Legal
Privacy Policy
Effective October 2, 2026
- There's no account. We don't know who you are.
- Your cards, photos and the places you found them are stored on your iPhone and in your own iCloud, not on our servers.
- To identify something, the app sends that photo to an AI model, only after you allow it. Faces are covered first. We don't store the photo, and it isn't used to train AI.
- Only the country and region go with a photo, never your exact location.
- Anonymous usage statistics (which features are used, never what's on your cards), which you can turn off in Settings. No advertising, no tracking across apps or websites.
- Who we are
- On your device
- Camera, photos & location
- AI identification
- Shared card data
- Usage statistics
- Purchases
- What we don't do
- Your rights
- Contact
Who we are
CollectAim (“the app”) is an iPhone app published by AimPoly LLC, a Wyoming limited liability company (“AimPoly”, “we”, “us”). This policy covers the app and this website, collectaim.com. If you have a question about it, write to support@collectaim.com.
Data stored on your device
Everything in your collection — your cards and the photos they're made from, the cut-out subject, names, facts, rarity, the date and the place of each find, whether you've seen, want or own something, and your settings — is stored on your iPhone. It is not sent to us, and we have no copy of it.
- iCloud. The app keeps your collection in sync across your devices using the private iCloud database of your Apple ID (Apple's CloudKit). Only your Apple ID can access it; we can't see or read it, and it uses your iCloud storage. Apple's handling of iCloud data is covered by Apple's Privacy Policy.
- Work done on your iPhone. Lifting the subject out of a photo, finding faces, reading text on signs and labels, recognising a photo of something already in your collection, the 3D rooms, card videos and the monthly wrap's charts are all made on your iPhone.
- Device backups. Like other app data, your collection may be included in your iPhone's iCloud or computer backups, under your Apple ID settings. We can't access those backups.
- Reminders. If you ask to be told when a sealed card opens, the reminder is created and shown by your iPhone; nothing about it is sent to us. To open waiting cards, iOS may let the app run briefly in the background, and it then sends the same identification request described below. You can turn notifications off in Settings → Notifications → CollectAim.
Removing a card in the app deletes it and its photos from your iPhone and, through sync, from your iCloud. Deleting the app removes the data from that iPhone; the iCloud copy stays until you delete CollectAim's data in Settings → [your name] → iCloud → Manage Storage.
Camera, photos and location
Camera
The camera is used only while you're taking a photo for a card. Photos aren't taken in the background.
Photos
To make cards from older photos, you choose them with the iOS photo picker. The app receives only the photos you pick, together with the date and location stored in them, and never sees the rest of your library. If you save a card video, iOS asks for permission to add it to your Photos; the app can't read your library with that permission.
Location
If you allow it, the app reads your location while you take a photo, so the card remembers where you found it. The exact coordinates stay on your iPhone and in your iCloud. To show a place name (for example “Kyoto”), your iPhone asks Apple's geocoding service, and the discovery map shows Apple Maps; both are run by Apple under Apple's privacy terms.
- Only the country and region of a find are sent with a photo for identification, because they help name local species and judge how rare something is where you are.
- Map pins are rounded to about 100 metres, so a screenshot of the map never shows an exact address.
- You can hide the place of any card (card → Show location). It disappears from the card, the map, travel boards, the wrap and anything you share; it isn't deleted, so you can show it again.
- You can stop location access at any time in Settings → Privacy & Security → Location Services → CollectAim.
People
CollectAim never identifies people. Before a photo leaves your iPhone, the app finds faces on the device and covers them with grey shapes. If a person is the main subject of a photo, no card is made.
AI identification
Naming what's in a photo uses a large language model. Before the first photo is sent, the app shows what is sent and where, and asks for your permission. Nothing is sent without it. You can withdraw it at any time in Settings → Privacy → AI identification; new cards then wait, sealed, until you allow it again.
What is sent
| Feature | Sent for that request |
|---|---|
| Identifying a photo | The photo, reduced in size, with faces covered; a rough guess of what it is made on your iPhone (for example “plant”); text read from signs or labels in the photo; the country and region; the app language. |
| “Not quite right?” | The same photo and details, the earlier identification, and the name you typed or chose. |
| “More about” a card | Only the name and category of the kind of thing (for example “Helianthus annuus”, plant) and the app language. No photo. |
| Monthly wrap story | A summary made on your iPhone: how many cards you found, counts per category, the name and rarity of your rarest card, the names of a few highlights and up to five place names. No photos or coordinates. |
Where it goes
- Our server — a small program running on Cloudflare Workers — receives the request, forwards it to the AI model and returns the answer. It doesn't store your photos or what you type. Its operational logs, kept for a few days, record only technical events (for example “identified, category: plant, rarity: rare”; for a correction, the earlier and the new name of the kind of thing).
- Cloudflare provides the hosting and the AI Gateway that carries the request. The gateway records usage figures such as token counts and timing, not the content of requests. Like any network provider, Cloudflare processes your IP address to deliver the request. See the Cloudflare Privacy Policy.
- Anthropic provides the Claude model that names the subject and writes the text. Under Anthropic's commercial terms, data sent through its API is not used to train its models; it may be retained for a limited period for safety and abuse monitoring. See Anthropic's Privacy Policy.
These providers may process data in the United States and other countries where they operate. We don't send Anthropic your name, email, device identifiers, exact location or anything that identifies you.
