Collectivision

Privacy Policy

Effective July 25, 2026 · Last updated July 25, 2026 · Version 1.0

The short version

  • We don't sell your data. Not to advertisers, not to data brokers, not to anyone. There is no version of Collectivision where your audience is the product.
  • There are no third-party trackers on this site. No ad pixels, no analytics SDKs, no session recorders. The only cookies we set are ones the site needs to work — which is why there's no cookie banner here.
  • We don't store raw IP addresses for chat or view counting. We store a one-way hash: enough to make a ban stick or avoid double-counting a view, useless for anything else.
  • View counts can't follow you around. They're scoped per video on purpose, so they can't be joined into a picture of what you watch.
  • We don't train AI on your content, and we don't give our providers the right to either.
  • You can get your data or delete it by emailing us, and we'll do it.

This summary is here to help you read the rest. Where it differs from the detailed sections below, the detailed sections are the ones that count.

1. Who this is about

Collectivision is a live video platform for artists, musicians, performers, venues, and the people who love what they make. We're based in Oregon, in the United States, and our infrastructure is primarily in the United States. In this policy, "we" and "us" mean Collectivision, and "you" means you.

This covers collectivision.net, Collectivision Studio, hosted spaces and galleries (including ones served on creators' own custom domains), share-code and file pages, live chat, and our apps.

One thing worth understanding up front: when you watch a creator's video or post in their chat, both we and that creator handle some information about it. We're responsible for the platform. The creator is responsible for what they do with what they can see — their chat, their audience, their donation links. If you have a question about a particular creator's practices, ask them directly.

Questions about anything on this page go to privacy@collectivision.net, and a human reads them. If you need a postal address for a formal request, ask and we'll provide one.

2. What we collect, and why

If you're just watching

You can watch a shared video without an account, and we keep this as thin as we can make it.

WhatWhy
A random ID in a cookie (cv_vid), stored as a hash tied to each individual videoSo one person rewatching isn't counted five times. It's scoped per video — the same visitor watching two videos leaves two unrelated rows, so it can't be assembled into a history of what you watch. Clearing the cookie just means you get counted again, which is the honest trade for not building a fingerprint.
If you enter a password for a gated page: a signed cookie proving you got inSo you don't have to re-enter it on every page.
Standard server and CDN logs — IP address, browser, page requested, timestamp — held by our hosting and CDN providersSecurity, abuse prevention, and working out why something broke. These sit with the providers in section 5 under their own retention schedules; we don't pull them into our database.

We set no advertising cookies, and there are no third-party analytics or tracking scripts anywhere on the site.

If you post in chat

WhatWhy
The display name you pick, your message, and the point in the video it was posted atIt's a chat — the message has to be stored and shown for it to work at all.
A signed session cookie (cv_chat)Keeps your name attached to your messages without making you create an account.
A salted one-way hash of your IP addressSo that a ban actually holds. We never store the raw IP, and the hash can't be turned back into one.
A Cloudflare Turnstile checkKeeps bots out of chat. Turnstile is a privacy-focused challenge — it doesn't track you across sites.

Chat is public to everyone who can see that page, and messages stay there until you or the space owner removes them. Please don't put anything private in it.

If you make a free viewer account

  • Your email address and a password — hashed by our authentication provider. We never see or store the plaintext.
  • An optional display name, so you're not just an email address in chat. If you don't pick one, we derive a starting point from your email and you can change it any time.
  • The videos you've favorited and the spaces you follow, so we can show you your own list.
  • Your email notification preferences and an unsubscribe token, so "new video from someone you follow" emails work and so a single click can stop them.

Every notification email has a working one-click unsubscribe. We don't send marketing email to viewer accounts.

If you join the waitlist

Your email address and which page you signed up from, so we can send you an invite code when a spot opens. That's the whole record.

If you have a Studio account

Everything above, plus what's needed to run a publishing account:

  • The invite code you redeemed and when — to keep track of invites and to stop code guessing.
  • Your spaces, projects, videos and files, including titles, descriptions, tags, filenames and file sizes.
  • The video and file content itself.
  • Access credentials you set on gated content — usernames as you entered them, passwords hashed.
  • Custom domains you've connected, plus their DNS and certificate status.
  • Donation links you configure, so they can be shown on your pages. The money itself never passes through us.
  • People you've added to a space and their roles.
  • Storage and bandwidth usage for your spaces, so you can see where you stand and so our costs don't surprise either of us.

