Privacy Policy
Effective July 25, 2026 · Last updated July 25, 2026 · Version 1.0
The short version
- We don't sell your data. Not to advertisers, not to data brokers, not to anyone. There is no version of Collectivision where your audience is the product.
- There are no third-party trackers on this site. No ad pixels, no analytics SDKs, no session recorders. The only cookies we set are ones the site needs to work — which is why there's no cookie banner here.
- We don't store raw IP addresses for chat or view counting. We store a one-way hash: enough to make a ban stick or avoid double-counting a view, useless for anything else.
- View counts can't follow you around. They're scoped per video on purpose, so they can't be joined into a picture of what you watch.
- We don't train AI on your content, and we don't give our providers the right to either.
- You can get your data or delete it by emailing us, and we'll do it.
This summary is here to help you read the rest. Where it differs from the detailed sections below, the detailed sections are the ones that count.
1. Who this is about
Collectivision is a live video platform for artists, musicians, performers, venues, and the people who love what they make. We're based in Oregon, in the United States, and our infrastructure is primarily in the United States. In this policy, "we" and "us" mean Collectivision, and "you" means you.
This covers collectivision.net, Collectivision Studio, hosted spaces and galleries (including ones served on creators' own custom domains), share-code and file pages, live chat, and our apps.
One thing worth understanding up front: when you watch a creator's video or post in their chat, both we and that creator handle some information about it. We're responsible for the platform. The creator is responsible for what they do with what they can see — their chat, their audience, their donation links. If you have a question about a particular creator's practices, ask them directly.
Questions about anything on this page go to privacy@collectivision.net, and a human reads them. If you need a postal address for a formal request, ask and we'll provide one.
2. What we collect, and why
If you're just watching
You can watch a shared video without an account, and we keep this as thin as we can make it.
| What | Why |
|---|---|
A random ID in a cookie (cv_vid), stored as a hash tied to each individual video | So one person rewatching isn't counted five times. It's scoped per video — the same visitor watching two videos leaves two unrelated rows, so it can't be assembled into a history of what you watch. Clearing the cookie just means you get counted again, which is the honest trade for not building a fingerprint. |
| If you enter a password for a gated page: a signed cookie proving you got in | So you don't have to re-enter it on every page. |
| Standard server and CDN logs — IP address, browser, page requested, timestamp — held by our hosting and CDN providers | Security, abuse prevention, and working out why something broke. These sit with the providers in section 5 under their own retention schedules; we don't pull them into our database. |
We set no advertising cookies, and there are no third-party analytics or tracking scripts anywhere on the site.
If you post in chat
| What | Why |
|---|---|
| The display name you pick, your message, and the point in the video it was posted at | It's a chat — the message has to be stored and shown for it to work at all. |
A signed session cookie (cv_chat) | Keeps your name attached to your messages without making you create an account. |
| A salted one-way hash of your IP address | So that a ban actually holds. We never store the raw IP, and the hash can't be turned back into one. |
| A Cloudflare Turnstile check | Keeps bots out of chat. Turnstile is a privacy-focused challenge — it doesn't track you across sites. |
Chat is public to everyone who can see that page, and messages stay there until you or the space owner removes them. Please don't put anything private in it.
If you make a free viewer account
- Your email address and a password — hashed by our authentication provider. We never see or store the plaintext.
- An optional display name, so you're not just an email address in chat. If you don't pick one, we derive a starting point from your email and you can change it any time.
- The videos you've favorited and the spaces you follow, so we can show you your own list.
- Your email notification preferences and an unsubscribe token, so "new video from someone you follow" emails work and so a single click can stop them.
Every notification email has a working one-click unsubscribe. We don't send marketing email to viewer accounts.
If you join the waitlist
Your email address and which page you signed up from, so we can send you an invite code when a spot opens. That's the whole record.
If you have a Studio account
Everything above, plus what's needed to run a publishing account:
- The invite code you redeemed and when — to keep track of invites and to stop code guessing.
- Your spaces, projects, videos and files, including titles, descriptions, tags, filenames and file sizes.
- The video and file content itself.
- Access credentials you set on gated content — usernames as you entered them, passwords hashed.
