Legal

Privacy Policy

Your collection can stay entirely on your device. This policy explains what changes when you choose connected features such as sign-in, sync, community matching, submissions, or public exhibits.

Effective date: July 13, 2026 · Last updated: July 24, 2026

1. Introduction

Pocket Museum ("we," "us," or "our") operates the Pocket Museum Android application, pocketmuseum.app, and related services. This Privacy Policy describes the information we collect, why we use it, when it may be shared, and the controls available to you.

2. Information we collect

Information you provide

  • Account information: your email address for passwordless sign-in, account identification, and service messages. An account is optional.
  • Profile information: a username, profile details, and visibility choices if you create a profile.
  • Collection content: photos, names, descriptions, tags, condition, acquisition details, notes, custom types, exhibits, wishlist entries, and related metadata.
  • Community content: reference images, collectible details, and other material you intentionally submit for moderation and possible publication.
  • Support and policy messages: information you include when contacting us.

Information created or collected through app features

  • Optional location: coordinates associated with an acquisition when you grant location permission and choose to record them.
  • Device and sync data: a locally generated device identifier, change records, vector clocks, and sync status needed to reconcile edits across devices and group members.
  • Authentication data: short-lived magic-link tokens, session tokens, and security records needed to sign you in and protect connected features.
  • Essential web storage: browser storage used for choices such as color theme and authentication state.
  • Payment status: subscription identifiers, plan, and transaction status received from Google Play or Stripe. We do not directly collect or store full payment-card details.

Information we do not collect for advertising

We do not use advertising SDKs, collect advertising IDs, sell personal information, or share personal information for cross-context behavioral advertising. We do not currently collect general product analytics or usage telemetry beyond information required to provide and secure the features described here.

3. Local and connected image processing

Pocket Museum's image embedding model and subject segmentation can run on your device. Local matching against references already stored on your device does not require sending a scan to Pocket Museum servers.

If you are signed in and intentionally use community image matching, submit a reference, enable cloud sync, or use another connected image feature, the relevant image, image-derived representation, or both may be sent to our servers to perform that request. Community matching compares the request with the moderated shared reference database. We do not use collection photos for unrelated advertising.

4. How we use information

  • Store, organize, search, display, back up, and restore your collection.
  • Perform local or connected image matching and improve result quality.
  • Authenticate accounts and send requested magic-link emails.
  • Synchronize content across your devices and invited sync-group members.
  • Operate public profiles and exhibits according to your visibility choices.
  • Review, moderate, attribute, and publish approved community submissions.
  • Process subscriptions, maintain entitlements, and administer contributor rewards.
  • Protect accounts, investigate misuse, enforce policies, and comply with law.
  • Respond to support, privacy, copyright, and account requests.

Depending on where you live, we process information to perform our contract with you, with your consent, for legitimate interests such as service security and improvement, and to meet legal obligations.

5. When information is shared

We do not sell your personal information. We may share it in these limited situations:

  • At your direction: with invited sync-group members or visitors to a public profile or exhibit you enable.
  • Community publication: approved submissions and contributor attribution may become visible in the shared reference database.
  • Service providers: vendors that host infrastructure, deliver email, process payments, or provide other functions on our behalf, subject to appropriate restrictions.
  • Safety and legal reasons: when reasonably necessary to comply with law, protect rights and safety, investigate fraud or abuse, or enforce our terms.
  • Business changes: as part of a merger, financing, acquisition, reorganization, or sale of assets, with appropriate notice and protections where required.

6. Public and shared content

Public profiles and exhibits are opt-in. Content you make public can be viewed, copied, or reshared by others outside our control. Sync-group members can view and edit the shared library according to available permissions.

Approved community submissions become part of a reference resource used by other collectors. Deleting your account does not necessarily remove approved reference facts and images from that resource, though we will evaluate valid privacy, safety, and intellectual-property requests.

7. Storage and security

  • Local-only mode: collection data, images, and preferences are stored in app-private storage on your device.
  • Connected mode: content needed for sync and other connected features is stored on servers in the United States.
  • Photo metadata: the app is designed to strip EXIF metadata before managed storage or upload. Location you intentionally record is stored as collection metadata.

We use safeguards including encrypted network connections, token-based authentication, single-use magic links with limited validity, and role-based server access. No storage or transmission method is completely secure, so we cannot guarantee absolute security.

8. Retention

We keep account and synced collection data while your account is active and as needed to provide the Services. After a valid account-deletion request, synced personal collection data is scheduled for deletion within 30 days, subject to backups, fraud prevention, dispute resolution, and legal obligations. Local data remains under your device controls and can be removed by clearing app data or uninstalling the app.

Approved community references may be retained independently because they support the shared database. Security, payment, and legal records may be kept for the period required by law or reasonably needed to protect the Services.

9. Your choices and rights

  • Local-only use: use core collection features without creating an account.
  • Permissions: grant or revoke camera and location permissions through device settings.
  • Visibility: control whether your profile and exhibits are public.
  • Sync: sign out to stop future account-based sync and return to local-only use.
  • Access and portability: view collection data in the app and use available backup or export tools.
  • Correction and deletion: edit or delete items and request account deletion.
  • Privacy rights: depending on your location, you may request access, correction, deletion, restriction, portability, or objection, and may appeal certain decisions.

We may need to verify your identity before completing a request. You may also have the right to complain to your local data-protection authority.

10. International processing

Pocket Museum and its providers may process information in the United States and other countries where privacy laws differ from those where you live. Where required, we use recognized safeguards for international transfers.

11. Children's privacy

Pocket Museum is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If a higher minimum age applies where you live, you must meet it or use the Services with appropriate parental authorization. Contact us if you believe a child provided personal information without proper consent.

12. Policy changes

We may update this policy as Pocket Museum changes. We will post the revised policy here, update the date above, and provide additional notice when required for material changes.

13. Contact

For privacy, account-data, or policy questions, email privacy@pocketmuseum.app.