Stitchkin is a cross-stitch app published by DEVELOPER LEGAL NAME, POSTAL ADDRESS (“we”, “us”). We are the controller of the personal data described here.
Questions, requests and complaints: support@stitchkin.com. We answer within two business days.
Most of what Stitchkin holds is not personal data we process at all, because it stays on your iPhone or iPad:
.xsd, .saga) and everything the app reads out of them — the grid, the palette, the legend;iCloud. If you turn on Settings → iCloud, the app copies your charts, progress and photos into your own private iCloud database, using Apple’s CloudKit. That copy lives in your Apple Account, under Apple’s terms and privacy policy. We cannot read it, and no key exists on our side that would let us. Turning the switch off stops the copying.
Sharing is always your move. When you share a recap image or a group invitation, iOS hands the file to the app you choose. Nothing is uploaded to us on the way.
Signing in is required to use Stitchkin, because your subscription and your place in the leagues live with your account.
| What | Exactly which data | Why |
|---|---|---|
| Account | Account identifier (a random UUID), email address, which provider you used (Apple or Google), and when the account was created and last used. If you use Sign in with Apple and choose to hide your address, we only ever see Apple’s private relay address. | To let you sign in on any device, to attach your subscription to you and to answer your support messages. |
| Profile | Display name (up to 24 characters) and one badge emoji out of five. Both are chosen by you and are visible to other members of your leagues and groups. | So people can tell each other apart in a league table or a group. |
| Leagues | Your weekly stitch count, your current league, your best league, weekly results and shields. | To run the weekly table. Leagues can be switched off in Settings → Leagues; your stitches then stay on the device only. |
| Groups | Groups you create or join: name, emoji, goal, deadline, visibility, invitation code, who the members are and how much each has stitched towards the goal. | To show the group to its members and count the shared goal. |
| Subscription | Purchase and renewal events from the App Store, which product you bought, whether the subscription is active, trial and expiry dates, and the country of your App Store account — collected through RevenueCat and tied to your account identifier. | To unlock the app on all your devices and to restore purchases. We never see your card, your bank details or your Apple Account password — payment happens entirely inside Apple. |
| Support messages | What you write in Settings → Send feedback (up to 2000 characters), plus the app version, iOS version and device model, and your account identifier. | To reproduce the problem and reply to you. |
| Reports | When you report a profile or a group: who reported, who or what was reported, the reason and your optional comment (up to 1000 characters). | To moderate names, badges and groups, and to keep a record of what was decided. See the Community Guidelines. |
| Usage statistics (optional) |
Events describing what happens in the app — a screen opened, a chart imported, an import that failed, a paywall shown, a purchase made — with properties such as your plan, how many charts you have, how many stitches in total, your league, iPhone or iPad, app language, app version and whether iCloud sync is on. Our analytics provider also records the device model, the operating system version and an approximate location (country level) derived from your IP address. Events carry your account identifier so that one person is not counted as several. | To see which parts of the app are used and where they break. Switch off Settings → Help improve the app and nothing further is sent. |
| Website | stitchkin.com is a static site. Our hosting provider keeps short-lived technical logs (IP address, user agent, requested address) to serve pages and block abuse. No analytics, no cookies, no trackers. | To keep the site up. |
Camera and photo library. The camera is used only when you take a picture of your work, and iOS asks you first. Pictures you pick from your library are handed over by the system picker one at a time, so the app never gains access to the library itself. Either way the image stays on the device.
| Provider | What it does for us | What it sees |
|---|---|---|
| Apple | App Store, payments, Sign in with Apple, iCloud, push delivery | Your purchase and your Apple Account — under Apple’s own privacy policy. Your iCloud copy is yours, not ours. |
| Sign in with Google, if you choose it | The sign-in itself, under Google’s privacy policy. | |
| Supabase | Accounts, database, moderation records | Everything in section 3 except statistics and purchases. |
| RevenueCat | Subscription state across devices | Purchase events and your account identifier. |
| Amplitude | Usage statistics, only while they are switched on | Events, device and app properties, IP-derived country, account identifier. |
| Cloudflare | Hosting stitchkin.com | Technical request logs for the website. |
Each of them acts on our instructions under a data processing agreement, and none of them may use your data for their own purposes. We add a provider only when the app needs it, and this page is updated when we do.
Some of these providers process data in the United States. Where personal data leaves the EEA or the UK, the transfer is covered by the European Commission’s Standard Contractual Clauses (with the UK Addendum where it applies) as part of our agreement with each provider.
Wherever you live, you may ask us for a copy of the data attached to your account, ask us to correct it, ask us to delete it, ask us to restrict or object to a particular use, or withdraw a consent you gave. If you are in the EEA or the UK you also have the right to data portability and the right to complain to your local data protection authority; if you are in California you have the rights to know, delete, correct and opt out, and we will not treat you differently for using them.
Write to support@stitchkin.com from the address your account uses. We answer within 30 days and never charge for it.
Stitchkin is not directed at children. You must be at least 13 years old to have an account — 16 in countries where that is the age of digital consent. We do not knowingly collect data from children below that age; if you believe a child has an account, write to us and we will remove it.
Traffic between the app and our servers is encrypted with TLS. Your sign-in session is stored in the iOS Keychain. On the server every table is protected by row-level security, so one account cannot read another’s rows; the wider access needed for moderation is limited to us. No system is perfect, and we will tell you and the relevant authority without delay if a breach ever affects your data.
When something material changes we update the date at the top of this page and, if the change affects how your data is used, tell you in the app before it takes effect. Earlier versions are available on request.
support@stitchkin.com · DEVELOPER LEGAL NAME, POSTAL ADDRESS