Skip to content
collapy— home
ProductPricingDocs
Sign inStart free
// legal

Privacy Policy

Last updated: 10 October 2026

Draft — under legal review. This text is not yet final.

This policy explains what personal data we process when you use Collapy — the website at collapy.com, the app at app.collapy.com, the documentation at docs.collapy.com and the Collapy API at api.collapy.com (together, the “Service”) — why we process it and what rights you have. It is written to meet the EU General Data Protection Regulation (GDPR) and Czech data-protection law.

1. Who is responsible

The controller of your personal data is:

Company
Corp42 s.r.o.
Registered office
Petrkov 24, 580 01 Lípa, Czech Republic
Company ID (IČO)
21440808
Registration
Commercial Register kept by the Regional Court in Hradec Králové (Krajský soud v Hradci Králové), file no. C 52743
Managing director
Jan Prokeš
Email
support@collapy.com

For anything related to privacy, write to support@collapy.com. We have not appointed a data protection officer; this address reaches the people who handle privacy requests.

2. What data we process

Account data

  • Your name and email address, and whether your email is verified.
  • Your password, stored only as a salted hash by our hosting provider — we never see it.
  • Optionally: a phone number and an avatar image you upload.
  • Two-factor authentication settings, if you turn them on, and the identity linked to your account if you sign in with Google or GitHub (your name, email address and provider account ID).
  • Sign-in sessions: when and from which device and browser you signed in, and the IP address used, so you and we can see active sessions and keep the account secure.

Organization and workspace content

Everything you and your team create in Collapy: organizations, workspaces, members and their roles, invitations, collections, requests (URLs, parameters, headers, bodies, auth settings), environments and their variables, test scenarios and synced-workspace settings. Secret variable values are stored encrypted. This content may itself contain personal data — for example names or emails in a request body. For that content you or your organization decide what goes in, and we process it on your behalf to run the Service.

Execution history and change log

When a request is sent, Collapy records who sent it, when, the request that went out and the response that came back, so your team can see it. Typed credentials (bearer tokens, basic-auth passwords, API-key values and common credential headers such as Authorization or Cookie) are replaced with <redacted> before the entry is stored, and secret variable values are masked. On the Ultra plan, every saved change to a request is kept in a change log with the author and a snapshot of the request; known credential fields are redacted there too.

Audit log

Privileged actions in an organization — for example member, role and workspace changes — are recorded with the acting user, the action, its target, the time and, where available, the IP address.

Support correspondence

If you email us, we keep the messages and the contact details you send.

Payment data

Paid plans are currently arranged through support. When self-service paid plans launch, payments will be handled by Stripe; we will receive billing details such as your company name, address, VAT ID and the last digits of your card, but never the full card number.

3. Why we process it, and on what legal basis

PurposeDataLegal basis (GDPR)
Creating and running your account, signing you in, two-factor authenticationAccount data, sessionsPerformance of a contract — Art. 6(1)(b)
Providing the Service: storing and syncing workspace content, sending requests, showing historyWorkspace content, execution history, change logPerformance of a contract — Art. 6(1)(b)
Transactional emails: email verification, password reset, invitations, security noticesName, email addressPerformance of a contract — Art. 6(1)(b)
Security, abuse prevention and enforcing plan limits and rate limitsSessions, IP addresses, audit log, usage countsLegitimate interest in a secure, working service — Art. 6(1)(f)
Answering support requestsSupport correspondence, account dataContract — Art. 6(1)(b), or legitimate interest — Art. 6(1)(f)
Billing and accounting (when paid plans launch)Billing details, invoicesContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)
Signing in with Google or GitHubIdentity data from the providerYour choice to use it, under the contract — Art. 6(1)(b); consent where required — Art. 6(1)(a)

Where we rely on consent, you can withdraw it at any time; this doesn’t affect processing that already took place. We do not use your data for advertising, sell it, or make decisions about you based solely on automated processing.

