Privacy Policy
Last updated: July 27, 2026
StitchSpeak is operated by Innovai Studio S.L. ("StitchSpeak", "we", "us"). This policy explains how we handle personal data when you use StitchSpeak to translate, save, export, and discuss knitting or crochet patterns.
Contact for privacy requests: support@stitchspeak.com. Innovai Studio S.L. is based in Spain. If you need company registration, tax, or postal details for a formal request, contact us and we will provide the applicable details.
1. Data controller
Innovai Studio S.L. is the data controller for the personal data described in this policy, unless a third-party provider acts as an independent controller for its own service, such as Lemon Squeezy checkout or Google sign-in.
2. Information we process
- Account data: your email address and name, plus a password hash for email accounts; or basic Google account information such as Google user ID, name, email address, and profile image.
- Pattern files: files you upload for translation, including PDFs, DOCX, TXT, or RTF files.
- Generated content: translated HTML, extracted text, thumbnails, export metadata, glossary lookups, and chat messages about a translated pattern.
- Credit and payment records: credit balance, checkout session references, Lemon Squeezy webhook event IDs, order references, and transaction metadata needed to grant credits and avoid duplicate grants.
- Technical data: secure session identifiers, local guest history, aggregated metrics, error status, timestamps, and request IDs needed to operate and secure the service. Request logs do not intentionally include pattern content or resource identifiers.
- Legal acknowledgements: the version and timestamp of the assisted-processing notice confirmed before a translation.
3. Why we use your data
- To provide the service: translate uploaded patterns, preserve layout, save your library, export files, and provide assisted chat about a pattern.
- To manage your account: keep you signed in, associate saved patterns with your account, and sync history across sessions.
- To process payments and credits: create checkout sessions, receive verified payment webhooks, grant credits, and prevent duplicate credit grants.
- To improve reliability and security: debug errors, prevent abuse, maintain service availability, and protect API keys server-side.
- To respond to requests: handle support, deletion, access, or correction requests.
4. Legal bases
Where GDPR applies, we rely on performance of a contract to provide paid and account features, legitimate interests to secure and improve the service, legal obligations for payment and accounting records, and consent where a feature specifically asks for it.
5. Assisted processing
Translation, glossary lookup, chat, and grading features are processed through the StitchSpeak server using Google Gemini. Assisted tech editing is processed through the StitchSpeak server using the OpenAI API. API keys are kept server-side and are not exposed in the browser. Uploaded files and extracted pattern content may be sent to the relevant processing provider solely to provide the feature you request.
Before translation starts, StitchSpeak shows an in-context notice and requires you to acknowledge this transfer and the need to review assisted output. Under the current Gemini API terms applicable in the EEA, Google states that prompts, files, and responses handled under Paid Services are not used to improve its products. Google may retain limited data for abuse monitoring under its terms. See Google's Gemini API terms and data-retention documentation.
For assisted tech editing, OpenAI states that API inputs and outputs are not used to train its models by default. Responses are requested without application storage; OpenAI may retain limited abuse-monitoring data under its applicable controls and terms. See OpenAI's API data-controls documentation.
6. Payments
Credit purchases are handled by Lemon Squeezy checkout. Lemon Squeezy may process payment details as an independent provider under its own terms and privacy policy. StitchSpeak stores the information needed to reconcile orders, credit balances, and webhook events.
7. Storage and retention
If you are signed in, StitchSpeak may store your source files, translated patterns, thumbnails, chat history, and credit balance so they are available across sessions. Guest history may be stored locally in your browser. Active account data is kept until you delete it or your account, subject to legal needs. Account deletion removes credentials, patterns, chats, source files, thumbnails, acknowledgements, and remaining credits. Required payment records are retained with an anonymized identifier. Encrypted disaster-recovery backups are retained for up to 30 days, so deleted data may remain inaccessible within a backup until it expires. Expired browser sessions, verification/reset tokens, and abandoned processing locks are removed automatically at least every six hours. You can download your data or delete your account from the account menu.
8. Local storage and cookies
StitchSpeak uses a Secure, HttpOnly, SameSite authentication cookie that JavaScript cannot read. Browser storage is used for guest history, temporary workflow hints, and preferences, not authentication secrets. Payment and sign-in providers may use their own cookies or storage when you interact with them.
9. Sharing and subprocessors
We do not sell your personal data. We share data only with providers needed to operate StitchSpeak: Railway and Vercel for hosting, Cloudflare R2 for encrypted backups, Google for sign-in and Gemini processing, OpenAI for assisted tech editing, Resend for account email, and Lemon Squeezy for checkout and payment reconciliation.
10. International transfers
Some providers may process data outside Spain or the European Economic Area. Where required, transfers use an adequacy decision, Standard Contractual Clauses, or another lawful safeguard offered by the provider.
11. Your rights
Depending on where you live, you may request access, correction, deletion, portability, restriction, or objection to processing of your personal data. Email support@stitchspeak.com to exercise these rights. If you are in Spain or the EU, you may also lodge a complaint with your local supervisory authority, including the Agencia Española de Protección de Datos (AEPD) at aepd.es.
12. Automated decisions
StitchSpeak does not use personal data to make decisions producing legal or similarly significant effects. Assisted features generate suggestions; you decide whether and how to use the output.
13. Changes
We may update this policy as StitchSpeak evolves. The date above shows the latest version.