Privacy Policy
Effective September 24, 2026
This policy explains what the Collectverse app for iPhone and Android, and this website, collect about you, why, where it is kept, who else handles it, and what you can do about it.
Collectverse ("we", "us") is responsible for your personal data — the controller under Brazil’s General Data Protection Law (LGPD, Law No. 13,709/2018) and, where it applies to you, the EU and UK GDPR. You can reach us at support@collectver.se.
The short version. We collect what you put into the app — your account details, your collections, your items and their photos — and use it only to run the app for you. No ads, no analytics, no tracking, and we never sell your data. Nothing you create is visible to anyone else. It is stored with Amazon Web Services in the United States. You can delete your account, and everything in it, from inside the app at any time.
What we collect
Your account
- If you sign up with email: your email address and a password. Passwords are handled by Amazon Cognito and are never visible to us.
- If you sign in with Apple or Google: the email address and name that Apple or Google shares with us. From Google we also receive the address of your Google profile picture, which becomes your profile photo until you choose another. If you use Apple’s Hide My Email, we receive a private relay address instead of your real one.
- If you continue as a guest: we create an account for you with a random identifier instead of an email address. It is a real account — what you create is stored on our servers exactly as it would be for any other account — but the sign-in details for it are kept only on your phone. If you delete the app or lose the phone before linking an email, Apple or Google to it, neither you nor we can get back into it.
- An account identifier we generate, which links your data together.
What you create
- Collections and items: names, descriptions, colours, icons, the fields you define and the values you fill in, and notes.
- Photos: item photos, collection covers, and your profile photo and banner. Photos are resized and re-encoded on your phone before they are uploaded, which removes the metadata cameras embed in them — including GPS location.
- Your profile: display name, tagline and featured collection, plus counts and badges worked out from your collections.
The app only uses the camera or your photo library when you ask it to, and only receives the photos you pick.
Technical data
- When something goes wrong, our servers record technical logs — error details and the account identifier involved. They are deleted automatically after 30 days. We do not log IP addresses ourselves; the Amazon Web Services systems that carry requests to us process them to route traffic.
- When it starts, the app downloads a public settings file from our servers. That request carries no account information.
- On your phone, the app keeps a copy of your collections and photos so they work offline, along with changes waiting to upload. Signing out deletes that copy and any changes still waiting. Two things can stay behind until you delete the app: a few settings, such as grid or list view, and recent responses from our servers in the phone’s network cache, which only the app can read. Deleting the app removes everything it stored.
What we don’t collect
No advertising identifiers, no analytics or crash-reporting tools, no location, no contacts, and no tracking across other apps or websites. This website sets no cookies and loads nothing from third parties.
Why we use it
| Purpose | Legal basis |
|---|---|
| Creating and running your account, storing your collections and syncing them between your devices | Performance of a contract with you (LGPD art. 7, V · GDPR art. 6(1)(b)) |
| Sending verification codes and password-reset emails | Performance of a contract with you |
| Keeping the service working and secure, through the logs described above | Our legitimate interest (LGPD art. 7, IX · GDPR art. 6(1)(f)) |
| Complying with the law, when it requires us to keep or disclose something | Legal obligation (LGPD art. 7, II · GDPR art. 6(1)(c)) |
We don’t send marketing email. We don’t use your data for advertising, for profiling, or for automated decisions about you, and we don’t use your collections or photos to train AI models.
Who else handles it
- Amazon Web Services (AWS) hosts everything: the database, photo storage and delivery, sign-in (Amazon Cognito) and our emails (Amazon SES). AWS processes the data only on our instructions, as our operator (processor), in its US East (N. Virginia) region.
- Apple and Google, only if you choose to sign in with them. They handle that sign-in under their own privacy policies, and we receive only what is listed above.
We don’t sell your personal data or share it with anyone for their own purposes. We will disclose it only if the law requires us to — a court order, for example — and, where we are allowed to, we will tell you.
The app has no paid features today. If we add them, payments will be handled by Apple and Google, and we will update this policy before that happens.
Transfers outside your country
Our servers are in the United States, so if you live elsewhere — in Brazil or the EU, for example — your data is transferred there. We rely on the data protection commitments AWS makes to its customers, including standard contractual clauses, to keep it protected to the standard your law requires.
How long we keep it
- Your account and everything in it: until you delete it. A guest account that is never linked stays until it is deleted from the app.
- When you delete your account, your profile, collections, items, photos and sign-in record are removed from our systems immediately. Two copies take a little longer to disappear: our database backups, which roll over after 35 days, and copies of photos held by our content delivery network, which expire within 24 hours. Neither is used for anything except recovering from a failure.
- Technical logs: 30 days.
- Emails you send us: as long as we need to answer them and deal with any follow-up.
Your rights
Under the LGPD (art. 18) — and, if it applies to you, the GDPR — you have the right to: confirm whether we process your data; access it; correct it; have unnecessary or excessive data anonymised, blocked or deleted; receive it in a portable format; know who we share it with; withdraw consent where we rely on it; object to processing; and have your account deleted.
The quickest way to exercise most of them is in the app itself: you can edit or delete anything you have created at any time, and delete your whole account in Settings → Account → Delete account. For anything else — a copy of your data, for instance — email support@collectver.se from the address on your account. We answer within 15 days, and may ask you to confirm the request is really yours. Guest accounts have no email address we can verify, so their holders need to use the options in the app. More detail is on the account deletion page.
You can also complain to Brazil’s National Data Protection Authority (ANPD, gov.br/anpd) or, in the EU or UK, to your local data protection authority.
Security
All traffic between the app and our servers is encrypted with HTTPS, including photo uploads, and data is encrypted at rest. Each account can reach only its own data. No system is perfectly secure; if an incident puts your data at relevant risk, we will tell you and the ANPD, as the law requires.
Children
Collectverse is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, write to us and we will delete it.
Changes to this policy
When we change this policy we will update the date at the top. If a change is material, we will tell you before it takes effect, in the app or by email.
Contact
Collectverse — support@collectver.se
This address is also our channel for data protection requests under the LGPD.