COLLECTORS CATALOGUES
CREATE YOUR OWN MUSEUM

Privacy Policy

Last updated 28 August 2026

This explains what Collectors Catalogues collects, why, who can see it, and what control you have. The short version: we collect what the app needs to work, we are careful with findspot locations in particular, and we do not sell your data or run ads — ever.

Who is responsible for your data

Collectors Catalogues, independently operated from Canada, is responsible for your data. For any privacy question or request, write to collectorscatalogues@gmail.com. When paid memberships launch, this section will name the registered operating entity.

What we collect

Account details: your email address, display name, an automatically generated @handle, and a securely hashed password. We never store your password itself, which is also why nobody here can look it up or tell you what it is.

Profile details you choose to add: country, location, collecting focus, a short biography, the year you started, links to your own social or website pages, and a profile picture. All of these are optional.

Your catalogue: the objects you record, their photographs and sketches, measurements, references, provenance entries, examination notes, and any private valuations you enter.

Findspot information: a place description and, if you choose to add one, precise coordinates and a photograph of the findspot. See the next section — this is the most sensitive thing the app holds.

Community activity: comments, Identification board posts, private messages between collectors, likes, favourites, friend connections, project and exhibition participation, and the reports you submit.

Operational records: email verification and password-reset codes, notifications, and basic server logs. Exhibition pages count visits and how many people are viewing at once — those counts are aggregate numbers, not a record of who visited what.

Findspot locations — the part that matters most

Where an object came out of the ground is genuinely sensitive information. Published carelessly, it is a map for looters. The app is built around that risk:

Exact coordinates are shown only to you, the owner of the record. Nobody else ever receives them — not other collectors, and not visitors to a public museum page.

Everyone else sees a deliberately blurred position: a point randomised within a wide circle, aggregated with other finds in the same broad region into a single shaded area with a count. The blurring is applied on our server before the data leaves it, so the precise figure is never sent to another person’s device.

A photograph of the findspot is treated the same way — visible only to you, because a photograph of a place can identify it just as effectively as a coordinate.

Exact coordinates are included in research exports only for items whose owner has specifically ticked the box to share them for that purpose. It is off by default and set per item.

You never have to record a findspot at all. A record without one is still a perfectly good record.

Who can see your content

You control this, and the controls are per museum rather than all-or-nothing. A museum set to hidden is visible only to you, including its items and its comment thread. A museum set to public can be browsed by other collectors and appears on public share pages. An item you have not yet placed in a museum appears on the shared register like any other record. To keep an item to yourself, mark the item itself private on its page, or place it in a hidden museum.

Items that are not placed in any museum are private until you place them — or until you share one yourself, for example by posting it to the Identification board.

Your profile appears in the collector directory unless you turn that off. Private messages are visible only to you and the person you are writing to.

Administrators can see reported content in order to moderate it, and can see the contact messages you send us. They cannot browse your private messages — with one exception: if you report a message another collector sent you, that message is copied into your report so it can actually be reviewed, because a report nobody is allowed to read would be no protection at all. Reporting is the only thing that ever places a private message in front of an administrator, and only the person who received it can do that. They cannot see your private valuations, and they cannot see your exact findspot coordinates other than any you have expressly chosen to share for research exports.

Why we use it, and on what basis

To provide the service you asked for: your account, your catalogue, and the community features — this is the performance of our agreement with you.

To keep the service safe and working: moderation, dealing with abuse, security, and backups — our legitimate interest in running a service that is not harmful.

To contact you about your account: verification codes, password resets, and notifications you have not switched off. Notification emails can be turned off in your profile at any time; security emails cannot, because they protect the account itself.

We do not use your information to build advertising profiles, and we do not make automated decisions that have legal effects on you.

Who we share it with

We share only what a supplier needs in order to do its job, and none of them are permitted to use it for their own purposes:

Map provider: the maps in the app are drawn by the map service on your device — Google Maps on Android, Apple Maps on iOS. Other collectors’ devices never receive your exact coordinates: the pins they see are blurred on our server first. When you view your own findspot, the map on your own device necessarily processes that location in order to draw it.

Email delivery: verification codes, password resets, and notification emails are sent through Resend, an email delivery service (which in turn relies on Amazon Web Services to deliver the mail). It necessarily sees your email address and the contents of the message.

