Privacy Policy

Effective Date: July 7, 2026

1. OUR PRIVACY PHILOSOPHY

At Collective Community Fund (CCF), we believe in Data Minimization. Our business model is built on utilizing idle device utility, not your personal identity. We do not sell your personal data because we do not collect it.

2. DATA WE COLLECT

CCF operates without accounts, logins, or personal profiles. The complete list of data associated with your use of the app is:

Anonymous device identifier: A random identifier generated on your device at first launch. It is not derived from your hardware, is never linked to your identity, and is used only to record your consent choices and contribution sessions.

IP address (only while Web Indexing is enabled): If you choose to enable Web Indexing, the Bright SDK uses your device's internet connection and IP address to download public web data. Your IP address is the only data Bright Data collects; it is not linked to your identity, and Bright Data does not track you.

Contribution session records: The duration and estimated contribution value of each session you run, keyed to your anonymous device identifier, so the app can show your impact.

Contact details you volunteer: If you use the Contact or Feedback forms, you may optionally include your name and email address so we can reply. These are used only to respond to you and are never linked to your device's contribution activity.

3. DATA WE DO NOT COLLECT

CCF does not access, collect, or store the following: Private files, photos, or videos. Personal messages, emails, or contacts. Browsing history. Biometric or health information. Your name, email address, or any personally identifiable information — except any name or email address you voluntarily provide through our Contact or Feedback forms.

4. THIRD-PARTY INFRASTRUCTURE PARTNERS

To facilitate the CCF mission, we integrate specialized third-party tools. Your use of the app is subject to their respective privacy practices.

Network Resource Sharing — Bright SDK: CCF utilizes the Bright SDK to share your device's idle internet bandwidth and IP address for public web indexing. This data is used strictly for technical resource aggregation and is not linked to your personal identity. Bright Data is fully GDPR and CCPA compliant.

Disbursement Processing — Mercury: All financial allocations are routed programmatically via Mercury directly to verified 501(c)(3) organizations. CCF does not hold, collect, or transmit financial data on your behalf.

NGO Discovery — Every.org: CCF uses Every.org exclusively to discover and verify recipient organizations. Every.org does not process payments or receive user data.

Impact Metrics: The My Impact screen displays contribution statistics computed entirely within the CCF system — your device's anonymous session totals (sessions completed, time contributed, estimated amounts generated) and community-level initiative totals. No third-party content or data source is used to produce this screen, and no user data is shared to display it.

5. USER CONTROL AND OPT-OUT

You are in total control of your contribution.

Explicit Opt-In: No network sharing occurs unless you enable Web Indexing and agree on Bright Data's consent screen.

Immediate Opt-Out: You may opt out of the Bright SDK at any time by disabling Web Indexing in the Settings menu. Upon opting out, all third-party SDK activity ceases immediately. Your anonymous device identifier is retained in our system solely to prevent duplicate consent records.

6. CHILDREN'S PRIVACY

CCF is not directed to children under 13, and we do not knowingly collect personal information from anyone, including children. The app requires no account, name, or email. On devices where iOS parental controls are enabled, the Web Indexing consent screen is not displayed and participation in the Bright Data network is not possible, by design. If you believe a child has used the app in a way that concerns you, contact privacy@collectivecommunityfund.com.

7. COMPLIANCE

CCF is designed to meet the standards of the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). As we do not store personal identifiers, we provide Privacy by Design.

8. CONTACT

For privacy-related inquiries contact: