Sttchr Privacy Policy
This Privacy Policy explains how Sttchr (“Sttchr,” “we,” “us”) collects, uses, and shares information when you use our sewing and pattern-projection tools. It covers both the Sttchr mobile app (for iPhone, iPad, and Android) and our website at sttchr.com (together, the “Service”). By using the Service you agree to this policy.
1. Summary
- We don’t sell your personal data, and we don’t use advertising SDKs or cross-app tracking (no App Tracking Transparency / IDFA ad tracking).
- Accounts. To use the Service you create an account with a phone number, email, or Apple/Google sign-in. We store basic account information to authenticate you on the app and website.
- Your pattern projects stay on your device by default. Imported PDFs, page layouts, crop and scale settings, and AR work are stored locally in the app’s private storage. We don’t upload your personal pattern files or camera video to our servers.
- Camera is optional and used only on your device for AR pattern tracing and live preview. Camera frames are processed on-device and are not sent to us.
- Community content is different. If you post comments or reels, or set up a creator profile, that content is uploaded to our servers and is publicly visible. Direct messages are stored on our servers and shared with the person you message.
- Product analytics and crash diagnostics are collected through PostHog to understand feature usage and keep the Service stable. On the website, analytics is off until you accept it, and you can change your choice at any time from Cookie settings in the footer or on your Account page. See our Cookie Policy.
- Purchases on mobile are handled by Apple/Google; web purchases and creator payouts, where offered, are handled by Stripe. We receive a purchase or payout record, not your full card or bank details.
- Notifications are optional. If you enable them, we store a device push token to send you notifications.
- Marketing email is optional and only sent if you opt in.
- You can delete your account and data at any time from inside the app, or by contacting us.
2. Information we collect and process
2.1 Account information
When you sign up on the app or the website, we collect and store the identifier you sign in with: a phone number, email address, or an Apple/Google sign-in identifier. If your sign-in provider gives us your name, we store that too. We assign your account a unique user ID. This is handled by Google Firebase Authentication and is used to sign you in and associate your purchases and entitlements with your account.
2.2 Content you create in Make and AR (stored on your device)
When you import PDF sewing patterns, crop pages, arrange layouts, calibrate scale, or trace in AR, that content is stored in the app’s private storage on your device. It may include file names, page images, crop settings, scale calibration, and layer positions. We do not upload this personal project content to our servers. (If you back up your device via iCloud or Google backup, your provider’s backup terms apply.)
2.3 Camera (optional)
With your permission, the app uses your device camera for AR pattern tracing and an optional live preview behind your pattern. Camera video is processed on your device only and is not transmitted to or stored by us. You can revoke camera access at any time in your device settings.
2.4 Purchases and payouts
If you buy patterns or a subscription in the mobile app, the transaction is processed by the Apple App Store or Google Play. We do not receive or store your credit card information. We do receive and store a record of your purchase (such as the product purchased and entitlement status) so we can unlock content you’ve paid for and validate purchases.
For purchases on the website, and for paying out creators who sell patterns, we use Stripe. When you pay through Stripe, your card details are collected and processed by Stripe and are not stored by us; we receive a confirmation and limited transaction details. If you are a creator and set up payouts, Stripe collects the information it needs to pay you and to meet legal and anti-fraud requirements (which may include your name, bank or payout account details, and tax identification). Stripe processes this information as an independent controller under its own privacy policy.
2.5 Usage and analytics
We use PostHog to understand how the Service is used, for example when you open the app, complete a crop, start tracing, view the shop, or make a purchase. This may include event names, in-app actions, your account’s user ID, your email (to link activity to your account), approximate location derived from IP at the time of the event, device and operating-system details, and app version. It does not include the contents of your pattern files or camera frames. Analytics collection is subject to your consent where required.
2.6 Crash reports and diagnostics
To keep the Service stable, we collect crash and error diagnostics through PostHog. This may include crash reports, error/exception details and stack traces, device model, operating-system version, and app version. We use this only to diagnose and fix problems.
2.7 Marketing email (optional)
If you opt in, your email address is sent to our email provider (Loops) so we can send you product updates and tips. You can unsubscribe at any time using the link in any email, and opting in is never required to use the Service.
2.8 Creator and shop features (optional)
If you become a creator, the information you provide for your public profile, such as your display name, avatar, banner image, bio, and social or website links, is uploaded to our backend (Google Firebase) and shown publicly. When you publish patterns or reels, you upload cover images, pattern files, and reel videos, along with listing details such as titles, descriptions, sizing, and price; published listings, reels, and profiles are publicly visible. Patterns submitted for sale may be reviewed by us before they go live. If you set up payouts, see Section 2.4 (Stripe).
2.9 Community and messaging
The Service includes social features. When you comment, like, save, follow, or post a reel, that activity is stored on our servers (Google Firebase). Comments, reels, and your public profile are visible to others. If you send a direct message to another user, the message is stored on our servers and is shared with the person you message. We may access or review community content and messages to operate the Service, enforce our terms, and protect against spam, abuse, and illegal content. Please don’t share sensitive personal information in public posts or messages.
2.10 Notifications and device tokens
If you enable notifications, we store a device push token through Firebase Cloud Messaging so we can send you notifications, for example a new direct message, a reply, or the status of a pattern you submitted. You can turn notifications off at any time in your device settings.
2.11 Cookies and local storage (website)
The website sets no cookies of its own, and we do not use advertising or cross-site tracking anywhere. What we do use is browser storage, in two groups.
Strictly necessary storage is set without asking, because the site cannot work otherwise: signing you in and keeping your session, holding a preference you set yourself, protecting purchases and creator accounts from bots and fraud (Firebase App Check with Google reCAPTCHA, which causes Google to set a _GRECAPTCHA cookie on its own domain), and remembering your analytics choice. That last one is stored even if you decline, because it is the only way we can honor the decline.
