Privacy policy
What data TRAMA processes, why, who it is shared with and how to control it.
Last updated:
1. Who is responsible for your data
The data controller is Jorge Morales López, tax ID (NIF) 77535351M, with address at Calle Cristóbal Colón, 48, 1º A, 41710 Utrera (Seville), Spain.
For anything related to your data, write to hola@tramastitch.com.
We have not appointed a Data Protection Officer: the law only requires one for public bodies and for organisations that process data on a large scale or special categories of data, which is not the case for TRAMA.
2. The short version
TRAMA stores what it needs so that your work follows you across devices: your patterns, your progress, your inventory and your journal. We do not sell your data, we show no advertising, and we share your content with no one unless you decide to publish it. We never ask you for the pattern PDFs you have bought.
3. What data we process, and why
Account
We process your email address, the name you choose to display and your password (stored encrypted by our authentication provider; we never see it). We need them to create your account, identify you, let you recover access and sync your work.
Your stitching content
When you use the app, the following is stored and linked to your account:
- Patterns, palettes and project folders.
- Stitching progress: marked cells, parked threads, bookmarks and per-section notes.
- Stitching sessions: when you stitched and how many stitches you made.
- Thread inventory, stock, storage locations and shopping lists.
- Journal entries, with the photos, GIFs or videos you attach.
- Images you generate with the AI assistant.
All of it is private by default. It only becomes visible to other people if you publish the project or mark a journal entry as part of your public story book.
Some data stays on your device only, on purpose, and is never uploaded — for example the Follow Along activity log.
Community
If you publish a project, we process the title, the description, the tags, the images and the progress you choose to show, together with the likes, saves and comments you receive or make. Also the public stitch count that appears in the stitchers’ ranking, and your participation in Stitch-Alongs (membership, shared progress and wall messages).
If you report someone else’s content, we store the report (which content and, if you write one, the reason), and we receive an email notice with the reported content and the name and identifier of the accounts involved, so that we can review it as soon as possible. The reported person is not told who reported them.
If you block someone, we store who you blocked and when, so that neither of you sees the other’s content. Nobody else can see that list, not even the blocked person.
Support and technical reports
Every time you import a pattern file (a PDF or a file from another program), the app sends us a technical record of the attempt so that we can detect and fix importer failures: the file name, its size and a fingerprint of it; the program that created the PDF, if the file states it; how the import ended and a few counts about the result (pattern size, number of threads and of pages); and the app version, the language and the model, operating system and memory of the device. That record never contains the pattern — not the grid, not the symbols, not the thread codes — and the file is not uploaded to our servers.
If an import fails, you can additionally send us a report from the app about how the file is built. You review it before sending it, and you can choose not to.
If you open a support ticket, we process what you tell us and any attachments you add.
TRAMA Pro subscription
If you subscribe, the purchase is made and charged by the store (App Store or Google Play). We never see or store your card or payment method details.
To know whether your subscription is active we use RevenueCat, which receives from the store and from the app:
- your purchase and subscription history in TRAMA: the plan, the purchase, renewal and end dates, cancellations and refunds, the amount, the currency, the country and the store of each purchase;
- the identifier of your TRAMA account, a random code that contains neither your email nor your name;
- the technical data inherent to any connection, such as the IP address.
We do not send RevenueCat your email, your name or any advertising identifier.
When the status of your subscription changes, RevenueCat notifies us. We store the plan and its dates in your account to give you access to TRAMA Pro, and a log of those notices so that we can resolve billing issues. The end date of your free trial is also stored in your account.
Notifications
If you enable alerts, we store a push notification identifier for your device. We use it to send you the reminders you have scheduled and the alerts of the Stitch-Alongs you take part in. TRAMA does not send marketing notifications of its own accord.
Technical data
Our infrastructure provider logs technical data about requests (IP address, timestamp, type of operation) for security purposes and to diagnose failures.
The app integrates no analytics, crash-reporting or advertising SDK.
4. Permissions the app asks for
| Permission | What for |
|---|---|
| Camera | Photograph an image you want to turn into a pattern, and scan thread skeins. |
| Photos | Choose images from your gallery and save the PDFs, PNGs, GIFs and videos you export. |
| Microphone | TRAMA does not record sound. The system may ask for this permission when using the camera; you can deny it without affecting any feature. |
| Notifications | Send you the reminders you schedule and the alerts of your Stitch-Alongs. |
All of them are optional and you can revoke them from the system settings. If you deny them, only the parts that depend on them stop working.
5. Legal basis for processing
- Performance of the contract: account, syncing of your content, social features you enable, and support.
- Consent: access to camera, photos, microphone and notifications; publishing projects and journal entries. You can withdraw it at any time.
- Legitimate interest: security of the service, abuse prevention, moderation of reported content and fixing importer failures (the technical record of each import).
- Legal obligation: where we are required to keep information under applicable law.
