Privacy Policy of the Stitchy Application
This document is a courtesy translation. In case of any discrepancy between the English and Russian versions, the Russian version available at https://stitchy.alexforge.org/legal/privacy/ prevails.
In Brief
The Stitchy App creates cross-stitch Patterns. A Pattern is built from your photograph directly on the Device: the picture is processed in the phone's memory, is not sent anywhere and is not saved even in the App itself.
An Account is not required. Without one, the App is fully functional and all data stays on the Device. If you sign in with your email address, your Works will be synchronized between your own Devices — only yours; they are not visible to other Users.
The App collects depersonalized statistics about its operation and crashes so that we can see errors and understand which features are needed. Neither photographs nor Patterns end up in these statistics.
We do not sell data, do not share it with advertising networks and do not show ads.
1. General Provisions
1.1. This Privacy Policy (hereinafter the "Policy") describes what data is processed in the Stitchy mobile application (hereinafter the "App"), for what purposes, how long it is stored, to whom it is transferred and how the User can manage it, including deleting it.
1.2. By installing and using the App, you agree to the terms of this Policy. If you do not agree with the Policy — do not use the App.
1.3. This Policy applies together with the User Agreement of the App, published in the same place where this Policy is published.
1.4. Personal data is processed in accordance with Federal Law of 27.07.2006 No. 152-FZ "On Personal Data", as well as the requirements of the distribution platforms (RuStore, Google Play, App Store).
2. Terms
- Personal data — any information relating to a directly or indirectly identified User of the App.
- Data processing — any operations with data: collection, recording, storage, modification, use, transfer, deletion.
- User — a natural person using the App.
- Device — a smartphone or tablet on which the App is installed.
- Operator — the person organizing the processing of data; identified in section 19.
- Account — a profile of the User on the Operator's server, created upon signing in with an email address.
- On-device processing — computations performed by the processor of the Device whose results do not leave the Device.
3. How Data Processing Is Organized
3.1. The App divides processing into two parts.
On the Device, everything that makes up the core functionality is performed: creating a Pattern from a photograph, stitching mode, progress counting, calculation of thread consumption and the shopping list. These computations do not require a network connection, and their results stay on the Device.
On the server, only what is necessary for the Account and for synchronizing Works between the User's Devices is processed (section 6), as well as depersonalized statistics about the App's operation (section 7).
3.2. An Account is not required. Without signing in, the App retains full functionality, and the User's data does not leave the Device.
3.3. The User's photographs are not processed on the server under any circumstances — see section 5.
4. Data Processed on the Device
4.1. Data that you enter or create yourself:
- the name specified in the profile (filled in optionally, may be skipped);
- the profile image, if you have chosen one;
- the titles of your Works;
- the generated embroidery Patterns, the marks of stitched crosses and the progress associated with them;
- the preview image of the finished Pattern, created by the App;
- statistics: the number of completed Works, the number of stitched crosses, time spent in stitching mode;
- settings: interface language, units of measurement, default thread manufacturer;
- a service identifier of the local profile, generated randomly and not linked to your identity, Device or advertising identifiers.
4.2. Without an Account, the data listed above does not leave the Device and is not accessible to the Operator. The only exception is the random service identifier of the profile: it is included in the depersonalized statistics to distinguish one installation of the App from another (section 7). When an Account is used, the data is synchronized under the terms of section 6.
5. Photographs
5.1. To create a Pattern, the App requests access to the camera or to the media library — only at the moment when you yourself choose the image source.
5.2. The selected photograph is processed in the RAM of the Device. Building the Pattern — dividing the image into cells and matching embroidery floss colors — is performed by the processor of the Device.
5.3. The original photograph selected for building a Pattern is not saved by the App: only the generated Pattern and its preview remain in the finished Work.
5.4. The App does not read the media library as a whole, does not index it and does not access photographs that you have not selected.
5.5. Photographs from which Patterns are built are not transferred to the Operator or third parties. Server-side processing of such images is not provided for.
