Legal
Privacy Policy
Last updated 3 September 2026
The privacy of your data — and it is your data, not ours — matters to us. In this policy we lay out what we collect and why, how your data is handled, and your rights over it. We promise we never sell your data: never have, never will.
This policy applies to Stitchist, the embroidery digitizing application at stitchist.app, and to our marketing pages. Stitchist is operated from the United States, and is responsible for the information described here.
For any question about your privacy or this policy, and to exercise any of the rights set out below, contact us at support@stitchist.app. We read everything sent there.
What we collect and why
Our guiding principle is to collect only what we need.
Identity and access
When you create an account we ask for an email address and a password, and optionally a display name. That is so you can sign in, so we can send you essential account email, and so your saved work has an owner. If you sign in with Google or GitHub instead, we receive your email address, your name and your profile picture from that provider, and we store an identifier linking your Stitchist account to it. We never receive your password for those services.
We will never sell your personal information, and we will not use your name in marketing without your permission.
Billing information
Stitchist Pro is a one-time purchase handled by Stripe. Card details are submitted directly to Stripe and never reach our servers. We store only a record that your account has purchased Pro, and the identifiers Stripe gives us to reconcile that purchase. Stripe's own handling of your payment data is covered by Stripe's privacy policy.
Your designs
We store the projects you choose to save to your account: their name, the design data itself, a thumbnail image, and the version history we keep so you can go back. This is so the Services work as intended and your work follows you between devices. We keep it as long as your account is active.
Designs you never save to your account are not retained. Artwork you upload to the auto-digitize, redwork or magic-wand tools is processed to produce stitches and is not kept afterwards; temporary working files live in a per-session directory and are deleted when that session is evicted.
Website and application interactions
Our servers record standard log data: IP address, request path, timestamp, response status and user agent. We use this to keep the Services running, to enforce rate limits, and to investigate errors and abuse.
We do not run third-party advertising, we do not use cross-site tracking, and we do not sell or share your information with data brokers.
Cookies
We use a single essential cookie to keep you signed in. It is set when you sign in, it is HttpOnly so scripts cannot read it, and it is removed when you sign out. We do not use advertising or tracking cookies. Your editor preferences are kept in your browser's local storage on your own device, not on our servers.
We also count a small number of anonymous product events in our own database, so we can tell how many people open the editor, draw something or reach a paid feature. Each record is the name of the event, the feature it relates to, and the day it happened. No identifier is stored: no account, no IP address, no session, no device or browser details, and nothing that could be linked back to you or joined up across visits. Nothing is sent to a third party, there is no analytics script on this site, and none of this data leaves our servers.
The "tell me when Pro opens" list
If you give us your email address to hear when a feature becomes available, we store that address and the page you gave it on, and nothing else. We use it once, for that announcement. Ask us at any time and we will delete it.
Voluntary correspondence
When you email us with a question or for help, we keep that correspondence, including your email address, so we have a history to reference if you get in touch again.
When we access or disclose your information
To provide the Services you have asked for. We use a small number of third-party processors:
- Stripe — payment processing for the one-time Pro purchase.
- Our hosting provider — application hosting, database and backups.
- Our transactional email provider — sending address verification, password reset and receipt email. We do not send marketing email.
- Google and GitHub — only if you choose to sign in with them.
No human at Stitchist looks at your designs except for limited purposes with your express permission — for example if an error stops an automated process and requires manual intervention, or if you ask us for help with a support case and we need to reproduce the problem. These cases are rare, and we look for root-cause fixes so they do not recur.
To investigate or prevent abuse. If we have reason to believe the Services are being used unlawfully, we may access the minimum data needed to investigate, and notify the appropriate authorities where warranted.
Aggregated and de-identified data. We may aggregate or de-identify information — for example counting how many accounts exist or how many designs were saved — and use that for any purpose, including improving the product. It cannot be traced back to you.
When required under applicable law. Our policy is not to respond to requests for user data unless compelled by valid legal process. Where we are permitted to, we will notify the affected user before disclosing anything.
