Legal
Privacy Policy
Effective date: TBD · Last updated: TBD
1. Who we are
CollectViz.ai (“we”, “us”), a California company, operates the CollectViz analytics service. Privacy contact: privacy@collectviz.ai.
2. What we collect and why
| Category | Examples | Why we process it |
|---|---|---|
| Account | Email address, hashed password, MFA factor metadata, sign-in timestamps | To create and secure your account; authenticate you |
| Collection data | CSV imports, portfolio snapshots, item-level data you choose to upload | To provide analytics and the Service features you use |
| AI research | Prompts derived from your collection, responses from AI providers, cached results | To generate research and decision support |
| Email import | The private inbound address we generate, CSVs forwarded to it, sender metadata | To stage collection CSV imports |
| Usage and diagnostics | API request counts, errors, basic device/browser info | To operate the Service, prevent abuse, and debug problems |
| Billing [when added] | Subscription state, billing email, payment processor IDs (we do not store card numbers) | To manage subscriptions and invoicing |
3. Where your data lives (sub-processors)
We rely on the following sub-processors. Each provider operates under its own terms and privacy policy, linked below. We do not sell your data to any of them, and we configure each to the most privacy-preserving option available.
- Supabase, Inc. — authentication, primary database (Postgres), and file storage. Data is stored in the United States (US East — Ohio, us-east-2) on Supabase's managed infrastructure. (privacy policy)
- Vercel Inc. — hosts the web app and serverless API routes; global edge network with primary compute in the United States. (privacy policy)
- OpenAI, L.L.C. — receives prompts (product, set, and inventory context) to generate research, leaderboard opportunity reads, and Ask CollectViz AI responses. We use OpenAI's API; per OpenAI's API data-usage policy, API inputs and outputs are not used to train OpenAI models by default. OpenAI may retain API content for up to 30 days for abuse-and-misuse monitoring. (privacy policy)
- Mailgun Technologies, Inc. — processes the inbound email address used by the collection CSV-import feature; receives forwarded CSVs and sender metadata. (privacy policy)
- Cloudflare, Inc. — serves Cloudflare Turnstile bot-protection challenges on the sign-up form (when enabled). (privacy policy)
- Google LLC (Sign in with Google) — when you use Google to sign in, Google shares your basic profile (email, name, account ID) with us per your Google permissions. We do not receive your Google password. (privacy policy)
- Apple Inc. (Sign in with Apple) — when enabled and you use Apple to sign in, Apple shares the relay or real email you authorize and a stable account identifier. (privacy policy)
- Error monitoring / observability provider — not currently enabled. We expect to introduce server-side error monitoring (e.g., Sentry) before public launch; this section will be updated and the provider added to the sub-processor list at that time. [Confirm with counsel once selected.]
- Product analytics provider (e.g., PostHog) — not currently enabled. We expect to introduce privacy-preserving product analytics to understand how features are used; when enabled it will run on an EU-hosted instance, identify you only by a pseudonymous account identifier (not your email address), and we will not use it for cross-site advertising or to sell your data. This section will be updated and the provider added to the sub-processor list when it is activated. [Confirm with counsel once activated; see also the cookies/consent note in the cookies section.]
- Stripe, Inc. (planned) — payment processing for paid plans. Stripe receives card details directly via Stripe Elements/Checkout; CollectViz never stores raw card numbers. Stripe is a PCI-DSS Level 1 service provider. (privacy policy)
International transfers. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. Where required (e.g., for EEA/UK users), we rely on the EU Standard Contractual Clauses and sub-processor commitments to provide an appropriate level of protection. [Confirm with counsel: whether a separate DPA / SCCs intake page is needed for EU business customers.]
4. Personal API keys
If you paste personal third-party API keys (for example, your own OpenAI key) into Settings, those keys are stored in your browser's local storage. They are not synced to our servers unless you explicitly opt in to a sync feature. If you sign out or clear your browser data, those keys are removed from that device.
5. AI processing
When you request AI research, the relevant context (product names, set, your inventory snippet, and aggregated portfolio metrics where relevant) is sent to OpenAI via the OpenAI API. Per OpenAI's API data-usage policies, API content is not used to train OpenAI's models by default. OpenAI may retain API content for up to 30 days for abuse-and-misuse monitoring, after which it is deleted (unless legally required to be retained longer).
CollectViz also caches AI responses on our own infrastructure to avoid repeating expensive calls. User-private inputs (cost basis, quantities owned, portfolio concentration, internal item IDs, and target sell rates) are sanitized out before any response is written to our shared/global AI memo cache; only reusable product- and set-level facts are stored globally. Per-user metrics are stored only in your own row-level-secured records.
We do not sell AI prompts or outputs, and we do not allow OpenAI to train on your prompts. [Confirm with counsel: whether the privacy policy should list an opt-out mechanism for users who do not want their prompts cached even in sanitized form.]
6. Your rights
You may:
- Export your collection data and AI memos from Settings — a downloadable JSON copy of your account data.