Analytics storage is used only if you accept it. On your first visit analytics is off: we make no analytics request and write no analytics identifier until you choose to allow it. You can change your mind at any time from Cookie settings in the site footer or on your Account page. Declining, or withdrawing later, deletes the analytics identifier from your browser. We also honor the browser Global Privacy Control (GPC) signal: if your browser sends it, analytics stays off and we do not ask.
Some browser storage is created by the Firebase SDK rather than by us directly, including IndexedDB databases for your sign-in session and for App Check tokens, and, only if you turn on browser notifications, a service worker and its messaging database.
Our stylesheets, scripts, and fonts are served from our own domain, so loading a page does not disclose your IP address to a font or CDN provider. Our Cookie Policy lists every item by name, with what it is for and how long it lasts. Clearing your browser storage will sign you out, reset these settings, and make us ask about analytics again.
2.12 Server logs
Like most online services, our hosting and backend (Google Firebase) automatically record technical log data such as your IP address, request times, and basic device/browser information. We use these logs to operate and secure the Service and to detect and prevent abuse.
3. How we use information
- Provide, operate, and secure the Service and your account.
- Authenticate you and remember your purchases and entitlements.
- Process purchases and creator payouts, and validate purchases.
- Power community features such as the shop, reels, comments, follows, and direct messages.
- Send notifications you’ve enabled.
- Understand usage and improve features (analytics).
- Diagnose crashes, fix bugs, and protect against spam, abuse, and fraud.
- Send marketing email if (and only if) you opt in.
- Respond to support requests and comply with legal obligations.
4. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the Service and your account, processing purchases and payouts); legitimate interests (security, fraud and abuse prevention, crash diagnostics, operating community features, and improving the Service); consent (analytics and marketing, where required); and legal obligations. You may withdraw consent at any time. On the website specifically, analytics storage and analytics events are set only with your consent, which you can withdraw whenever you like from Cookie settings; withdrawing does not affect processing that already took place.
5. Where information is stored and how long we keep it
Pattern projects in Make and AR are stored on your device. Account data, purchase and entitlement records, creator content, community posts, and direct messages are stored on Google Firebase servers (which may be located in the United States). Payment and payout data is handled by Stripe; analytics and crash data are stored by PostHog (US cloud). We keep account, purchase, and creator information for as long as your account is active; community content and messages for as long as needed to provide the feature; and analytics/diagnostics data for a limited period needed for the purposes described above. We may retain limited records longer where required for legal, tax, or fraud-prevention purposes. When you delete your account, we delete your associated account data, and you may request deletion of other data as described in Section 7.
6. Sharing and service providers
We do not sell your personal data. We share information only with service providers that process it on our behalf, and as required by law:
| Provider | Purpose |
|---|---|
| Google Firebase (Google LLC) | Authentication, database, cloud functions, file storage, hosting, push notifications, app integrity |
| Stripe | Website payments and creator payouts (where offered) |
| PostHog | Product analytics and crash/error diagnostics |
| Google reCAPTCHA (Google LLC) | Firebase App Check on the website: verifies requests come from the real Sttchr site, to protect purchases and creator accounts from automated abuse |
| Loops | Marketing email (only if you opt in) |
| Apple / Google | Sign-in and in-app purchases |
Community content and direct messages are also shared with other users as part of how those features work, as described in Section 2.9. We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of our users or the public.
7. Your choices and rights
- Delete your account: open the account menu in the app and choose Delete Account, or contact us at the email below. This permanently deletes your account and associated data.
- Camera and notifications: grant or revoke camera and notification access in your device settings.
- Marketing: opt out anytime via the unsubscribe link.
- Cookies and local storage: use Cookie settings in the website footer or on your Account page to allow or withdraw analytics at any time. See Section 2.11 and our Cookie Policy for the full list, or clear your browser storage to remove everything at once.
- Access, correction, deletion, portability, and objection: depending on your region (including under GDPR/UK GDPR and the CCPA/CPRA), you may request access to, correction of, or deletion of your personal data, and you have the right not to be discriminated against for exercising these rights. Contact us at the email below to make a request.
8. California privacy (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request access to or deletion of it, to correct it, and to not be discriminated against for exercising your rights. In the past 12 months we have collected the categories of personal information described in this policy, including identifiers (such as account ID, email, phone), commercial information (purchases and entitlements), internet/network activity (usage analytics, logs), approximate location (derived from IP), and user-generated content (community posts and messages). We use and share this information with our service providers for the business purposes described above.
We do not sell or “share” your personal information (as those terms are defined under the CCPA/CPRA) for cross-context behavioral advertising. Because we do not sell or share, there is no opt-out to submit; where applicable, we also honor browser Global Privacy Control (GPC) signals. You may exercise your rights by contacting us at the email below; we will verify your request using your account information.
9. Children’s privacy
Sttchr is not directed to children under 13 (or the minimum age required in your country, such as 16 in parts of the EEA). We do not knowingly collect personal information from children under that age. If you believe a child has provided us information, contact us and we will delete it.
10. International users
We and our service providers may process and store your information in the United States and other countries, which may have different data-protection laws than your own. By using the Service, you understand your information may be transferred to and processed in those countries.
11. Changes to this policy
We may update this policy from time to time. We will revise the “Effective date” above and, for material changes, provide additional notice in the app or on the website. Your continued use of the Service after changes take effect constitutes acceptance.
12. Contact
Questions or privacy requests: sttchr.app@gmail.com.
13. App stores
Your use of the mobile app is also subject to the terms and privacy practices of the Apple App Store and Google Play. Mobile purchases are governed by the applicable app store’s terms.