Privacy policy
Last updated: 2026-07-21. This document explains what data the ColorCollect app ("the app", "we") and this website collect, why, and how long it stays around. This is not legal advice.
Summary
- Solo mode — nothing leaves your device.
- Group mode — photos and a chosen display name are sent to our backend (Supabase) so the people in your room can see them. Photos are auto-deleted from the server shortly after the room is finalized (typically within an hour), and at most 24 hours after a room goes inactive.
- Optional geotagging — if you opt in, GPS coordinates are saved locally with each photo. They are not sent to our servers unless you also opt in to sharing a photo's location with your group room.
- Optional crash reports — off by default. You can opt in from Settings → Privacy.
- We do not sell your data and we do not show ads. The app contains no third-party trackers; this website uses Google Analytics, but only after you accept cookies (see section 6).
- Optional in-app purchases — an optional premium unlock and optional donations (a "tip jar"). Payment is handled entirely by the App Store / Google Play; we never see or store your payment details. All core features remain free.
1. What we collect
1.1 Local storage (always)
The app stores the following on your device only:
- Montages — the grid, target color, frame style, and the cell photos you've taken.
- Settings — theme choice, display name, the random anonymous account id we generate the first time you use Group mode, and your crash-reporting / location preferences.
- Upload queue — pending photo uploads in Group mode, until they succeed or you discard them.
- Notification schedule — when you set a deadline on a group montage, a one-hour-before reminder is scheduled with the device's local notification system. The reminder text contains only the room code — no photos or display names.
You can clear all of this with Settings → Delete account & all data, or by uninstalling the app.
1.2 Backend storage (only in Group mode)
When you create or join a Group montage, the following is sent to our backend (Supabase, hosted in the EU):
- Anonymous account id — a random UUID generated on first launch. We do not ask for your email, phone number, or any other identifying information.
- Display name — the name you choose to be shown to other participants in your rooms.
- Room metadata — the room name (if the host set one), grid size, target color, frame style, deadline (if you set one), participant list, who owns which cell.
- Photo uploads — each photo you submit to a Group room is uploaded as a JPEG (max 350 KB). Photos are stored in encrypted-at-rest storage and served via short-lived signed URLs to other participants.
- Votes — in Vote-mode rooms, which candidate you voted for per cell.
- Per-day counters — number of rooms you created and photos you uploaded each day, for abuse prevention. Retained 30 days.
- IP address (implicit) — like every internet service, our backend sees the IP address you connect from. Supabase logs it for security purposes (rate limiting, abuse detection) according to their own retention policy. We do not separately store or analyse IPs.
1.3 Geotagging (opt-in)
If you enable "Save photo locations" in Settings, the app reads the GPS coordinates of each cell photo and stores them on your device. They are used to show your montages on an in-app map. By default these coordinates stay on your device only and are not included in Group-mode uploads.
There is a separate, also-optional setting, "Share photo location with my group". If you turn it on, the location of photos you add in a Group room is uploaded alongside the photo so the other participants in that room can see where it was taken on their map. This applies only to Group mode — your solo montage locations are never uploaded. Coordinates shared this way are stored with the group photo and are removed when that photo is deleted from our backend (within 7 days of the montage being finalized).
You can turn either setting off at any time. Turning off sharing stops new uploads; existing coordinates on the device remain until you delete the photo or the app.
1.4 Crash reports (opt-in)
Crash reporting is off by default. If you turn it on under Settings → Privacy → Send crash reports, the app sends anonymous crash diagnostics to Sentry (sentry.io) on the next launch. These reports include the stack trace, the OS version, the app version, and the anonymous account id — but not photos, room codes, display names, or device identifiers like IMEI / advertising id. You can turn the setting off again at any time; once off, no further reports are sent.
1.5 Notifications (Android 13+)
If you create a group montage with a deadline, the app schedules a one-hour-before local reminder using the system notification service. On Android 13+ the system will ask you for notification permission the first time. You can revoke it any time in system settings. Reminders are scheduled and fired entirely on your device — nothing is sent to a push server.
