Privacy Policy of Collec

Last updated: May 7, 2026

1. Introduction

Collec, operated by SOMA Corporation (hereinafter referred to as "we," "us," or "our"), is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our services, including our website (collec.ai), browser extension, web application, and other related platforms (collectively referred to as the "Services"). By using the Services, you consent to the practices described in this Privacy Policy.

2. Information We Collect

2.1 Personal Information

Account Information: When you create an account with Collec, we may collect your name, email address, password, and other registration details. We use OAuth-based authentication through Supabase, and we do not store your passwords directly.

Usage Information: We collect information about how you use the Services, such as the features you access, the collections you create, the links you save, and the actions you take within the Services. This includes information about your device, browser type, IP address, and the date and time of your activities.

Collection Data: When you use our browser extension or web application to save, organize, and share web resources, we store the URLs, page titles, descriptions, screenshots, text scraps, color palettes, and other metadata you choose to collect.

Communication Information: If you contact us through email, chat, or other communication channels, we will collect the information you provide in your messages, including your name, contact details, and the content of your inquiries.

Payment Information: When you purchase a paid subscription, our third-party payment processor (Stripe) collects your billing details and payment card information to process the transaction. We do not store full payment card numbers on our servers.

2.2 Non-Personal Information

Analytics and Performance Data: We use analytics tools to collect non-personal information about the performance of the Services, such as page load times, error rates, and traffic sources. This information helps us improve the quality and performance of the Services.

Device and Connection Information: We collect information about your device, such as the device type, operating system, and network information. This information is used to optimize the Services for your device and to provide a seamless user experience.

3. How We Use Your Information

3.1 Provide and Improve the Services

We use your personal information to create and manage your account, provide you with access to the Services, and deliver the features and functionality you request, including collection management, AI-powered chatbot assistance, and collaborative workspace features.

Your usage information helps us understand how you interact with the Services, identify areas for improvement, and develop new features and enhancements to meet your needs.

3.2 AI-Powered Features

When you use our AI chatbot or AI-assisted features, your prompts and relevant context (such as page content you are viewing) may be sent to third-party AI service providers (such as OpenAI, Anthropic, or Google) to generate responses. We do not use your personal conversations to train AI models.

3.3 Communication

We may use your contact information to send you important updates, announcements, and administrative messages related to the Services, such as service changes, security alerts, and legal notices.

If you opt-in, we may also send you marketing communications, such as newsletters, product promotions, and event invitations. You can unsubscribe from these marketing emails at any time by following the instructions provided in the email.

3.4 Analytics and Research

We use analytics tools to analyze the usage patterns and trends of the Services. This helps us gain insights into user behavior, measure the effectiveness of our efforts, and make data-driven decisions to improve the Services.

4. Cookie Policy

4.1 Essential Cookies

Essential cookies are required for the proper functioning of the Services. These cookies enable you to access and use the basic features of the Services, such as logging in and navigating between pages. We use Supabase authentication cookies to maintain your session. Without these cookies, the Services may not function properly.

4.2 Analytics Cookies

Analytics cookies help us analyze how you use the Services and improve their performance. We use Amplitude for analytics, which collects information such as the number of visitors to the Services, the pages they visit, and how long they stay on each page.

Our Amplitude integration also uses autocapture and Session Replay. Autocapture automatically logs your interactions with the Services (such as clicks and page navigation), and Session Replay records a visual playback of your browsing sessions, which may include content displayed on your screen. We use this data solely to diagnose issues and improve the usability of the Services.

5. Data Sharing and Disclosure

5.1 Third-Party Service Providers

We may share your personal information with third-party service providers who assist us in operating the Services. These include:

  • Supabase: Authentication, database, and storage
  • Cloudflare: Web hosting, CDN, and R2 object storage
  • OpenAI / Anthropic / Google: AI chatbot and content generation
  • Resend: Transactional email delivery
  • Stripe: Payment processing and billing
  • Amplitude: Analytics and session replay

These service providers are contractually obligated to protect your personal information and use it only for the purposes for which it was shared.

