Privacy Policy
Who this is about
TrophyShelf is developed and operated by Vinay Are, an individual (“we”, “us”). This policy covers the TrophyShelf mobile apps for iOS and Android, the public pages at this domain, and the backend services behind both. Where the law uses the term, we are the data controller for the information described here.
What we collect
Things you give us directly
- Your mobile number. Signing in sends a one-time code by SMS. There is no password and no other sign-in method, so the number is not optional — it is your account.
- Your profile. A username, your name, an optional profile photograph, and an optional email address. If you add an email we send a verification link to it; until you follow the link it is stored but unverified.
- Your collectibles. Photographs, the collectible type, and whatever fields that type asks for — condition, description, what you paid, what you think it is worth, where you got it, and the category-specific details such as a set name, a casting or a certification number.
- Your collections, including their names and whether each one is public.
- Abuse reports, if you file one from a public page — the reason you pick, the note you write, and the page you are reporting.
Things we record while the app runs
- Product analytics. A fixed list of events — which step of the add flow you reached, whether a detection finished, whether a paywall was shown, how long a feed session lasted. Every event carries your account ID and a small number of counts, durations and flags. None of them can carry free text. There is no way for the app to send your name, your phone number, a collectible's title, a field you typed, or a model's reply to our analytics, because the code that sends events accepts no such value.
- Crash reports, including the device model, the operating-system version and the stack trace, so a crash can be fixed.
- Performance measurements. How long the app takes to start, and how long a few named operations take — how long reading your photos with AI took, and how much of that was the network. These are durations and sizes attached to a fixed list of operation names. They carry nothing you typed and nothing about what the collectible is, for the same reason the analytics above cannot: the code that records them accepts only numbers.
- Device attestation. Before your app talks to our backend, Apple or Google issues a token confirming the request came from a genuine, unmodified copy of the app. We see the verdict, not an identifier we could track you with. It is what stops strangers spending our AI budget.
- A push notification token, only if you turn notifications on. Turning them off, or signing out, removes it.
- Counts on public pages — how many times a public collectible has been viewed, shown in a feed, saved or shared. These are totals. We do not record who viewed what, and a page's own owner is not counted as a viewer of it.
Things that stay on your phone
An unfinished add-a-collectible draft, photographs waiting to upload, your theme choice, and the identity of the signed-in account are stored on the device itself. Drafts and queued photographs are deleted when the item publishes or you discard it; signing out clears the rest.
Photographs and AI
Filling in a collectible's details from a photograph is the point of the product, and it works by sending your photographs to a model that is not ours. This is the part of the policy worth reading twice.
- Which model. Google's Gemini API. Your photographs go from the app to our own server, and from there to Google. The app never talks to Google's model directly.
- When. Only when you ask. Adding a collectible with autofill sends up to three of the photographs you picked. Asking for enhanced details, a condition assessment or a value estimate on an existing collectible sends that collectible's photographs and the fields already on it. Nothing is sent in the background, and nothing is sent for a collectible you never run an AI action on.
- What travels with them. The photographs, the type of thing you are cataloguing, and the field names that type uses. Your name, your username, your phone number and your account ID are not included in the request.
- Web search. The value estimate — where offered — additionally asks the model to search the public web for comparable sales. It searches for the item, not for you.
- What comes back. Suggested values. They are suggestions: AI-filled fields are badged in the app so you can see which ones to check, low-confidence answers are left blank rather than guessed, and you can edit or clear any of them before saving.
- Retention at Google. Google processes the request under its own terms for the Gemini API, which govern whether and for how long it retains the content. We do not control that, and you should read Google's terms if it matters to you. We do not store the raw model reply beyond the values you keep.
Photographs are resized and re-compressed on your device before they are uploaded anywhere, so the full-resolution original never leaves the phone.
What is public, and what is not
There are two switches, and each one governs its own page independently:
- A collectible's own switch decides whether it has a public page. Inside a collection you have made public, collectibles are public by default; you can mark any of them private, and a private one appears nowhere — not on a public page, not in the feed. A collectible you have left public has a page wherever it is filed, including inside a collection that is private.
- A collection's switch decides whether the collection has a page of its own and whether it is listed on your profile. A collection is private when you create it and stays private until you change it. Making it private removes the collection's own page and takes it off your profile; it does not withdraw the public collectibles inside it, which keep their own pages until you change each one.
So the switch to check, for any one collectible, is that collectible's own. A private collection is not a container that hides what is in it.
A public page needs no account and no app. Anyone with the link can open it, and search engines can index it. It shows the photographs, the details you filled in, your username and profile photograph, and the item's view count.
Turning something private is not instant everywhere. The page is removed within seconds, but public pages are served through a cache that keeps a copy for up to ten minutes, so a link somebody already has may keep working for that long. There is no way for us to purge it sooner. The same is true of your photographs' own URLs, and of any copy somebody has already saved or screenshotted — which is true of anything published anywhere, and is worth remembering before you make something public.
Your own numbers — impressions, taps, where views came from — are yours. Only the plain view count is shown publicly.
Cookies on trophyshelf.app
Everything above is about the app. This section is about this website — the pages you are reading now.
