Privacy Policy
This policy explains what data Collom collects, why, where it is kept and for how long, who else handles it, and the rights you have over it. It covers the cookies and browser storage we use and the companies we rely on. If anything is unclear, write to privacy@collom.io.
1. What this covers
This policy covers the Collom website at collom.io, the Collom app at app.collom.io, our API, and the sites, public pages and forms that people publish with Collom on collom.app or on their own domains. "Collom", "we" and "us" mean the business that runs the service.
It applies to you if you have an account, if you were invited to a workspace, if you visit a site or page published with Collom, or if you answer a form made with Collom.
2. Your account and your workspace are treated differently
For your account data, such as your name, email address and sign-in records, Collom decides how it is used and is the controller. This policy describes that use.
The content of a workspace belongs to the workspace owner: the person who created it, or the organisation they created it for. For personal data inside that content, the workspace owner is the controller and Collom is a processor that handles it on their instructions, under the data processing terms in our Terms of Service. If your question is about what a workspace holds about you, ask its owner first. We will help where Collom itself has to act.
3. Information we collect
We collect what we need to run the service and nothing for advertising.
- Account details: your name, your email address, your password (stored only in hashed form, which cannot be read back) and the date you accepted our terms.
- Sign-in sessions: when you sign in we record the time, your IP address and your browser's user agent, so that a session can be recognised and ended.
- Workspace content: the pages, database rows, comments, mentions and files you and your teammates create, the sites and forms you build, and the settings of the workspace.
- Membership and sharing: which workspaces you belong to, your role in each, the groups and spaces you are in, and what has been shared with you.
- Change records: when you edit, we record who made the change and when, which is what makes live editing, page history and undo work. What each change contained is erased from these records after 30 days.
- Page views inside a workspace: when you open a page we count the view against your account, so that the page's editors can see how many views and readers it has had.
- Audit events: when someone changes members, sharing, publishing, sites, domains, API tokens, connected apps, webhooks or exports, or deletes something for good, we record who did it, when, and from which IP address. Workspace owners and admins can read and download this log.
- API and integration records: the names of API tokens and connected apps (their secrets are stored only as hashes), the addresses of your webhooks, and a log of webhook deliveries.
- Email records: which notification emails you have turned off, and a record of the emails we have sent you.
- Technical data: the IP address and request details that any web server receives, used to deliver pages, to limit the rate of requests and to stop abuse.
- Messages you send us: what you write to our support and other addresses, so that we can answer and keep a record of what was agreed.
We do not ask for payment details, because Collom has no paid plans yet. When it does, card numbers will be handled by a payment provider and will not be stored on our servers, and this policy will be updated first.
4. Information that comes from other people
Other people can put information about you into Collom. A workspace owner or admin can add you as a member or guest. Teammates can mention you, assign things to you and write about you in pages and rows. Someone who runs a form decides what it asks. In each of these cases the workspace owner is responsible for that information, and we hold it for them.
5. How we use information
We use the information above for these purposes and no others.
- To run Collom: signing you in, storing and syncing your workspace, showing each person only what they are allowed to see, searching, exporting, and serving the sites and forms you publish.
- To send service email: password resets, security notices, notices about your exports, domains, tokens and webhooks, and the notifications you have chosen to receive.
- To keep the service safe: limiting the rate of requests, telling people from bots on public forms, investigating abuse, and enforcing our Terms of Service.
- To support you when you write to us, and to fix faults.
- To understand how the service is used in aggregate, from counts such as the number of workspaces, pages and edits. We run no product analytics tool to do this.
- To meet legal obligations and answer lawful requests.
We do not sell personal data. We do not share it for advertising. We do not use your content or your personal data to train AI models, and Collom has no AI features.
6. Legal bases
Where a law such as the Nigeria Data Protection Act (NDPA) or the EU or UK GDPR applies, we rely on these bases.
- Contract: to provide the service you signed up for, including your account, your workspaces and the service email that goes with them.
