Privacy Policy
Sprinting Bobbin Studio
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Sprinting Bobbin Studio stores your project names, garment photos, stop snapshots, fabric labels, machine settings, materials, storage notes, operations and dependencies, completion history, restart checks, templates and workshop preferences on your iPhone. Reminder dates and project names are used for local notifications. The app creates a random installation secret in the device Keychain when backup is used. If you enable backup, the app sends an encrypted copy of the journal, including photos, to our backend and sends a separately derived authorization token over HTTPS to authorize that request. The server stores the encrypted copy under a hash of the authorization token; it does not receive or store the device secret or the plaintext journal. Requests for educational puzzles and public pages also reach the hosting infrastructure, which receives network information such as IP address, request time and requested route. The app has no user accounts, advertising or analytics SDKs.
How we use information
Local information lets you resume a sewing project, plan operations for the time available, save a stopping point, review history and reuse templates. Optional backup allows you to restore the last encrypted journal on a device that still has the same installation secret. We do not promise recovery after reinstalling or losing that secret. Public puzzle requests update educational content, with bundled content available offline. Local notifications remind you of a return time that you explicitly choose. Hosting and minimal operational error logs are used to run and diagnose the service.
Service providers and sharing
Railway hosts the backend and its persistent storage and handles network requests as an infrastructure provider. Railway infrastructure may process request metadata and operational logs. The application server logs startup information and request identifiers with error codes for server failures, without journal contents or installation secrets. The journal is encrypted on the device before transmission; the backend does not have the derived encryption key. There are no advertising, analytics, email delivery or social sign-in recipients. If you use system photo sharing, the destination you select receives the image under its own practices. Apple provides the device photo picker, camera permission controls, Keychain and local notification services; scheduled reminders are local rather than a remote push service.
Data retention
The local journal remains until you delete projects or all local data, or remove the app subject to iOS storage and backup behavior. The server keeps one latest encrypted journal per installation secret until it is replaced or you delete the server backup. Turning backup off stops uploads but does not delete a stored copy. No automatic expiration period is implemented. The app does not set a fixed retention period for Railway infrastructure logs or infrastructure recovery copies, and we do not claim a deletion schedule for those provider-managed records. No scheduled application-level backup of the server volume is configured. iOS device backups may include local application files depending on your device settings; the installation secret uses a device-only Keychain accessibility setting and does not migrate to another device.
Deleting your information
You can delete a project in its detail screen after confirmation. When backup is enabled, a later successful upload replaces the server journal with the updated copy; until then the old encrypted backup may still contain that project. Settings offers Delete server backup, which switches off uploads and removes the live encrypted record, and Delete all local and server data, which confirms server deletion before clearing the local journal and pending reminders. If the server cannot be reached, the app retains local data and reports that deletion was not confirmed so you can retry. These controls do not delete images that were already in your photo library or copies you separately shared or retained in device backups. Provider-managed logs and recovery copies are separate from the live record and are not guaranteed to be immediately erased by the app. The Keychain secret is retained to avoid falsely promising recoverability or creating a new identity during a failed deletion.
Permissions and your choices
Camera access is requested only when you choose Take photo and is used to photograph your sewing work. The system photo picker lets you select individual pictures without giving the app unrestricted library access. A system share action can save or send a picture only when you choose that destination. Notification permission is requested only when saving a reminder. You can withdraw camera or notification permission in iOS Settings and remove reminders in the app. Refusing these permissions does not prevent ordinary project and operation editing; you can choose a library photo instead of using the camera. No location, contacts, microphone or tracking permission is requested. Backup is optional and can be switched off in Settings.
Your privacy rights
For privacy questions or applicable access, correction or deletion requests, contact Flavia91Irecombe@icloud.com. You can view and edit your local journal and use the deletion controls without creating an account. Rights under applicable law may include access, correction, deletion, objection or a complaint to a competent data protection authority. Because the server holds encrypted records indexed by an installation-secret hash rather than your name or email, we may be unable to identify or decrypt your record from an email address alone. Never send your installation secret by email. The supplied address is a public privacy contact, not an in-app messaging or account service.
Security
The app uses iOS protected local file storage, atomic journal writes, a random 32-byte device Keychain secret and HTTPS for backend communication. Backup encryption uses AES-GCM with a 256-bit key derived from that secret using HKDF-SHA256. A one-way, purpose-separated SHA256 derivation produces an authorization token without sending the encryption secret. Each authorized server request can access only the record indexed by its own authorization-token hash; another installation cannot read or delete it. The backend validates tokens and data format, limits request size and uses atomic storage writes. No common client credential is shipped. Anyone who obtains the device installation secret could authorize requests and derive the encryption key; someone who obtains only the derived authorization token could read or delete ciphertext but cannot derive the encryption key, so protect your device and do not share the secret. No system can guarantee absolute security or availability.
Children’s privacy
This sewing journal is designed for adult home sewists and is not directed to children. It does not ask for age or knowingly create child profiles. If you believe personal information about a child has been submitted, contact Flavia91Irecombe@icloud.com; use the app deletion controls where possible because server journals are encrypted and not indexed by a person's name.
Changes to this policy
We may update this policy when the app's actual processing or hosting changes. The current policy is published on this page with its effective date and linked from app Settings. Material changes will be reflected in the policy and relevant app information. Review this page periodically and contact Flavia91Irecombe@icloud.com with questions.