5.2 Legal Requirements

We may disclose your personal information if required to do so by law, regulation, or legal process, such as a court order, subpoena, or government investigation. We may also disclose your information to protect our rights, property, or safety, or the rights, property, or safety of others.

5.3 Business Transfers

In the event of a merger, acquisition, sale of assets, or other business transfer, your personal information may be transferred to the acquiring or successor entity. We will notify you of any such transfer and the applicable privacy policies of the new entity.

5.4 International Data Transfers

Collec is operated from the Republic of Korea, and the third-party service providers listed in Section 5.1 are located outside Korea, primarily in the United States. By using the Services, your personal information may be transferred to and processed in these countries.

Such transfers occur over secure networks at the time you use the relevant feature of the Services. The categories of data transferred, the recipients, and the purposes are as described in Sections 2 and 5.1, and each provider retains the data only for as long as necessary to deliver its service. Where required for transfers from the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses.

6. Browser Extension Data

Our browser extension (Collec Extension) requires certain permissions to function properly:

  • activeTab: To capture screenshots and extract page information from the current tab
  • storage / unlimitedStorage: To store your collections, settings, and cached data locally on your device
  • tabs: To access tab information (URL, title) for saving and organizing web resources
  • sidePanel: To display the Collec side panel interface
  • contextMenus: To provide right-click save shortcuts
  • notifications: To confirm save actions
  • scripting: To inject save-related UI into the current tab on demand
  • identity: To complete OAuth (Google) sign-in inside the extension
  • cookies: Used only to read the Supabase authentication cookie on Collec-owned domains (collec.ai, www.collec.ai,app.collec.ai) so that signing in on the web automatically signs you in to the extension. We do not read, write, or delete cookies from any other site.
  • alarms: To schedule periodic background sync of your saved data

6.1 Host Permissions (Sites the Extension Runs On)

The extension declares <all_urls> as a host permission. This is required because users need to save links, capture screenshots, or scrape text from arbitrary web pages they visit. Content scripts run on a page only when:

  • The user opens the floating action bar on that page, or
  • The user invokes a save / capture action (via context menu, keyboard shortcut, or side panel button)

We do not transmit page content to our servers unless you explicitly trigger a save action. Passive browsing data (URLs you visit but do not save) is not collected.

6.2 Extension Storage (Local vs. Synced)

Local-only data: User preferences, UI state, cached collections, and draft items are stored in chrome.storage.local on your device. This data does not leave your device unless you sign in and opt to sync.

Synced data: When you sign in, items you explicitly save (links, text scraps, screenshots, collections, workspace metadata) are uploaded to our Supabase database and Cloudflare R2 object storage for cross-device access and collaboration. Screenshots are stored in a private bucket and served only via short-lived signed URLs.

Workspace metadata: Workspace names, member email addresses, and collection structures are visible to other members of the same workspace.

6.3 Offline Mode

You can use the extension while signed out. In that mode, all data stays inchrome.storage.local and nothing is transmitted to our servers.

7. Regional Privacy Rights

7.1 GDPR (European Economic Area)

We are committed to complying with the General Data Protection Regulation (GDPR). If you are a resident of the European Economic Area (EEA), you have certain rights under the GDPR, including the right to access, correct, delete, and port your personal information, as well as the right to object to or restrict the processing of your information. To exercise these rights, please contact us using the information provided in the "Contact Us" section below.

7.2 CCPA / CPRA (California, USA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following rights:

  • Right to Know: request disclosure of the categories and specific pieces of personal information we collect about you, the sources, the business purposes, and the categories of third parties we share it with.
  • Right to Delete: request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: request correction of inaccurate personal information.
  • Right to Opt-Out: opt out of the "sale" or "sharing" of your personal information. We do not sell your personal information for monetary consideration (see Section 8).
  • Right to Limit: limit the use and disclosure of sensitive personal information.
  • Right to Non-Discrimination: we will not discriminate against you for exercising any of these rights.

