Privacy Policy

Effective Date: September 13, 2026

Thank you for using Gingham. We respect your privacy and are committed to protecting it. This Privacy Policy explains what information Gingham and the third-party services it relies on collect, and how that information is used. The app does not require you to create an account.

The short version: the photos you turn into patterns, and the patterns you make, save and export, are processed and stored only on your device. They are never uploaded to us or to anyone else. Gingham has no server of its own. The only information that leaves your phone is what Google Play and the services listed in Section 3 collect for billing, crash reporting and anonymous usage analytics.

1. Your Photos and Your Patterns

When you make a pattern, Gingham converts the photo you chose into a cross stitch, bracelet, crochet, knitting or fuse bead chart. The conversion runs entirely on your device. Your photo is not sent anywhere to produce the pattern, and no online image or AI service is involved. The color palettes (for example thread and bead color charts) ship inside the app.

If you save a pattern, Gingham stores the pattern, its settings, a small preview image and a copy of the source photo in the app's database and the app's private storage on your device only. They are never uploaded as part of saving. You can delete any saved pattern, together with its photo copy and preview, from within the app at any time.

Gingham can export a pattern as a PDF or an image file. That export is created on your device and goes only where you send it using Android's own share sheet. We never receive a copy.

Gingham turns off Android's cloud backup and device-to-device transfer for its data, so your photos and patterns are not copied to a Google Drive backup either.

2. Permissions

To choose a photo, Gingham uses the Android photo picker. The picker hands the app only the specific image you chose — the app is not granted access to the rest of your photo library, and Gingham declares no storage or camera permission at all.

Gingham does not request location, contacts, microphone or notification permissions, and it does not collect the Android Advertising ID (the permission is stripped from the app and Analytics ad-id collection is switched off).

3. Third-Party Services

Gingham uses the following third-party services, which may collect information as described below. These services are operated by their respective providers under their own privacy policies.

Google (for Firebase Analytics, Crashlytics and Remote Config) and RevenueCat each act as independent data processors under their own standard Data Processing Agreements, which apply automatically to all customers using their services — we do not need a separately negotiated DPA with either of them.

4. Legal Basis for Processing (EEA/UK Users)

If you are located in the European Economic Area, the UK, or another jurisdiction requiring a stated legal basis, we (and our processors) rely on:

We do not rely on consent as the legal basis for analytics or crash reporting; where local law requires opt-in consent for non-essential analytics (e.g. under ePrivacy rules), we will provide a consent mechanism before those services activate.

5. International Data Transfers

The third-party services listed above (Google/Firebase, RevenueCat) may process and store data on servers located outside your country, including in the United States. These providers rely on the EU Standard Contractual Clauses (and, for Google, certification under the EU-U.S. Data Privacy Framework) as the legal mechanism for these transfers. By using the app, you acknowledge this transfer. Your photos and patterns are not part of any such transfer, because they never leave your device.

6. Data Retention

We retain data collected by our third-party services for only as long as necessary:

7. Your Rights

Depending on where you live, you have rights over the data collected about you by the third-party services described above. The patterns you create in Gingham are already entirely under your own control on your device: you can view them, change them, export them, and delete them, all from within the app and without asking anyone. Uninstalling the app removes everything it stored on your device.

If you are in the EEA, UK, or a similar jurisdiction (GDPR), you have the right to:

If you are a California resident (CCPA/CPRA), you have the right to:

If you are in Brazil (LGPD — Lei Geral de Proteção de Dados), you have the right to:

We do not sell or share personal information for cross-context behavioral advertising, so there is no "opt-out of sale/share" to exercise.

To exercise any of these rights, including deletion of the analytics, crash or purchase data held by Firebase or RevenueCat about your installation, contact us at the email below; we aim to respond within 30 days (15 days for LGPD access requests, extendable once with justification). Because the app has no account, including the app's version and the approximate date you installed it helps us locate that data. You may also exercise rights over a specific processor's own data directly with that processor (links in the Third-Party Services section above). As a solo developer with only occasional, low-risk processing of the kind described in this policy, we rely on the Article 27 GDPR exemption from appointing a dedicated EU representative.

8. Children's Privacy

Gingham is a general-audience app for people who make stitch and bead crafts. It is not directed at children, its Google Play target audience does not include children under 13, and we do not knowingly collect personal information from children under 13 (or the minimum age of digital consent in your country, where that age is higher).

The app is in any case built to collect very little from anyone, whatever their age:

If you are a parent or guardian and believe that information has been collected from your child through the app, contact us at the email in Section 11 and we will delete it.

9. Security

Your photos and patterns live only in the app's private storage on your device, where other apps cannot read them. Files you export are written to the app's temporary cache and shared only with the app you choose in the share sheet, using a one-time read permission. Data collected by the third-party services above is transmitted over encrypted connections and protected by their own security measures; no method of transmission or storage is 100% secure.

10. Changes to This Policy

We may update this Privacy Policy from time to time as the app's features or the third-party services it uses change. Material changes will be reflected here with an updated effective date. You are advised to review this page periodically.

11. Contact Us

If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact the developer:

Data Controller: Gabriel Machado, São Paulo, Brazil

Email: machadowg@gmail.com