Legal

Privacy Policy

Effective October 2, 2026

The short version

Who we are

CollectAim (“the app”) is an iPhone app published by AimPoly LLC, a Wyoming limited liability company (“AimPoly”, “we”, “us”). This policy covers the app and this website, collectaim.com. If you have a question about it, write to support@collectaim.com.

Data stored on your device

Everything in your collection — your cards and the photos they're made from, the cut-out subject, names, facts, rarity, the date and the place of each find, whether you've seen, want or own something, and your settings — is stored on your iPhone. It is not sent to us, and we have no copy of it.

Removing a card in the app deletes it and its photos from your iPhone and, through sync, from your iCloud. Deleting the app removes the data from that iPhone; the iCloud copy stays until you delete CollectAim's data in Settings → [your name] → iCloud → Manage Storage.

Camera, photos and location

Camera

The camera is used only while you're taking a photo for a card. Photos aren't taken in the background.

Photos

To make cards from older photos, you choose them with the iOS photo picker. The app receives only the photos you pick, together with the date and location stored in them, and never sees the rest of your library. If you save a card video, iOS asks for permission to add it to your Photos; the app can't read your library with that permission.

Location

If you allow it, the app reads your location while you take a photo, so the card remembers where you found it. The exact coordinates stay on your iPhone and in your iCloud. To show a place name (for example “Kyoto”), your iPhone asks Apple's geocoding service, and the discovery map shows Apple Maps; both are run by Apple under Apple's privacy terms.

People

CollectAim never identifies people. Before a photo leaves your iPhone, the app finds faces on the device and covers them with grey shapes. If a person is the main subject of a photo, no card is made.

AI identification

Naming what's in a photo uses a large language model. Before the first photo is sent, the app shows what is sent and where, and asks for your permission. Nothing is sent without it. You can withdraw it at any time in Settings → Privacy → AI identification; new cards then wait, sealed, until you allow it again.

What is sent

FeatureSent for that request
Identifying a photoThe photo, reduced in size, with faces covered; a rough guess of what it is made on your iPhone (for example “plant”); text read from signs or labels in the photo; the country and region; the app language.
“Not quite right?”The same photo and details, the earlier identification, and the name you typed or chose.
“More about” a cardOnly the name and category of the kind of thing (for example “Helianthus annuus”, plant) and the app language. No photo.
Monthly wrap storyA summary made on your iPhone: how many cards you found, counts per category, the name and rarity of your rarest card, the names of a few highlights and up to five place names. No photos or coordinates.

Where it goes

These providers may process data in the United States and other countries where they operate. We don't send Anthropic your name, email, device identifiers, exact location or anything that identifies you.

Shared card data

So that the same kind of thing gets the same rarity for everyone, our server keeps a table of kinds of things that have been identified (for example “Common kingfisher”) with the rarity first given to them, and the “More about” text written for each kind and language. For wild plants, animals and fungi it also keeps how many sightings GBIF, the Global Biodiversity Information Facility, has recorded in a country; to get that number, only the species name and the country are sent to GBIF. None of this is linked to you, your photos or your device.

Protecting the service from abuse

To make sure requests come from a genuine copy of the app, CollectAim uses Apple's App Attest. Your iPhone creates a random key for this installation, Apple confirms it belongs to an unmodified copy of CollectAim, and each request is signed with it. Our server stores only that key's random identifier and public key, deleted after 180 days without use, and counters for the daily limits: how many photos it identified today, corrections made today, and shares and wraps this month, kept for up to 40 days. This contains nothing about you or your cards and isn't shared with Anthropic.

Usage statistics

To learn which features help people and where they get stuck, the app sends a small set of anonymous usage events. They are on by default, and you can turn them off at any time in Settings → Privacy → Share usage statistics; nothing more is sent after that.

What is sent

Never sent: photos, card names or species, places or coordinates, facts, anything you type, your name, email or any account, and no advertising identifier.

Who processes it

Events go to PostHog, an analytics service, on its EU cloud. Each installation gets a random statistics ID created by the app; it isn't linked to your identity, your Apple ID or your requests to our server, and we never try to identify you from it. Your IP address is discarded when an event arrives, and no location is derived from it. See PostHog's Privacy Policy.

We use these statistics only to improve CollectAim, never for advertising, and we don't sell or share them. We keep them only as long as they're useful for that purpose.

Purchases

Pro is sold through Apple's App Store. Apple processes the payment; we never see your payment details, name or Apple ID. The app receives a record from Apple, signed by Apple, that Pro is active.

Because identification costs us money to run, each request from a Pro subscriber includes that signed record: the subscription's order number, the plan, its dates, and the store country and price. It never contains your name, Apple ID or payment details. Our server checks Apple's signature and that the subscription is active or in Apple's billing grace period. So that one subscription can't be shared across many phones, the server keeps the subscription's original order number together with the random App Attest identifiers of the installations that used it (at most six in 30 days). When Apple notifies us that a subscription was refunded or revoked, we mark that order number so it no longer counts as Pro. This record is kept for up to 400 days after it was last updated, isn't linked to anything else about you, and is never shared.

Apple's handling of purchases is covered by Apple's Privacy Policy.

What we don't do

This website

collectaim.com uses no cookies, no analytics and no third-party scripts or fonts. Our hosting provider, Cloudflare, processes standard request data such as IP addresses to serve the site and protect it from abuse. The sample photos on this site are in the public domain or released under CC0.

Children

CollectAim isn't directed to children under 13, and we don't knowingly collect personal information from them. The app doesn't ask anyone for personal information; the only data it sends is described above.

Your rights

Depending on where you live — for example under the EU/UK GDPR or California's CCPA — you may have rights to access, correct, delete or port your personal data and to object to its processing. Because your collection stays on your device and in your own iCloud, and we keep no copy of your photos or requests, you can exercise these rights directly: view and edit everything in the app, and delete it by removing cards, deleting the app and its iCloud data. If you have any request or complaint, contact us and we'll respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

The usage statistics carry only a random ID that we can't link to you, so we can't look them up by name or email. Turning off Share usage statistics stops them; deleting the app removes the ID.

Where GDPR applies, the legal basis for identifying a photo is your consent, given in the app before the first photo is sent (Art. 6(1)(a)), together with performing the service you asked for (Art. 6(1)(b)); and for usage statistics our legitimate interest in understanding and improving the app (Art. 6(1)(f)), which you can object to at any time by turning them off.

Security

Requests between the app and our server are encrypted in transit (HTTPS) and signed with the app's App Attest key. Data on your iPhone is protected by iOS, including device encryption when your phone is locked.

Changes to this policy

If we change how the app handles data, we'll update this page and the date at the top, and for significant changes we'll mention it in the app's release notes before it takes effect.

Contact

AimPoly LLC, 30 N Gould St Ste 50550, Sheridan, WY 82801, USA — support@collectaim.com