2. How long we keep things
- Local data on your device — Until you delete the app, or use Settings → Delete account & all data.
- Group-room photos — Auto-deleted from our servers shortly after the room is finalized (typically within an hour), and at most 24 hours after a room goes inactive.
- Unfinalized rooms older than 30 days — Auto-deleted.
- Per-day abuse-prevention counters — 30 days, then deleted.
- Crash reports (if you opt in) — 90 days at Sentry, then deleted.
3. Who can see your data
- Local data — only you.
- Group-room photos and votes — only the participants of the room you're in. Anyone with the 6-character room code can join the room and see its contents, so treat the code like a password — only share it with people you want in the montage.
- We (the operators) — Supabase support staff can technically access the database in the course of providing the hosted service. We do not routinely access user data and do not share it with anyone else.
4. International transfers
Our backend is hosted on Supabase in the EU (Frankfurt). If you're outside the EU, your data is transferred to and stored in the EU.
5. Your rights
You can:
- Delete everything in one tap — Settings → Delete account & all data. This wipes every montage, photo, room, setting, and the anonymous account id on this device, and asks our backend to delete every server-side row tied to your anonymous account (participations, photo uploads, votes, abuse-prevention counters, and the auth record itself). This action cannot be undone.
- Delete only local data — uninstall the app, or use the in-app delete buttons next to individual montages.
- Request server-side deletion by email — if the in-app deletion fails (e.g. you have no internet at the time), email lancimator@gmail.com with the anonymous account id from Settings and we will purge the server-side data manually within 30 days.
- Export your data — montages live on your device and can be saved to your gallery via the share sheet. To request a copy of server-side data, email the support address above.
6. Cookies & trackers
6.1 In the app
The app does not use cookies, advertising identifiers, or third-party trackers. We do not integrate Facebook SDK, Google Ads, or similar.
6.2 On this website
This website (the marketing and link-in-bio site) uses Google Analytics (GA4) to understand aggregate traffic — for example how many people visit, which pages they view, and roughly where visitors come from. Google Analytics sets cookies to do this.
Analytics is consent-gated: by default we tell Google to store nothing (analytics_storage and ad_storage are set to "denied"), so no analytics cookies are written and no data is sent until you press Accept on the cookie banner. If you press Decline (or ignore the banner), analytics stays off. Your choice is remembered in your browser's local storage so we don't ask again; you can reset it by clearing this site's site data in your browser.
We use analytics only in aggregate. We do not use it for advertising, ad personalization, or to build a profile of you — ad_storage, ad_user_data, and ad_personalization are left denied even after you accept. Google processes this data as described in Google's privacy policy. The website does not integrate Facebook SDK, Google Ads, or similar.
7. In-app purchases
ColorCollect offers optional in-app purchases: a one-time premium unlock and a set of optional donations (a "tip jar"). There are no subscriptions, and purchasing is never required — all core features are available for free.
All in-app purchases are processed entirely by the platform's own payment system — Google Play Billing on Android and the App Store on iOS. We never receive, see, or store your payment card or billing details; the store handles the transaction and only tells the app whether a purchase succeeded.
When you buy the premium unlock, the app records that purchase in a flag stored locally on your device so it can remember your entitlement; this flag is not sent to our backend. Donations are consumable and unlock nothing — they are simply a way to support development.
For your purchase history, refunds, and the data the store itself collects to process payments, see Apple's and Google's respective privacy policies.
8. Children
The app is rated for ages 12 and up. We do not knowingly collect data from children under 13. If you believe a child has used the app, email us and we will delete the relevant account.
9. Changes to this policy
Material changes will be announced in the app's release notes and reflected in the "Last updated" date at the top of this document.
10. Contact
Questions, complaints, or deletion requests: lancimator@gmail.com