← Back to CollectViz
Draft — pending counsel and privacy review. Previously blank [TODO] sections have been populated with industry-standard defaults so reviewers have a complete document, not a skeleton. Items still requiring a business decision are flagged inline with [Confirm with counsel]. This policy is not in force until reviewed, finalized, and dated.

1. Who we are

CollectViz.ai (“we”, “us”), a California company, operates the CollectViz analytics service. Privacy contact: privacy@collectviz.ai.

2. What we collect and why

CategoryExamplesWhy we process it
Account Email address, hashed password, MFA factor metadata, sign-in timestamps To create and secure your account; authenticate you
Collection data CSV imports, portfolio snapshots, item-level data you choose to upload To provide analytics and the Service features you use
AI research Prompts derived from your collection, responses from AI providers, cached results To generate research and decision support
Email import The private inbound address we generate, CSVs forwarded to it, sender metadata To stage collection CSV imports
Usage and diagnostics API request counts, errors, basic device/browser info To operate the Service, prevent abuse, and debug problems
Billing [when added] Subscription state, billing email, payment processor IDs (we do not store card numbers) To manage subscriptions and invoicing

3. Where your data lives (sub-processors)

We rely on the following sub-processors. Each provider operates under its own terms and privacy policy, linked below. We do not sell your data to any of them, and we configure each to the most privacy-preserving option available.

International transfers. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. Where required (e.g., for EEA/UK users), we rely on the EU Standard Contractual Clauses and sub-processor commitments to provide an appropriate level of protection. [Confirm with counsel: whether a separate DPA / SCCs intake page is needed for EU business customers.]

4. Personal API keys

If you paste personal third-party API keys (for example, your own OpenAI key) into Settings, those keys are stored in your browser's local storage. They are not synced to our servers unless you explicitly opt in to a sync feature. If you sign out or clear your browser data, those keys are removed from that device.

5. AI processing

When you request AI research, the relevant context (product names, set, your inventory snippet, and aggregated portfolio metrics where relevant) is sent to OpenAI via the OpenAI API. Per OpenAI's API data-usage policies, API content is not used to train OpenAI's models by default. OpenAI may retain API content for up to 30 days for abuse-and-misuse monitoring, after which it is deleted (unless legally required to be retained longer).

CollectViz also caches AI responses on our own infrastructure to avoid repeating expensive calls. User-private inputs (cost basis, quantities owned, portfolio concentration, internal item IDs, and target sell rates) are sanitized out before any response is written to our shared/global AI memo cache; only reusable product- and set-level facts are stored globally. Per-user metrics are stored only in your own row-level-secured records.

We do not sell AI prompts or outputs, and we do not allow OpenAI to train on your prompts. [Confirm with counsel: whether the privacy policy should list an opt-out mechanism for users who do not want their prompts cached even in sanitized form.]

6. Your rights

You may:

To make a request, email privacy@collectviz.ai from the address associated with your account. We will acknowledge your request within 7 days and substantively respond within 30 days. Where applicable law (e.g., GDPR Art. 12(3), California Civil Code § 1798.130) allows or requires an extension for complex requests, we may extend by up to an additional 60 days and will explain why. We may need to verify your identity before fulfilling the request.

You also have the right to lodge a complaint with your local data-protection authority (for example, your EU member-state DPA, the UK ICO, or your state attorney general).

7. Retention

8. Security

We take a defense-in-depth approach. Current measures include:

No security is perfect. If you discover a vulnerability or have a concern, please email security@collectviz.ai. We ask that you give us a reasonable time to investigate and remediate before public disclosure.

9. Cookies and similar technologies

We use only the cookies and browser-storage entries strictly necessary to operate the Service and remember your preferences. We do not use third-party advertising cookies, do not embed analytics trackers that profile you across sites, and do not sell cookie-derived data.

Name / patternTypePurposeLifetime
sb-*-auth-token Supabase auth (1st-party, strictly necessary) Keeps you signed in between page loads Session + refresh token; cleared on sign-out
cf_* (Turnstile) Cloudflare Turnstile (strictly necessary, signup only) Bot/abuse protection on sign-up Short-lived (per challenge)
collectviz.* (localStorage) 1st-party browser storage (functional) Remembers UI preferences and in-progress drafts — e.g., collectviz.passwordSetupNudgeDismissed, collectviz.marketIntel.submissionBuilder, portfolio filters, and any personal third-party API keys you enter Persists until you clear browser data or sign out
IndexedDB (CollectViz cache) 1st-party browser storage (functional) Caches portfolio snapshots and dossier data for offline-friendly performance Persists until you clear browser data

Because we only use strictly-necessary and functional storage, we do not currently display a cookie consent banner. If we add analytics or marketing cookies in the future (e.g., for opt-in product analytics), we will present a consent prompt where required by law (e.g., EU/UK ePrivacy). [Confirm with counsel: review this table after launch instrumentation lands — any product-analytics or Sentry SDK that drops a cookie/ID needs to be listed here, and a consent banner added where required.]

10. Children and minimum age

The Service is intended only for adults. Consistent with our Terms of Service, you must be at least 18 years old (or the age of majority in your jurisdiction) to create an account, and the Service is not directed to or intended for anyone under that age. We do not knowingly collect personal data from anyone under the applicable age. If you believe a person under that age has provided us personal data, contact us at privacy@collectviz.ai and we will delete it.

[Confirm with counsel: final COPPA (US, under 13) and GDPR-K (EU/UK, child-consent age 13–16, varies by member state) posture, and whether any age verification or parental-consent mechanism is warranted given the collectible-card audience.]

11. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email to your account address or by prominent in-app notice at least 30 days in advance of the effective date. Non-material changes (clarifications, typos, sub-processor address updates) may be made without prior notice but will be reflected in the "Last updated" date at the top of this page.

12. Contact

Privacy questions, data requests, or complaints: privacy@collectviz.ai.

Security reports: security@collectviz.ai.

General/legal: legal@collectviz.ai.

CollectViz.ai — California, United States.