- Delete your account from Settings, which removes your data per the retention schedule below.
- Request a copy of the personal data we hold about you.
- If you are in the EEA, UK, California, or another covered jurisdiction, exercise rights of access, correction, deletion, portability, restriction, and objection, as applicable.
To make a request, email privacy@collectviz.ai from the address associated with your account. We will acknowledge your request within 7 days and substantively respond within 30 days. Where applicable law (e.g., GDPR Art. 12(3), California Civil Code § 1798.130) allows or requires an extension for complex requests, we may extend by up to an additional 60 days and will explain why. We may need to verify your identity before fulfilling the request.
You also have the right to lodge a complaint with your local data-protection authority (for example, your EU member-state DPA, the UK ICO, or your state attorney general).
7. Retention
- Account and collection data: retained while your account is active.
- After account deletion: removed from production systems within 30 days. Encrypted backups (Supabase Pro point-in-time recovery) may retain data for up to 7 days after deletion, after which it is overwritten in the normal backup rotation.
- AI research cache (user-scoped): retained while your account is active to avoid repeating costly AI calls; cleared on account deletion.
- AI research cache (global, sanitized): reusable product/set facts with user-private fields removed may be retained indefinitely as a shared knowledge base for the Service and are not tied to your account after deletion.
- Usage and diagnostic logs: retained for up to 12 months for security, abuse detection, and debugging, then deleted or aggregated.
- Billing records: retained as required by applicable tax and accounting law (typically 7 years in the U.S.).
8. Security
We take a defense-in-depth approach. Current measures include:
- Supabase Auth with optional TOTP multi-factor authentication and a 12-character minimum password length.
- Row-level security (RLS) policies on every protected table, enforcing strict per-user data isolation, plus cross-user isolation tests in our test suite.
- All traffic encrypted in transit via HTTPS/TLS. Supabase encrypts data at rest.
- HMAC-verified inbound webhooks (e.g., Mailgun) to prevent spoofing.
- Server-side AI proxying so personal API keys never leave your browser.
- Per-user, per-month token budgets and rate limiting on cost-bearing endpoints to contain abuse.
- Service-role secrets and third-party API keys held only on the server (Vercel serverless environment); never exposed to the browser bundle.
No security is perfect. If you discover a vulnerability or have a concern, please email security@collectviz.ai. We ask that you give us a reasonable time to investigate and remediate before public disclosure.
9. Cookies and similar technologies
We use only the cookies and browser-storage entries strictly necessary to operate the Service and remember your preferences. We do not use third-party advertising cookies, do not embed analytics trackers that profile you across sites, and do not sell cookie-derived data.
| Name / pattern | Type | Purpose | Lifetime |
|---|---|---|---|
sb-*-auth-token |
Supabase auth (1st-party, strictly necessary) | Keeps you signed in between page loads | Session + refresh token; cleared on sign-out |
cf_* (Turnstile) |
Cloudflare Turnstile (strictly necessary, signup only) | Bot/abuse protection on sign-up | Short-lived (per challenge) |
collectviz.* (localStorage) |
1st-party browser storage (functional) | Remembers UI preferences and in-progress drafts — e.g.,
collectviz.passwordSetupNudgeDismissed,
collectviz.marketIntel.submissionBuilder, portfolio filters, and any
personal third-party API keys you enter |
Persists until you clear browser data or sign out |
| IndexedDB (CollectViz cache) | 1st-party browser storage (functional) | Caches portfolio snapshots and dossier data for offline-friendly performance | Persists until you clear browser data |
Because we only use strictly-necessary and functional storage, we do not currently display a cookie consent banner. If we add analytics or marketing cookies in the future (e.g., for opt-in product analytics), we will present a consent prompt where required by law (e.g., EU/UK ePrivacy). [Confirm with counsel: review this table after launch instrumentation lands — any product-analytics or Sentry SDK that drops a cookie/ID needs to be listed here, and a consent banner added where required.]
10. Children and minimum age
The Service is intended only for adults. Consistent with our Terms of Service, you must be at least 18 years old (or the age of majority in your jurisdiction) to create an account, and the Service is not directed to or intended for anyone under that age. We do not knowingly collect personal data from anyone under the applicable age. If you believe a person under that age has provided us personal data, contact us at privacy@collectviz.ai and we will delete it.
[Confirm with counsel: final COPPA (US, under 13) and GDPR-K (EU/UK, child-consent age 13–16, varies by member state) posture, and whether any age verification or parental-consent mechanism is warranted given the collectible-card audience.]
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email to your account address or by prominent in-app notice at least 30 days in advance of the effective date. Non-material changes (clarifications, typos, sub-processor address updates) may be made without prior notice but will be reflected in the "Last updated" date at the top of this page.
12. Contact
Privacy questions, data requests, or complaints: privacy@collectviz.ai.
Security reports: security@collectviz.ai.
General/legal: legal@collectviz.ai.
CollectViz.ai — California, United States.