Privacy Policy
Effective October 4, 2026
The short version
- We collect only what the app needs to work: your sign-in details, your profile, and the content you create.
- If you agree, the mobile apps measure installs, launches, sign-ups and purchases, to know which of our ads work (see “Advertising and measurement” below). Nothing in your collections is ever part of it. We never sell or rent your data.
- Public collections are visible to everyone; private collections are visible only to you.
- You can delete your account and all of your data at any time from inside the app.
Who we are
Collectionist is operated by Nicolas Frugoni, an individual developer based in Barcelona, Spain, who is the data controller for the personal data described here. Because we are established in the EU, the General Data Protection Regulation (GDPR) and Spanish data protection law apply. Contact: nfrugoni19@gmail.com.
What we collect
Account information
You sign in with Apple, Google or an email address and password through Firebase Authentication. We receive a unique user ID, your name and your email address (if you use Sign in with Apple and choose “Hide My Email”, we only receive an Apple relay address), and — for Google — your profile photo if you have one.
Profile
Your username, bio, profile photo and your direct-message preference (everyone, people you follow, or nobody).
Content you create
Collections and items (names, descriptions, categories, photos, tags, attributes such as condition, year, estimated value or purchase price, and custom fields), set checklists, comments, likes, follows, direct messages, blocks and the reports you submit.
Purchases
If you buy Premium, Apple processes the payment — we never see your card or payment details. Apple sends us signed purchase records (product, transaction identifiers, purchase/expiry dates, renewal and refund status) linked to a random identifier we generate for your account, so we can unlock Premium for you.
On Android, Google Play processes the payment the same way. Google Play gives us the purchase token, product, purchase and expiry dates and renewal status for your subscription, linked to the same random identifier, and we check it with Google Play to unlock Premium.
Barcode lookups
When you scan a barcode, the barcode number (and nothing else about you) is sent from our servers to public product databases to suggest item details: Open Library and Google Books (books), Discogs and MusicBrainz (music), Open Food Facts, Open Beauty Facts and Open Products Facts, and UPCitemdb. Results are cached without any link to you.
When you save an item with a barcode, we also keep the product facts you entered (its name, category and descriptive attributes, never condition, prices, dates or notes) in a shared barcode catalog, so the next collector who scans the same code gets a suggestion. An entry is only suggested to others if it came from a public collection or if at least two collectors saved the same name, and it never shows who saved it. Deleting your account removes your entries.
Technical data
Like any online service, our hosting provider records basic request logs (such as IP address, time and request type) used for security and to keep the service running. We do not use these logs to profile you.
We do not collect your precise location, contacts, or browsing history. The advertising identifier of your phone is read only if you agree when the app asks (see “Advertising and measurement” below).
Public and private content
Each collection is either public or private, and you can change this at any time.
- Public collections and their items and photos, your comments, and your profile (username, photo, bio, follower counts and public collections) can be seen by anyone, including in the app’s feeds and search and on share links on this website (for example
collectionist-backend.web.app/c/…). - Private collections and their items are only shown to you. (Photos are stored at long, unguessable web addresses; anyone you give such an address to could open that photo.)
- Direct messages are visible to you and the other participant. They are encrypted in transit but not end-to-end encrypted; we only look at a message if it is reported to us or if required by law.
How we use your data and why (legal bases)
- To provide the service you asked for — your library, sharing, social features, messaging and Premium (performance of our contract with you, GDPR Art. 6(1)(b)).
- To keep the community safe — filtering objectionable text, handling reports, blocking, preventing abuse and securing our systems (our legitimate interests, Art. 6(1)(f)).
- To comply with the law — for example tax records of purchases held by Apple, or valid requests from authorities (Art. 6(1)(c)).
We don’t use the content you create for advertising, and we don’t make automated decisions that have legal or similarly significant effects on you.
Who processes your data
We don’t sell or share your personal data with third parties for their own purposes. We use these service providers (processors) to run Collectionist:
- Google (Firebase / Google Cloud) — authentication, database, photo storage, servers and this website. Data may be processed in the United States and other countries where Google operates, protected by Google’s data processing terms, the EU–US Data Privacy Framework and/or Standard Contractual Clauses.
- Apple — Sign in with Apple and App Store purchases.
- Google Play — purchases in the Android app.
- Google Sign-In — if you choose to sign in with Google.
- Meta (Facebook and Instagram) and Google Analytics for Firebase — mobile apps only, and only if you agree; receive the usage events described under “Advertising and measurement”.
- Open Library, Google Books, Discogs, MusicBrainz, Open Food/Beauty/Products Facts and UPCitemdb — receive only barcode numbers, as described above.
How long we keep it
We keep your data for as long as you have an account. When you delete your account we permanently delete your profile, collections, items, photos, comments, likes, follows, conversations and notifications, and your sign-in record. Residual copies in server logs expire within about 30 days. Reports you filed may be kept while we need them to resolve a safety issue.
Deleting your account
Advertising and measurement
We advertise Collectionist on Instagram and Facebook. To learn which ads lead to installs, the mobile apps can tell Meta, and Google Analytics for Firebase, that the app was installed or opened, that an account was created, or that a subscription was bought. They report that these things happened and never what they were about: no collection, item, comment, message, photo, barcode or name is ever part of it, and it is not linked to your Collectionist account.
Nothing is sent unless you agree. On iPhone the app asks for permission to track you, using Apple’s standard prompt. On Android the app asks once after you sign in, and “No thanks” is a complete answer. If you agree, Meta may match these events to your phone’s advertising identifier to measure our ads. If you decline on iPhone, no advertising identifier is read and Meta only learns, in aggregate and through Apple’s privacy-preserving attribution, that an ad led to an install.
You can change your choice at any time: on iPhone in Settings → Privacy & Security → Tracking; on Android in Collectionist → Settings → Ad measurement (and in your phone’s Settings → Privacy → Ads, where you can also reset or delete your advertising ID). The website does not use Meta or Google Analytics.
Your rights
You have the right to access, correct, delete, restrict or object to the processing of your personal data, and to receive a copy of it in a portable format (you can also export any collection to CSV in the app). To exercise these rights, email nfrugoni19@gmail.com; we’ll reply within one month. You can also complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (AEPD), or your local authority.
Children
Collectionist is not intended for children under 14, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we’ll delete it.
Security
All traffic is encrypted with HTTPS, data is stored with Google Cloud’s security controls, and access to content is enforced on our servers. No system is perfectly secure, but we work to protect your data and will notify you and the authorities of a breach where the law requires.
Changes
If we change this policy we’ll update the date above and, for significant changes, let you know in the app.