4. Who processes data for us

We use a small number of service providers (processors) that act on our instructions under data-processing agreements:

ProviderWhat forWhere
Appwrite (Appwrite Cloud) Hosting of the Service: database, authentication, file storage, cloud functions and transactional email. All account data and workspace content is stored here. Frankfurt, Germany (EU) — fra.cloud.appwrite.io
Google WorkspaceOur support mailbox (support@collapy.com)EU / per Google’s data-processing terms
Google, GitHubOnly if you choose to sign in with them — they confirm your identity to usPer the provider’s own terms; may involve the USA
StripePayment processing — only once paid plans launchEU / per Stripe’s data-processing terms

Requests you send to third-party APIs from Collapy go to the servers you choose. What those servers do with the data is governed by their operators, not by us.

5. Transfers outside the EU

By default your data is stored and processed in the EU (Frankfurt). We do not transfer it outside the European Economic Area, except where a provider listed above does so under its own terms — for example Google or GitHub when you choose to sign in with them, or Google for support email. Such transfers rely on an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission’s standard contractual clauses.

6. How long we keep data

  • Account data — for as long as your account exists. Account deletion is not self-service yet; ask at support@collapy.com and we will delete your account and the personal data tied to it.
  • Workspace content — until you or your organization delete it, or the organization is deleted.
  • Execution history — a rolling window per organization: the newest 1 000 entries on Free, 10 000 on Pro and 100 000 on Ultra. Older entries are removed automatically.
  • Change log (Ultra) — up to 250 000 entries per organization; removed if the organization leaves Ultra.
  • Audit log — 7 days on Free, 30 days on Pro and 90 days on Ultra.
  • Support emails — as long as needed to handle the request, and then for up to 3 years in case of follow-up questions or claims.
  • Billing records (when paid plans launch) — as long as Czech accounting and tax law requires, currently up to 10 years.

7. Security

  • All traffic to collapy.com, app.collapy.com and api.collapy.com is encrypted (HTTPS).
  • Data is stored in Appwrite Cloud in Frankfurt (EU), with the hosting provider’s storage protections. In addition, these fields are stored in encrypted database columns: request headers, bodies and auth settings; environment variable values and secret variable values; the request and response headers, bodies, parameters and auth settings kept in execution history; change-log snapshots; and test assertion results.
  • Secret variable values are not displayed in the request editor, and are filled in server-side when a request is sent from the web app.
  • Typed credentials are redacted before an execution is stored in history.
  • Access is controlled by organization and workspace roles; you can turn on two-factor authentication for your account.

8. Cookies and local storage

We use one essential cookie: the session cookie set by api.collapy.com when you sign in. It keeps you signed in on collapy.com and app.collapy.com and is strictly necessary for the Service, so it does not require consent. The app also keeps some preferences and unsaved drafts in your browser’s local storage, on your device only.

We use no analytics, no advertising and no tracking cookies or pixels. Fonts are served from our own domain, so loading a page does not send your IP address to a font provider. That is why there is no cookie banner.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • have inaccurate data corrected — most of it you can edit yourself in your profile;
  • have your data erased;
  • restrict processing in certain cases;
  • data portability — receive data you gave us in a structured, machine-readable format;
  • object to processing based on our legitimate interest;
  • withdraw consent where processing is based on consent.

To use any of these rights, write to support@collapy.com from the email address of your account. We answer within one month. For content in a shared organization, we may need to involve the organization’s owner, who controls that content.

10. Complaints

If you believe we handle your data unlawfully, you can lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.gov.cz. You may also contact the authority in the EU country where you live or work. We’d appreciate the chance to sort it out with you first.

11. Children

Collapy is a tool for professionals and is not intended for anyone under 16. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy as the Service changes. The date at the top shows the latest version. For material changes we will notify account holders by email or in the app before they take effect.

13. Contact

Corp42 s.r.o., Petrkov 24, 580 01 Lípa, Czech Republic — support@collapy.com.

© 2026 Corp42 s.r.o.
DocsPricingTermsPrivacyImprintsupport@collapy.com