Privacy Policy

Effective date: March 1, 2026

HeroBase (“we”, “our”, “us”) is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights as a user.

1. Data We Collect

Account data: When you create an account, we collect your email address and, if you sign in with Google, your name and profile photo. You may also add a display name, username, bio, and avatar.

Collection data: Comics you add to your Arsenal (condition, purchase price, purchase date, notes), your Hunt wishlist (max price, priority), and scan history (which comics you've scanned, when, and whether they were cache hits).

Usage data: Standard server logs including IP addresses and request timestamps for security and performance purposes. We do not use third-party analytics trackers.

2. How We Use Your Data

We use your data to deliver the HeroBase service: authenticating you, storing and displaying your collection, generating AI valuations, and showing you relevant recommendations. We use aggregated, anonymized data (e.g., average purchase prices by condition) to power Community Prices — your individual prices are never exposed to other users.

3. What We Share

We do not sell your data. We do not share your personal information with third parties for their marketing purposes. Your public Collector ID profile (display name, username, bio, public collection) is visible to anyone with the link — you control what appears there. Community Prices are aggregated from multiple users and never attribute prices to individuals.

We use Anthropic's Claude API to process comic cover images you upload during scanning. Uploaded images are processed and then stored in your account. Refer to Anthropic's privacy policy for how they handle API inputs.

4. Data Storage

Your data is stored in Supabase (PostgreSQL database and file storage), hosted in the United States and/or European Union. We use Supabase's Row Level Security to ensure your collection data is only accessible by you.

5. Your Rights

Export: You can download a CSV of your entire collection at any time from Control Panel → Export Collection.

Deletion: You can request account deletion by emailing privacy@herobasehq.com. We will delete your account and all personal data within 30 days. Anonymized aggregate data (e.g., community price contributions with no identifying information) may be retained.

Correction: You can update your profile information at any time from your Collector ID page.

6. Cookies

HeroBase uses only essential cookies required for authentication (session tokens). We do not use advertising cookies or third-party tracking cookies.

7. Children's Privacy

HeroBase is not directed at children under 13. We do not knowingly collect data from children under 13.

8. Changes to This Policy

We may update this policy from time to time. We'll notify you of significant changes by email or via an in-app notice.

9. Contact

Questions about this policy? Email us at privacy@herobasehq.com.