Privacy Policy
Effective 18 August 2026 · Version 1.0
Collecta holds the things you find interesting, which over time is a revealing collection. So, in plain terms: we do not sell your data, we do not run advertising, we do not embed third-party trackers or analytics, and we do not train AI models on your content. We do send what you capture to AI providers to be read — that is what the product is — and section 4 names every one of them and says exactly what each one sees.
1. Who we are
Collecta is made by Alpha Intel Labs. For the purposes of the UK and EU GDPR we are the data controller for the personal data described here. Reach us at alphaintellabs@gmail.com — that address is also our privacy contact.
2. What we collect
Account information
Your email address, an encrypted form of your password (we never see the password itself), and anything you choose to add to your profile: a display name, a short "about me" that helps the AI write for you, your timezone, and your note preferences — format, tone, depth, output language, and any custom instructions you write.
Everything you capture
This is the bulk of it, and it is the whole point of the product:
- the sources you share in — links, pasted text, articles, social posts, video URLs, PDFs, images and screenshots, voice notes, recorded conversations, exported chat logs;
- the files themselves, stored in your own private area of our storage;
- the notes the AI writes from them — titles, summaries, breakdowns, key points, tags, extracted source text, transcripts;
- your buckets and their descriptions, your annotations and any files you attach to them;
- your conversations with a note or a bucket, and any research reports and briefings generated for you;
- the entities the AI pulls out of notes (people, works, organisations, places, events, claims, concepts) and the links between notes that share them;
- numeric representations of your notes ("embeddings"), which make meaning-based search possible.
Usage records
A record of each metered action you take — a capture, a question, a briefing, a research report, a chat message, a dictation, minutes of recording — with a timestamp. This is how plan allowances are enforced and how we spot abuse. It records that an action happened, not what was in it.
Billing information
Your plan, subscription status, and any promotional grant. Card numbers never touch our servers. Payment details are handled entirely by our payment provider, or by Apple or Google if you subscribe inside a future app-store build.
Technical logs
Our hosting and database providers record standard server logs — IP address, browser user-agent, requested path, timestamps, error traces — for security, debugging and abuse prevention. We do not build behavioural profiles from them.
We do not collect: advertising identifiers, location data, contacts, your device's other apps, or any third-party analytics or tracking pixels. Collecta ships with no analytics SDK of any kind.
3. Why we hold it
| What | Why | Legal basis (UK/EU) |
|---|---|---|
| Account details | To give you an account, log you in, and reset your password. | Performance of a contract |
| Content you capture | To read it, write a note from it, file it, search it, and show it back to you. | Performance of a contract |
| Preferences | To write notes in the format, tone and language you asked for. | Performance of a contract |
| Usage records | To enforce plan allowances and detect abuse. | Performance of a contract; legitimate interests |
| Billing records | To take payment, apply the right plan, and meet tax obligations. | Contract; legal obligation |
| Technical logs | To keep the service up, secure and debuggable. | Legitimate interests |
| Account emails | Password resets, confirmations, and notices about your plan or these policies. | Contract; legitimate interests |
4. Who else sees it
Collecta cannot work without sending your content to AI providers to be read. That is the trade you are making, so here is the complete list of who we use and what each one gets. We do not add a processor to this list without updating this page.
| Processor | What it receives | What for |
|---|---|---|
| Supabase | Your account, all your content, and all your uploaded files. | Database, authentication, and file storage. This is where your library actually lives. |
| OpenAI | The text of what you capture, and the notes written from it. | Every text-only task: analysing text and web pages, note and bucket chat, question answering, briefings, entity extraction, and the written synthesis of a meeting transcript. |
| Google (Gemini API) | Audio, images, PDFs and video you capture; the text of notes when generating embeddings or a web-grounded report. | Everything that isn't plain text: transcription, reading images and documents, watching videos, generating embeddings for search, and research reports that search the live web. |
| Inngest | Content passing through the processing pipeline while a capture is being worked on. | Running capture and export jobs reliably in the background, with retries. |
| Vercel | Requests to the app, including IP address and standard log data. | Hosting and serving the application. |
| Supadata | The YouTube URL you shared. Nothing else about you. | Fetching a video's transcript, which YouTube blocks server-hosted apps from retrieving directly. |
| Cloudflare | The hostname of a link you share, as a DNS lookup. | Checking that a URL doesn't point at a private or internal address before our servers fetch it. See section 7. |
| RevenueCat, and its payment processor | An account identifier, your email, and your subscription state. | Subscriptions, renewals and refunds. If you subscribe inside a future app-store build, Apple or Google handles the payment instead. |
| Resend | Your email address and the contents of the message. | Sending account email — password resets, confirmations, service notices. |
Beyond that list, we disclose personal data only where the law compels us to, or to establish or defend a legal claim. If Alpha Intel Labs is ever sold or merged, your data may transfer to the acquirer, who would be bound by a policy no less protective than this one; we would tell you before that happened.
We do not sell personal data, and we do not share it for cross-context behavioural advertising — including as those terms are defined under California law.
5. AI training
We do not use your content to train AI models, our own or anyone else's, and we do not permit our providers to. We access OpenAI and Google through their paid developer APIs, whose terms provide that submitted content is not used to train their models. Both providers may retain content briefly for abuse monitoring under their own policies:
Nobody at Alpha Intel Labs browses your library. We access an individual account's content only if you explicitly ask us to, in order to investigate a problem you have reported.
6. Recordings and transcripts
Recorded conversations are treated differently from everything else, because audio of other people is the most sensitive thing the product handles.