When something breaks

We record technical error reports: an error fingerprint, the message and stack trace, which route and method it happened on, the status code, and which release was running. This is how we find and fix bugs, and it's the only thing we use it for. An error report can incidentally include personal data if it happened to be in the request that failed — we try to keep that out, and we don't go looking through these for anything but the bug.

3. What we don't collect

  • We don't collect your precise location.
  • We don't fingerprint your device or browser.
  • We don't buy data about you from anyone.
  • We don't scan the contents of your videos for advertising or profiling.
  • We don't use your content, your chat, or your metadata to train AI models, and we don't grant our providers the right to.
  • We don't currently process payments, so we hold no card or bank details. When paid plans launch, a payment processor will handle that and we'll update this page before it goes live.
  • We don't send SMS. There's an unused phone-number field left over from planned text notifications; nothing writes to it and nothing sends to it. It goes away or gets used properly with explicit consent — not quietly in between.

5. Who else touches your data

We're a small team standing on other people's infrastructure, and you should know whose. These are our processors — companies that handle data on our behalf, under contracts requiring them to protect it and barring them from using it for their own purposes. Processing is primarily in the United States, with CDN delivery from edge locations worldwide.

ProviderWhat they handle for us
SupabaseDatabase and authentication — accounts, profiles, chat, favorites, and content metadata
Bunny.netVideo hosting and transcoding, file storage, and CDN delivery, along with the request logs that come with serving traffic
NetlifyWebsite hosting and custom-domain provisioning, and server access logs
CloudflareDNS for platform domains, and Turnstile bot checks on signup and chat
ResendTransactional email — account notices and follow notifications

We keep this table current. If we add a provider that materially changes how your data is handled, we'll update it and note it in the changelog at the bottom of this page.

Beyond that, we share personal data only when:

  • You ask us to — for example, connecting an integration.
  • The law requires it — a valid subpoena, warrant, or court order. We check that legal demands are actually valid, we push back on overbroad ones, and where we're legally allowed to tell you about a demand for your data, we will.
  • Safety requires it — to prevent imminent serious harm, or as legally mandated for child safety reporting.
  • The business changes hands — in a merger or acquisition, with notice to you, and the acquirer bound by this same policy until it gives you notice and a chance to leave.

We have never sold personal data, and we never will. We also don't "share" it for cross-context behavioral advertising, as California law defines that term.

6. Cookies

Every cookie we set is functional — there are no advertising or analytics cookies here, which is why you won't find a consent banner.

CookieWhat it's forHow long
Authentication cookiesKeeps you signed in to your accountSession, refreshed as you use it
cv_vidA random ID so one person's rewatch isn't counted as many views1 year
cv_chatYour chat session and the display name you pickedAbout 6 months
vc_…Proof that you passed a password gate on protected content24 hours

They're set httpOnly, sameSite=lax, and secure in production — which means scripts running on the page can't read them. Blocking them mostly still works: you can watch, but you'll re-enter passwords and won't stay signed in.

7. How long we keep things

DataHow long we keep it
Account dataWhile your account is open
Your contentWhile your account is open, or until you delete it
Chat messagesUntil you or the space owner deletes them, or the video comes down. We don't currently expire them on a schedule.
View recordsKept as part of a video's view count for as long as the video exists. Individual rows hold only a per-video hash, never an IP.
Ban recordsFor as long as the ban is in force
Error reportsUntil they're resolved and cleared out. These hold technical detail about failures, not profiles of people.
Waitlist entriesUntil you're invited, or until you ask us to remove you
Server and CDN logsHeld by the providers in section 5 under their own retention schedules, typically weeks rather than months

Where we've said "until you delete it," that's the literal truth rather than a euphemism — we don't currently run automatic expiry on chat, views, or error reports. As we add scheduled deletion, we'll put the actual periods in this table rather than leaving it vague.