Hosting: the server and database run on DigitalOcean, a cloud hosting provider, in a data centre in New York, in the United States. Your information is therefore stored and processed in the United States, even though we operate from Canada.

App updates: the app checks for over-the-air updates through Expo (expo.dev). To serve the right update, Expo receives your device’s IP address and basic technical details about your app version. Expo does not receive your account details or anything in your catalogue.

App distribution: the app is installed through Google Play or the Apple App Store, and when paid membership launches, those stores will process the payment. We never see or hold your card details. The browser version is served from our own servers, with no app store involved.

We may also disclose information if the law genuinely requires it, or to protect someone’s safety.

If the service is ever transferred to another operator, your data would transfer with it, and we would tell you beforehand so you could export and leave first if you preferred.

What we never do

We do not sell your personal information, and we never will.

We do not run advertising, and we do not share your data with advertisers or data brokers.

We do not publish anyone’s exact findspot.

We do not use third-party analytics or tracking software in the app.

How long we keep it

Your account and catalogue are kept for as long as your account exists.

Verification and password-reset codes expire quickly — within 24 hours and one hour respectively — and are erased as soon as they are used.

Some records are deliberately permanent for the integrity of the register, and survive account deletion in a reduced form: retired identification numbers, provenance entries you wrote on objects now owned by someone else, and the frozen snapshot taken when an object changed hands. Where we can, these are separated from your name and reduced to what the historical record actually requires.

We keep nightly backup copies of the database and uploaded files, held for 14 days, so that nothing is lost to an accident or a technical fault. When you delete something it leaves the live service immediately; it then also ages out of these backups within 14 days.

Your rights and choices

You can see and correct most of your information directly in the app, at any time, in your profile and on each record.

You can export your entire catalogue yourself — as a CSV spreadsheet or a PDF dossier — from your profile. This is free for everyone, member or not, and it is deliberately not a paid feature: leaving should never cost anything.

You can delete your account yourself, at any time, from your profile — no need to ask us. It asks for your password, because it cannot be undone.

Deleting your account always erases your email address, profile details, private messages, private valuations, saved sign-in on the device you delete from, exact findspot coordinates, and findspot photographs. Your account can never be signed into again.

At the moment you delete, you choose what happens to your catalogue. Either your entries stay on the public register credited to "a former collector" — with exact findspots reduced to the blurred area that was already public — or your museums, items, photographs, posts, and comments are removed outright and their identification numbers retire with them.

A small amount of information survives in either case, because the register would otherwise be rewritable: provenance entries you wrote on objects now owned by someone else, and the frozen snapshots taken when an object changed hands. Your name is scrubbed from these; they are kept as the work of "a former collector".

If you would rather we did it for you, email collectorscatalogues@gmail.com from your account’s address.

Depending on where you live you may also have the right to object to or restrict certain processing, to receive your data in a portable format, and to lodge a complaint with your local data protection authority. In the UK that is the ICO; in Canada, the Office of the Privacy Commissioner. We would rather you came to us first so we can put it right.

Children

Collectors Catalogues is not intended for children under 16, and we do not knowingly collect their information. If you believe a child has created an account, tell us and we will remove it.

Security

Passwords are stored only as bcrypt hashes, never as text. Connections to the server are encrypted. Saved sign-in details on your phone are held in the device’s secure keystore; in the browser version they are held in ordinary browser storage instead, which the browser protects but which is not a keystore. Signing out clears them either way.

So that the app works in the field without a signal, records you have already opened are kept in private storage on your own device, and finds you catalogue while offline wait there until you reconnect. Both are erased when you sign out.

No service can promise perfect security. If a breach ever affects your personal information, we will tell you and the relevant regulator as quickly as the law requires and as plainly as we can.

Where your data is held

Your data is stored on servers in the United States (New York). If you are using the app from Canada or anywhere else, your information is transferred to and stored in the United States, protected by appropriate safeguards. You should be aware that data held in the United States can, in some circumstances, be accessed by United States authorities under their laws.

Changes to this policy

If we change this policy in a way that materially affects you, we will tell you in the app or by email before it takes effect, and we will always show the date it was last updated at the top of this page.

Terms of Service