5.6. The camera and photo permissions can be revoked at any time in the Device settings; in that case only the creation of a new Pattern and changing the profile image will stop working.
6. Account and Synchronization
6.1. Signing in to the App is performed with an email address confirmed by a one-time code. No password is used.
6.2. When an Account is used, the following is processed:
- the email address — for signing in, identifying the Account and contacting the User;
- the profile name and image — if the User has provided them;
- the Works created by the User: Patterns, stitching progress, statistics and settings — for synchronization between the User's Devices;
- the date and time of creation and modification of records — for resolving conflicts during synchronization;
- technical information about requests to the server (IP address, versions of the operating system and the App), recorded in server logs for security and diagnostics.
6.3. An Account is not required: without signing in, the App retains full functionality, and the data remains only on the Device.
6.4. Synchronization applies only to your own Works. The App does not publish them, does not show them to other Users and does not provide for data exchange between Users.
6.5. The Operator does not request or process passwords for your email. Access to the Account is protected by control over access to the mailbox specified at sign-in.
6.6. The server side of the App is hosted in the territory of the Russian Federation.
7. Analytics and Diagnostics
7.1. To assess operational stability and understand which features are in demand, the App uses the Yandex AppMetrica service (right holder — YANDEX LLC).
7.2. The following is processed via AppMetrica:
- the App installation identifier assigned by the service, and the random service identifier of the profile created by the App at first launch; neither of them is linked by the Operator to the identity of the User;
- technical information about the Device: model, operating system version, language, screen resolution, connection type;
- information about the App version, installations, updates and launches;
- usage events: which screens were opened and which actions were performed, as well as aggregated action counters (for example, the number of created and completed Works) — in depersonalized form, without the contents of your Works and without your images;
- information about errors and crashes, including the log of technical events of the App preceding the failure; the contents of your Works are not written to the log;
- the IP address, from which the servers of the service determine the approximate location down to the region. The App does not request or receive access to the geolocation of the Device.
7.3. The contents of your photographs, Patterns and Works are not transferred to analytics.
7.4. Collection of advertising identifiers (IDFA on iOS, Advertising ID on Android) is disabled. The App does not track Users across other apps and websites and does not transfer data to advertising networks.
7.5. The AppMetrica servers are located in the territory of the Russian Federation.
7.6. Terms of use of the service: https://yandex.ru/legal/appmetrica_termsofuse/
8. What Is Not Processed
- the geolocation of the Device (location access permission is not requested);
- the contact list, calendar, microphone, files outside the App's private storage;
- the contents of the media library, other than images selected by the User themselves;
- advertising identifiers and any cross-service identifiers for transfer to advertising networks;
- payment data and bank card data — the App has no paid features;
- special categories of personal data (concerning health, beliefs, ethnicity, etc.);
- biometric personal data.
9. Purposes of Processing
Data is processed solely so that:
- the App performs its functions: shows your Works and progress, keeps statistics, preserves settings between launches;
- when an Account is used — the User is identified at sign-in and their Works are transferred between their Devices;
- the stability and security of the App's operation are ensured, and errors are found and fixed;
- enquiries from Users are answered.
Profiling, legally significant automated decision-making, marketing mailings and transfer of data for advertising purposes are not carried out.
10. Legal Grounds for Processing
10.1. The data processed on the Device (sections 4 and 5) is processed by the User themselves by means of the App; it is not transferred to the Operator.
10.2. Account data (section 6) is processed on the basis of the User's consent, expressed by the action of signing in to the App, and for the purposes of performing the User Agreement. Consent may be withdrawn by deleting the Account.
10.3. Statistics and crash information (section 7) are processed with the User's consent, expressed by installing and using the App. It can be withdrawn by ceasing to use the App and removing it from the Device.
