Legal
Privacy Policy
Effective date: August 18, 2026
This policy describes how Pinporium handles personal information when you use our app and website. We built Pinporium for collectors — your trust matters as much as your vault.
Who we are
Pinporium (“Pinporium,” “we,” “us”) operates the Pinporium mobile application and the website at https://pinporium.app (together, the “Service”). This Privacy Policy explains how we handle personal information when you use the Service.
Questions about privacy: help@pinporium.app.
Information we collect
Depending on how you use Pinporium, we may collect:
- Account information — email address, authentication data, and sign-in via Apple, Google, or email and password (Supabase Auth). Public username (
@handle), optional display name, optional location, and optional avatar. - Vault and pin photos — pins you add (Owns, Traders, ISOs, Grails, DISOs), Pin Boards, notes, nicknames, grade, artist and variant details, price paid, and photos you take or pick from your library (front and back of pins, not only a profile photo).
- Offers (trade and for sale) — offer terms, notes, status you report, shipping address you save for coordination, and (for sales) a sale contact email. Pinporium does not process payments.
- Public profile choices — what other collectors can see (stats, Traders gallery, vault pins, Pin Boards). Defaults: stats and trade pins on; full vault and Pin Boards off.
- Catalog contributions — pin data and photos you submit for the shared community catalog, plus reviewer outcomes.
- Push tokens — Expo Push device identifiers used to hand off to Apple APNs or Google FCM, stored for signed-in collectors who allow notifications.
- Crash and device context — crash logs and coarse device or app context via Sentry. We do not send vault photos to Sentry as a product feature.
- Communications — messages you send us (support, feedback, or legal requests), and transactional email we send you (for example catalog submission decisions).
- Website usage — if you visit pinporium.app, standard web analytics or similar tools we configure for the site.
Demo mode uses local sample data on your device. It does not create a Pinporium account, profile, or push token.
Pin photos, cutouts, and identify
Collectors photograph pins (front and back) or pick images from the library. Photos are stored in our storage; pin metadata (artist, variant, grade, notes, price paid, and similar fields) is stored in our database.
Optional background removal can run on your device (iOS Vision / Android ML Kit). That processing stays on the device.
If on-device cutout is unavailable, the app may send a pin photo to remove.bg through Pinporium servers. The app does not ship that vendor API key.
Optional pin identify and catalog-match helpers may send a pin photo to Anthropic Claude Haiku through Pinporium servers. The app does not ship that vendor API key. We send photos for identification or cutout, not to train our own models. Vendors process data under their own policies — see Anthropic Privacy and remove.bg Privacy. We do not promise how those vendors train their systems.
How we use information
We use information to:
- Provide your account, Vault, catalog, Hunt lists, and Pin Boards
- Help collectors coordinate Offers (trades and for-sale listings) — matching, status, and details you choose to share with a counterparty
- Review and moderate catalog submissions and other user content
- Send optional push notifications you enable: Offers (trade and for sale) and catalog submission decisions
- Send transactional email (for example catalog review outcomes)
- Fix crashes, keep the Service reliable, and prevent abuse
- Comply with law and enforce our Terms of Service
We do not send Hunt ISO match alerts, Drop Zone push, or marketing blasts today.
Processors we use
These providers help us operate the Service. Each has its own privacy policy.
- Supabase (Postgres, Auth, Storage, Edge Functions) — account, Vault, Offers, catalog, and files
- Apple and Google — sign-in
- Expo, Apple APNs, and Google FCM — push delivery
- Anthropic — optional pin identify (photo via our server)
- remove.bg — optional cutout fallback (photo via our server)
- Sentry — crash reports
- Resend — transactional email (catalog decisions and similar service messages)
Offers (trade and for sale)
Offers are coordination only. Pinporium does not process payments, hold escrow, or run platform checkout. After collectors agree, they may share a shipping address and (for sales) a sale contact email so they can ship to each other. Pinporium is not a party to the trade or sale.
Do not share more personal information than you are comfortable providing to another collector.
User content and the community catalog
User-generated content includes vault photos, public profiles, Offer notes, and catalog submissions. Do not submit content you do not have the right to share.
The community catalog is a shared reference. Approved catalog entries can remain after account deletion, with the contributor id cleared so your name is not shown. That is intentional — the catalog is a community database.
Report and block
You can report a collector from their profile menu (spam, harassment, scam or trading fraud, inappropriate content, or other). Reports are reviewed by Pinporium and do not auto-block.
You can block a collector to hide both sides from new Offers. Open unshipped Offer threads are cancelled. Their profile can still open with a banner and no listing actions. Unblock from the profile or Settings.
Pin or catalog data issues use Report an issue on pin detail — not the collector report.
How long we keep information
We retain information while your account is active and as needed to provide the Service, resolve disputes, enforce agreements, and meet legal obligations. See Delete your account for what we remove when you delete, and what may remain (approved catalog rows, anonymized Offer history for the other collector, and similar exceptions).
Security
We use reasonable technical and organizational measures to protect information. No method of transmission or storage is completely secure; use a strong password and keep your device credentials private.
Your choices and rights
Depending on where you live, you may have the right to:
- Access, correct, or delete personal information we hold about you
- Export your data where the product supports it
- Control public profile visibility in Settings
- Turn off Push: Offers and Push: Catalog in the app (and OS permission)
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority
To delete your account, use in-app Settings → Delete Account (two confirms). Steps are also on our account deletion page. For other rights, contact help@pinporium.app. We may need to verify your identity before responding.
Children
Pinporium is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
International users
If you access Pinporium from outside the United States, your information may be processed in the U.S. or other countries where our providers operate. Those countries may have different data protection laws than yours.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Material changes may be communicated in the app or by email where appropriate. Continued use after changes take effect means you accept the updated policy.
Contact
Privacy inquiries: help@pinporium.app.
Back to home · Privacy Policy · Terms of Service · Delete account