Privacy Policy
TrixiStitches ("the Service", "we", "us") is a web app that helps you read knitting and crochet patterns: it imports pattern PDFs, highlights your chosen size, offers an abbreviation glossary, and can generate a row-by-row Pattern Worksheet for a pattern. This policy explains what information the Service handles, why, how it is stored, and the choices you have. The Service is operated by Ruan Mentz and hosted at https://trixistitches.com.
1. Information we handle
a. Account information (Google Sign-In)
If you sign in with Google, we receive and store a stable Google account identifier, your email address, and your display name. We use these only to create and recognise your account and to associate your saved connections with you. We do not receive your Google password.
b. Connected storage providers
If you connect Dropbox, Google Drive, or Ravelry, the provider issues us an access token so the Service can, on your instruction, list the PDF files available in that account and download the specific file you choose to import. We request the minimum access needed:
- Google Drive — read-only access (the
drive.readonlyscope) to list and download PDF files you select. We never create, modify, or delete files in your Drive. - Dropbox — read access to file metadata and file contents, to list and download PDFs you select.
- Ravelry — read access to your own pattern library and the ability to generate a download link for a PDF you select.
The contents of a file are downloaded only when you explicitly choose to import it, and are then processed in your browser for reading. We do not browse, index, or copy your files in the background.
c. Pattern analysis
The "pattern at a glance" summary (craft, sizes, gauge, materials, and abbreviations) is computed entirely in your browser using built-in rules. No AI is involved and your pattern text is never sent anywhere to produce it.
d. Data stored in your browser
Your reading progress, selected size, line notes, counters, preferences, and small first-page thumbnails of patterns you open are stored locally in your browser (localStorage) and stay on your device. Thumbnails are never uploaded to us. If you are signed in, your reading progress is also saved to your account (see (f)) so it follows you between devices. You can delete this local data at any time from the in-app Privacy panel.
e. Projects and stored pattern files
If you are signed in, you can save "projects" — the things you are making — to your account. A project stores the details you enter (name, status, yarn, needle/hook size, gauge, dates, and notes) and its reading progress. So that you can reopen a project later (and keep working across devices, and see any charts or diagrams in the pattern), we also store a copy of the pattern PDF you attach to that project on our server. Because each project keeps its own copy and its own progress, you can run several projects from the same pattern — for different people or sizes — independently. If the same PDF is used by more than one of your projects we keep a single copy to minimise storage. These files are private to your account and are not shared with other users. You can delete a project at any time, which deletes its stored PDF and progress; deleting the pattern's last remaining project removes the stored file entirely.
f. Operational data
To keep the Service reliable and secure we record privacy-safe operational metrics such as request counts, response status codes, and latency. These records never include raw pattern text, provider tokens, API keys, or your file names.
g. Voice control (optional, opt-in)
Hands-free voice control is off by default. When you enable it, speech recognition is performed by your web browser, not by TrixiStitches. Some browsers (for example Chrome and Edge) transcribe by sending short snippets of microphone audio to the browser vendor's servers; others process it on your device. Your microphone is only active while you are listening, we never receive or store your audio, and you can turn voice off at any time (the tap controls keep working without it).
2. How we use information
- To authenticate you and maintain your session.
- To list and import the specific files you choose from a connected provider.
- To generate a Pattern Worksheet checklist for a pattern, on the Ultimate plan, when you request it.
- To operate, secure, debug, and improve the reliability of the Service.
We do not sell your personal information, and we do not use it for advertising.
3. How information is stored and protected
- Provider access tokens are encrypted at rest and stored on our server. They are never returned to the browser or exposed in the app interface.
- Your session is carried by an
HttpOnlycookie, transmitted over HTTPS in production. - When you import a pattern to read, its contents are processed in your browser. We do not retain a copy of that file unless you attach it to a project (see 1(e)); a pattern you only open to read, without saving a project, is not stored on our server.
- Pattern PDFs you attach to a project, and your project details and reading progress, are stored on our server (hosted by Render) so your projects persist and sync across your devices. They are private to your account. You can remove them at any time by deleting the project.
- Local reading data remains in your browser under your control.
No method of transmission or storage is completely secure, but we apply reasonable safeguards appropriate to the data involved.
4. Sharing and third parties
We share information only as needed to run the features you use:
- Identity & storage providers you choose to connect: Google, Dropbox, Ravelry.
- Voice recognition: your web browser's own speech recognition (e.g. Google for Chrome/Edge), used only while you have hands-free voice turned on. See (g).
- Hosting: Render, our hosting provider.
- Legal: where required by law or to protect rights, safety, and security.
5. Data retention and your choices
- Disconnect / sign out from the in-app Privacy panel to end your session.
- Revoke access at any time directly with the provider — for Google via Google Account permissions, and similarly in your Dropbox or Ravelry account settings. Revoking invalidates the token we hold.
- Delete local data (progress, notes, counters, settings) from the Privacy panel.
- Delete a project from the in-app Projects panel to remove that project, its stored pattern PDF, and its reading progress from our server.
- Delete your account from the in-app Privacy panel (signed-in users). That permanently removes the Google identifier, email, name, stored provider connections, cloud reading progress, projects, yarn stash, and pattern files we hold, and cancels any paid subscription immediately. You can also email [email protected] and we will delete it for you.
We retain account and connection data only while your account is active or as needed to provide the Service, and delete it on request as described above.
6. Children
The Service is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their personal information.
7. International users
The Service is hosted by Render and your information may be processed in the country where our hosting and processing providers operate. By using the Service you understand your information may be transferred to and processed in those locations.
8. Changes to this policy
We may update this policy from time to time. We will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you. Continued use of the Service after a change means you accept the updated policy.
9. Contact
Questions or requests about this policy or your data: [email protected] (operated by Ruan Mentz).