- Legitimate interests: keeping Collom secure, preventing abuse, limiting request rates, keeping audit records and counting page views in a way that does not identify visitors. We have weighed these against your interests and keep the data involved to a minimum.
- Legal obligation: where the law requires us to keep or disclose something.
- Consent: where we ask for it. You can withdraw it at any time, which does not affect what was done before.
7. Published sites, public pages and forms
If you visit a site or a public page that someone published with Collom, we do not set a cookie and we do not load any third-party tracker. To count views we make a visitor code from your IP address and browser user agent, scrambled with a secret key that includes the date. The code changes every day, cannot be turned back into your IP address, and is not linked to anything else. We store that code, the page, the day and a count. We do not store your IP address, your user agent, the site you came from or your country. The publisher sees totals only.
Your browser also keeps a short note, in session storage, of the pages you have just opened, so that reopening one within 30 minutes is not counted again. It is cleared when you close the tab.
If you answer a form, we store the answers you give and any files you attach, and pass them to the workspace that made the form. Some of your answers may be included in a notification email to the people who run it. We do not store your IP address or your browser details with your answers. Your IP address is used for a couple of minutes to limit how many answers one address can send, and, if you are not signed in, it is sent to Cloudflare with the result of a check that you are a person and not a bot.
The person or organisation that published the site or runs the form decides what is on it and what happens to your answers. They are the controller of that data, and questions about it should go to them. Where a site embeds content from elsewhere, such as a video, that content loads from its own provider.
9. Analytics, advertising and tracking
Collom has no advertising and no advertising cookies. We do not use a third-party analytics tool, session recording, tracking pixels or fingerprinting on our website, in the app or on the sites people publish. The emails we send are built without images or tracking pixels. Fonts and scripts are served from our own servers, not from a third-party network. Because nothing tracks you across sites, there is nothing for a "Do Not Track" or Global Privacy Control signal to switch off.
11. Sub-processors
These companies handle personal data for us. Each is bound by data protection terms, and we remain responsible for what they do with your data.
Railway (Railway Corporation, United States)
- What it does for us
- Runs our servers, databases, search index and file storage.
- Data involved
- Account data, workspace content, uploaded files, and the records described in this policy.
- Where
- The Netherlands.
Cloudflare (Cloudflare, Inc., United States)
- What it does for us
- Runs our DNS, carries traffic for published sites and forms on collom.app and on connected domains, issues their certificates, and runs the person check on public forms.
- Data involved
- IP addresses and requests of visitors to published sites and forms, and the names of connected domains.
- Where
- Cloudflare's global network, at the location nearest the visitor.
Resend (Plus Five Five, Inc., United States)
- What it does for us
- Sends our email.
- Data involved
- The recipient's email address and the content of the email, which can include names, page titles, parts of comments and form answers.
- Where
- Sent from Ireland. Resend may keep records of sent messages in the United States.
| Provider | What it does for us | Data involved | Where |
|---|---|---|---|
| Railway (Railway Corporation, United States) | Runs our servers, databases, search index and file storage. | Account data, workspace content, uploaded files, and the records described in this policy. | The Netherlands. |
| Cloudflare (Cloudflare, Inc., United States) | Runs our DNS, carries traffic for published sites and forms on collom.app and on connected domains, issues their certificates, and runs the person check on public forms. | IP addresses and requests of visitors to published sites and forms, and the names of connected domains. | Cloudflare's global network, at the location nearest the visitor. |
| Resend (Plus Five Five, Inc., United States) | Sends our email. | The recipient's email address and the content of the email, which can include names, page titles, parts of comments and form answers. | Sent from Ireland. Resend may keep records of sent messages in the United States. |
We will update this list, and give notice to workspace owners, before we add or replace a provider that handles personal data. We use no payment provider, no error-reporting service and no analytics provider today.
12. Other services your browser contacts
A few features make your browser fetch something directly from another service. That service receives your IP address, as any website you visit does, and its own privacy policy applies. We send it nothing else.