Finally, if Stitchist is ever acquired by or merged with another company, we will notify you well before any of your personal information is transferred or becomes subject to a different privacy policy.
Your rights with respect to your information
We apply the same data rights to everyone, regardless of where they live:
- Right to know and to access — what we hold about you and how it is used.
- Right to correction — to have inaccurate information put right.
- Right to erasure — to have your personal information deleted.
- Right to restrict or object to processing.
- Right to portability — to receive your information in a portable form. You can export your designs yourself from the editor at any time.
- Right to complain to a supervisory authority.
- Right not to be discriminated against for exercising any of these rights.
You can review and edit your account details, and delete individual projects, from inside the app — deleting a project removes it immediately. To exercise any other right, including to request a copy of everything we hold or to delete your account entirely — which removes the account, its projects, its version history and its linked sign-in identities — email support@stitchist.app. There is no self-serve delete button; a person handles the request. We may need to verify your identity before we act, which normally means confirming you control the account's email address.
If you are in the United States
Depending on your state — including California, Colorado, Connecticut, Virginia and a growing number of others — you may have specific rights to know what personal information is collected about you, to access a copy of it, to have it corrected or deleted, and to opt out of its sale or of targeted advertising.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not run targeted advertising, so there is nothing to opt out of. We will not discriminate against you for exercising any privacy right. To make a request, email us at the address above; if an authorised agent acts for you, we will ask for written proof of their authority. You may appeal a refusal by replying to our decision, and you may complain to your state Attorney General.
If you are in the UK or the EEA
Stitchist is operated from the United States, but it is available to you, so UK and EU data protection law applies to our handling of your information. Our legal bases are:
- Performance of a contract — to give you an account, store your designs, and deliver what you have purchased.
- Legitimate interests — to keep the Services secure, prevent abuse, and understand aggregate usage.
- Legal obligation — to keep records we are required to keep, such as for tax.
- Consent — where we ask for it, which you may withdraw at any time.
You also have the right to lodge a complaint with your local supervisory authority; in the UK that is the Information Commissioner's Office.
How we secure your data
All data is encrypted via TLS when transmitted between our servers and your browser. Passwords are stored hashed, never in plain text. Session cookies are signed and HttpOnly. Database backups are encrypted. We rate-limit sensitive endpoints to frustrate brute-force attempts.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security — but if we ever become aware of a breach affecting your personal data, we will notify you and the relevant authority as the law requires.
What happens when you delete something
Deleting a project removes it and its version history from the application immediately. It may persist in encrypted backups for a short period before those backups age out.
When your account is closed, its projects, version history, sessions and linked sign-in identities are deleted, and the thumbnails it owned are reclaimed. Backups age out on a rolling basis, so deleted data may persist in them briefly before being overwritten.
Data retention
We keep your information for as long as it is needed for the purposes described here. Account and project data are retained until you delete them or close your account. Temporary editing sessions are discarded when the session is evicted. Server logs are kept for a short operational window and then rotated away.
Location of site and data
The Services are operated from the United States. Our servers and backups are located in Virginia, in the United States.
If you are located in the United Kingdom, the European Economic Area, or anywhere else outside that region, please be aware that any information you provide to us will be transferred to and stored in the United States, which has different data protection laws. By using the Services or providing us with your personal information, you consent to that transfer. Where personal data is transferred out of the UK or EEA we rely on the appropriate safeguards required by UK and EU data protection law.
Children
The Services are not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, email us and we will delete it.
Changes and questions
We may update this policy as needed to comply with relevant regulations and reflect new practices. Whenever we make a significant change we will refresh the date at the top of this page and take any other appropriate steps to notify users.
Any questions, comments or concerns about this policy, your data, or your rights over it? Email support@stitchist.app and we will be happy to answer.
Adapted from 37signals' open-source policies, used under CC BY 4.0. Modified for Stitchist: rewritten for a single product with no advertising and no third-party tracking, narrowed to the data this application actually handles, and given a UK/EEA section because the Services are offered internationally from the United States.