Never uploaded
Source photos, source file names, your full bead inventory, and undo history stay on your device.
Your source photo never leaves your browser. We receive limited technical requests, anonymous aggregate feature counts, and information you choose to send through sharing or email.
Last updated:
Source photo → pattern workspace → local export
Optional share data, anonymous aggregate counts, support messages, and technical requests only
Source photos, source file names, your full bead inventory, and undo history stay on your device.
A share link sends a compressed bead grid and optional details. Email opens your own mail app.
No account, advertising cookies, third-party analytics, or cross-site behavioral tracking. We keep only anonymous aggregate feature counts.
Most of the pattern maker runs entirely in your browser. Image decoding, color matching, editing, bead counts, PNG export, and print/PDF preparation happen on your device.
The application code does not set cookies. Browser storage keeps language and progress settings, same-session link reuse, anonymous metric delivery markers, and share recovery data: pending pattern data only until confirmation, plus a completed share's SHA-256 content fingerprint, random share ID, and deletion credential until deletion or site data is cleared. You can clear this storage in your browser.
Before a new share request, the creating browser saves the pending pattern data, random share ID, and a separate deletion credential so a lost response can be retried safely. After confirmation, the pending pattern data is removed; the browser keeps the content fingerprint mapped to the random share ID, plus the separate deletion credential, so the same completed link can be recovered across tabs. The credential is not part of the public share link or QR code.
Anonymous product metrics count a small set of successful milestones, fixed error codes, and structured feedback. We do not create user identifiers, store event-level histories, or include your image, pattern contents, file name, title, or author.
We do not sell personal information or share it for cross-context behavioral advertising. Because there is no such sale or sharing, Global Privacy Control and Do Not Track signals do not change the site's behavior.
| Information | Where it is handled | Why | Retention |
|---|---|---|---|
| Source photo and file name | Your browser only | Convert and edit the pattern | Until you reset, close, or refresh the page |
| Language preference and build-along progress | Browser localStorage | Remember language, progress, and a dismissed tip | Until you clear site data; completed build progress is removed |
| Share-link reuse record | Browser sessionStorage | Avoid creating duplicate links in the same tab session | Until the tab session ends or you clear site data |
| Anonymous metric delivery markers | Browser sessionStorage | Avoid counting the same milestone twice in one tab session | Until the tab session ends or you clear site data |
| Pending share request and creator deletion credential | Browser localStorage | Safely retry an unconfirmed creation and authorize deletion | Pending request data until creation is confirmed; credential until deletion or site data is cleared |
| Confirmed share SHA-256 content fingerprint and random share ID | Browser localStorage | Recover the same completed link across tabs without storing the pattern, QR code, or deletion credential in this receipt | Until that share is deleted or you clear site data |
| Shared pattern | Vercel Private Blob, retrieved through our API | Reopen the bead grid from an unlisted capability link | Pattern data has no automatic expiry today and is kept until deletion or service retirement; after deletion, a minimal marker remains to prevent recreation |
| Technical request data | Vercel hosting and short-lived runtime logs | Deliver, secure, rate-limit, and debug the service | Application runtime logs are currently available for up to one hour on the Hobby plan; provider security records follow Vercel's policies |
| Anonymous feature metrics and structured feedback | Daily aggregate counters in Upstash Redis through our same-origin metrics API | Measure whether the requested workflow works and where fixed stages fail | Daily aggregate counters for up to 120 days; no user-level event history |
| Support email | Email forwarding and mailbox providers | Respond to your question or privacy request | Only as long as needed to resolve the request and keep essential records |
Browser storage is not sent to us merely because it exists. The page reads it locally to restore the feature you used.
When you request a page or API, Vercel may process standard technical data such as IP address, user agent, requested URL, time, status, and security signals. The locale endpoint uses Vercel's two-letter country header only to suggest a language and returns a no-store response.
Our share API writes logs with a request ID, stable result code, HTTP status, request size, and pattern cell count. It is designed not to log pattern contents, titles, author labels, Blob URLs, full share URLs, deletion credentials, or credential hashes.
The metrics API accepts only documented event names and fixed enum values, then immediately increments daily aggregate counters in Upstash Redis. It rejects extra fields and does not log event payloads.
We use Vercel to host the site, API, and private share storage, and Upstash to keep anonymous aggregate counters. Support email is forwarded by Namecheap and then handled by the destination mailbox provider. These providers may process data in countries where they operate under their own terms.
We use information only to provide and improve requested features, keep the service secure and reliable, respond to messages, and meet legal obligations. We do not use automated decision-making or profiling.
Where applicable, we rely on legitimate interests to operate and secure the service, on your request or consent for optional sharing and support, and on legal obligations when required.
The core editor can be used without an account and without transmitting a source photo. If you are under 13 or under the digital-consent age where you live, ask a parent or guardian before creating a share link or emailing support.
Children should not enter a real name, contact information, school, or other identifying details in optional fields. A parent or guardian can ask us to delete a shared pattern or support message by contacting us.
You never need to attach the image you uploaded. Source photos stay in your browser, and support requests should not contain them.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to complain to a local authority.
Send requests to support@mybeadpattern.com. A complete share URL helps us locate data but does not prove creation. New shares should be deleted with the creator credential held by the creating browser. We cannot delete older shares or shares whose credential was lost because they have no reliable creator proof; support will not bypass this credential or ask for your source photo.
You can clear language, build, and session information yourself through browser site-data settings. You can also use the site without creating a share link or sending email.
Clearing site data also removes creator deletion credentials from that browser; it does not delete the online share itself. Delete the online copy first if you still need to revoke its link and QR code.
We use data minimization, strict share validation, private storage, random unlisted IDs, same-origin checks, rate limiting, and logs that omit pattern contents. No online system is perfectly secure.
We may update this policy if features, providers, or legal requirements change. We will change the date above and provide additional notice if a change materially affects how information is handled.
mybeadpattern is an independent, non-commercial project. For privacy questions, access requests, or deletion requests, email support.