When you close your account, we keep your content available for 30 days in case you change your mind or forgot to export something, then delete it. If you'd rather it went immediately, say so and we'll do that. We may hold a minimal record that an account existed and when it closed, plus anything a legal hold or tax law requires.

8. Your rights

Wherever you live, you can ask us to:

  • Show you what we hold about you.
  • Send you a copy in a portable format.
  • Fix something that's wrong.
  • Delete your data and your account.
  • Stop a particular use, or withdraw consent you'd given.
  • Object to processing we've based on legitimate interests.

How: email privacy@collectivision.net from your account address and tell us what you want. We'll acknowledge within 5 business days and complete it within 30 days, or tell you why we need longer — we won't take longer than the law allows. It's free, unless a request is genuinely excessive or repetitive.

Right now these requests are handled by a person rather than a button in your settings. We'd rather tell you that plainly than imply an automated flow that doesn't exist yet; self-serve export and deletion are on the way.

We won't treat you worse for exercising any of these rights — no degraded service, no different pricing, no friction designed to make you give up.

A note on deletion: some things can't be pulled back. If your chat message was quoted by someone else, or a viewer downloaded a video you'd allowed downloads on, deleting on our side doesn't reach those copies. CDN edge caches and encrypted backups also take a little while to roll off — we won't serve or restore that content in the meantime.

If you're in the EU, UK, or Switzerland

You have the rights above under the GDPR and its equivalents, plus the right to complain to your local supervisory authority. We'd appreciate the chance to put something right first, but you're not required to come to us before going to them. Your data is processed in the United States; where a transfer needs a legal mechanism, we rely on the European Commission's Standard Contractual Clauses with our processors.

If you're in California

Under the CCPA and CPRA you have rights to know, delete, correct, and opt out of the sale or sharing of personal information. We don't sell or share personal information as those terms are defined, so there's nothing to opt out of — but the email above works for everything else. You can use an authorized agent; we'll just ask for proof they're authorized.

If you're elsewhere in the US

Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other states give similar rights. Same email, same process — we apply the same handling to everyone rather than running different tiers by geography.

9. Security

We use current, reasonable measures: TLS everywhere, passwords hashed by our authentication provider, row-level security on every database table with no direct public access, signed and httpOnly cookies, hashed rather than raw IP addresses, scoped credentials for infrastructure, and production data access limited to people who need it.

No system is perfectly secure, and we won't pretend otherwise. If there's a breach affecting your personal data, we'll notify you and the relevant regulators as the law requires, and we'll tell you what we actually know as soon as we reliably know it — not weeks later once the messaging is polished.

Security researchers: we want your reports and we won't punish you for them. Send findings to security@collectivision.net. If you act in good faith — staying in your own accounts, not accessing or taking anyone else's data, not degrading the service, and giving us reasonable time to fix things before publishing — we won't pursue legal action against you, and we'll credit you if you'd like.

10. Children

Collectivision isn't for children under 13, and we don't knowingly collect their personal data. Studio accounts require you to be 18, or the age of majority where you live.

If you believe a child under 13 has given us personal data, email privacy@collectivision.net and we'll delete it.

Creators: if your own audience includes children, that brings obligations on your side too — COPPA in the US, the Age Appropriate Design Code in the UK, and similar rules elsewhere. Worth looking into before you build for a young audience.

11. Changes to this policy

This is a young platform and this page will change as it grows. Material changes — anything that meaningfully affects what we collect, why, or who sees it — get at least 30 days' notice by email to your account address and a notice on the site before they take effect. Clarifications and corrections take effect when posted.

Either way, the changelog at the bottom of this page records what changed and when, so you can see the history without diffing two walls of text. We won't apply a change retroactively to data we've already collected in a way that would surprise you.

12. Getting in touch

What you needWhere to send it
Privacy questions, data access, export, or deletionprivacy@collectivision.net
Security reportssecurity@collectivision.net
Anything elsehello@collectivision.net

A human reads all of these. If you need a postal address for a formal request, ask and we'll provide one.

Changelog

DateWhat changed
July 25, 2026First published version.