Legal
This Privacy Policy describes how Collection Port ("we", "us", or "our") handles information when you use the Collection Port mobile application (the "App") on Android. Please read it carefully.
Collection Port is developed and maintained by an independent developer. If you have any questions or concerns about this policy, you can reach us at:
Email: anubys383@gmail.com
Collection Port is a local, offline-first application. All data you create inside the App — including collections, records, fields, templates, images, and attachments — is stored on your device using a local database (Room/SQLite) and app-private file storage. By default, this data:
If you choose to enable optional cloud sync (see Section 2.5), a copy of your collection data may be uploaded to storage you configure (FTP, WebDAV, or Google Drive). Sync is entirely optional and off by default.
The free version of the App displays advertisements served by Google AdMob, including banner ads on some screens and full-screen interstitial ads at certain points in the App (for example, when adding a sync account). In order to serve ads, Google may collect and use the following information:
This data is collected and processed by Google LLC under their own privacy policy. You can review it at: https://policies.google.com/privacy
You can opt out of interest-based advertising or reset your Advertising ID at any time via: Android Settings → Privacy → Ads
The App offers an optional one-time in-app purchase called Collection Port Premium (product ID: full) that permanently removes ads. All payment transactions are processed exclusively by Google Play and are subject to Google's Terms of Service and Privacy Policy. We do not collect, store, or process your payment card details or billing address. The App only receives a confirmation of whether a valid purchase exists for your Google account.
Collection Port Premium removes advertising only. Core features — including import/export backup, cloud sync, collections, analytics, and editing — remain available in the free version.
When you first open the App or access the walkthrough / "What's New" screens, the App may load promotional images from our static website: https://collection-port.web.app
These requests are standard HTTPS image loads. No personal data is intentionally sent to this server as part of these requests beyond what your device includes in any standard HTTP request (IP address, device/browser headers). We do not log or store these requests.
The App offers an optional cloud sync feature that lets you back up and restore your collection data to storage you control. This feature is entirely optional and is disabled until you configure a sync account.
What is synced: When enabled, the App may upload and download your collection data, metadata, and attachments (such as cover images) to keep a remote backup in sync with your device.
When sync runs: Sync may occur when you manually trigger it, when you restore from a cloud account, when you save collection data (for all enabled accounts), or periodically in the background (approximately every 3 hours) for enabled accounts that have network connectivity. A periodic sync schedule is registered when the App starts.
Supported providers:
appDataFolder (an app-specific area, not your general Drive files), connected via Google Sign-In through Google Play servicesWhat is not synced: Draft collections and draft records are excluded from sync. Attachments are transferred using content-hash deduplication (SHA-256) so identical files are stored once remotely.
Credentials: To connect to your chosen provider, the App stores connection details on your device — such as server address, username, password (FTP/WebDAV), or an OAuth access token (Google Drive). These credentials are encrypted using Android Keystore and are never transmitted to us.
Third-party storage: Synced data is stored on the server or cloud account you configure. We do not operate the sync backend. Your use of FTP, WebDAV, or Google Drive is subject to that provider's terms and privacy policy. For self-hosted FTP or WebDAV servers, the App may connect over unencrypted HTTP or FTP if that is how your server is configured.
Device identifier: During sync, the App may write your device's ANDROID_ID to remote lock files on your configured storage to coordinate concurrent sync operations. This identifier is not sent to Collection Port.
Collection Port uses the Google Drive API solely to allow you to back up, restore, and sync your Collection Port data upon your explicit request (when you configure and use Google Drive sync). Access is limited to the minimum scopes needed for this feature, which may include drive.appdata and/or drive.file.
Google Drive is not used for advertising, analytics profiling, resale of data, or unrelated product features. We do not read Google Drive files unrelated to Collection Port backup/sync functionality.
Collection Port's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
Clear declaration: Your catalog content, descriptions, and attachments are never collected, sold, or processed on external servers owned by the developer or by third parties acting on our behalf for content hosting. Optional sync sends data only to destinations you choose (Google Drive, WebDAV, or FTP/FTPS). Advertising and billing are handled by Google as independent services as described elsewhere in this Policy.
The App includes a separate Import/Export feature that lets you create and restore local backup files. This feature is available to all users and is distinct from optional cloud sync (Section 2.5) and from Collection Port Premium (Section 2.3).
What is included: When you create a backup, the App packages your non-draft collections into a .cpb file — a ZIP archive containing a collection.xml manifest plus locally stored media attachments (such as cover images). The backup includes collection structure, record data, field values, and local image files. Web-linked media is not included.
Format and encryption: Backup files are standard ZIP archives with XML metadata. They are not encrypted. Anyone with access to a backup file can read its contents.
Where files are stored: Export and import use Android's system file picker (Storage Access Framework). You choose where to save or open a backup — for example, on-device storage, an SD card, or a location provided by another app (such as a cloud storage app). The App does not automatically upload backup files anywhere; processing happens on your device only.
When it runs: Backup and restore are initiated manually by you. There are no automatic or scheduled local backups in this feature. While a backup or import is running, the App may show a progress notification.
Import behavior: Restoring from a backup merges data into your local database. The App temporarily extracts files to app-private storage during import and removes them when the operation completes. If import fails, partially extracted media files are rolled back.
Your responsibility: Exported .cpb files remain wherever you saved them until you delete them. The App does not track or manage backup files after export. Protect backup files as you would any file containing your personal data.
When you choose to share an image or file from the record gallery or elsewhere in the App, the App copies the selected file to a temporary app cache folder and opens Android's system share sheet. You choose the recipient app or contact. We do not receive or store shared content, and no sharing occurs unless you explicitly tap Share.
Without cloud sync enabled, the App behaves as a fully offline, local-only application.
| Permission | Reason |
|---|---|
INTERNET |
Required to load advertisements (AdMob), walkthrough images, and cloud sync (when enabled). |
com.google.android.gms.permission.AD_ID |
Required by Google AdMob to serve and measure ads using the resettable Advertising ID. |
com.android.vending.BILLING |
Required to verify and process in-app purchases via Google Play. |
POST_NOTIFICATIONS |
Used to display optional progress notifications for long-running background tasks (e.g. import/export and cloud sync). |
FOREGROUND_SERVICE / FOREGROUND_SERVICE_DATA_SYNC |
Used to keep import, export, and cloud sync operations running reliably in the background without being interrupted by the OS. |
ACCESS_NETWORK_STATE |
Used to detect network connectivity before cloud sync operations. |
ACCESS_WIFI_STATE |
Used to inspect network state when connecting to FTP or WebDAV servers. |
ACCESS_LOCAL_NETWORK |
Used to connect to FTP or WebDAV servers on your local network (for example, a NAS on your home Wi‑Fi). Requested when you configure or use LAN-based sync. |
We do not sell, rent, or share your personal data with third parties, except:
appDataFolder, at your direction. We do not control or access that remote storage.Cloud sync sharing occurs only when you configure and enable a sync account. We never receive a copy of your synced data.
All user-generated data is stored locally on your device. You can delete all App data at any time by:
Uninstalling the App removes all locally stored data, including encrypted sync credentials. We have no ability to recover it once deleted.
Cloud sync data: Deleting or disabling a sync account in the App removes its encrypted credentials from your device and stops future sync operations. Remote copies stored on your FTP/WebDAV server or Google Drive remain until you delete them on that service. Disabling sync does not automatically remove remote backups.
Exported backup files: Manual .cpb backups (Section 2.6) that you saved via the system file picker remain in the location you chose until you delete them yourself. The App does not delete or manage those files after export.
The App is configured to exclude its database and settings from Android's automatic cloud backup and device-to-device transfer features. Your collection data does not leave your device via the Android backup system. To keep a copy of your data, use the manual Import/Export feature (Section 2.6) or optional cloud sync (Section 2.5).
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability.
How to delete your data:
appDataFolder area where applicable), and revoke App access in your Google Account security settings..cpb files: Delete them from wherever you saved them.GDPR / UK GDPR (where applicable): Processing may be based on performance of a contract (features you request), consent (where required), legitimate interests (security and essential App operation), or legal obligation.
CCPA / CPRA (California, where applicable): We do not sell personal information as “sale” is commonly understood. Depending on advertising configurations, certain sharing of identifiers with advertising partners may constitute “sharing” for cross-context behavioral advertising. You may exercise applicable opt-out rights through device advertising settings and by contacting us. We do not knowingly sell or share the personal information of consumers under 16 years of age.
Collection Port is not directed at children under the age of 13 (or the applicable age of digital consent in your country). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with information, please contact us at anubys383@gmail.com and we will take steps to address the situation.
We implement reasonable technical measures to protect your locally stored data. Sync credentials are encrypted on your device using Android Keystore and AES. When cloud sync is enabled, data transfers use provider-appropriate encryption — HTTPS/TLS for WebDAV and Google Drive when your server URL uses HTTPS; for FTP and FTPS, encryption depends on your server configuration. The App allows unencrypted HTTP and FTP connections to support self-hosted servers, so you should prefer HTTPS, FTPS, or a trusted local network when possible.
Manual backup files (.cpb) are not encrypted. If you save backups to shared or cloud-accessible locations, their security depends on how you store and protect those files.
The security of remote sync copies depends on the provider and settings you choose. We encourage you to use a device screen lock, keep your Android OS up to date, and protect access to your FTP, WebDAV, or Google accounts.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this document. Continued use of the App after any changes constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.
If you have any questions, requests, or concerns about this Privacy Policy or the App's data practices, please contact us:
Email: anubys383@gmail.com
See also our Legal & Privacy Center and Terms of Service.
This privacy policy was written for the Collection Port Android application distributed via Google Play, including Google Cloud OAuth consent screen verification requirements.