- Recording only happens when you start it. Collecta does not listen in the background, and never records without an active session you began.
- The audio is uploaded to your private storage area, transcribed, and written up.
- The audio file is deleted 30 days after capture. This is automatic and not optional. The note page tells you when it has expired.
- The transcript and the written note are kept permanently, until you delete them.
- Whether you were entitled to make a recording is your responsibility, not ours — see section 8 of the Terms.
Voice dictation in the capture box is transcribed and handed straight back to you as text. No audio file is stored from it.
7. Links you share in
When you share a URL, our servers fetch that page in order to read it. The site you linked to will see a request from our infrastructure — its own IP address, not yours. Before fetching, we resolve the hostname (via Cloudflare's DNS-over-HTTPS resolver) and refuse anything that resolves to a private, internal or loopback address, re-checking at every redirect. That check protects our systems; it also means a link cannot be used to make Collecta reach somewhere it shouldn't.
8. When you share something
- A public share link makes that note or bucket readable by anyone holding the URL, without an account. We do not index it, but we cannot stop anyone the link reaches from reading, copying or forwarding it. Treat it as publishing.
- Revoking a link stops future access immediately. It cannot recall what has already been read.
- In a bucket open for contributions, what a contributor shares in is visible to you, and it also remains in that contributor's own library.
- An export archive redacts share-link tokens, so a leaked archive is not also a set of live keys to your published pages.
9. How long we keep it
| What | Kept for |
|---|---|
| Notes, buckets, transcripts, reports, files | Until you delete them, or your account is deleted. |
| Items you put in Trash | 30 days, then permanently removed. Restorable until then. |
| Recorded audio | 30 days from capture, then automatically deleted. The transcript and note remain. |
| Usage records | As long as needed to enforce allowances and investigate abuse, then deleted. |
| Rate-limit records | Cleared automatically within days. |
| Billing records | As long as tax and accounting law requires, typically seven years. |
| Technical logs | Per our hosting providers' standard retention, typically weeks. |
10. Getting your data out
Settings → Export produces a complete archive of everything: your notes, buckets, transcripts, annotations, research reports, chat histories and preferences, as both readable Markdown and lossless JSON, with your uploaded files included alongside.
Export is available on every plan, including the free one. We consider an export feature that only unlocks once you are paying to be a hostage arrangement rather than a product.
11. Deleting your data
- Individual notes and buckets can be deleted from within the app at any time. They sit in Trash for 30 days first.
- To delete your entire account and everything in it, email alphaintellabs@gmail.com from the address on the account. We complete deletion within 30 days and confirm when it is done.
- Deletion is irreversible. Export first if you want to keep anything.
- Deleting your account also removes your content from our AI providers' systems to the extent they retain it; their short-term abuse-monitoring copies expire under their own schedules.
- We may retain billing records where the law requires it, and anonymised aggregate counts that cannot identify you.
12. Security
- All traffic is encrypted in transit (HTTPS/TLS). Content and files are encrypted at rest by our storage providers.
- Every database table enforces row-level security, so a query can only ever return rows belonging to the account making it. This is enforced by the database, not only by application code.
- Uploaded files live under a per-account path, and the server verifies that a file you reference is genuinely yours before it is read.
- Administrative access is limited to founders, requires an explicitly allow-listed address, and does not include browsing user libraries.
- Passwords are hashed by our authentication provider and are never visible to us.
No system is perfectly secure. We do not claim otherwise, and you should not put something into Collecta that would be catastrophic to have exposed.
13. Cookies
Collecta sets cookies for one purpose: keeping you signed in. There are no advertising cookies, no analytics cookies, and no third-party cookies. A small amount of ordinary local browser storage also remembers your theme choice. Because none of this is used for tracking, there is no cookie banner to dismiss.
14. Where processing happens
Collecta's infrastructure and its AI providers are based in the United States, and your data is processed there and in other countries where those providers operate. If you are in the UK, the EEA or Switzerland, transfers out of your region rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which our processors incorporate into their terms.
15. Your rights
Wherever you live, you can ask us to do any of the following, and we will not charge you or treat you differently for asking:
- Access — get a copy of what we hold. Self-serve via Export, or ask us.
- Correct — fix anything inaccurate. Most of it is editable in the app.
- Delete — remove specific content, or the whole account.
- Port — take your data elsewhere. The JSON archive is designed for exactly this.
- Object or restrict — object to processing based on legitimate interests, or ask us to limit it.
- Withdraw consent — where we relied on consent, withdraw it at any time.
- Complain — to your local data protection authority. In the UK that is the ICO; in the EU, your national supervisory authority. We would rather you came to us first.
California residents have the rights to know, delete, correct, and opt out of sale or sharing under the CCPA/CPRA. As stated in section 4, we do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of — but the other rights apply, and are exercised through the same address below.
Email alphaintellabs@gmail.com from your account address. We respond within 30 days.
16. Children
Collecta is not for children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, write to us and we will delete it. Where local law sets a higher digital consent age, that age applies instead.
17. If something goes wrong
If a breach occurs that is likely to put your rights or your data at risk, we will notify the relevant supervisory authority within 72 hours where required, and tell affected users directly and without undue delay. We will tell you what happened, what was exposed, and what to do about it — not a euphemism about "an incident involving certain systems".
18. Changes to this policy
We may update this policy. The date at the top changes when we do. If a change materially affects how your data is handled — a new processor, a new purpose, a longer retention period — we will tell you by email or in the app before it takes effect.