Legal

Privacy policy

What Collably collects, why we collect it, and the control you have over your data.

Last updated Jul 4, 2026 · interim policy, under review before counsel sign-off.

What we collect

  • Account data — your email address and authentication identifiers, used to sign you in and secure your account.
  • Profile data — the display name, bio, niches, platforms, portfolio, and location you choose to add. Location is used only for local-first matching, never for demographic targeting.
  • Sensitive attributes you provide once — date of birth (to confirm you are 18 or older) and, optionally, gender. These are never shown to brands or agencies and are never used to rank, filter, or match you.
  • Activity data — campaigns you post or apply to, deals, messages, reports you file, and notifications, so the marketplace can function.
  • Technical data — the minimum request and device information needed to operate the service securely and prevent abuse.

Why we use it

We use your data to run the marketplace: to authenticate you, show your public profile to counterparties, match campaigns and creators fairly, deliver messages and notifications, and keep the platform safe. We do not sell your personal data, and matching is demographic-free by design — age, date of birth, and gender are structurally withheld from the people you work with.

Your rights: export & erasure

You can export a copy of your data or permanently delete your account at any time from Settings → Privacy & your data. Deletion removes your profile and personal data; some records may be retained where we are legally required to keep them (see retention below).

Retention

We keep your data for as long as your account is active. When you delete your account we remove your personal data promptly, retaining only what is necessary to comply with legal obligations, resolve disputes, and enforce our terms — for example, records of safety reports and their outcomes.

Contact

Questions about your privacy or a data request can be sent to our privacy contact. (Operator TODO: set a monitored privacy mailbox before launch — no contact address is published here until the operator designates one.)