6. Who we share data with
We do not sell your data and we do not share it for advertising purposes. We work with these providers, which act as data processors:
| Provider | What for | Data involved |
|---|---|---|
| Supabase | Authentication, database and file storage | Account and all of your synced content |
| RevenueCat, Inc. | Management of TRAMA Pro subscriptions | Identifier of your TRAMA account and purchase/subscription history |
| OpenAI | Generating images with the AI assistant | The text you write, the style options you choose and, if you use one, the reference image |
| Anthropic | Suggesting ideas in the AI assistant and reviewing the quality of the generated images | The options you choose in the assistant, the titles already proposed and the generated image |
| Resend (Plus Five Five, Inc.) | Sending your account emails (confirmation and password recovery) and notifying us of content reports | Your email and the content of the message; in report notices, the reported content and the name and identifier of the accounts involved |
| Apple / Google | App distribution and delivery of push notifications | Device notification identifier |
| Cloudflare, Inc. and Google LLC | Receiving and storing the emails you send to hola@tramastitch.com | Your email address and the content of your message |
The AI assistant is switched off for now. While it is, nothing is sent to OpenAI or Anthropic.
When you pay for a subscription, Apple and Google process your purchase data (payment method, billing) as independent controllers, under their own privacy policies.
7. International transfers
Some providers may process data outside the European Economic Area. Where that happens, the transfer relies on the standard contractual clauses approved by the European Commission, or on an adequacy decision.
-
Supabase stores the database and the files in its West EU region (Ireland).
-
RevenueCat, Inc. processes subscription data in the United States, on Amazon Web Services and Snowflake servers. The transfer relies on the European Commission’s standard contractual clauses (module 2, controller to processor), included in its data processing agreement.
-
Resend (Plus Five Five, Inc.) processes emails in the United States. The transfer relies on the European Commission’s standard contractual clauses (module 2) included in its data processing agreement, and the company is certified under the EU–U.S. Data Privacy Framework.
-
OpenAI and Anthropic process data in the United States. While the AI assistant is switched off, nothing is sent to them; before switching it on we will update this policy with the specific mechanism covering the transfer.
-
Supabase server functions may run in the data centre closest to where the request comes from; stored data stays in Ireland.
-
The support mailbox goes through Cloudflare, Inc. and Google LLC, which may process emails in the United States under their standard contractual clauses and their EU-US Data Privacy Framework certification.
8. How long we keep data
We keep your account and your content for as long as the account is active. If you delete it, your personal content and your publications are erased immediately. They may still appear for up to 7 days in the daily database backups, which are overwritten within that period and are only ever used to restore the service after a serious failure. We will keep anything longer only where we must do so to comply with a legal obligation or to resolve an issue you have open with us.
Technical import records and reports are kept for 12 months while we work on improving the importer, and are deleted sooner if you delete your account.
The push notification identifier is deleted when you turn alerts off, sign out or uninstall the app.
The reports you make and the blocks you set are kept while you have an account and are deleted when you delete it. The report notices we receive by email are deleted once the case is closed.
Your subscription data is kept while you have an account. When you delete it, we delete the plan, its dates and the log of purchase notices, and we ask RevenueCat to delete your history. Purchase receipts are kept by Apple or Google under their own policies.
9. Cookies and automated decisions
This website uses no analytics or advertising cookies, and does not track your browsing. The app integrates no advertising SDK either.
Nor do we take automated decisions producing legal effects on you, and we do not build profiles for advertising purposes. The only automatic thing in the community is an offensive-word filter: if a text you are about to publish contains one, it is not published and the app tells you so that you can change it. It has no effect on your account. The suggestions the app makes — palettes, automatic layers, backstitch outlines — are design aids applied to your own pattern, not assessments about you as a person.
10. Your rights
You can exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent you have given.
Write to hola@tramastitch.com from your account’s address and we will reply within the legal time limit.
You do not need to write to us to delete your account: you can do it yourself from the app, under Profile → Delete account. Deletion is immediate and irreversible. If you cannot sign in, follow the instructions in Delete your account.
Deleting your account does not cancel your TRAMA Pro subscription, if you have one: it is billed by the store and you must cancel it there. We explain this in Delete your account.
If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es) or with the supervisory authority of your country.
11. Minors
TRAMA is not directed at people under 18 and we do not knowingly collect data from anyone below that age. If we find an account in that situation, we will delete it.
12. Security
Your data travels encrypted and access to the database is restricted by per-user policies: each person can only read and write their own, except for content that has been expressly published. No system is infallible; if a breach occurred that affects your rights, we would notify you as required by law.
13. We do not look at your patterns
Your private projects are shown to no one. The team does not access their content in day-to-day work; it could only do so if you expressly authorise it when opening a support case, or if a legal obligation required it.
That is why the PDF import report describes how your file is built, not what it draws: to fix the importer we do not need to see your pattern, and that pattern belongs to whoever designed it.
14. Changes to this policy
If we change anything relevant we will tell you inside the app before it takes effect. The date of the latest revision appears at the top of this page.