11. Transfer of Data to Third Parties
11.1. The Operator does not sell personal data and does not transfer it for marketing purposes.
11.2. Data may be transferred to the following categories of recipients, and only to the extent necessary for the operation of the App:
- YANDEX LLC (the AppMetrica service) — the depersonalized technical, diagnostic and behavioral data listed in section 7. Servers in the Russian Federation;
- technical infrastructure providers engaged by the Operator to host the server side of the App and to deliver sign-in code emails. Such providers act on the instructions of the Operator, process data solely to the extent necessary to provide the respective service and may not use it for their own purposes. The servers are located in the territory of the Russian Federation;
- app stores (RuStore, Google Play, App Store) — with respect to the distribution of the App and aggregated download statistics, under their own policies;
- authorized state bodies — in cases expressly provided for by law.
11.3. No cross-border transfer of personal data takes place: the server side and the analytics service are hosted in the territory of the Russian Federation.
12. Retention Periods
12.1. Data on the Device is stored until the User deletes it (section 14) or deletes the App.
12.2. Account data is stored for as long as the Account exists. After its deletion, personal data is deleted; individual records may be retained for a limited period where required by law or for the resolution of disputes, after which they are deleted or depersonalized.
12.3. Server logs and diagnostic information are stored for the limited time necessary to ensure security and fix errors.
12.4. Information in AppMetrica is stored in accordance with the terms of the service.
13. Data Storage and Protection
13.1. Data on the Device is stored in the private (sandbox) directory of the App, inaccessible to other apps.
13.2. The local storage is encrypted with the AES algorithm. The encryption key is generated on the Device and stored in the protected system storage (Keychain on iOS, Keystore on Android).
13.3. Data exchange with the server and the analytics service is performed over the secure HTTPS protocol.
13.4. The Operator applies organizational and technical measures to protect data from unauthorized access, modification, disclosure and destruction.
13.5. Absolute protection cannot be guaranteed: the safety of data also depends on the physical safety of the Device, on it being locked with a passcode and on the User's control over the mailbox specified at sign-in.
14. Data Deletion
14.1. All the data created in the App on the Device can be deleted in two ways:
1. In the App itself: Profile → Settings → "Delete data". Works, Patterns, progress, statistics and settings are erased irreversibly. 2. By removing the App from the Device — all of its storage is deleted along with it.
14.2. When an Account is used, its deletion together with all associated data is performed in the App: Profile → Settings → "Delete account". Deletion is irreversible.
14.3. You can also send a deletion request to stitchy@alexforge.org from the email address specified in the Account.
14.4. An individual Work can be deleted from the list of Works at any moment. A deleted Work cannot be restored: the original photograph is not saved, and the Pattern cannot be built again.
15. User Rights
The User has the right to:
- receive information about the processing of their personal data;
- demand the rectification, blocking or deletion of their data;
- withdraw consent to data processing by deleting the Account, as well as by ceasing to use the App and removing it from the Device;
- revoke the camera and photo access permissions in the Device settings;
- file a complaint with the authorized body for the protection of the rights of personal data subjects.
To exercise these rights, send a request to stitchy@alexforge.org. A response is provided within the period established by law.
16. Device Permissions
| Permission | When requested | Purpose |
|---|---|---|
| Camera | when the "Camera" source is selected | take a photograph for building a Pattern |
| Photo access | when the "Gallery" source is selected | select a photograph for a Pattern or a profile image |
| Internet | no prompt, standard access | sign-in, synchronization, transfer of statistics |
Pattern creation, stitching mode and all calculations work without a network connection.
17. Children
The App is not intended for use by persons under the age at which independent consent to the processing of personal data is permitted under applicable law. The Operator does not knowingly collect data of minors. If you become aware that a minor's data has been provided without the consent of a legal representative, report this to stitchy@alexforge.org so that it can be deleted.
18. Changes to This Policy
The Operator may update this Policy. The current version is always available at the address where the Policy is published; the date of the last update is indicated at the beginning of the document. Material changes are communicated to Users by means of the App or in another available way.
19. Contacts
For all questions related to this Policy and data processing:
Operator: Alexander Sergeevich Seednov
Status: individual (natural person)
Email: stitchy@alexforge.org