Privacy Policy

The short version
  • We do not sell or share your personal data, and we never have.
  • No advertising trackers, no ad pixels, no third-party analytics. Our analytics are our own.
  • We use no analytics cookies and no cross-session tracking identifier, which is why you have never seen a cookie banner from us.
  • Your designs are yours. Delete a private design and it is removed from our servers and your synced devices. Publishing to the Haberdashery is different. A published snapshot, and any copies other members made from it, are separate objects that deleting your original does not erase (section 8).
  • We do not store the content of your AI requests.

The rest of this page is the detail behind those claims.

1. Who we are

StitchBlock Studio LLC, PO Box 2302, Idaho Falls, ID 83403, US, operates StitchBlock at stitchblockstudio.com. We are the data controller for the personal data described here. Contact us at info@stitchblockstudio.com.

2. What we collect, and why

Account information

Your email address, display name, and a user ID, held by our authentication provider (Clerk) and in our own database. We need this to give you an account and to sign you in.

Billing information

Your plan, billing period, and any purchases, keyed to your user ID. Payments run through Stripe. Card details never touch our systems. We keep billing records for as long as you have an account, for billing integrity and tax records.

Your designs

Quilt projects, thumbnails, saved blocks, fabric photos you upload, and your stash, stored in our database and object storage so they sync between your devices. This is content you create; we hold it to provide the Service.

AI usage

When you use an AI feature, we record the task, the credits used, token counts and a timestamp against your user ID, so we can meter your allowance. The content of the request (your prompt and any photo) is forwarded to Google's Gemini API to produce the result and is not stored by us. Google's handling of that request is governed by their API terms.

This website

The pages on www.stitchblockstudio.com record one event per page you open: which of our pages it was (a fixed list — home, pricing, contact, privacy, terms), and how you arrived, meaning the name of the website that linked you (for example facebook.com, never the page you were on) or the campaign tag on a link we posted. It carries a session token that lives in your browser tab and dies when you close it, and it is sent to our own servers — this site loads no third-party script, and the token is never passed to the app or to anyone else. No cookies, no address, no page URL. Retained for 180 days.

App analytics

We record a closed, fixed vocabulary of product events (things like "opened the cut list", "exported a pattern") with the app version. Before you sign in, these carry a session token that lives in your browser tab and dies when you close it. There is no identifier that follows you between sessions or between sites. After you sign in, events are bound to your user ID by our server; the app never self-reports who you are. When you open the app we also note how you arrived: the name of the website that linked you (for example facebook.com, never the page you were on) or the campaign tag on a link we posted. Event records never contain your email or name. Retained for 180 days.

Error reports

When something breaks, we record a truncated error message and stack trace and the page path. Query strings are stripped in your browser before the report is sent. Retained for 30 days.

Embedded and shared designs

When a StitchBlock design is embedded on another site, we record a small fixed set of events with a short-lived anonymous session ID, the hostname of the embedding site, and a coarse country or region code where our edge network supplies one. Retained for 365 days.

If you arrive from an embed and then create an account, a single-use handoff ID links that one embed session to the resulting account, so a creator can see that their embed led to a sign-up. That link is recorded on our server, not in your browser.

Bug reports and feature requests

If you use the bug icon in the top bar to report a bug or request a feature, we store what you write, the page you were on, your browser's user-agent string, your window size, and any recent error messages from your session. If you are signed in, the report is linked to your account so we can reply.

A bug report may also include a copy of the design you had open, because for most bugs the design is the only way to reproduce the problem. That copy is used for fixing the bug and nothing else. We delete it 90 days after the report is closed, and delete the whole report after 365 days. A report that is still open stays until we have dealt with it.

What we deliberately do not collect

We do not store raw IP addresses. Rate limiting happens in memory; embed requests keep at most a coarse region code, never the address itself. We have no advertising identifiers, no fingerprinting, and no third-party trackers on any of our surfaces.

