Privacy
Your collection belongs to you. It’s private by default, exportable at any time, and public only if you choose.
Last updated October 4, 2026
Draft for legal review
This draft describes what The Collector does today in plain language. It hasn’t been reviewed by a lawyer yet, and the wording may change before it takes effect. Open questions for review:
- The legal entity that operates The Collector and a contact address for privacy requests.
- Minimum age, and how we handle accounts of younger collectors.
- How long database backups and hosting logs keep data after it is deleted.
- The legal basis for each use of data and for transfers to the United States (GDPR, UK GDPR).
- Data processing agreements with each service listed below.
The short version
- We collect what you record about your comics, what you need to sign in, and what billing requires.
- Your collection, notes, photos, prices and storage locations are visible only to you.
- A public profile is off until you turn it on, and shows only what you choose.
- We don’t sell your data and we don’t show ads.
- You can export everything as CSV or JSON, and delete your account, from Settings.
What we collect
Account. Your email address, which you sign in with through one-time codes. If you sign in with Google or Apple, we receive the email address and name they share. Our authentication provider records your signed-in sessions: the browser or app, the IP address and when each was last used. You can see and end them in Settings → Devices.
Profile. A username, display name, photo, bio, location and website, all optional, plus your privacy and notification choices.
Your collection. The comics you own, want or sold and what you record about each copy: edition, grade, slab certificate, signatures, purchase and sale prices, value, storage location, tags, notes and photos. Also the series you follow and the conversations you have with the assistant.
Scans. Barcodes your camera reads and the cover photos you take while scanning. Photos are stored in private storage so a scan can be reviewed and identified.
Billing. If you subscribe to a paid plan, your plan, its status and renewal date, and the customer id our payment processor gives us. Card details go straight to the payment processor; we never see or store them.
Stores. If you run a shop on The Collector: the business details you publish (name, address, phone, email, hours), your listings, holds and the messages exchanged with collectors, and the seller fees owed. If you request a hold as a collector, the shop sees your request and the messages you send it.
Usage of AI features. For each AI request we record which model ran, how many tokens it used and what it cost, to keep your plan’s monthly allowance.
How we use it
- To run The Collector: show your collection, identify comics, keep your devices in sync and send sign-in codes.
- To read covers and answer the assistant. Cover photos and assistant messages, with the collection details the assistant needs, are sent to AI models (see below). Barcode scans and manual entry never use AI.
- To estimate values from anonymized prices, if you share them (see community value estimates).
- To bill paid plans and seller fees, and to enforce plan limits.
- To keep the service secure and working: preventing abuse, fixing errors, and measuring page performance.
We don’t sell personal data, share it for advertising, or use your collection to train AI models.
What other people can see
Nothing in your collection is public by default. If you turn on your public profile in Settings → Privacy, anyone with the link can see your display name, username, photo, bio, location and website, the comics you own (cover, series and issue, grade, signed or key), your runs and key issues, and how many comics, series and keys you have. Values and your wishlist appear only if you switch them on as well. Search engines may index a public profile.
Never public: notes, storage locations, purchase prices, certificate numbers, photos of your copies, and any copy you hide from your showcase. Your profile photo is stored at an unlisted web address so it can be shown on a public profile; it isn’t linked from anywhere while your profile is private.
The catalog shows how many collectors own or want an issue, as a total count with no names. Shops see what you send them when you request a hold.
Community value estimates
Values in The Collector come from what collectors actually pay and sell for. When sharing is on, a price you record for a copy is added to an anonymous pool: the issue and edition, price, currency, grade, grading company, whether it’s signed, and the date. Your name, your account and the copy itself are never part of it, and a price band is only shown once at least three prices back it.
Sharing is on by default for new accounts. You can turn it off in Settings → Privacy; that also removes the prices you’ve already shared. When you delete your account, the prices you shared stay in the pool, still without anything that links them to you, unless you choose to remove them too.
Services that process your data
We use these services to run The Collector. Each processes data only to provide its part of the service.
- Supabase: our database, sign-in and file storage, hosted in the United States (AWS, us-east-1). It sends sign-in codes and email-change links.
- Vercel: hosts the website and API, measures page views and performance (see cookies and analytics), and runs the AI Gateway we use to reach AI models.
- AI model providers, reached through the Vercel AI Gateway: currently Google (cover reading), Anthropic (cover reading and the assistant) and OpenAI (fallback and search). They receive the cover photos and assistant messages described above, with your account id so we can meter usage.
- Stripe: payment processing for paid plans and seller fees. Stripe receives your email address and the payment details you enter at checkout.
- Google and Apple, only if you choose to sign in with them.
When you search the catalog or scan a book, our server may look up the title or barcode in Metron’s public comic database. Nothing that identifies you is sent with those lookups.
Cookies and analytics
We use cookies only to keep you signed in. A few display preferences stay in your browser’s local storage on that device and aren’t sent to us, like your theme, how your library, wishlist and runs are shown, and the scanner’s sound and camera settings. We don’t use advertising or cross-site tracking cookies.
Vercel Web Analytics and Speed Insights record page views and loading performance without cookies: the page address, referrer, browser, device type and approximate country. Before anything is sent, pairing codes in phone pairing links and one-time sign-in tokens in sign-in links are removed from the address.
Keeping and deleting data
We keep your data while your account exists. When you delete your account in Settings → Account, we cancel any paid plan and remove your payment details from Stripe, then delete your profile, collection, photos, scans, assistant conversations, notifications and settings.
What stays, without anything that identifies you:
- Anonymized prices you shared, unless you choose to remove them when you delete.
- Purchases you completed through a shop, in that shop’s sales records and seller-fee billing.
- Catalog corrections that were already applied to the shared catalog.
- A record that an account was deleted, kept in our audit log with an internal id only.
Stripe keeps records of past payments as the law requires. Backups and hosting logs may hold deleted data for a limited time before they expire.
Your choices and rights
- See and take your data: export your full collection as CSV or JSON in Settings → Your data, free on every plan.
- Correct it: everything you recorded can be edited in the app.
- Limit it: keep your profile private, hide copies, stop sharing prices, and mute notification types.
- Delete it: delete copies one by one or your whole account.
Depending on where you live, you may have further rights, such as to object to some uses or to complain to a data protection authority. Until a contact address is published here, use the account tools above.
Security
Everything travels over HTTPS. Database rules restrict each collection to its owner, photos of your copies and scans sit in private storage that only your account can open, and phone pairing uses short-lived single-use codes that we store only as hashes. Staff with admin access can see account data to run the service, and every change they make is recorded in an audit log.
Changes and contact
If we change how we handle your data, we’ll update this page and its date, and tell you in the app before a significant change takes effect.