Privacy Policy

What we collect, what we do with it, and what we will never do with it — described as Kollekta actually works today, not as we hope it might.

Draft — under legal review. This document is published in draft so it can be read alongside the alpha. It has not yet been reviewed by our lawyers, and will be finalised before Kollekta opens beyond the invite-only alpha.

The short version

  • We never sell your data. Not to advertisers, not to data brokers, not to anyone. There is no version of Kollekta where that changes.
  • We collect what we need to run the app for you, and not much else.
  • The Kollekta app sets no cookies, and does no analytics or advertising tracking. Our marketing website uses Google Analytics — but only if you accept its cookie banner. If anything changes in the app, we'll tell you and ask first.
  • Your collection is visible only to you (and our administrators) today. If sharing features arrive, you'll choose what others see.
  • We use aggregated, de-identified data — combined across accounts so it identifies no one — to power comparisons and community features.
  • Your Discogs data is yours. We only touch it because you told us to, and we never hand it to anyone else.

1. Who we are

2. What we collect, and why

2.1 When you join the waitlist

  • Email address — to send your confirmation and, later, your invitation
  • Country — to pace invitation waves
  • Approximate collection size — to decide which wave suits you
  • Format mix (vinyl / CD / cassette / digital / other, as percentages) — same
  • How you manage your collection today — same
  • Which streaming services you use — same

2.2 When you have an account

  • Email address — sign-in, account email, and to contact you about the Service
  • First and last name — to address you properly; first name is required at signup
  • Username — identifies your account
  • Password — sign-in. Handled by our authentication provider (Supabase) — it is hashed, and we never see or store your plain password
  • Avatar image, if you upload one — displayed in your profile
  • Your streaming service preferences — to show the right listen-on buttons

2.3 Your collection data

2.4 If you connect Discogs

  • Your Discogs username — Identifies the connected account
  • Discogs access tokens — Encrypted at rest using AES-256-GCM. The encryption key is held as a server-side secret, separate from the database
  • Your Discogs collection and wantlist — Retrieved on your authorisation, stored so the app works, and kept in sync
  • A cached snapshot of your Discogs collection and wantlist — Held on your account record so we can compute what has changed since the last sync, without re-downloading everything
  • we never transfer it to any third party;
  • we never use it for advertising or marketing, and we never feed it to any advertising or marketing platform. This is an absolute rule at Kollekta, not a current preference — see section 5;
  • we never make it public (see section 6);
  • we don't aggregate it into anything we sell.

2.5 Technical and activity data

  • Activity events — Significant actions: signing in, signing up, running a Discogs sync. Each record includes your IP address and browser user-agent. We use these to operate the Service, investigate problems, and detect abuse
  • Search performance measurements — When you search, your browser reports timings: how long the request took, its size, whether the connection was cold, and the number of characters you typed (not what you typed). The measurement itself contains no identifier and no search text; it is emitted to our hosting provider's logging. The request carrying it is authenticated, so it is not anonymous to us in the strictest sense — we're telling you rather than claiming otherwise. We use it only to make search faster
  • Server logs — Our hosting provider (Cloudflare) records requests, including IP addresses, as part of running the service and protecting it from abuse

2.6 If you contact us

Replies and conversations. We can reply to your message, and you can reply back — in the app under Profile → Support, and by email. Everything in that conversation is stored with the original ticket: what we wrote, what you wrote, and any screenshots either of us attached. When we reply we also send that reply to your email address.

"Remove from my list" does not delete anything. You can clear a ticket from your own Support list. That hides it from you; we keep our copy — the message, the whole conversation and any screenshots — as an operational record. If you want something you sent us genuinely erased, ask us (see section 13) and we'll delete it.

2.7 What we do NOT collect

  • No payment details today. Kollekta is currently free. If we introduce paid features, payments will be handled by a specialist payment provider — we'd receive confirmation of payment, not your full card details — and we'll update this policy first.
  • No advertising identifiers. There is no advertising ID, tracking pixel or cross-site profile in the Kollekta app, and your personal information is never sent to advertising platforms — not for anyone's advertising, including our own. Our marketing website uses Google Analytics (loaded only if you accept its cookie banner) and may add advertising measurement in future, with consent where required (section 3). We may also add product analytics inside the app to understand how features are used and improve them — never for advertising — and we'll update this policy first.
  • No precise location. We don't ask for or track your location. You may in future be able to set a city or timezone in your profile so features like insights and comparisons work properly — that's information you choose to give us.
  • No contacts. We will never ask for your contacts.
  • Camera — only if you scan, and the pictures never leave your device. Kollekta can use your device camera to read a barcode off a record sleeve so you don't have to type the number. Access is requested only when you start a scan, is entirely optional, and is controlled in your browser and device settings. The camera picture is read on your devicewe never upload, store or transmit any image, video or frame from it. The only thing that reaches us is the barcode number itself, handled exactly like a number you typed into the search box. A future Kollekta mobile app may also offer optional microphone access (recognising what you're playing) on the same terms.
  • We don't buy personal information about you from anyone.

3. Cookies and storage on your device

  • Your sign-in session (a token from our authentication provider) — keeps you signed in. Essential — the app can't work without it
  • Interface preferences: sidebar state, view mode, artwork size, panel width, expanded sections, dismissed notices, filters — remembers how you like the app. Functional
  • The last album you logged a play for — prevents accidental double-logging. Functional

How we handle cookies and consent

  • Essential — sign-in and security, the basics the Service can't run without. No consent needed (they're strictly necessary).
  • Functional — remembering your preferences and choices. Used to improve your experience; described here.
  • Analytics — understanding how people find and use Kollekta. Only where you've agreed, where consent is required.
  • Advertising measurement — measuring our own marketing, on the marketing site only, never inside the app. Only where you've agreed, where consent is required.

4. Who we share it with

  • Supabase — Authentication and our database — this is where your account and collection live. Australia (Sydney region)
  • Cloudflare — Hosting and application processing, caching, file storage (avatars, artwork, feedback screenshots), bot protection (Turnstile), image resizing, and request logging. Global network
  • Resend — Sending transactional email — your confirmation, invitation, sync notifications and account emails. They receive your email address and the content of those emails
  • Discogs — Only if you connect a Discogs account, and only to sync your own data with your own Discogs account
  • when you tell us to — for example, connecting Discogs, or following a link to Apple Music or Spotify;
  • when the law requires it — a court order, or a lawful request from an authority. We'll tell you where we're allowed to;
  • to protect people — to investigate fraud, abuse, security incidents, or threats to someone's safety;
  • in a business transfer — if the Kollekta business is transferred (including a transfer to a company, such as FNRBLR Pty Ltd), your information moves with it, subject to this policy. We'll tell you.

Within FNRBLR

A note about album artwork

Who at Kollekta can see your data

5. The Discogs advertising wall — a commitment

Your Discogs-synchronised collection and wantlist will never be sent to, or used by, any advertising, marketing or analytics platform.

6. What others can see

7. How long we keep it, and how to get rid of it

Deleting your account

  • We first disable the account. You're signed out and can't sign back in. Your data still exists at this point, so that an accidental or disputed deletion can be reversed.
  • A full deletion removes your account and your collection, Up Next, Want List and play history.
  • A disabled account is purged automatically after 30 days. A daily job permanently deletes accounts whose 30-day window has passed — so a disabled account doesn't sit around indefinitely, and you don't have to chase us. Ask us to delete sooner and we'll action it straight away rather than wait for the window.
  • What we keep afterwards is listed immediately below — it's deliberately narrow.

What survives a deletion

  • Feedback and support messages you sent, and the full conversation that followed — the link to your account is removed, but the messages, their technical context and any screenshots remain, as an operational record.
  • A record of the deletion itself. When an account is deleted we keep a narrow history row: the email address, the username, when the account was created and when it was deleted, and the reason. We keep it so we can recognise a returning applicant, honour a re-invite, and stop a removed account being immediately recreated. It holds no names, no collection content and no counts.
  • Administrative audit records of the deletion itself, which include the email address and username of the deleted account.
  • Your waitlist application, if you joined via the waitlist — this is currently retained. Ask us and we'll delete it.
  • Backups, which cycle out over time.

Other retention

  • Support conversations (your ticket, our replies, yours, and any screenshots) — Retained as an operational record, including after you remove a ticket from your list or delete your account. Ask us and we'll delete it
  • Deleted-account history (email, username, dates, reason) — Retained after the account is gone, so we can recognise a returning applicant and honour a re-invite
  • Waitlist applications — Retained until you ask us to delete them
  • Activity events (incl. IP, user-agent) — Retained for the life of the account; deleted with it. We have not yet set a shorter limit — we intend to
  • Search performance measurements — Held in our hosting provider's logs under their retention settings; contain no identifier
  • Server/request logs — Per Cloudflare's retention

8. Your rights

  • ask what we hold about you, and get a copy;
  • correct anything that's wrong (much of it you can edit yourself in your profile);
  • ask us to delete your account and data (section 7);
  • withdraw consent — disconnect Discogs, or stop using the Service;
  • object to, or ask us to restrict, certain processing;
  • ask for portability of data you gave us, in a machine-readable form;
  • complain if you think we've mishandled your information.

9. Where your data is, and international transfers

10. Security

  • Discogs tokens are encrypted at rest with AES-256-GCM; the key is a server-side secret held separately from the database.
  • Passwords are hashed by our authentication provider; we never see them.
  • Everything is served over HTTPS.
  • Data endpoints require authentication; administrative endpoints require an administrator account and are audit-logged.
  • Public forms are rate-limited and protected by Cloudflare Turnstile.

11. Children

12. Changes to this policy

13. Contact

  • Privacy, legal, copyright / takedown, security reportslegal@fnrblr.com
  • General and support — help@kollekta.app
  • Post — FNRBLR, Workit Spaces, Unit A1/35–39 Bourke Road, Alexandria NSW 2015