binovy.

Binovy Privacy Notice.

Version 0.6 (alpha) · Effective August 23, 2026

Binovy is operated by Dutchtown Technical Institute, LLC ("DTI", "we"), a Tennessee company. This notice explains what we collect at binovy.com, what's public by design, who processes data for us, and how to reach us. The alpha is offered to users in the United States and is 18+.

Privacy requests: abuse@binovy.com (answered within 30 days).

What we collect

  • Account: email address, password (stored as a hash by our authentication provider — we never see it), display name, and optionally your location and bio.
  • Your catalog: piece records, photos, stories, collections. Photos are sanitized on upload: the file we store and serve carries no embedded metadata, and GPS/location data is destroyed on arrival — never stored, anywhere. Camera metadata that is not location (make, model, lens, capture time) is kept in an internal provenance store, because when a machine's photo record is its history, the camera data is part of that history. It is not publicly accessible and is retained for the life of the record.
  • Community activity: comments, votes, follows, watches, reports you file.
  • Work requests: when you send a repair request to a network shop, the request, the message thread, and any address you explicitly share are visible to the other participant and to binovy's moderation team. Messages cannot be edited or deleted; a shared address can be withdrawn while the request is open.
  • Marketplace activity: bids, simulated checkouts, and (only when real transactions launch) payment and payout records. Card details go directly to Stripe; we never store card numbers. Sellers who onboard complete identity verification (KYC) directly with Stripe.
  • Operational data: session tokens, first-party view counts, server logs, and — once error reporting is enabled — crash reports. We use no third-party analytics, no advertising trackers, and we do not sell personal information. The only browser storage we use is what keeps you signed in.

Public by design

Binovy publishes a collecting record. If you make your profile, collections, or pieces public, they are visible to anyone on the internet. Comments on public pages are public. Realized sale results are a permanent public record. If you delete your account, your catalog and photos are removed, and persistent records (sale results, moderation traces) are pseudonymized — your handle is replaced with a neutral placeholder.

Realized sale results carry the buyer's and the seller's handles unless you turn record identity off in settings. Custody chains and service-log authorship carry handles under the same setting. Costs you record on a piece stay with its record and pass to the piece's next owner; they are never shown publicly.

Who processes data for us

ProviderWhat they handle
Supabaseaccounts and sign-in, database, photo storage
Googleoptional sign-in: we receive your name and email address from your Google account
GitHuboptional sign-in: we receive your name and email address from your GitHub account
Discordoptional sign-in: we receive your name and email address from your Discord account
Stripepayments, and identity verification for sellers
OVHcloudserver hosting
AnthropicAI-assisted listing text — the piece record and the seller's draft story pass through their API when a curator uses the assist; not used by the provider to train models
EasyPostshipping labels and delivery addresses (when shipping is real)
Resendsign-up, account, and auction event emails (outbid, ending soon, won, saved-search alerts); delivery and click metrics are measured
Sentryerror tracking; API error reports carry request metadata, never photo content
YouTube / Vimeoembedded videos, loaded in privacy-enhanced mode

Each receives only what it needs to do its job.

Analytics

Binovy runs first-party analytics, self-hosted on our own server: the page path, the referring site, and a general browser class — never more. There are no cookies, no pixels, and no third parties: no third-party trackers, ever.

Retention and deletion

We keep your data while your account exists and as long as we need it to run the Service or meet legal obligations. To access, correct, or delete your data, email abuse@binovy.com; we respond within 30 days. Deletion follows the pseudonymization rule above for permanent public records. During the alpha, data may also be reset as described in the Terms of Service. Photo provenance follows the record, not the account: it survives account deletion like the other pseudonymized permanent records. Work-request threads and shared addresses follow the job's record, not the account, and freeze when the request closes.

Security

Data is protected with industry-standard measures: transport encryption, row-level access controls in the database, and time-limited signed URLs for photos. No system is perfectly secure; if a breach affects your data, we will notify you as required by law.

Changes

Updates to this notice are effective when posted, with the version and date above. Questions: support@binovy.com.