— Legal —
Privacy Policy
Last updated: 2 August 2026
Stitcheree is a tool for cross-stitchers to keep track of their floss, their patterns and their finished pieces. This policy explains what we collect, why, and what we do not do. We have tried to write it in plain language rather than legalese.
Stitcheree is run by Kyryl Lytvynenko, an individual (not a company), based in Estonia — referred to below as “we” or “us”. For any question about this policy, or to exercise any of the rights below, email hello@stitcheree.com.
What we collect
Account details
When you create an account we store your first name, surname and email address. If you register with a password, we never store the password itself — only a hash produced with Argon2id, which cannot be reversed back into your password. If you sign in with Google instead, we receive your email address and your given and family names from Google, and no password is stored at all.
The things you create
- Your floss inventory — the DMC colour codes you own and whether you have marked them as running low.
- Your pattern library — titles, designer names, the colours a pattern needs, your stitching progress, any colour substitutions you record, and the chart PDF you upload.
- Your gallery — photos of finished pieces, their captions, and the pattern you link them to, if any.
Pattern charts
The PDF you upload for a pattern is stored on our server so it is still there when you come back — on another day, or another device. It is private to your account: it is only ever served back to you while you are signed in, it is never shown to other users, and it is not indexed or shared. Deleting the pattern deletes the file; closing your account deletes all of them.
Until 21 August 2026 these files were read for their colour list and then discarded. If you would rather a chart was not kept, delete the pattern and the file goes with it.
Technical data
Our server keeps ordinary web server logs, which may include your IP address and browser user agent, for security and troubleshooting. We do not build profiles from them.
Cookies
Stitcheree uses two cookies, both strictly necessary, and nothing else:
- nuxt-session — an encrypted cookie that keeps you signed in. Without it you would be logged out on every page load. It is cleared when you sign out.
- stitcheree-cookie-notice — remembers that you have dismissed the cookie notice, so it does not reappear on every visit. It expires after one year.
There are no analytics cookies, no advertising cookies, and no third-party cookies. We do not use Google Analytics or any comparable product, and there are no tracking pixels, social media widgets or embedded third-party scripts anywhere in the app. Web fonts are served from our own servers, so loading a page does not tell Google (or anyone else) that you visited.
Because both cookies are strictly necessary to provide a service you have asked for, they do not require your prior consent under the ePrivacy Directive. That is why the notice has an acknowledgement rather than an accept/reject choice — there is nothing optional to switch off. If we ever add anything non-essential, we will ask for your consent first.
What we deliberately do not do
Some of these are worth spelling out, because they are design decisions rather than promises:
- Photo location data is removed. Your browser re-encodes every photo before it is uploaded, which discards the EXIF metadata block — including GPS coordinates your camera may have recorded.
- The automated photo check happens on your device. Photos are screened in your browser before upload. A photo that fails the check is never transmitted to us at all.
- We do not sell, rent or share your personal data for marketing, and we do not run advertising.
Why we are allowed to use your data
Under the EU GDPR — and the UK GDPR where it applies to you — our legal bases are:
- Performance of a contract — to give you an account and store the inventory, patterns and photos you put into it.
- Legitimate interests — to keep the service secure, prevent abuse, and fix faults.
- Legal obligation — where we must retain or disclose something by law.
Who else sees your data
Your inventory, patterns and photos are private to your account. Other users cannot see them, and every request for a photo is checked against the signed-in account before the file is served.
We share data only with:
- Our hosting provider — Hetzner Online GmbH (Germany), whose servers store the database, the uploaded photos and the pattern charts on our behalf. Your data stays within the EU.
- Google — only if you choose to sign in with Google, and only to authenticate you. Their handling is governed by Google's own privacy policy.
- Authorities — where we are legally required to.
How long we keep it
We keep your account data for as long as your account exists. Deleting a pattern or a photo removes it from our database, along with the file behind it — the chart PDF for a pattern, the image for a photo. You can close your account yourself, at any time, from Profile → Close your account: that deletes the account and everything in it — your floss box, every pattern and its chart, and every photo — and it cannot be undone. Backups, if any, are overwritten on their normal cycle.
Your rights
If you are in the EEA or the UK, you have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- ask us to restrict or stop processing it;
- receive your data in a portable, machine-readable form;
- complain to a data protection authority — either the one where you live, or ours: the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee.
Much of this you can do yourself inside the app. For anything else, email hello@stitcheree.com and we will respond within one month.
Security
Passwords are hashed with Argon2id. The session cookie is encrypted and signed, so it cannot be read or forged. Every database query for your content is scoped to your account, so one person's identifier can never return another person's file. No system is perfectly secure, but we take this seriously and will tell you promptly if a breach affects your data.
Children
Stitcheree is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top. If a change is significant — particularly anything that would add tracking or new cookies — we will tell you in the app before it takes effect.
Contact
Kyryl Lytvynenko — Stitcheree
Kopli 96a-11, Tallinn, Estonia
hello@stitcheree.com
stitcheree.com