Shared card data
So that the same kind of thing gets the same rarity for everyone, our server keeps a table of kinds of things that have been identified (for example “Common kingfisher”) with the rarity first given to them, and the “More about” text written for each kind and language. For wild plants, animals and fungi it also keeps how many sightings GBIF, the Global Biodiversity Information Facility, has recorded in a country; to get that number, only the species name and the country are sent to GBIF. None of this is linked to you, your photos or your device.
Protecting the service from abuse
To make sure requests come from a genuine copy of the app, CollectAim uses Apple's App Attest. Your iPhone creates a random key for this installation, Apple confirms it belongs to an unmodified copy of CollectAim, and each request is signed with it. Our server stores only that key's random identifier and public key, deleted after 180 days without use, and counters for the daily limits: how many photos it identified today, corrections made today, and shares and wraps this month, kept for up to 40 days. This contains nothing about you or your cards and isn't shared with Anthropic.
Usage statistics
To learn which features help people and where they get stuck, the app sends a small set of anonymous usage events. They are on by default, and you can turn them off at any time in Settings → Privacy → Share usage statistics; nothing more is sent after that.
What is sent
- That onboarding was completed, and whether AI identification was allowed.
- That a photo was taken or imported, and how its identification ended (a card, already in the collection, waiting for a connection or for discoveries, couldn't be identified, or a person) with the card's category and rarity tier.
- Whether a new card was added or not, and, for “Not quite right?”, where it was used, whether a suggestion or a typed name was chosen and whether it was accepted — never what you typed.
- That a card video, wrap or room tour was shared, and whether it earned extra discoveries.
- That the Pro screen was shown and where from, and whether a purchase completed, was cancelled or failed (plan only — never payment details).
- Switching between the 3D rooms, the 2D album and the map; which kind of room was opened or newly unlocked; opening “More about” (category only); marking a card seen, wanted or owned; opening the monthly wrap; removing a card (category only).
- That a request to our server succeeded or failed, and how long it took.
- That the app was installed, opened or updated.
- Context sent with each event: app version, whether it's a TestFlight build, app language, the language, region and time zone set on your iPhone, device model, iOS version, screen size, whether you're on Wi-Fi or cellular, whether Pro is active, the number of cards you have, and the album view you use.
Never sent: photos, card names or species, places or coordinates, facts, anything you type, your name, email or any account, and no advertising identifier.
Who processes it
Events go to PostHog, an analytics service, on its EU cloud. Each installation gets a random statistics ID created by the app; it isn't linked to your identity, your Apple ID or your requests to our server, and we never try to identify you from it. Your IP address is discarded when an event arrives, and no location is derived from it. See PostHog's Privacy Policy.
We use these statistics only to improve CollectAim, never for advertising, and we don't sell or share them. We keep them only as long as they're useful for that purpose.
Purchases
Pro is sold through Apple's App Store. Apple processes the payment; we never see your payment details, name or Apple ID. The app receives a record from Apple, signed by Apple, that Pro is active.
Because identification costs us money to run, each request from a Pro subscriber includes that signed record: the subscription's order number, the plan, its dates, and the store country and price. It never contains your name, Apple ID or payment details. Our server checks Apple's signature and that the subscription is active or in Apple's billing grace period. So that one subscription can't be shared across many phones, the server keeps the subscription's original order number together with the random App Attest identifiers of the installations that used it (at most six in 30 days). When Apple notifies us that a subscription was refunded or revoked, we mark that order number so it no longer counts as Pro. This record is kept for up to 400 days after it was last updated, isn't linked to anything else about you, and is never shared.
Apple's handling of purchases is covered by Apple's Privacy Policy.
What we don't do
- No account or sign-in, and we don't ask for your name, email or phone number.
- No storing of your photos or your collection on our servers.
- No identifying of people, ever.
- No crash-reporting or advertising SDKs, and no advertising identifier.
- No tracking across other companies' apps or websites.
- No access to your contacts, microphone or full photo library.
- No selling or renting of data, ever.
This website
collectaim.com uses no cookies, no analytics and no third-party scripts or fonts. Our hosting provider, Cloudflare, processes standard request data such as IP addresses to serve the site and protect it from abuse. The sample photos on this site are in the public domain or released under CC0.
Children
CollectAim isn't directed to children under 13, and we don't knowingly collect personal information from them. The app doesn't ask anyone for personal information; the only data it sends is described above.
Your rights
Depending on where you live — for example under the EU/UK GDPR or California's CCPA — you may have rights to access, correct, delete or port your personal data and to object to its processing. Because your collection stays on your device and in your own iCloud, and we keep no copy of your photos or requests, you can exercise these rights directly: view and edit everything in the app, and delete it by removing cards, deleting the app and its iCloud data. If you have any request or complaint, contact us and we'll respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
The usage statistics carry only a random ID that we can't link to you, so we can't look them up by name or email. Turning off Share usage statistics stops them; deleting the app removes the ID.
Where GDPR applies, the legal basis for identifying a photo is your consent, given in the app before the first photo is sent (Art. 6(1)(a)), together with performing the service you asked for (Art. 6(1)(b)); and for usage statistics our legitimate interest in understanding and improving the app (Art. 6(1)(f)), which you can object to at any time by turning them off.
Security
Requests between the app and our server are encrypted in transit (HTTPS) and signed with the app's App Attest key. Data on your iPhone is protected by iOS, including device encryption when your phone is locked.
Changes to this policy
If we change how the app handles data, we'll update this page and the date at the top, and for significant changes we'll mention it in the app's release notes before it takes effect.
Contact
AimPoly LLC, 30 N Gould St Ste 50550, Sheridan, WY 82801, USA — support@collectaim.com