← Home
CHOIL · PRIVACY

Privacy.

Last updated September 2026

The short version

CHOIL, operated by Airglow LLC (Kansas), is a private vault for your collection. We store what you put in it, use it only to run the app, never sell it, and let you delete it. We don't run ad trackers.

What we collect

  • Account: your email and/or mobile number, used only for passwordless sign-in and notifications you opt into.
  • Your collection: the items, specs, prices, notes, photos, and receipts you add. Receipts use private storage; owner access is required to generate a short-lived signed link. Anyone holding that link can open it until it expires.
  • Profile: handle, display name, bio, and avatar you choose to share with friends.
  • Creator video engagement. When you open a video in CHOIL, we count the open against your account and that video, including first and most recent open times and whether it was on web or mobile. Only CHOIL admins can see member-level counts. Deleting your account removes those member-level records; anonymous totals remain. We also estimate foreground playback seconds within CHOIL and count playback sessions, using player progress and state. Paused, buffering, background, and skipped time are excluded. Session identifiers prevent duplicate counts. These are CHOIL measurements, not YouTube Analytics; we cannot measure viewing after you leave CHOIL. We may share aggregate results with creators, without member identities.
  • Security log: we record security, admin, and destructive events (logins, role changes, deletions, exports) with a truncated IP address (part of the address removed) and device string. Our cleanup process is configured to remove activity entries older than 90 days. We do not keep a general browsing history.

YouTube and your optional Google connection

CHOIL uses YouTube API Services for creator and video information, wheel comments, and live chat. Embedded YouTube players serve content from Google, which may include advertisements and collect device, browser, and playback information under the Google Privacy Policy.

If you choose to connect YouTube, Google asks for permission. We receive your YouTube channel ID and title and authorization tokens, and store the connection with your CHOIL account on our server. We do not receive your Google password. We use this connection to identify the channel you are acting as and to like a video or subscribe to a channel only when you choose that action. We check whether you already subscribe before adding a subscription. Comments open on YouTube.

Google receives the video or channel identifier and the action you request. Supabase stores the connection and Vercel processes these requests for CHOIL; Google tokens are not sent to your browser or app. We do not sell this Google user data, use it for advertising, or send it to AI models. Our use and transfer of Google user data is subject to the Google API Services User Data Policy, including its Limited Use requirements.

The connection is retained to provide the actions you authorize. When you check your connection, we refresh channel details that are at least a day old. Our daily cleanup removes channel details that have not been refreshed for 29 days; checking the connection or requesting an action also clears expired details. This cleanup preserves your authorization token so you can keep using the connection. To remove the stored channel details and authorization token without deleting your CHOIL account, open Manage YouTube connection and choose Disconnect YouTube. This deletes the connection from CHOIL and attempts to revoke access with Google. If Google cannot confirm revocation, we show a link to finish in your Google account. You can also revoke access directly through Google account permissions. Successful CHOIL account deletion removes the stored connection too. Disconnecting does not remove likes or subscriptions from YouTube; manage those on YouTube. For deletion help or privacy questions, contact support@choil.app.

YouTube giveaway claims

Selected winners can verify control of the winning YouTube channel through Google with read-only access. Guests do not need a CHOIL account; guest Google tokens are discarded after verification. Members may save a connection for later wins and remove it in Settings.

The giveaway creator sees the selected channel and claim status. Shipping details and tracking are available to that creator and the verified claimant, and CHOIL removes them 90 days after the first claim submission. CHOIL retains prize and fulfillment history after removing personal details. YouTube identity from a draw expires after 29 days of its original retrieval, which also closes verification for that selection. Hourly cleanup removes expired data; opening a claim page also runs cleanup.

Use “Delete my claim details” on the claim page in the browser used to verify, or contact support@choil.app if you no longer have access. Deletion closes the claim and may prevent delivery. Removing a member’s YouTube connection closes its existing claims and removes the associated YouTube identity; deleting the CHOIL account also removes its shipping details. A browser cookie permits claim access for one day and deletion for up to 90 days. Creators may retain information already received outside CHOIL; contact the creator about those copies.

AI processing

AI features, including valuation, photo identification, spreadsheet import, and collection questions, send relevant inputs to models through Vercel AI Gateway. Inputs can include item details, spreadsheet cells, questions, and photos, depending on the feature. Photo identification also sends image data to Google Cloud Vertex AI to compare images and to Google Cloud Vision for web matching. Uploaded collection photos may also be processed by Google Cloud in the background to prepare visual matches for your own collection. The optional setting below controls reference use for other members. CHOIL does not train AI models on your private collection. Vercel states that its gateway does not use prompts or responses for training; upstream providers have separate processing and retention terms. Google Cloud's terms prohibit training on customer data without permission or instruction. These are distinct from a promise that providers retain nothing. See Vercel's data-use documentation and Google Cloud's service terms. Helping identification is opt-in. In Settings you can choose to let your item photos — with only the make and model you recorded — serve as visual reference when CHOIL identifies a photo, which makes identification better for every member. Nothing else goes with them: no name, handle, notes, prices, or values, and this reference feature does not publish or sell them or use them to train models. It's off unless you turn it on, and switching it off stops the use.

