Privacy Policy
Version 1.0 · Last updated: July 13, 2026
Collektor is built by collectors. Your collection is yours — we don't sell it, mine it, or advertise against it.
SOIBITS, LLC (the “Company”, “we”, “us”, or “our”) is committed to maintaining robust privacy protections for its users. This Privacy Policy (“Privacy Policy”) is designed to help you understand how we collect, use, and safeguard the information you provide to us and to assist you in making informed decisions when using our Service.
For purposes of this Privacy Policy, “Site” refers to the Company's website, which can be accessed at https://collektor.io; “App” refers to the Collektor mobile application; and “Service” refers to the Site and the App together — a personal collection catalogue in which users record, organize, and optionally share the items they collect. “You” refers to you, as a user of our Service.
By accessing our Service, you accept this Privacy Policy and our Terms of Use, and you consent to our collection, storage, use and disclosure of your Personal Information as described in this Privacy Policy.
The short version
- Guest mode stores nothing on our servers. If you use Collektor without an account, your items, photos, and collections never leave your device.
- We never sell your data, and we don't run ads.
- Your collections are private by default. Nothing is visible to anyone else until you explicitly change a collection's visibility.
- You can delete your account and all its data at any time, from inside the app.
I. Information we collect
We collect “Non-Personal Information” and “Personal Information.” Non-Personal Information includes information that cannot be used to personally identify you, such as anonymous usage data, platform and device types, referring/exit pages and URLs, preferences you submit, and aggregate statistics. Personal Information includes information that identifies you or could reasonably be linked to you, such as your email address, display name, and the content you associate with your account, which you submit to us through the registration process or your use of the Service.
1. Using Collektor without an account (guest mode)
Collektor works fully offline in guest mode. In this mode the App stores everything — items, collections, wishlists, and photos — in a local database on your device. No account is created, and none of that data is transmitted to us. If you delete the App without creating an account, that data is gone. If you later create an account, your local collection (including photos added while offline) is uploaded and synced to it.
2. Information you provide by registering for an account
To sync your collection across devices or use the community features, you must create an account. Depending on how you sign up, we receive:
- Email and password — the password is stored hashed; we never see or store it in plain text.
- Sign in with Apple — Apple provides us a user identifier and, if you allow it, your name and email. If you use Apple's Hide My Email, we only ever see the relay address.
- Google Sign-In — Google provides us your Google account's email, name, and profile picture.
3. Your collection data
Once you have an account, the content you create in the App is stored on our servers so it can sync to your other devices:
- Items — names, categories, descriptions, notes, condition, purchase and current value, barcodes, custom fields, and tags
- Collections and wishlists, and how items are grouped into them
- Photos and videos you attach to items
- Your profile — display name and avatar
- Community activity — posts, follows, and blocks, if you use the community features
4. Purchase and subscription information
If you purchase a Collektor Pro subscription, the purchase is processed by the app store you bought it through (Apple or Google). We never receive or store your payment card details. We receive from the app store the information needed to provide your subscription: your subscription status and tier, the product purchased, transaction and renewal identifiers, and purchase timestamps. We use this information to unlock subscription features, verify entitlements across your devices, and handle support questions about your subscription.
5. Information collected via technology
To operate and improve the quality of the Service, we collect certain technical information automatically:
- Server logs. Our servers record standard operational logs (IP address, timestamps, request metadata, and error diagnostics) needed to run and secure the Service. These are used for debugging and abuse prevention, not for profiling you.
- Website analytics. The Site uses Google Analytics 4 to count visits and understand which parts of the page people read. Analytics cookies are disabled until you accept them in the consent banner — if you decline, or ignore it, no analytics cookies are set. We also record which app-store button you clicked. IP addresses passed to Google Analytics are anonymised. We may use both persistent and session cookies; persistent cookies remain on your computer after you close your session and until you delete them, while session cookies expire when you close your browser.
- Fonts. The Site loads fonts from Google Fonts, which means Google's font servers see your IP address when the page loads. No cookies are set by that request.
- The App does not use Google Analytics or third-party advertising or tracking SDKs.
6. Children's privacy
The Service is not directed to anyone under the age of 13. The Service does not knowingly collect or solicit information from anyone under the age of 13, or allow anyone under the age of 13 to sign up for the Service. In the event that we learn that we have gathered personal information from anyone under the age of 13 without the consent of a parent or guardian, we will delete that information as soon as possible. If you believe we have collected such information, please contact us at soibits@soibits.com.
II. How we use and share information
Personal Information
Except as otherwise stated in this Privacy Policy, we do not sell, trade, rent or otherwise share for marketing purposes your Personal Information with third parties without your consent. We share Personal Information only with vendors who are performing services for the Company, and only to the extent needed to operate the Service:
- Amazon Web Services — hosting, database, and file storage. Your synced data is stored on our own infrastructure hosted with AWS in the United States (us-east-1). We use self-hosted, open-source backend software — your data is not handed to a third-party backend-as-a-service vendor.
- Apple and Google — if you choose to sign in with them (to authenticate you), and if you purchase a subscription through their app stores (to process payment and manage the subscription). Payment card details are collected and held by Apple or Google, never by us.
- Google Analytics — on the Site only, and only if you accept analytics cookies.
Those vendors use your Personal Information only at our direction and in accordance with our Privacy Policy. In general, the Personal Information you provide to us is used to operate the Service and to help us communicate with you — for example, to respond to questions, provide technical support, notify you of material changes, and (if you opt in) inform you about product updates.
We may share Personal Information with outside parties if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to meet any applicable legal process or enforceable governmental request; to enforce applicable Terms of Use, including investigation of potential violations; to address fraud, security or technical concerns; or to protect against harm to the rights, property, or safety of our users or the public as required or permitted by law.
What other users can see
Every collection has a visibility setting, and the default is private:
- Private — only you. Enforced at the database level, not just hidden in the interface.
- Friends — only people who follow you and whom you have not blocked.
- Public — any signed-in Collektor user can view it.
Photos are stored in a private storage bucket and served through short-lived signed links, so they are not accessible to anyone who does not have permission to see the item they belong to. Content you post to the community features is visible according to the visibility you choose when posting.
Non-Personal Information
In general, we use Non-Personal Information to help us improve the Service and customize the user experience. We also aggregate Non-Personal Information in order to track trends and analyze use patterns. This Privacy Policy does not limit in any way our use or disclosure of Non-Personal Information, and we reserve the right to use and disclose such Non-Personal Information at our discretion.
Business transfers
In the event we undergo a business transaction such as a merger, acquisition by another company, or sale of all or a portion of our assets, your Personal Information may be among the assets transferred. You acknowledge and consent that such transfers may occur and are permitted by this Privacy Policy, and that any acquirer of our assets may continue to process your Personal Information as set forth in this Privacy Policy. If our information practices change at any time in the future, we will post the policy changes to the Site so that you may opt out of the new information practices.
III. How we protect information
We implement security measures designed to protect your information from unauthorized access. Your account is protected by your account password (or your Apple/Google sign-in) and we urge you to take steps to keep your personal information safe by not disclosing your credentials. We further protect your information with technological security measures including encryption of data in transit (TLS), row-level access controls enforced at the database level, private photo storage with short-lived signed URLs, and firewalled infrastructure. However, these measures do not guarantee that your information will not be accessed, disclosed, altered or destroyed by breach of such safeguards. By using our Service, you acknowledge that you understand and agree to assume these risks.
IV. Data retention and deletion
We keep your account data for as long as your account exists. When you delete your account from within the App, your items, collections, photos, and profile are deleted from our systems. Backups are rotated and purged on a rolling schedule, so deleted data may persist in encrypted backups for a limited period before it ages out. We may retain subscription transaction records after account deletion where needed for tax, accounting, and fraud-prevention purposes, as permitted by law. Data stored locally on your device in guest mode is under your control and is removed when you delete the App.
V. Your rights regarding the use of your Personal Information
You have the right at any time to prevent us from contacting you for marketing purposes. When we send a promotional communication to a user, the user can opt out of further promotional communications by following the unsubscribe instructions provided in each promotional e-mail. Please note that notwithstanding your promotional preferences, we may continue to send you administrative emails, including, for example, periodic updates to this Privacy Policy.
Wherever you live, you can also:
- Access and export your data — contact us and we will provide it.
- Correct anything wrong — most of your data is editable directly in the App.
- Delete your account and its contents, from the App or by contacting us.
- Withdraw analytics consent on the Site at any time by clearing your browser's site data for collektor.io.
If you are in the EU/EEA or the UK, the GDPR provides these rights explicitly — including the rights of access, rectification, erasure, restriction, portability, and objection — plus the right to lodge a complaint with your local data protection authority. If you are a California resident, the CCPA/CPRA provides comparable rights, including the right to know, delete, and correct; we do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. We will not discriminate against you for exercising any of these rights.
VI. Links to other websites
As part of the Service, we may provide links to or compatibility with other websites or applications. However, we are not responsible for the privacy practices employed by those websites or the information or content they contain. This Privacy Policy applies solely to information collected by us through the Service. We encourage our users to read the privacy statements of other websites before proceeding to use them.
VII. Changes to our Privacy Policy
The Company reserves the right to change this Privacy Policy and our Terms of Use at any time. We will notify you of significant changes to this Privacy Policy by sending a notice to the primary email address specified in your account or by placing a prominent notice in the App or on the Site. Significant changes will go into effect 30 days following such notification. Non-material changes or clarifications will take effect immediately. You should periodically check the Site and this privacy page for updates.
VIII. Contact us
If you have any questions regarding this Privacy Policy or the practices of this Service, or want your data exported or deleted, please contact us:
SOIBITS, LLC
131 Continental Dr
Newark, Delaware 19713