- Custom domains you've connected, plus their DNS and certificate status.
- Donation links you configure, so they can be shown on your pages. The money itself never passes through us.
- People you've added to a space and their roles.
- Storage and bandwidth usage for your spaces, so you can see where you stand and so our costs don't surprise either of us.
When something breaks
We record technical error reports: an error fingerprint, the message and stack trace, which route and method it happened on, the status code, and which release was running. This is how we find and fix bugs, and it's the only thing we use it for. An error report can incidentally include personal data if it happened to be in the request that failed — we try to keep that out, and we don't go looking through these for anything but the bug.
3. What we don't collect
- We don't collect your precise location.
- We don't fingerprint your device or browser.
- We don't buy data about you from anyone.
- We don't scan the contents of your videos for advertising or profiling.
- We don't use your content, your chat, or your metadata to train AI models, and we don't grant our providers the right to.
- We don't currently process payments, so we hold no card or bank details. When paid plans launch, a payment processor will handle that and we'll update this page before it goes live.
- We don't send SMS. There's an unused phone-number field left over from planned text notifications; nothing writes to it and nothing sends to it. It goes away or gets used properly with explicit consent — not quietly in between.
4. Why we're allowed to use it
If you're in the UK, EU, or somewhere with similar law, these are our lawful bases for processing:
- Performing our contract with you — running your account, hosting your content, and delivering it to the people you've chosen.
- Legitimate interests — keeping the service secure, preventing abuse and fraud, counting views so creators know how they're doing, and understanding errors so we can fix them. We've weighed these against your interests, and the design reflects it: hashed identifiers instead of IP addresses, per-video scoping instead of cross-site tracking.
- Consent — optional things like following a space for email updates. You can withdraw it at any time, and the unsubscribe link in every email is the fastest way.
- Legal obligation — tax and accounting records, responding to valid legal process, and mandatory reporting of child sexual abuse material.
5. Who else touches your data
We're a small team standing on other people's infrastructure, and you should know whose. These are our processors — companies that handle data on our behalf, under contracts requiring them to protect it and barring them from using it for their own purposes. Processing is primarily in the United States, with CDN delivery from edge locations worldwide.
| Provider | What they handle for us |
|---|---|
| Supabase | Database and authentication — accounts, profiles, chat, favorites, and content metadata |
| Bunny.net | Video hosting and transcoding, file storage, and CDN delivery, along with the request logs that come with serving traffic |
| Netlify | Website hosting and custom-domain provisioning, and server access logs |
| Cloudflare | DNS for platform domains, and Turnstile bot checks on signup and chat |
| Resend | Transactional email — account notices and follow notifications |
We keep this table current. If we add a provider that materially changes how your data is handled, we'll update it and note it in the changelog at the bottom of this page.
Beyond that, we share personal data only when:
- You ask us to — for example, connecting an integration.
- The law requires it — a valid subpoena, warrant, or court order. We check that legal demands are actually valid, we push back on overbroad ones, and where we're legally allowed to tell you about a demand for your data, we will.
- Safety requires it — to prevent imminent serious harm, or as legally mandated for child safety reporting.
- The business changes hands — in a merger or acquisition, with notice to you, and the acquirer bound by this same policy until it gives you notice and a chance to leave.
We have never sold personal data, and we never will. We also don't "share" it for cross-context behavioral advertising, as California law defines that term.
7. How long we keep things
| Data | How long we keep it |
|---|---|
| Account data | While your account is open |
| Your content | While your account is open, or until you delete it |
| Chat messages | Until you or the space owner deletes them, or the video comes down. We don't currently expire them on a schedule. |
| View records | Kept as part of a video's view count for as long as the video exists. Individual rows hold only a per-video hash, never an IP. |
| Ban records | For as long as the ban is in force |
| Error reports | Until they're resolved and cleared out. These hold technical detail about failures, not profiles of people. |
| Waitlist entries | Until you're invited, or until you ask us to remove you |
| Server and CDN logs | Held by the providers in section 5 under their own retention schedules, typically weeks rather than months |
Where we've said "until you delete it," that's the literal truth rather than a euphemism — we don't currently run automatic expiry on chat, views, or error reports. As we add scheduled deletion, we'll put the actual periods in this table rather than leaving it vague.