California's "Shine the Light" law (Civil Code §1798.83) entitles California customers to request, once per year, a list of personal information disclosed to third parties for direct-marketing purposes. We do not currently disclose personal information to third parties for their direct-marketing use.

To exercise any of these rights, contact us at the email address in Section 14.

7.3 PIPA (Republic of Korea)

If you are a resident of the Republic of Korea, the Personal Information Protection Act (PIPA, 개인정보 보호법) grants you the following rights:

  • Right to Access (열람권): request access to your personal information.
  • Right to Correction & Deletion (정정·삭제권): request correction or deletion of your personal information.
  • Right to Suspend Processing (처리정지 요구권): request that we suspend the processing of your personal information.
  • Right to Object to Automated Decision-Making (자동화 결정 거부권):refuse decisions made solely by automated means that significantly affect your rights or obligations, and request human review.
  • Right to Data Portability (전송 요구권): request that we transfer your personal information to you or to another controller in a structured, machine-readable format.

To exercise these rights, contact our designated personal information protection officer at the email address in Section 14. We will respond within the period prescribed by PIPA (within 10 days, extendable by an additional 10 days with notice).

7.4 Data Retention

We retain your personal information only as long as necessary to fulfill the purposes for which it was collected:

  • Account information: for the duration of your account and for a reasonable period after deletion (up to 30 days) to handle restoration requests.
  • Saved collections, links, captures, text scraps: until you delete them or your account is deleted.
  • Browser-extension cached data (local-only): remains on your device until you uninstall the extension or clear extension storage.
  • Usage / analytics data: retained for 12 months, after which it is anonymized or deleted.
  • Records required by law (e.g., billing records): retained for the period required by applicable law (typically 5 years for transactional records under Korean Commercial Code).

8. Do Not Sell My Personal Information

We do not sell your personal information to third parties for monetary consideration. However, as described in the "Data Sharing and Disclosure" section above, we may share your information with third-party service providers and in certain legal circumstances.

9. Data Security

We implement reasonable security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These security measures include encryption via HTTPS/TLS, row-level security policies in our database, access controls, and secure authentication through Supabase. However, no security system is 100% secure, and we cannot guarantee the absolute security of your personal information.

10. Children's Privacy

The Services are not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete the information as soon as possible.

11. Content Rights and Liability

11.1 Your Content

You retain ownership of the content you save, create, and organize within Collec, including links, text scraps, screenshots, notes, and other materials. By using the Services, you grant us a limited license to store, process, and display your content solely for the purpose of providing the Services to you.

11.2 AI-Generated Content

Content generated through our AI-powered features (such as the chatbot or content summarization) may be subject to the terms and conditions of the underlying AI service providers (such as OpenAI or Anthropic). You are free to use AI-generated content for personal and commercial purposes, but you acknowledge that such content may not be protected by copyright in all jurisdictions.

11.3 User Liability

If your content infringes on the rights of others, you will be solely responsible for such infringement. This includes any claims arising from the content you save, share, or publish through the Services.

12. Account Suspension

12.1 Circumstances

We reserve the right to suspend or terminate your account if you violate our Terms of Service, engage in fraudulent activities, or fail to comply with applicable laws and regulations.

12.2 Appeal Process

If you believe your account has been suspended in error, you may submit an appeal within 14 days by contacting us at support@collec.ai. Our team will review your appeal within 7 business days.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or industry standards. When we make changes, we will post the updated version on our website and indicate the date of the last update. Your continued use of the Services after the effective date of the updated Privacy Policy constitutes your acceptance of the changes.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal information, please contact us at:

support@collec.ai

Privacy Officer: Jun-seok Heo (Chief Executive Officer)
Email: support@collec.ai

Discord Community

Content with creators &
coders, join our discord crew!

Join Server Now
Newsletter

Get fresh updates, exclusive offers, &
product news—straight to your inbox.