will delete it.

17. Automated decisions

We do not use your data for profiling or for automated decisions that produce legal effects for you within the meaning of Art. 22 GDPR. The automatic hiding of a reported card described in section 7 is a temporary protective measure, and a person reviews every case.

18. Changes to this policy

We may update this policy as the App evolves. Each version carries a version number, shown at the top. When we change something that matters, we ask you to look at the new version in the App before you carry on.

19. Contact

Questions about this policy or your data: privacy@collectery.de.