BrickLens
Privacy Policy
What we collect, why, and what we never do with it.
The short versionWhat we collectHow we use itWho sees itAI & trainingRetentionYour rightsCookiesSecurityChildren
The short version
- Your collection, scans, photos, prices and notes are private to you unless you choose to share something.
- We never sell your data and we show no ads.
- Scan photos and your corrections help us improve identification. You can opt out.
- Delete your account any time; it wipes your data from our systems.
1. What we collect
Account
Email address, first name, and a hashed password (we never store the password itself). If you sign in with Google: your Google account email, name and Google user ID. Sign-in sessions, and for the mobile app an API token that lets the app act as you.
Scans and photos
Photos you take or upload to identify a figure, and photos you attach to items in your collection. The result of each scan (figure, confidence, price at the time, processing time) is stored with your account as scan history.
Collection data
Figures and sets you add, quantity, condition, what you paid and when, condition-grading answers, notes, wishlist items and target prices, and sales you record (price, venue, date).
Preferences
Onboarding answers: themes you collect, how you describe yourself as a collector, rough collection size, where you buy and sell.
Feedback
When you tap "Not it?" or choose a different candidate, we store that correction linked to the scan.
Technical
IP address, device and browser type, and request logs, kept by our hosting platform for security, rate limiting and debugging. If you accept the cookie banner on the website, an anonymous visitor identifier is set to count visits (see Cookies).
What we don't collect
No precise location, no contacts, no advertising identifiers, no payment details (BrickLens is free), and no data from other apps on your device.
2. How we use it
- To run the Service: identify your photos, show prices and insights, keep your collection, sign you in.
- To improve identification: scan photos and corrections are used to evaluate and retrain our models (Section 4).
- To personalize: your themes order Search suggestions and shape insights.
- To communicate: account emails (sign-in, security, deletion confirmation).
- To protect the Service: abuse detection, rate limiting and security.
Our legal bases, where they apply: performance of our contract with you (running the Service), our legitimate interests (security, improving identification, personalization you'd reasonably expect), and consent (the analytics cookie), which you can withdraw at any time.
3. Who sees it
- No one, by default. Your collection, scans, notes, photos, prices paid and sales are private to your account. Sharing is opt-in: a share card or a figure-page link is visible to whoever you send it to. Figure pages show the figure and market data, never your collection or identity.
- Service providers acting on our instructions: our hosting and database platform (Benmore, which we operate), Amazon Web Services (United States) for the identification model, cloud object storage for uploaded photos, and an email delivery provider for account messages.
- Data sources we query (BrickLink, Rebrickable) receive the figure or set identifier we're looking up, never your identity.
- Legal and safety. We may disclose data when required by law, to enforce our Terms, or to protect the rights and safety of users and the Service. If Incognito Productions LLC is acquired or the Service changes hands, your data may transfer to the successor under this policy.
4. AI and model training
BrickLens matches your photo against a catalog of figures using computer-vision models we operate ourselves. Your photos are not sent to any third-party AI service. Scan photos and your corrections may be used to evaluate and retrain those models so identification improves for everyone. Training happens within our own systems; photos used for training are not shared with third parties or used for anything else. To opt out, email [email protected] from your account address and we will exclude your account within 30 days, or simply delete the scans you don't want used.
5. Retention and deletion
- Account and collection data are kept while your account exists.
- Delete your account from Profile → Danger zone → Delete my account. This immediately deletes your scans, feedback, collection, wishlist, sales, value snapshots, API tokens and preferences from our database and anonymizes your account record. Uploaded photos are unlinked immediately and purged from storage within 30 days.
- Routine backups roll off within 30 days.
- Aggregated, de-identified statistics (for example how often a figure is scanned) may be kept indefinitely.
- Security logs are retained for a limited period by our hosting platform and then deleted.
6. Your rights
Wherever you live, you can access, correct, export, delete and object to processing of your data. Export: Collection → Export CSV. Delete: Profile → Delete my account. Anything else, including access requests, correction, opting out of model training or withdrawing consent: email [email protected] and we will respond within 30 days. We'll verify requests using the email on your account.
EU, UK and Switzerland: you also have the right to data portability, restriction, and to lodge a complaint with your local supervisory authority. California: we do not sell or "share" personal information as those terms are defined in the CCPA/CPRA, and we don't use it for cross-context behavioral advertising; you may exercise your rights above and we will not discriminate against you for doing so. Do Not Track: we don't track you across other sites, so there is nothing to disable.
7. Cookies and local storage
- Essential: a session cookie keeps you signed in and a CSRF token protects forms. These are required for the site to work.
- Analytics (optional): if you accept the banner, an anonymous first-party visitor cookie counts page views and session length. It contains no personal data, and there are no third-party trackers.
- Local storage on your device remembers small conveniences, such as that you've completed onboarding or your theme preferences for search. The mobile app keeps your sign-in token in the device's secure keychain.
8. Security
All traffic is encrypted in transit (HTTPS). Passwords are hashed. Access to production systems is restricted to the operator and protected by keys and IP allow-listing. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the relevant authorities as the law requires.
9. International transfers
Our servers are in the United States. If you use BrickLens from elsewhere, your data is transferred to and processed in the US. Where the law requires safeguards for such transfers, we rely on standard contractual clauses with our providers and on your consent to this policy.
10. Children
BrickLens is not directed to children under 13 and we don't knowingly collect their personal data. If you believe a child has created an account, email [email protected] and we will delete it.
11. Changes to this policy
We'll post updates here with a new effective date and, for material changes, notify you in the app or by email before they take effect.
12. Contact
Incognito Productions LLC · [email protected]