Privacy Policy
Stitch is a small daily ritual: one question a day, answered by you and one other person. This policy explains what we collect, why, who touches it, and what you can make us do about it. We tried to write it the way we write the app: plainly.
Who is responsible. Anthony Machette ("Stitch", "we") is the controller of your personal data. Contact us any time at support@stitchdaily.app.
Data protection contact / privacy officer: support@stitchdaily.app.
What we collect, and why
| Data | Why | Legal basis (UK/EU) | Kept for |
|---|---|---|---|
| Phone number | To sign you in with a text-message code. There are no passwords. | Performance of our contract with you | Until you delete your account |
| First name | So your person sees who wrote each answer. | Contract | Until you delete your account |
| Your answers and reactions | The whole point. Visible only to the people in your thread, and only once enough of you have answered. | Contract | Until you delete your account |
| Time capsule note | Sealed for a year, then shown back to you. Nobody else can read it. | Contract | Until you delete your account |
| Time zone offset | So a pair in two countries gets the same question on the same day, and your reminder arrives in your morning. | Contract | Until you delete your account |
| Push notification token | For notifications about your own threads: the morning question, an evening reminder if it is still open, when your person answers, and a nudge from them. You choose the hour, or turn the daily ones off. | Consent (you can turn notifications off) | Until you turn them off or delete your account |
| Usage & diagnostics | Which screens get used and whether things crash. Never your answers. | Consent — You → Your data → Help improve Stitch | Up to 14 months (Google Analytics retention) |
| Purchase records | To unlock a group thread you paid for, and to remove it if you are refunded. | Contract; legal obligation (tax records) | Up to 7 years where tax law requires |
| Advertising identifiers | Stitch is free and paid for by short, optional rewarded videos. | Consent (EEA/UK); opt-out elsewhere | Set by Google — see their policy |
| Ad records we keep ourselves | One row for each ad you watch — which reward it was for, what it earned, and when — so we know whether the free version pays for itself. It is tied to your account rather than kept anonymously, so that deleting your account deletes these too. | Legitimate interests (running a sustainable free app) | Until you delete your account |
Who else touches it
We keep the list short on purpose. Each of these acts as our processor or, where marked, as an independent controller:
- Google Firebase (authentication, database, notifications, analytics, crash reporting) — processor. Data is stored on Google Cloud in the United States.
- Google AdMob and the ad networks that fill its inventory — independent controllers for the advertising data they receive. Their policy.
- RevenueCat — processor, for the one-time group thread purchase. It receives a purchase identifier, not your answers.
- Apple and Google Play — independent controllers for payments; we never see your card.
International transfers. If you are in the UK, EEA, Switzerland, Canada, Australia or New Zealand, your data is transferred to and stored in the United States. For UK/EEA transfers we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum), which are part of our agreement with Google. You can ask us for a copy of the safeguards.
Ads, and what "sale" means
Stitch has no subscriptions and no coins. The only way we make money is a short video you can choose to watch, to unlock a bonus question, a shuffle, or a streak repair — plus one optional $2.99 group thread. We never show ads you didn't ask for.
When you watch one, AdMob and the network that filled it may receive your device's advertising identifier, approximate location derived from your IP address, and basic device details. On iOS we ask first, through Apple's App Tracking Transparency prompt. In the UK, EEA and Switzerland we ask for consent through Google's form.
Do not sell or share my personal information. We do not sell your answers, ever, and we never will. But under California's CCPA/CPRA — and under the "targeted advertising" rules in Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Delaware, Florida, Iowa, Minnesota, Nebraska, New Hampshire, New Jersey, Tennessee, Utah and Maryland — showing you a personalised ad counts as "sharing" or "selling" personal information. You can switch that off, and still use every part of the app:
- In the app: You → Your data → Ad privacy choices.
- iOS: Settings → Privacy & Security → Tracking → turn off for Stitch.
- Android: Settings → Google → Ads → Delete advertising ID.
We honour Global Privacy Control signals where the law requires it. We do not knowingly sell or share the personal information of anyone under 16.
What we don't do
- We don't sell your answers, and we don't share them with advertisers.
- We don't read your answers. Security rules limit access to the people in a thread; a partner's answer is unreadable — to them and to our own database queries — until the gate opens.
- We don't use your answers to train anything, and we don't send them to any AI service. The daily questions are written in advance by people.
- We don't profile you to make decisions about you. There is no automated decision-making with legal or similarly significant effects.
- We don't message the number you sign in with, other than the one-time code.
Your rights, and how to use them
Get a copy. In the app: You → Your data → Download a copy of my data. It builds a machine-readable file of your profile, threads, answers and capsule on the spot. Answers written by other people are listed but not reproduced — those are theirs.
Delete your account. In the app: You → Delete my account. This permanently erases your profile, every answer you wrote, your capsule and your sign-in. The people you were paired with keep their own answers.
Correct something. Change your name in the app; email us for anything else.
Object, restrict, or withdraw consent. Turn off analytics and ad personalisation in the app, notifications in your phone's settings, or email us.
Ask a human. support@stitchdaily.app. We answer within 30 days (45 in the US states that allow it), free of charge, and we will never treat you differently for asking.
You may use an authorised agent. We may need to verify who you are before acting — usually by asking you to confirm from the phone number on the account.
If you think we got it wrong, you can complain to your regulator, and we would rather you told us first:
- UK: Information Commissioner's Office, ico.org.uk.
- EEA: your national data protection authority.
- Canada: Office of the Privacy Commissioner, priv.gc.ca; in Quebec, the Commission d'accès à l'information.
- Australia: Office of the Australian Information Commissioner, oaic.gov.au.
- New Zealand: Office of the Privacy Commissioner, privacy.org.nz.
- US states: your state Attorney General. In several states you may appeal a refusal by replying to our decision; we will respond within 45 days.
Security, and what a breach means
Data is encrypted in transit and at rest by Google Cloud. Access to production is limited and logged. If a breach ever puts you at risk, we will tell you and the relevant regulator within the time the law allows — 72 hours for the UK and EEA, and as soon as practicable under the Australian, New Zealand and Canadian regimes.
Children
Stitch is for adults and older teens: 13+, or 16+ in the EEA and anywhere else local law sets a higher age for consent. We don't knowingly collect data from younger children. If you believe a child has signed up, email us and we will delete the account.
Changes
If this policy changes in a way that matters, we'll say so in the app before it takes effect. The date at the top is always the current version.