When you close your account, we keep your content available for 30 days in case you change your mind or forgot to export something, then delete it. If you'd rather it went immediately, say so and we'll do that. We may hold a minimal record that an account existed and when it closed, plus anything a legal hold or tax law requires.
8. Your rights
Wherever you live, you can ask us to:
- Show you what we hold about you.
- Send you a copy in a portable format.
- Fix something that's wrong.
- Delete your data and your account.
- Stop a particular use, or withdraw consent you'd given.
- Object to processing we've based on legitimate interests.
How: email privacy@collectivision.net from your account address and tell us what you want. We'll acknowledge within 5 business days and complete it within 30 days, or tell you why we need longer — we won't take longer than the law allows. It's free, unless a request is genuinely excessive or repetitive.
Right now these requests are handled by a person rather than a button in your settings. We'd rather tell you that plainly than imply an automated flow that doesn't exist yet; self-serve export and deletion are on the way.
We won't treat you worse for exercising any of these rights — no degraded service, no different pricing, no friction designed to make you give up.
A note on deletion: some things can't be pulled back. If your chat message was quoted by someone else, or a viewer downloaded a video you'd allowed downloads on, deleting on our side doesn't reach those copies. CDN edge caches and encrypted backups also take a little while to roll off — we won't serve or restore that content in the meantime.
If you're in the EU, UK, or Switzerland
You have the rights above under the GDPR and its equivalents, plus the right to complain to your local supervisory authority. We'd appreciate the chance to put something right first, but you're not required to come to us before going to them. Your data is processed in the United States; where a transfer needs a legal mechanism, we rely on the European Commission's Standard Contractual Clauses with our processors.
If you're in California
Under the CCPA and CPRA you have rights to know, delete, correct, and opt out of the sale or sharing of personal information. We don't sell or share personal information as those terms are defined, so there's nothing to opt out of — but the email above works for everything else. You can use an authorized agent; we'll just ask for proof they're authorized.
If you're elsewhere in the US
Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other states give similar rights. Same email, same process — we apply the same handling to everyone rather than running different tiers by geography.
9. Security
We use current, reasonable measures: TLS everywhere, passwords hashed by our authentication provider, row-level security on every database table with no direct public access, signed and httpOnly cookies, hashed rather than raw IP addresses, scoped credentials for infrastructure, and production data access limited to people who need it.
No system is perfectly secure, and we won't pretend otherwise. If there's a breach affecting your personal data, we'll notify you and the relevant regulators as the law requires, and we'll tell you what we actually know as soon as we reliably know it — not weeks later once the messaging is polished.
Security researchers: we want your reports and we won't punish you for them. Send findings to security@collectivision.net. If you act in good faith — staying in your own accounts, not accessing or taking anyone else's data, not degrading the service, and giving us reasonable time to fix things before publishing — we won't pursue legal action against you, and we'll credit you if you'd like.
10. Children
Collectivision isn't for children under 13, and we don't knowingly collect their personal data. Studio accounts require you to be 18, or the age of majority where you live.
If you believe a child under 13 has given us personal data, email privacy@collectivision.net and we'll delete it.
Creators: if your own audience includes children, that brings obligations on your side too — COPPA in the US, the Age Appropriate Design Code in the UK, and similar rules elsewhere. Worth looking into before you build for a young audience.
11. Changes to this policy
This is a young platform and this page will change as it grows. Material changes — anything that meaningfully affects what we collect, why, or who sees it — get at least 30 days' notice by email to your account address and a notice on the site before they take effect. Clarifications and corrections take effect when posted.
Either way, the changelog at the bottom of this page records what changed and when, so you can see the history without diffing two walls of text. We won't apply a change retroactively to data we've already collected in a way that would surprise you.
12. Getting in touch
| What you need | Where to send it |
|---|---|
| Privacy questions, data access, export, or deletion | privacy@collectivision.net |
| Security reports | security@collectivision.net |
| Anything else | hello@collectivision.net |
A human reads all of these. If you need a postal address for a formal request, ask and we'll provide one.
Changelog
| Date | What changed |
|---|---|
| July 25, 2026 | First published version. |