Privacy Policy
How StitchSnap handles accounts, browser previews, uploaded images, pattern data, cookies, and optional service providers.
Scope and contact
This Privacy Policy explains how StitchSnap handles information when you browse stitchsnap.app, create an account, contact support, or use the crochet pattern tools. StitchSnap is the service name used on this site; the support contact for privacy questions is hello@stitchsnap.app.
Information we process
Account and support information
If you register, Better Auth processes the email address, display name, authentication records, sessions, and security events needed to sign you in and protect the account. A support or contact form can include your name, email address, and message. If you join an enabled newsletter, we process the email address and subscription status needed to send and manage that subscription.
Images and pattern data
The browser decodes and samples a selected JPG, PNG, or WebP image locally before showing the grid. Choosing an image does not by itself upload the original file. When you save a preview, the service receives the grid, settings, and, if supplied by the browser save request, the source image so the private pattern session can be restored. The saved record can include a random pattern ID, mode, grid hash, color grid, gauge settings, yarn assumptions, and generated PDF metadata.
Technical and security information
The service may receive a hashed anonymous pattern-session identifier, request timestamps, rate-limit counters, error details, and basic browser or network information needed to deliver the request and prevent abuse. We do not use the original IP address as the pattern identifier, and application logs should not contain image contents, source filenames, payment secrets, or download tokens.
How we use information
We use information to:
- provide the requested grid preview, saved pattern, measurements, yarn estimate, and PDF preview;
- authenticate accounts, send requested email, and respond to support requests;
- maintain D1 records, private R2 objects, and short-lived KV rate-limit data;
- detect abuse, enforce upload and request limits, diagnose failures, and improve reliability; and
- comply with applicable legal obligations or respond to lawful requests.
StitchSnap does not claim ownership of images or pattern content you submit. We process them only as needed to provide the requested service, protect the service, or meet a legal obligation.
Storage and deletion
Saved anonymous patterns are retained for up to seven days. The pattern session cookie also has a seven-day maximum age. A saved pattern can contain private source and preview objects in Cloudflare R2; the service removes those objects and associated metadata when you delete the pattern or when retention expires. Expired records are rejected before they can be restored, and scheduled cleanup removes expired objects as available.
You can delete a saved preview from the workbench. You can also contact support to request access, correction, or deletion of personal information. Some records may be retained when required for security, fraud prevention, dispute handling, or legal compliance; when retained, access is restricted and the record is deleted when the obligation ends.
Cookies and similar technologies
The essential stitchsnap_pattern_session cookie is an HttpOnly, SameSite cookie used to associate an anonymous browser with its saved patterns. It contains a random identifier; the database stores a hash rather than the raw identifier. Better Auth may set essential session and security cookies when you sign in. The workbench also uses browser localStorage to remember the last pattern ID so the private preview can be restored; localStorage is not a cookie.
Analytics providers and Crisp chat are loaded only when their production environment variables are configured. They may use cookies or similar technologies under their own policies. StitchSnap does not currently represent advertising cookies as active. See the Cookie Policy for the current list and controls.
Service providers and international transfers
The application runs on Cloudflare Workers. Cloudflare D1 stores application metadata, R2 stores private pattern objects, and KV supports short-lived rate limiting and caching. Better Auth provides account authentication. Depending on the enabled configuration, Cloudflare Email, Resend, a newsletter provider, analytics providers, and Crisp may process the information needed for their specific service. Waffo payment processing is not enabled in the current public release; if a payment provider is enabled later, this policy and the checkout disclosure will be updated before payment collection.
Providers may process data in countries other than where you live. We use provider contracts, access controls, and configuration safeguards appropriate to the service, but no internet transmission or storage system can guarantee absolute security.
Your choices and rights
You can use the browser preview without creating an account, decline to upload an image, remove a saved pattern, block optional scripts, or contact us about your personal information. Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data. We may need to verify a request before acting on it. You may also contact your local data-protection authority.
Children and policy changes
StitchSnap is not directed to children who are below the minimum age required to use online services in their location. If you believe a child provided personal information, contact us so we can review and delete it when appropriate.
We may update this policy when the product, providers, or legal requirements change. The date in the front matter and at the top of the published page identifies the latest revision. Material changes will be highlighted in the product when practical.