Privacy policy
Last updated:
Under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), for the Hoopy app for iPhone and Android and for this website. If this translation and the Italian version differ, the Italian version prevails.
In short
- Your photos, drawings, projects, fonts and embroidery files stay on your phone. They never reach our servers.
- We don't store your email or your name. Of your Apple or Google sign-in we keep only an encrypted fingerprint that doesn't tell us who you are.
- We process a small amount of technical data, only to run the plans: counting designs, recognising purchases, preventing abuse.
- The data lives on Cloudflare, with the database in the European Union. Purchases go through Apple and Google only, via RevenueCat.
- You can delete your account from the app at any time.
1. Who the controller is
The controller is [RAGIONE SOCIALE], registered office at [SEDE], VAT number [PARTITA IVA] (“we”, “us”). For any question about this policy or your data, email us at [EMAIL DI CONTATTO].
[DPO: state whether a data protection officer has been appointed and how to reach them, or delete this sentence]
2. What stays on your phone
Hoopy is built so your work never leaves your phone. The engine that turns pictures into stitches runs inside the app, even offline. We do not receive, see or keep:
- the photos, drawings, logos or other pictures you pick;
- the words of your lettering, your projects, the fonts you import, or the embroidery files you open or export;
- the email and name Apple or Google associate with your sign-in. The app keeps them on the phone only, to show them in your profile.
When you save or share a file, you send it where you choose (a messaging app, for example), and from then on that service's privacy policy applies.
3. What data we process
To run your account and plans, the app talks to a service of ours (the “account cloud”). Every request is signed with a key created in your phone's security chip, which never leaves it. The account cloud processes the following:
a) Your account ID
The first time you open the app, it creates an anonymous account: a random ID that contains nothing about you. It's also the ID RevenueCat uses to recognise your purchases.
b) Signing in with Apple or Google, if you do
Signing in is optional. If you sign in, the app sends us the sign-in token issued by Apple or Google. The token contains your ID with that provider and may also contain your email. We verify it and keep only an HMAC fingerprint of the ID, computed with a secret key: we store neither your email nor the ID in readable form, and the token itself is not kept. The fingerprint lets us find your account again on another phone.
c) Your devices
For each phone: an ID, its public key (the private key stays on the phone), the platform (iOS or Android), when it registered and last checked in, the results of integrity checks (point f), and whether the welcome designs have already been used on that phone.
d) Designs, tokens and receipts
To count your plan's designs even while you work offline, the account cloud gives your phone signed single-use tokens and gets back a “usage” record for every new design: the token used, the phone, the time, the type of content (picture or lettering) and its SHA-256 fingerprint. The fingerprint is a code computed from the content. It lets us recognise content you've already paid for, so exporting it again stays free, but the picture can't be rebuilt from it. For lettering the fingerprint is computed from the text; with very short texts, like a name, someone who had it could in theory check whether it matches a text they guessed. We also keep the signed receipts for content you've paid for.
e) Subscriptions and purchases
For your plan and top-ups we know the product, the store, the original transaction ID, the start and expiry dates, the status (active, cancelled, expired, refunded…) and whether it renews. This reaches us from RevenueCat, which gets it from Apple or Google. We never receive your card or payment details: the store handles payment.
If you use a discount code, we keep the code, the offer, when it was reserved and redeemed and by which account, and a note of who handed it out (a shop, for example).
f) Integrity checks
To protect the plans' limits, the app asks Apple (App Attest and DeviceCheck) or Google (Play Integrity) to confirm that it's the genuine app and that the phone hasn't been tampered with. We receive and check the result. With DeviceCheck and Play Integrity's “device recall”, Apple and Google keep two bits for us tied to the phone, which survive reinstalling the app. We use them only to know whether the welcome designs have already been used on that phone.
g) Security reports
We log cases that may point to abuse or an error (for example a subscription used on too many phones, a token used twice, a signature that doesn't check out, a purchase that arrived before the account), with the account ID and the technical details needed to understand them.
h) Connection data
Like any internet service, when the app or your browser connects, Cloudflare processes your IP address and the technical details of the request to deliver it and protect it from attacks. We don't store IP addresses in the account database. The service's technical logs are kept by Cloudflare for a short time [CHECK: Workers Logs retention for the Cloudflare plan in use].
i) This website
This website uses no cookies and no visitor analytics, loads no fonts, scripts or content from other sites, and has no forms. It's served by Cloudflare Pages, which processes connection data as described in point h.
