Stitchkin

Privacy Policy

Last updated 9 September 2026 · Applies to the Stitchkin app for iPhone and iPad and to stitchkin.com

In short

1. Who we are

Stitchkin is a cross-stitch app published by DEVELOPER LEGAL NAME, POSTAL ADDRESS (“we”, “us”). We are the controller of the personal data described here.

Questions, requests and complaints: support@stitchkin.com. We answer within two business days.

2. What never leaves your device

Most of what Stitchkin holds is not personal data we process at all, because it stays on your iPhone or iPad:

iCloud. If you turn on Settings → iCloud, the app copies your charts, progress and photos into your own private iCloud database, using Apple’s CloudKit. That copy lives in your Apple Account, under Apple’s terms and privacy policy. We cannot read it, and no key exists on our side that would let us. Turning the switch off stops the copying.

Sharing is always your move. When you share a recap image or a group invitation, iOS hands the file to the app you choose. Nothing is uploaded to us on the way.

3. What we receive, and why

Signing in is required to use Stitchkin, because your subscription and your place in the leagues live with your account.

WhatExactly which dataWhy
Account Account identifier (a random UUID), email address, which provider you used (Apple or Google), and when the account was created and last used. If you use Sign in with Apple and choose to hide your address, we only ever see Apple’s private relay address. To let you sign in on any device, to attach your subscription to you and to answer your support messages.
Profile Display name (up to 24 characters) and one badge emoji out of five. Both are chosen by you and are visible to other members of your leagues and groups. So people can tell each other apart in a league table or a group.
Leagues Your weekly stitch count, your current league, your best league, weekly results and shields. To run the weekly table. Leagues can be switched off in Settings → Leagues; your stitches then stay on the device only.
Groups Groups you create or join: name, emoji, goal, deadline, visibility, invitation code, who the members are and how much each has stitched towards the goal. To show the group to its members and count the shared goal.
Subscription Purchase and renewal events from the App Store, which product you bought, whether the subscription is active, trial and expiry dates, and the country of your App Store account — collected through RevenueCat and tied to your account identifier. To unlock the app on all your devices and to restore purchases. We never see your card, your bank details or your Apple Account password — payment happens entirely inside Apple.
Support messages What you write in Settings → Send feedback (up to 2000 characters), plus the app version, iOS version and device model, and your account identifier. To reproduce the problem and reply to you.
Reports When you report a profile or a group: who reported, who or what was reported, the reason and your optional comment (up to 1000 characters). To moderate names, badges and groups, and to keep a record of what was decided. See the Community Guidelines.
Usage statistics
(optional)
Events describing what happens in the app — a screen opened, a chart imported, an import that failed, a paywall shown, a purchase made — with properties such as your plan, how many charts you have, how many stitches in total, your league, iPhone or iPad, app language, app version and whether iCloud sync is on. Our analytics provider also records the device model, the operating system version and an approximate location (country level) derived from your IP address. Events carry your account identifier so that one person is not counted as several. To see which parts of the app are used and where they break. Switch off Settings → Help improve the app and nothing further is sent.
Website stitchkin.com is a static site. Our hosting provider keeps short-lived technical logs (IP address, user agent, requested address) to serve pages and block abuse. No analytics, no cookies, no trackers. To keep the site up.

4. What we never collect

Camera and photo library. The camera is used only when you take a picture of your work, and iOS asks you first. Pictures you pick from your library are handed over by the system picker one at a time, so the app never gains access to the library itself. Either way the image stays on the device.

5. Legal bases (EEA and UK)

6. Who else processes your data

ProviderWhat it does for usWhat it sees
AppleApp Store, payments, Sign in with Apple, iCloud, push deliveryYour purchase and your Apple Account — under Apple’s own privacy policy. Your iCloud copy is yours, not ours.
GoogleSign in with Google, if you choose itThe sign-in itself, under Google’s privacy policy.
SupabaseAccounts, database, moderation recordsEverything in section 3 except statistics and purchases.
RevenueCatSubscription state across devicesPurchase events and your account identifier.
AmplitudeUsage statistics, only while they are switched onEvents, device and app properties, IP-derived country, account identifier.
CloudflareHosting stitchkin.comTechnical request logs for the website.

Each of them acts on our instructions under a data processing agreement, and none of them may use your data for their own purposes. We add a provider only when the app needs it, and this page is updated when we do.

7. International transfers

Some of these providers process data in the United States. Where personal data leaves the EEA or the UK, the transfer is covered by the European Commission’s Standard Contractual Clauses (with the UK Addendum where it applies) as part of our agreement with each provider.

8. How long we keep things

9. Your choices and your rights

Switches in the app

Rights you can exercise

Wherever you live, you may ask us for a copy of the data attached to your account, ask us to correct it, ask us to delete it, ask us to restrict or object to a particular use, or withdraw a consent you gave. If you are in the EEA or the UK you also have the right to data portability and the right to complain to your local data protection authority; if you are in California you have the rights to know, delete, correct and opt out, and we will not treat you differently for using them.

Write to support@stitchkin.com from the address your account uses. We answer within 30 days and never charge for it.

10. Children

Stitchkin is not directed at children. You must be at least 13 years old to have an account — 16 in countries where that is the age of digital consent. We do not knowingly collect data from children below that age; if you believe a child has an account, write to us and we will remove it.

11. Security

Traffic between the app and our servers is encrypted with TLS. Your sign-in session is stored in the iOS Keychain. On the server every table is protected by row-level security, so one account cannot read another’s rows; the wider access needed for moderation is limited to us. No system is perfect, and we will tell you and the relevant authority without delay if a breach ever affects your data.

12. Changes to this policy

When something material changes we update the date at the top of this page and, if the change affects how your data is used, tell you in the app before it takes effect. Earlier versions are available on request.

13. Contact

support@stitchkin.com · DEVELOPER LEGAL NAME, POSTAL ADDRESS