3. Legal bases (EEA/UK)

Providing your account, designs, sync, and AI featuresPerformance of a contract
Billing and tax recordsContract; legal obligation
Product analytics and error reportingLegitimate interests: improving a service you use, with pseudonymous data and short retention
Security and abuse preventionLegitimate interests

4. Cookies and local storage

We use strictly necessary storage only:

We set no analytics or advertising cookies, and nothing we store is a persistent cross-site or cross-session tracking identifier, which is why we do not show a consent banner.

5. Global Privacy Control and Do Not Track

We honor Global Privacy Control and Do Not Track by construction: we do not sell or share personal data, we do not run cross-site tracking, and we have no advertising third parties, so there is nothing for the signal to switch off. That holds for every visitor, whether or not the signal is sent.

6. Who we share data with

We do not sell your personal data, and we do not share it for advertising. We use these service providers ("subprocessors") to run StitchBlock:

ClerkAuthentication and account records
StripePayment processing
RailwayDatabase and API hosting
CloudflareWeb hosting, object storage, and edge delivery
GoogleGemini API (AI requests only)

These providers process data in the United States. We may also disclose data where legally required, or to protect our rights, users, or the security of the Service. If we are ever involved in a merger or acquisition, we will tell you before your data is transferred to a new controller.

7. How long we keep things

Account and billing recordsLife of your account
Your designs and thumbnailsUntil you delete them (private designs)
Haberdashery publicationsUntil removed by you or a moderator; the published snapshot is retained after unpublishing
AI usage meteringLife of your account (billing integrity)
AI request contentNot stored
Website analytics180 days
App analytics180 days
Error reports30 days
Embed analytics365 days
Bug reports and feature requestsAny design attached to a report is deleted 90 days after the report is closed; closed reports are deleted after 365 days. Open reports are kept until we deal with them
Shares and preview imagesUntil you disable the share

Records expire automatically on these schedules.

8. Your rights and choices

Deleting a design. When you delete a project it is removed from our servers and propagates as a deletion to every device you sync with. Two honest exceptions. If you published a design to the Haberdashery, the published snapshot is retained even after you unpublish it, so moderation history and copies already in flight stay coherent, and copies other members made in their own libraries belong to them. And our disaster-recovery backups are additive: deleted images can persist in backup storage indefinitely. Backups are never served to anyone and exist only so a storage failure cannot destroy everyone's work.

Deleting your account. Email info@stitchblockstudio.com and we will remove your authentication record, your database rows, and your stored files. The same two exceptions apply: Haberdashery snapshots and member copies are retained, and backup copies persist in backup storage.

Access, correction, portability, objection. You can ask us for a copy of your personal data, to correct it, to delete it, or to object to or restrict processing. Email info@stitchblockstudio.com; we respond within 30 days. You can export your designs yourself at any time as .quilt files, on any plan.

A limitation, stated honestly: analytics events are pseudonymous and are not exposed as a per-user feed. We can delete the events tied to your user ID, but we cannot show you a readable history of them, and pre-sign-in events are not linked to you at all so we cannot find them to return.

If you are in the EEA or UK, you may complain to your local supervisory authority. If you are in California, you have rights to know, delete, and correct, and a right to opt out of sale or sharing. We do neither, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.

9. Children

StitchBlock is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, contact info@stitchblockstudio.com and we will delete it.

10. Security

Payments are handled entirely by Stripe. Passwords and sign-in are handled by Clerk. Data is encrypted in transit, and analytics data is separated from identifying information by design: our event schemas make it impossible for personal details to end up in an event record. No system is perfectly secure, but we would rather architect a risk away than manage it.

Report a vulnerability to info@stitchblockstudio.com.

11. Changes to this policy

We will update this page when our practices change, and change the "last updated" date. For material changes we will give notice in the app or by email before they take effect.

12. Contact

info@stitchblockstudio.com · StitchBlock Studio LLC, PO Box 2302, Idaho Falls, ID 83403, US.