Privacy Policy
Last updated 9 September 2026
Stitches is a cross stitch pattern editor for macOS, Windows, iOS, Android and the web. This policy explains what the app does with your information, and in particular what it does with data from your Google Account.
The short version
Stitches has no server. Your patterns are stored on your own device, or in storage you connect and control, such as your Google Drive or an S3 bucket you run. Nothing you make is sent to the developer, and there is no analytics, tracking or crash reporting of any kind.
What the app accesses
Your patterns and the files beside them
Patterns, and any PDFs, images or sprite sheets you import, are held wherever you tell the app to keep them:
- on the device you are using;
- in your Google Drive, if you connect it;
- in an S3 compatible bucket, if you configure one.
These are your accounts and your storage. The developer has no access to them.
Google Account data
If you choose to connect Google Drive, Stitches requests three permissions and no others:
drive.file |
Lets the app create and manage only the files it creates itself. It cannot see, open or list anything else in your Drive. This is a deliberately narrow permission: the rest of your Drive is invisible to Stitches. |
userinfo.email |
Your email address, shown in the app so you can tell which account is connected. |
userinfo.profile |
Basic profile information, used for the same purpose. |
On first connection the app creates a folder called Stitches App
Data in your Drive and keeps your patterns there. You can move that
folder wherever you like from within the app. Because of the narrow permission
above, files you add to that folder yourself are not visible to Stitches.
What is stored on your device
The app keeps a small amount of information locally so it can work between launches: your sign in tokens, which storage you have connected, your recently opened files, your preferences, and cached copies of patterns you have opened. On desktop and mobile, credentials are held in the operating system keychain. In the web app they are held in your browser's own storage, which never leaves your browser.
How the data is used
Solely to provide the app. Reading and writing your patterns, showing which account is connected, and remembering where your files live. There is no other purpose.
What is not done with it
- It is not sold, rented or traded.
- It is not shared with any third party, because it is never received in the first place.
- It is not used for advertising or profiling.
- It is not used to train machine learning models.
- It is not analysed, aggregated or measured. Stitches contains no analytics, telemetry or crash reporting.
Google user data obtained through the permissions above is used only to provide and improve the features you are using it for, and is never transferred to anyone else except as required by law. Stitches complies with the Google API Services User Data Policy, including its Limited Use requirements.
Who the app talks to over the network
- Google, to sign you in and to read and write the files Stitches created in your Drive.
- Your own storage endpoint, if you have configured an S3 compatible bucket. You choose the address; the app does not know it otherwise.
There are no other network destinations. In particular there is no server operated by the developer that receives your patterns or your account information.
Keeping it safe
All traffic to Google and to storage endpoints uses HTTPS. Credentials are kept in the operating system keychain on desktop and mobile. The permission Stitches asks of Google is limited to the files it creates, which means a problem with the app cannot expose the rest of your Drive.
In the web app, credentials are held in browser storage rather than a keychain, because a browser has no keychain to offer. If that matters to you, use the desktop or mobile app.
Keeping and deleting it
Nothing is retained by the developer, because nothing is collected. Your data lives in your storage and under your control, for as long as you keep it.
To remove Stitches from your Google Account entirely:
- Revoke access at myaccount.google.com/permissions. The app immediately loses all access to your Drive.
- Delete the
Stitches App Datafolder in your Drive, if you also want the patterns gone. Revoking access alone does not delete them.
To clear what is held locally, sign out in the app's settings, or uninstall it. In the web app, clearing site data for the app's address removes everything it has stored in your browser.
Children
Stitches is not directed at children under 13 and does not knowingly collect information from them. Since it collects no personal information at all, there is nothing held about any user of any age.
Your rights
Rights of access, correction, erasure and portability apply to data a service holds about you. Stitches holds none, so there is nothing to request. Your patterns are already in your possession, in ordinary files you can copy, move or delete yourself.
Changes
If this policy changes, the date at the top changes with it. If a change ever alters what the app does with your data rather than merely how it is described, that will be called out in the app before it takes effect.
Contact
Questions about this policy or about the app can go to support@stitches.info.