Privacy
REV 2026-07-26 · PLAIN LANGUAGE, THE WHOLE POLICY
WHAT WE COLLECT
If you request access: your email address, the time you asked, and your browser's user-agent string.
If you have an account: your email address, your name if your sign-in provider gives us one, and the public key of the passkey you registered. We never see a password, because there aren't any. Plus the patterns and documents you make, their thumbnails, and which view you had open.
Each time you sign in we store that session's IP address and browser, so we can tell your sessions apart and cut one off if it is ever stolen.
If you file a bug report from inside the app: what you wrote, the category you picked, the page you were on, your browser's user-agent, and your email if you left one. We keep a report until the bug in it is fixed, and then we delete it. If a bug goes unfixed, the report still goes after 365 days.
A security log of the actions that matter for keeping accounts safe: a sign-in attempt refused for coming too fast, a team member added, removed or changed, a share link minted or revoked, a document deleted or restored, an account deactivated, reactivated or deleted. Each entry records what happened, when, whether it succeeded, and the account and item identifiers involved. It holds no email address, no IP address, no name, and nothing from inside a pattern. We keep it for 400 days so we can look into abuse and work out what actually happened after a security incident, and then each entry is deleted automatically.
If you email [email protected]: whatever you send us. That's the complete list.
YOUR PATTERNS
Your patterns are yours. Nobody here reads them. Nothing trains on them. We do not sell them, rent them, or hand them to anyone, full stop. If you ask us for help with a specific file, we will ask before opening it.
The only people who ever see a pattern are the people you hand it to yourself, which is the next section.
You can export any pattern as production DXF at any time, which is the format the industry already runs on. Nothing you draw is trapped here.
WHEN YOU SHARE
Three things in the product show a document to someone else. You choose all three, and you can undo all three.
A team. Everyone you add to a team can open every document in that team's library. Owners and editors can change them, viewers can only look. We store the team's name, who is in it, and each person's role.
A share link. Minting one creates a secret web address that opens that one document, read only, with no sign-in. Anyone who has the address can read it, so treat a link you have sent as public. It stops working 30 days after you make it, you can revoke it sooner, and deleting the document kills it immediately.
Fit notes. A note you leave on a document stores its text, your name, and which piece it points at, so the rest of your team can read it. It reaches exactly as far as the document does.
While you and a teammate have the same document open, we hold your name in memory so each of you can see the other is there. It is never written down, and it is gone the moment you close the tab.
WHY
Your email exists so we can send you an invite and tell you about the product you asked for, and nothing else. Asking for access is your consent to receive that; every email we send includes a way out. An account exists to keep your patterns where you left them.
ANALYTICS
Cookieless, aggregate page analytics (Cloudflare Web Analytics). No cookies, no fingerprinting, no cross-site tracking, no ad pixels. We see visit counts, not you.
WHERE IT LIVES
Your account and your patterns live on our Cloudflare account. These are the companies that process a piece of your data for us:
Backblaze holds our backups, in the United States. They
are encrypted before they leave us, so Backblaze cannot read them.
Resend sends our email, so it handles your address when we write to
you.
Google, only if you choose to sign in with Google, and only to confirm
your email is really yours.
Stripe processes subscriptions, so it handles payment and billing
identifiers, not your pattern files.
Fly.io provides transient compute. Selected pattern and export payloads
pass through it while the app runs imports, grading, and exports.
Cloudflare runs the site, the app, storage, and the analytics above.
Nobody on that list is allowed to sell, share, or rent your data, and neither are we.
DEACTIVATION
Deactivating is not deleting, and the difference is the point. Account settings let you take your account offline instead: we sign you out everywhere, stop serving every document you shared, and stop anyone reaching your account at all. Nothing is erased. Your patterns, their saved versions, your fit notes and your team memberships stay exactly as you left them, and we go on holding them for you.
Sign in again with your passkey or with Google and confirm, and it all comes back. There is no deadline on that, and we will not quietly delete a deactivated account. If you want the data gone rather than paused, deleting is the separate and permanent choice below.
Deactivating does not stop a paid subscription. Your money is not your data and we will not touch it without being asked, so a subscription left running keeps charging you. Cancel it before you deactivate, or use the billing link we show you on the deactivated account.
DELETION
Account settings in the app are the primary way to delete your account. Live deletion begins immediately after you reauthenticate with your passkey or with Google. Your account, your patterns, their saved versions, and your fit notes are removed, and every share link you minted stops working. Some live-system cleanup may drain asynchronously, but it finishes within seven days.
Asking to delete also sends a confirmation link to your verified email. That is deliberate: a deletion request you did not make should be visible to you rather than silent. Following the link still asks you to sign in again before anything is removed, so the email on its own deletes nothing.
Deleting also cancels a paid subscription straight away, and time you have already paid for is not refunded. That is why the app offers to cancel your subscription first, so you can use what you bought and close the account afterwards.
If you cannot authenticate, email [email protected] from the address you signed up with so we can verify the request and help.
We use your verified email while your user-account deletion is being completed, then remove it from our live deletion evidence when the deletion completes. We keep non-email evidence that your user-account deletion completed for 400 days for security, compliance, and dispute handling, then it is automatically deleted.
The security log described at the top of this page also outlives your account, and that is deliberate. Its entries run their full 400 days from when each one happened, whether or not you are still here, because a log you could erase by closing your account would be worth nothing in the situation it exists for. What stays is a record that an action occurred and the account identifier that did it. It never held your email address, your name, or your IP, so what remains cannot be read back into you by anyone who does not already hold that identifier.
One honest caveat: our backups are write-once on purpose, so that a mistake or a break-in cannot erase your work. A deleted pattern can still sit in an encrypted backup nobody can read for up to 30 days after it leaves the live product, and then it ages out for good.
IF WE ARE BREACHED
If someone gets at your data and there is a real risk of harm to you, we tell you and the Office of the Privacy Commissioner of Canada, as the law requires. You get what we know, when we know it, and what to do about it. We would rather send you an awkward email than let you find out later.
CHANGES
This is revision 2026-07-26. If we ever collect something new or add a company to the list above, this page changes first and we tell every account holder.
TERMS
The rules for using the product itself (payment, sharing, what happens if an account closes) live on the terms page.