4. Why we process it, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the app, your account, the welcome designs and the plans you buy, including offline | a, b, c, d, e | Performance of a contract (Art. 6(1)(b) GDPR) |
| Finding your account, plan and paid designs on another phone | a, b | Performance of a contract (Art. 6(1)(b)), at your request when you sign in |
| Handling discount codes | e | Performance of a contract (Art. 6(1)(b)) |
| Protecting the plans' limits and preventing abuse and fraud | c, d, f, g | Legitimate interest in a fair, sustainable service (Art. 6(1)(f)) |
| Delivering the service and the website, and defending them from attacks | h, i | Legitimate interest in security (Art. 6(1)(f)) |
| Meeting legal obligations, such as accounting, or answering the authorities | e | Legal obligation (Art. 6(1)(c)) |
The information the app reads or stores on your phone (the device key, integrity proofs, tokens) is strictly necessary to provide the service you ask for. We don't profile you, we don't use your data for advertising, and we don't sell it. We don't take decisions based solely on automated processing that have legal effects on you: turning down a token or a welcome design only affects use of the service, and you can always write to us.
Providing the data is optional, but without the data in section 3 we can't give you the welcome designs or the plans. Opening, resizing and converting embroidery files works without signing in.
5. Who we share it with
We don't share your data with anyone except these providers, and only as far as needed:
- Cloudflare, Inc. hosts the account cloud (Cloudflare Workers) and its database (Cloudflare D1, created in the European Union jurisdiction), and this website (Cloudflare Pages). It acts as our processor.
- RevenueCat, Inc. manages purchases, renewals and restores and verifies store receipts. It receives the anonymous account ID and purchase data from the stores. It acts as our processor.
- Apple provides the App Store and payments, Sign in with Apple, App Attest and DeviceCheck. For its own services Apple acts as an independent controller under its own privacy policy.
- Google provides Google Play and payments, Sign in with Google and Play Integrity. For its own services Google acts as an independent controller under its own privacy policy.
[CHECK: roles, contracting entities and data processing agreements (DPAs) with Cloudflare and RevenueCat]
6. Transfers outside the European Union
The account database is in the European Union. Some providers are based in the United States (Cloudflare, RevenueCat, and the parent companies of Apple and Google) and may process data outside the Union, for example for support, security or to run their services. In those cases the transfer relies on the European Commission's adequacy decision for the EU-US Data Privacy Framework, for providers certified under it, or on the standard contractual clauses approved by the Commission. [CHECK for each provider]
7. How long we keep it
- Account, devices, designs, tokens, receipts, top-ups and security reports: for as long as the account exists. When you delete it (section 9) we erase them from the database straight away. [TO DECIDE: how long before inactive anonymous accounts are deleted, e.g. 24 months after last check-in]
- Tokens and permits expire on their own within seven days; unused ones go back into the quota.
- Subscriptions: when you delete your account, the subscription record (product, dates, store transaction ID) stays with no link to any account, because the subscription belongs to the store and must remain restorable. [TO DECIDE: how long to keep it after expiry]
- Redeemed discount codes and the IDs of events received from RevenueCat: for as long as needed to stop the same code or event counting twice. [TO DECIDE]
- Data needed for legal obligations: for the period the law requires.
When you delete your account, we also ask RevenueCat to delete the matching customer. Data that Apple and Google keep for their own services (such as purchase history or the two DeviceCheck and Play Integrity bits) follows their rules.
8. Your rights
You can ask us at any time to access your data, correct or erase it, restrict its processing, receive it in a machine-readable format (portability) and object to processing based on legitimate interest. Email us at [EMAIL DI CONTATTO].
Since we know neither your name nor your email, we may ask you for details that help us identify your account, or ask you to make the request from the app. We'll reply within one month.
If you believe the processing breaches the GDPR, you can lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the authority of the country where you live or work.
9. How to delete your account
In the app, open your Profile (the button at the top right of the project list), choose Delete my account and confirm. The account cloud immediately erases your account, phones, design count, receipts, tokens and top-ups. Projects on your phone stay there; to remove them, uninstall the app.
Deleting your account does not cancel your subscription: do that from your Apple or Google account settings. Welcome designs you've already used don't come back if you delete your account.
10. Children
Hoopy is not meant for children under 14 and does not knowingly collect their data. [CHECK the minimum age and the store age ratings] Purchases are subject to Apple's and Google's rules and parental controls. If you think a child has given us data, let us know and we'll delete it.
11. How we protect your data
We collect the bare minimum. The app's requests are signed with a key that stays in the phone's security chip; tokens, permits and receipts are signed by the account cloud; of sign-ins we keep only an HMAC fingerprint; the database has no public address and only our service can reach it. No measure is perfect: if a breach affecting you ever happens, we'll tell you as the law requires.
12. Changes to this policy
If we change how we process data, we'll update this page and the date at the top. If the changes are significant, we'll also tell you in the app.
13. Contact
[RAGIONE SOCIALE], registered office at [SEDE], VAT number [PARTITA IVA]. Email: [EMAIL DI CONTATTO].