CollectorBucket
YOUR COLLECTION, YOUR SPACE

Privacy & your photos.

CollectorBucket is an early version of a collection notebook with optional discovery. Here’s how this version works.

Your items start private.

Personal collection records and photos are associated with your signed-in account. New uploads are private. After its photos pass screening or a moderator approves it, and you review the details, you can choose “Show this find in Discover.” Shared items expose only their photos, name, category, material, dimensions, condition, public story, city, and country. Purchase cost, storage location, private notes, account identifier, and email are never included in discovery. Shared finds are visible to people who can access CollectorBucket under the site’s audience settings. Turn sharing off to remove an item and its photos from discovery and its find page. People who already copied or downloaded a shared photo may retain their copy. Example finds contain invented objects and locations, clearly labeled as illustrative.

Places and browsing.

City and country are entered by you; image recognition does not infer a location from a photo. “My area” is an optional preference stored on your device for browsing and prefilling your own uploads. No GPS or exact address is requested. Choosing a different country or worldwide browsing is always available.

Saved finds.

Your shortlist stores only find identifiers on this device, without sign-in or a copy of anyone’s private records. It does not sync between devices. Shared finds are checked again when you open Saved; a find made private or held for review is omitted. Illustrative examples remain labeled. Clearing browser storage removes the shortlist.

Sign-in and storage.

Sign-in is provided by ChatGPT. The app receives your account identifier and email from the hosting platform so it can connect you to your own records. Collection details are stored in Cloudflare D1; uploaded images are stored in Cloudflare R2. The app uses your account identifier to check access to each record and photo. Email is used in the current request for administrator authorization; the app stores your email only if you opt in to message copies, and removes it when you opt out. It does not store a password. A display name supplied by ChatGPT is optional. Sign-in methods are controlled by ChatGPT; this version has no independent passkey registration.

Uploaded photos.

This version accepts JPG, PNG, and WebP. Your browser resizes photos to a maximum dimension of 1,400 pixels and saves a JPEG copy for upload. This removes embedded metadata such as camera location, but anything visible in the image remains visible. Keep your original full-resolution photos elsewhere.

Background cleanup.

AI cleanup is enabled for new photos by default. A self-hosted U²-Net-p model runs on your device to separate the object from its background. Preview the result before saving and turn cleanup off if it removes glass, fine edges or useful details. Cleanup does not generate a new object or retouch its marks and wear, but segmentation can remove parts by mistake. The resized original and any cleaned copy are both stored; use Photo & community preferences to restore originals. Existing uploads are not automatically changed. If cleanup cannot run, the original is kept. Both original and cleaned photos are screened before sharing. Removing a photo removes both copies.

Automatic screening and suggestions.

Every uploaded photo, including additional views, is submitted for automatic screening. When the same photo or text was checked for your account within the last 30 days, its cached screening summary may be reused. Otherwise it is sent to a Cloudflare Workers AI model to check for inappropriate content, relevance to collectible objects, and recognition confidence. The system suggests a name and category and may request an additional view. There is no switch to skip screening. Potentially inappropriate photos are blocked before storage. Uncertain, unrecognized, unrelated, or unavailable screening results keep a record private for moderator review. Checks can miss content or flag acceptable photos; they are not a guarantee of safety or authenticity.

Moderator access and comments.

The site administrator can review flagged private photos and public item details, approve or reject finds and comments, ask for better photos, and resolve reports. The review desk does not expose purchase costs, private storage locations, or private collection notes. A decision log records review actions and blocked attempts; images from blocked new uploads are not retained.

Comments require sign-in, automatic text screening, and moderator approval before others see them. Your chosen display name appears publicly, but your email and account identifier do not. Pending comments are visible to you and the administrator. You can remove your comment. Reports and daily limits help reduce abuse. Public text is screened before a find is shared. Comments disappear from public view if a find is unshared or held for review.

Cloudflare’s handling of inference data is described in its Workers AI data-usage documentation.

Votes and private contact.

Collectors can disable comments, votes, or private contact requests for each find. Voting requires sign-in; one vote is allowed per account per find, and collectors cannot vote for their own finds. Only approved, shared finds accept new activity.

Contact requests and replies stay in the platform inbox. Your chosen display name is visible to the other participant; your email and account identifier are not. A collector must accept a new contact request before replies can be sent. Messages are screened, links and personal contact details are refused, and uncertain messages wait for administrator review. Participants can block and report messages. Administrators can see flagged or reported message text, and review actions are logged. Limits allow three new contact requests and 30 messages per account per day; a short-term limit also applies.

Email copies are optional and off by default. When a verified sending service is connected and you opt in, approved messages can be sent to the email supplied by ChatGPT, up to ten copies a day. You can opt out in Inbox or through an email unsubscribe link. Bounces and spam complaints turn copies off. Email delivery and inbox placement depend on the recipient provider and are not guaranteed. Message threads remain after a find is removed so participants can retain their conversation; the removed find no longer accepts new contacts.

Export and removal.

Export records to download your item details as JSON. Images are not embedded; download them individually from each item. Open My collection and choose a find. “Remove photo” deletes the selected image when the find has more than one photo; the remaining find becomes private until you choose to share it again. “Remove find” deletes the stored record and all of its uploaded images. A confirmation appears before deletion. To delete the last photo, remove the find. If storage removal is interrupted, “Retry photo removal” completes it from My collection. Derived screening summaries and content fingerprints in the screening cache expire after 30 days; cached summaries do not contain the uploaded image or submitted text itself. Review decision logs may remain. You can remove all your items this way. This version does not offer a separate account-deletion workflow.

Early-version limits.

Up to eight photos can be added at a time, with up to 500 saved photos per account. If connected, photo screening is limited to 30 submissions per account per day. The site also has a shared daily automatic-checking allowance of 100 units: a new photo check uses four, and a new text check uses one. Cached summaries use no units. The administrator can pause new automatic checks. This is a usage guardrail, not a promise of unlimited free service; hosting, storage, and provider allowances still apply. Rechecking an existing find is limited to three attempts per item; additional photo submissions use the daily allowance. New comments and reports are each limited to 20 per account per day. If screening is unavailable or its limit is reached, photos may be saved privately for moderator review and cannot be shared until cleared. Keep your own backups of important records and original images.

Back to your collection