Privacy Policy

Last updated 11 October 2026

collect3r is a personal disc catalog: you track physical music releases you own or want, with an optional public profile.

Who provides the service

collect3r is operated at collect3r.app. Privacy questions: [email protected].

Account and sign-in

Sign-in is handled by Awth (email one-time codes and passkeys). Awth is a separate service with its own practices.

When you sign in, collect3r stores:

  • A link to your Awth account id (awth_sub)
  • Your email address (kept in sync when Awth provides it)
  • An opaque session token hash on the server (we store a hash, not the raw token)
  • Optionally, a short-lived Awth access token on the session only while first-login onboarding is pending, then it is cleared

collect3r does not store your password. Passkeys live with Awth.

On your device

The iOS app may keep:

  • Your collect3r session token in the system Keychain so you stay signed in
  • A local copy of your library (for faster browsing) in app storage; it is excluded from device backups and cleared on sign-out, account delete, or account mismatch
  • Cached cover images for releases you view
  • A local appearance preference (light / dark / system)

Library and catalog data

We store your library: which MusicBrainz releases you marked owned or wishlist, optional private notes, and when you added them.

Release metadata (title, artist, format, barcode, cover URL, and related fields) is fetched from MusicBrainz and Cover Art Archive through our API and may be cached so the app does not call those services directly. Search and barcode lookups go through collect3r as well.

Public profiles

Profiles are private by default. If you set a username and turn on collection and/or wishlist visibility, visitors can open /u/{username} on collect3r.app and see that public list (covers and release basics). Public pages do not show your email or your private notes.

If you have linked an Awth account, the public page may show your Awth avatar when one is available.

What we do not sell

We do not sell your personal information. We do not run third-party advertising SDKs in the app for this purpose.

Retention and deletion

Your collect3r data stays while your account exists. In Settings you can delete your collect3r account, which removes your user record, sessions, and library items on this service.

Deleting collect3r does not delete your Awth identity. Manage or delete that at awth.dev if you want.

Service logs

The server may log technical request details (paths, status codes, timing) and operational events to run and debug the service. Logs are not used to build advertising profiles.

Contact

Privacy questions: [email protected].

Changes

If this policy changes in a meaningful way, we will update the date on this page.

These pages describe how collect3r works today. They are not a substitute for legal advice.