- Map view: map tiles are loaded from OpenStreetMap.
- Embeds: a video, design, map, post or other embed that someone adds to a page loads from its provider, such as YouTube, Vimeo, Loom, Figma, Google Maps, X, CodePen, Miro, Spotify or GitHub.
- Link previews: when someone pastes a link, our server fetches the page to read its title and description. The preview image is then loaded by your browser from the site it belongs to, without telling that site which page you were on.
13. Where data is kept
We run Collom from Nigeria. Accounts, workspace content, uploaded files and the search index are stored on servers in the Netherlands. Email is sent from Ireland, and our email provider may keep records of sent messages in the United States. Visitors to published sites reach them through Cloudflare's network, at the location nearest to them.
This means your data may be handled in a country other than your own, including countries whose laws protect personal data differently. Where personal data moves between countries, we rely on a safeguard the law recognises, such as standard contractual clauses or the equivalent under the NDPA, so that it keeps the same protection. Write to privacy@collom.io if you want to know more about the safeguard used for a particular transfer.
14. How long we keep data
We keep data for as long as it is needed for the purpose it was collected for. The periods below are the ones in force during early access; where a period depends on a plan, the pricing page shows it.
Account details
- Until your account is deleted.
Sign-in sessions
- They expire 7 days after you last used them, and end at once when you sign out or reset your password.
Workspace content
- Until you delete it, or the workspace is deleted.
Pages in the trash
- 90 days. They are then deleted for good, together with their comments, their history and the files uploaded to them. You can also delete a page for good from the trash at any time.
Page history
- 180 days.
Uploaded files
- Until the page they belong to is deleted for good, or the workspace is deleted.
Change records
- What each change contained is erased after 30 days.
Backups
- Up to 30 days. Deleted data leaves our backups as they expire.
Audit log
- Until the workspace is deleted.
View counts for published pages
- 400 days.
Export files
- 7 days after they are made.
Invitation links
- 7 days. Password reset links last 1 hour and work once.
Webhook delivery log
- Until the webhook is deleted.
IP addresses used for rate limits
- About 2 minutes.
Messages you send us
- While the matter is open, and for up to 2 years after.
| Data | How long we keep it |
|---|---|
| Account details | Until your account is deleted. |
| Sign-in sessions | They expire 7 days after you last used them, and end at once when you sign out or reset your password. |
| Workspace content | Until you delete it, or the workspace is deleted. |
| Pages in the trash | 90 days. They are then deleted for good, together with their comments, their history and the files uploaded to them. You can also delete a page for good from the trash at any time. |
| Page history | 180 days. |
| Uploaded files | Until the page they belong to is deleted for good, or the workspace is deleted. |
| Change records | What each change contained is erased after 30 days. |
| Backups | Up to 30 days. Deleted data leaves our backups as they expire. |
| Audit log | Until the workspace is deleted. |
| View counts for published pages | 400 days. |
| Export files | 7 days after they are made. |
| Invitation links | 7 days. Password reset links last 1 hour and work once. |
| Webhook delivery log | Until the webhook is deleted. |
| IP addresses used for rate limits | About 2 minutes. |
| Messages you send us | While the matter is open, and for up to 2 years after. |
Deleting a workspace is immediate and cannot be undone. Its pages, rows, files, exports, search entries and records are removed straight away, and its sites and domains are disconnected. The accounts of its members are not deleted with it.
You can ask for your account to be deleted from Settings, under Your account. A member of our team reviews every request and completes it within 30 days, and you can cancel until then. Your account, your private pages and any workspace that only you are in are then deleted for good. What you wrote in workspaces you share with other people stays with those workspaces, and their owners can remove it.
We may keep a record for longer where the law requires it, or where we need it to establish or defend a legal claim. That includes a note that a deletion request was carried out.
15. Security
We design Collom to protect your data, and these measures are in place today.
