Privacy // built into the workflow

Privacy, mapped clearly

Your source photo never leaves your browser. We receive limited technical requests, anonymous aggregate feature counts, and information you choose to send through sharing or email.

Last updated:

On your device

Source photo → pattern workspace → local export

Clear boundary
Our service

Optional share data, anonymous aggregate counts, support messages, and technical requests only

Never uploaded

Source photos, source file names, your full bead inventory, and undo history stay on your device.

Only when you ask

A share link sends a compressed bead grid and optional details. Email opens your own mail app.

No advertising profile

No account, advertising cookies, third-party analytics, or cross-site behavioral tracking. We keep only anonymous aggregate feature counts.

1. The short version

Most of the pattern maker runs entirely in your browser. Image decoding, color matching, editing, bead counts, PNG export, and print/PDF preparation happen on your device.

The application code does not set cookies. Browser storage keeps language and progress settings, same-session link reuse, anonymous metric delivery markers, and share recovery data: pending pattern data only until confirmation, plus a completed share's SHA-256 content fingerprint, random share ID, and deletion credential until deletion or site data is cleared. You can clear this storage in your browser.

Before a new share request, the creating browser saves the pending pattern data, random share ID, and a separate deletion credential so a lost response can be retried safely. After confirmation, the pending pattern data is removed; the browser keeps the content fingerprint mapped to the random share ID, plus the separate deletion credential, so the same completed link can be recovered across tabs. The credential is not part of the public share link or QR code.

Anonymous product metrics count a small set of successful milestones, fixed error codes, and structured feedback. We do not create user identifiers, store event-level histories, or include your image, pattern contents, file name, title, or author.

We do not sell personal information or share it for cross-context behavioral advertising. Because there is no such sale or sharing, Global Privacy Control and Do Not Track signals do not change the site's behavior.

2. What information goes where

Information Where it is handled Why Retention
Source photo and file name Your browser only Convert and edit the pattern Until you reset, close, or refresh the page
Language preference and build-along progress Browser localStorage Remember language, progress, and a dismissed tip Until you clear site data; completed build progress is removed
Share-link reuse record Browser sessionStorage Avoid creating duplicate links in the same tab session Until the tab session ends or you clear site data
Anonymous metric delivery markers Browser sessionStorage Avoid counting the same milestone twice in one tab session Until the tab session ends or you clear site data
Pending share request and creator deletion credential Browser localStorage Safely retry an unconfirmed creation and authorize deletion Pending request data until creation is confirmed; credential until deletion or site data is cleared
Confirmed share SHA-256 content fingerprint and random share ID Browser localStorage Recover the same completed link across tabs without storing the pattern, QR code, or deletion credential in this receipt Until that share is deleted or you clear site data
Shared pattern Vercel Private Blob, retrieved through our API Reopen the bead grid from an unlisted capability link Pattern data has no automatic expiry today and is kept until deletion or service retirement; after deletion, a minimal marker remains to prevent recreation
Technical request data Vercel hosting and short-lived runtime logs Deliver, secure, rate-limit, and debug the service Application runtime logs are currently available for up to one hour on the Hobby plan; provider security records follow Vercel's policies
Anonymous feature metrics and structured feedback Daily aggregate counters in Upstash Redis through our same-origin metrics API Measure whether the requested workflow works and where fixed stages fail Daily aggregate counters for up to 120 days; no user-level event history
Support email Email forwarding and mailbox providers Respond to your question or privacy request Only as long as needed to resolve the request and keep essential records

Browser storage is not sent to us merely because it exists. The page reads it locally to restore the feature you used.

4. Technical requests and service providers

When you request a page or API, Vercel may process standard technical data such as IP address, user agent, requested URL, time, status, and security signals. The locale endpoint uses Vercel's two-letter country header only to suggest a language and returns a no-store response.

Our share API writes logs with a request ID, stable result code, HTTP status, request size, and pattern cell count. It is designed not to log pattern contents, titles, author labels, Blob URLs, full share URLs, deletion credentials, or credential hashes.

The metrics API accepts only documented event names and fixed enum values, then immediately increments daily aggregate counters in Upstash Redis. It rejects extra fields and does not log event payloads.

We use Vercel to host the site, API, and private share storage, and Upstash to keep anonymous aggregate counters. Support email is forwarded by Namecheap and then handled by the destination mailbox provider. These providers may process data in countries where they operate under their own terms.

We use information only to provide and improve requested features, keep the service secure and reliable, respond to messages, and meet legal obligations. We do not use automated decision-making or profiling.

Where applicable, we rely on legitimate interests to operate and secure the service, on your request or consent for optional sharing and support, and on legal obligations when required.

5. Children and families

The core editor can be used without an account and without transmitting a source photo. If you are under 13 or under the digital-consent age where you live, ask a parent or guardian before creating a share link or emailing support.

Children should not enter a real name, contact information, school, or other identifying details in optional fields. A parent or guardian can ask us to delete a shared pattern or support message by contacting us.

You never need to attach the image you uploaded. Source photos stay in your browser, and support requests should not contain them.

6. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to complain to a local authority.

Send requests to support@mybeadpattern.com. A complete share URL helps us locate data but does not prove creation. New shares should be deleted with the creator credential held by the creating browser. We cannot delete older shares or shares whose credential was lost because they have no reliable creator proof; support will not bypass this credential or ask for your source photo.

You can clear language, build, and session information yourself through browser site-data settings. You can also use the site without creating a share link or sending email.

Clearing site data also removes creator deletion credentials from that browser; it does not delete the online share itself. Delete the online copy first if you still need to revoke its link and QR code.

7. Security, changes, and contact

We use data minimization, strict share validation, private storage, random unlisted IDs, same-origin checks, rate limiting, and logs that omit pattern contents. No online system is perfectly secure.

We may update this policy if features, providers, or legal requirements change. We will change the date above and provide additional notice if a change materially affects how information is handled.

Controller and privacy contact

mybeadpattern is an independent, non-commercial project. For privacy questions, access requests, or deletion requests, email support.

Email privacy support