Privacy Policy
Thingalog is a catalog-as-a-service platform. This policy describes what data we collect from you, what we do with it, and the choices you have.
We wrote this in plain language on purpose. If anything here is unclear, email [email protected].
What we collect
Account information
- Email address — used to sign you in and contact you about your account.
- Password — hashed by Supabase Auth. We never see or store your plaintext password.
- Google profile (optional) — if you sign in with Google, we receive your email address and basic profile information from Google. We do not request your contacts, calendar, or any other Google data.
Catalog content you create
- Templates, items, fields, and values — the structured data that makes up your catalog.
- Photos — image files you upload, stored in Supabase Storage.
- Photo metadata (EXIF) — camera, date, and GPS data embedded in photos you upload. This is extracted and stored alongside the photo so you can search and filter on it. EXIF can contain location data; if that matters to you, strip it before uploading.
- API keys — if you create API keys for programmatic or MCP access, we store a SHA-256 hash of each key. We cannot recover a key after it's issued; you see it once at creation.
Technical information
- Session cookies — we set a cookie containing your Supabase auth token so you stay signed in. We do not use tracking cookies or third-party analytics.
- Server logs — our hosting provider records standard request information (IP address, user agent, request path, timestamp). These are used for debugging and abuse prevention, and are discarded on a rolling basis.
How we use your data
We use your information to operate the service: authenticate you, store and serve your catalog, let you search and export it, enforce our Terms, and respond to support requests.
We do not sell your data. We do not share it with advertisers. We do not use it to train machine learning models.
AI processing (important)
Public catalogs — read this carefully
When you mark a catalog as public, its content becomes accessible to anyone with the URL — not just people who sign in, not just people you invite. That means:
- Search engines (Google, Bing, etc.) can crawl and index your catalog.
- AI crawlers and scrapers may copy your content into training datasets, archives, or caches. We cannot prevent this.
- Third parties can cache, mirror, screenshot, or re-publish whatever you put up.
- Photos you upload to a public catalog are themselves public URLs — anyone can load them directly.
- Once content is public, removing it from your catalog does not remove it from other people's copies.
If you would not be comfortable with something appearing on the front page of Google next week, do not put it in a public catalog. Keep your catalog private if you need control over who sees it.
Third-party services we use
- Supabase — authentication, file storage, and the routing database (privacy policy).
- Neo4j Aura — the graph database holding your catalog content (privacy policy).
- Anthropic — the Claude API, for AI-powered features (privacy policy).
- Railway — application hosting (privacy policy).
- Cloudflare — DNS and edge traffic routing (privacy policy).
- Google Sign-In — only if you choose to sign in with Google (privacy policy).
Content moderation and photo scanning
To keep the platform safe and to comply with applicable law, Thingalog scans or will scan uploaded photos for known illegal imagery (including child sexual abuse material) before they are stored. Matches are quarantined, logged, and — where required — reported to the National Center for Missing & Exploited Children (NCMEC) under 18 U.S.C. § 2258A. Account information associated with a match may be preserved and reported.
Public catalogs also include a report button; submitted reports route to our moderation queue with your IP and user agent attached so we can investigate abuse.
Data export and deletion
You own your catalog. You can export it at any time as a ZIP archive containing your templates, items, values, and photos.
To delete your account and all associated catalogs, email [email protected] from the address on the account. We remove account and catalog data within 30 days of confirmation, except records we are required to retain (e.g. moderation logs tied to legal reporting obligations).
Security
We use TLS for all traffic, store passwords only as hashes via Supabase, and hash API keys before storing them. Catalog data is isolated per tenant at the database layer. No system is perfectly secure — if you believe your account has been compromised, email us immediately.
Children
Thingalog is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, email us and we will delete it.
International users
Thingalog is operated from Canada. When you use the service, your data may be stored and processed in Canada, the United States, and other countries where our service providers operate. By using Thingalog, you consent to this transfer.
Changes to this policy
We may update this policy as the platform evolves. Material changes will be announced on the landing page and, where appropriate, by email to account holders. The "Last updated" date at the top tells you when the current version took effect.
Contact
Privacy questions, data export or deletion requests, and any other concerns: [email protected].