We count visits with Firebase Analytics, which is Google Analytics underneath, so we can see which pages help and which are ignored. It records the page you opened, roughly where in the world you opened it from, and what kind of device and browser you used. None of it is tied to a TrophyShelf account — you do not need one to read this site, and nothing here is joined to the account data described above.
Nothing is stored on your device until you agree. A banner asks the first time you visit. Until you choose “Allow” the analytics run without cookies: we see that a page was opened, and nothing that could recognise you on a later visit.
- If you allow it, Google sets cookies named _ga and _ga_CXST7C77Y7, which last up to two years and let us tell a returning visitor from a new one.
- If you decline, no cookie is set and no identifier is kept. The answer itself is remembered in your browser’s local storage, so you are not asked again.
- We never ask for advertising consent here, because this website carries no ads. The advertising signals stay switched off for everybody, whichever way you answer.
To change your mind, clear this site’s cookies and site data in your browser; the banner then asks again on your next visit. A browser set to block cookies will also stop it, and nothing on this site depends on it working.
These are the only cookies this website sets. There are none for advertising, and no other third-party tracker.
Ads
The free plan shows ads between your collections, in a collection, and in the feed. They are served by Google AdMob. A TrophyShelf Pro subscription removes every one of them.
What the ad network gets. Your device's advertising identifier, and the coarse context any ad request carries — country, device type, language. That is all. It does not receive your phone number, your name, your collection, your photographs, or anything you have typed into the app.
What it is used for. Choosing which ad to show, and measuring whether it was seen. The advertising identifier is the device's rather than your account's, and we do not join the two.
Your choice. Where the law requires it, you are asked before any personalised ad is served, and you can decline — ads still appear, chosen without using your identifier. On iOS the system also asks separately whether the app may track you, and No there is a full answer: nothing about it is asked again.
You can reset or delete the advertising identifier at any time in your device settings, on either platform. Doing so breaks the link between you and anything previously associated with it.
Pro contacts no ad network at all. This is not a setting that hides the ads — with a subscription active the app never starts the ad software, never asks for consent, and never reads the identifier.
If you report a page
The report form on a public page can be used without an account, so we have nothing to rate-limit it by except your network address. We take your IP address, combine it with a secret value and store only the resulting one-way hash, purely to count how many reports have come from one place in the last hour. The address itself is not stored, and the hash is not linked to any account.
We keep the report itself — its reason, its note, and which page it was about — as a moderation record. A report survives the reported account being deleted, because otherwise deleting and re-registering would erase the history of what was reported.
How long we keep it
- Your account and everything in it — until you delete it. Cataloguing is only worth doing if the catalogue is still there next year.
- An account you have asked us to delete — 30 days, then permanently. Your public pages, your posts in the feed and your notification tokens go immediately; the rest is held so you can restore it by signing in. Nothing about the wait depends on you coming back — if you do not, it is deleted on the date either way.
- Deleted collectibles and collections — removed when you delete them, along with their photographs and any public page.
- Analytics and crash reports — retained for as long as Firebase's own retention settings keep them, which is a matter of months rather than years.
- Report rate-limit hashes — an hour.
- Moderation records — kept, as described above.
- Records we are required to keep, such as records of a purchase, for as long as the law requires.
Your choices
- Change what is visible. Any collectible or collection can be switched between public and private at any time, from the app.
- Edit or delete anything you added, including photographs.
- Turn notifications off, in the app or in your phone's settings. Doing so removes the push token.
- Delete your account. Settings → Delete Account, and you will be asked to type your username to confirm. Your public pages and your posts in the feed come down straight away, and your account is deleted 30 days later — your collectibles, photographs, collections, saved items and profile, and finally your sign-in record. You have those 30 days to change your mind: sign in again and choose Restore, and everything comes back as it was. The same screen offers Continue deletion, which signs you out and leaves the deletion running — it deletes nothing at the moment you tap it. The full deletion route is here. It does not cancel a subscription — Apple and Google own that, and you have to cancel it in the App Store or Play Store, or you will keep being charged. That matters more here, not less: the 30 days are 30 more days of billing if you do not cancel.
- Ask for a copy of your data. The app has no export button yet. Write to us and we will send you what we hold.
- Object, correct, restrict or complain. Depending on where you live you may have the right to object to or restrict how we process your information, to have it corrected, or to complain to a data protection authority. Write to us and we will act on it.
We do not charge for any of this and we will not make you close your account to exercise it.
Children
TrophyShelf is not for children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, write to us and we will remove it. Where local law sets a higher age for consent to data processing, that age applies instead.
Keeping it safe
Traffic is encrypted in transit and data is encrypted at rest by the underlying Google Cloud services. Access to your collection is enforced by server-side rules rather than by the app: another account cannot read your private collectibles even with a modified copy of the app. Requests to our backend must carry a device attestation token, and your signed-in session is held in the iOS Keychain or Android's encrypted storage.
No system is perfect. If we ever discover a breach affecting your information, we will tell you and the relevant authority as the law requires.
Changes to this policy
When this policy changes we update the date at the top. If a change materially affects what we do with your information we will tell you in the app before it takes effect.
Getting in touch
Email developer.trophyshelf@gmail.com, or use Settings → Help and support inside the app. We answer privacy requests within 30 days and usually much sooner.
Email is the fastest route and the best one for a privacy request; we will give a postal address on request if you need to write to us. This policy is governed by the law of India.