Product facts you enter about an item — such as steel, blade length, movement or case size, never prices, notes, condition, serials or photos — may be combined with other members' entries to improve CHOIL's shared reference catalog. No member is identified.

Where data is processed

Our primary database is hosted in Supabase's US East region in the United States. Our hosting, communication, payment, diagnostic, and AI providers may process data in other countries. CHOIL does not guarantee US-only processing or storage across every provider.

If you use the Snipe browser extension

Snipe is our optional browser extension that shows live market value while you watch knife and EDC auctions on Whatnot, browse eBay item pages, or ask it about an item on any other page. It runs entirely in your own browser:
  • What it reads: the current lot or listing's title and price from the page you're viewing, sent to CHOIL only to look up a valuation. It never places bids or acts on your behalf.
  • On any other page: nothing happens until you open Snipe on it yourself — "Snipe value" from the right-click menu, "Snipe this page" in the toolbar popup, or the keyboard shortcut. From then on, that page's overlay works from what you selected — and, to name the item when you selected nothing or asked it to identify from the screen, it also reads the page's title, and on YouTube the video's description and how far into the video you are (knife channels list each knife against a timestamp, which beats guessing from a blurry frame). Whatever it settles on is sent to CHOIL as the item to identify and price.
  • Sold prices from your eBay session: eBay shows sold listings only to signed-in shoppers, so when you run a value check Snipe asks eBay for the matching sold results from your own browser, using the eBay session you are already signed in to. Your eBay password and cookies stay in your browser and are never sent to CHOIL. What we receive is the search title it started from, the search terms it built, the time of the fetch, and each sold row's title, price, currency, sold date, link and condition where eBay shows one. This happens once per value check you asked for, on the item in front of you — Snipe does not crawl eBay, run searches you did not ask for, or fetch anything while you are idle.
  • What we do with those rows: we store them against your own account and use them in your price checks for that item. Because they come from a session only you are signed in to, we cannot verify them for anyone else, so they are not shared with other members and do not become part of CHOIL's pooled market data.
  • Screen captures: only when you click "Check prices" and confirm a region, it captures that selected area and sends it with relevant on-screen item text to our identification feature. Captures are processed in the moment and not retained.
  • Messages in the overlay: for members, the overlay carries a small inbox. On Whatnot and on the right-click overlay it fetches your own conversation list — who you're talking to, unread counts, and a short preview of the last message — to keep the unread badge current, refreshing roughly every 45 seconds while the tab is visible and no conversation is open. The eBay overlay does not fetch it. Full message text is fetched only for a conversation you open.
  • How it signs in: a revocable token you generate from your CHOIL account — not your password or cookies. Revoke it anytime from your account.
  • What it stores on your device: that token, the overlay's position, your preferred capture-box dimensions, and the text you last selected for a "Snipe value" lookup, in the browser's local extension storage. That selection is written when you right-click so the overlay can read it, and it stays there afterwards — replaced by the next "Snipe value", and gone when you clear the extension's storage or remove the extension.
Snipe is an independent buyer's tool and is not affiliated with Whatnot or eBay.

Cookies

CHOIL uses first-party cookies for sign-in and secure account connections, including a short-lived cookie when you connect YouTube. CHOIL does not set advertising trackers. Embedded third-party content, including YouTube players, may access cookies or similar device storage under that provider's privacy policy.

Sharing

Your profile starts private. Public profiles, item links, listings, community posts, wishlists, and comparisons each have their own sharing controls. Collection photos, message images, and avatars use public image URLs; anyone with a URL can view the image, even if the associated profile or collection is private. Receipts use private storage and expiring links. See how we secure your data. We use processors to run the service, including Supabase (database/auth/storage), Vercel (hosting/AI gateway), Resend (email), Telnyx (SMS), Stripe (web payments), RevenueCat (mobile purchase management), Sentry (error diagnostics), and Linear (support and error tracking).

Your control

Edit or delete any item anytime — and you don't have to delete your account to remove data; see choil.app/data-deletion. Export your whole collection to CSV from the vault. Sign out of all devices from Settings. To delete your account and everything in it, use Settings → Delete account in the app, go to choil.app/account/delete, or contact us from the support page.

Contact

Questions about your data? Reach us via the support page or at support@choil.app.

CHOIL · operated by Airglow LLC (Kansas) · choil.app