- All traffic is encrypted in transit with TLS 1.2 or later, and browsers are told to use HTTPS only.
- Passwords are stored only in hashed form. Nobody at Collom can read your password.
- The session cookie cannot be read by scripts. Resetting your password signs you out everywhere.
- API tokens and the secrets of connected apps are shown once and stored only as hashes. Webhook deliveries are signed so that the receiver can check they came from us.
- Access rules are enforced on our servers wherever content is read, including search, the API and exports, so that people only see what has been shared with them.
- Our database is backed up every day, so that we can restore the service after a failure.
- Our internal tools are separate from customer accounts, limited to the team members who need them, and every action taken in them is logged.
No system is perfectly secure, and we cannot promise that yours will never be reached by someone it should not be. Use a password you use nowhere else. If you find a weakness, write to security@collom.io.
16. Who at Collom can see your data
To support you, our team can see your account details (your name, your email address, when and from where you signed in, and the workspaces you belong to) and information about a workspace, such as its members, sites, domains, plan and usage. These tools do not show the content of your pages, your password, or any token or secret. Everything our team does with them is logged.
A small number of people who operate our systems are able to reach stored data. They do so only when it is needed to keep the service running, to investigate a fault or a report of abuse, or because the law requires it, and they are bound by a duty of confidentiality.
17. Emails we send
We send two kinds of email. Service email is part of running your account: password resets and changes, export notices, confirmation of a request to delete your account, and notices to owners and admins about tokens, connected apps, domains and webhooks. It cannot be turned off.
Notification email tells you about mentions, replies, reminders and, if you asked for it, new answers to a form. Every one has a link to stop that kind of email or all of them for that workspace, and you can change the same settings under Activity in the app.
We send no marketing email and no newsletter. If that ever changes, it will be opt-in.
18. Your rights
Depending on where you live, including under the NDPA in Nigeria and the GDPR in the EU and the UK, you have the right to:
- Know what personal data we hold about you and get a copy of it.
- Take your data with you. You can export pages and databases as Markdown, HTML, CSV or PDF from the app at any time.
- Have data that is wrong or incomplete corrected.
- Have your data deleted, subject to the periods above. You can ask for your account to be deleted from Settings.
- Object to processing that rests on our legitimate interests, or ask us to restrict it.
- Withdraw consent where processing rests on it.
- Not be subject to a decision made only by automated means that significantly affects you. We make no such decisions.
- Complain to a data protection authority, such as the Nigeria Data Protection Commission, the UK Information Commissioner's Office, or the authority in the EU country where you live.
To use any of these rights, write to privacy@collom.io from your account's email address. We answer within 30 days, or sooner where your law says so, and we do not charge for a reasonable request. We may need to confirm who you are first.
If your request is about the content of a workspace that someone else owns, we will pass it to the workspace owner, because they decide what happens to that data.
We do not sell personal data or share it for advertising, in any sense those words have under laws such as the California Consumer Privacy Act, and we will not treat you differently for using your rights.
19. Children
Collom accounts are for adults. You must be at least 18, or the age of legal majority where you live, to have one, and Collom is not directed at children. We do not knowingly collect personal data from children. If you believe a child has given us personal data, write to privacy@collom.io and we will delete it.
20. If something goes wrong
If we learn of a breach of personal data that is likely to put you at risk, we will tell you and the relevant authority without undue delay, within the time your law sets. We will say what happened, what data was involved, what we have done about it and what you can do. Workspace owners are told about any breach that affects their workspace, so that they can meet their own duties.
21. Changes to this policy
We may update this policy as Collom changes. For a change that matters, we will give notice in the app or by email before it takes effect, and the date at the foot of this page will change.
22. Contact
For questions, requests or complaints about privacy, write to privacy@collom.io. For security problems, write to security@collom.io. For anything else, write to support@collom.io. If you are not satisfied with our answer, you can go to your data protection authority.
Last updated 3 October 2026.