Uzora is a local-first cross-stitch companion. It has no advertising and does not track you across other companies’ apps or websites. No account is required for core use.
Data stored on your device
Imported pattern files and derived thumbnails, stitching progress, sessions, notes, journal attachments, and app preferences are stored in the app’s private storage. They may be included in your device backup according to Apple’s backup settings. Backup files you export go only where you choose to share them.
Uzora also stores the access tier, subscription expiry, elapsed paid subscription coverage, and recent Plus PDF-import timestamps locally so it can enforce the features shown in the app.
Purchases and subscriptions
Apple processes all in-app purchases and subscription payments. Uzora requests localized product information and verified transaction history from StoreKit to unlock and restore a subscription and to determine whether it is currently active. Uzora does not receive or store card or bank details, your Apple Account password, or a full purchase receipt.
Apple handles subscription renewal, management, cancellation, and refunds under your Apple Account. A failed or cancelled purchase does not upload payment data to Uzora.
Optional sync
A build may offer opt-in cloud sync. It remains inactive until you sign in and enable it. When enabled, your email address authenticates your account and your selected chart and progress data is stored so your own devices can restore it. It is not shared with other users or used for advertising. You can sign out at any time.
Optional failed-file diagnostics
If Uzora cannot open a supported chart, the error screen may offer Send file to the developers. A failed import never uploads anything automatically. Uzora first asks you to confirm that the original file may contain copyrighted or personal information.
If you confirm, the original file, its filename, the app version and build, operating-system version, and technical import error are uploaded to a private Supabase Storage bucket. App clients have write-only access: they cannot list, download, replace, or delete reports. Uzora’s developers and diagnostic tools use a report only to reproduce the failure and improve file compatibility. Reports are not published, shared with other users, used for advertising, or added to a permanent test corpus without separate permission. They are deleted when no longer needed and always within 90 days.
The app shows a diagnostic ID after sending. Email that ID to support to request earlier deletion.
Product analytics
Product analytics is on by default for new installations and can be turned off at any time in Settings. If you installed Uzora while analytics was opt-in, it stays off until you answer the one-time question the update shows you. It sends a small allowlisted set of product events: for example whether onboarding or an import succeeded, whether the first stitch was marked, which tools and broad feature actions get used, the install channel and platform, the device language, and coarse session ranges. An installation and session receive random pseudonymous identifiers so return use can be understood.
Analytics never contains pattern titles or contents, filenames, chart coordinates, notes, photos, email addresses, raw error messages, receipts, or payment information. It is not sold, used for advertising, combined with third-party data, or given to data brokers. Supabase processes these events on Uzora’s behalf. Disabling Share private usage analytics clears queued events and the random identifier from the device and stops future collection. The random identifier itself is replaced with a new one after 13 months, so it cannot follow an installation indefinitely. Previously delivered pseudonymous events are kept for no more than 13 months, then deleted or aggregated without the installation identifier.
Crash reports
Some builds may include crash reporting. If enabled, it contains technical crash information such as a stack trace, device class and OS version, but no chart content, photos or personal data. Builds without a configured crash-reporting service send no crash reports.
The launch waiting list (website only)
The website offers a form to be told when Uzora reaches Google Play and the App Store. It collects the email address you type, the platform you pick, and the language the page was in — nothing else, and no part of it comes from the app. The address is used for exactly one message, the one announcing the public release; it is not a newsletter, it is never sold or passed to anyone else, and it is not linked to any analytics identifier. Signing up again from another device updates your platform choice instead of adding a second entry. Ask us to remove your address at any time and we will, before or after that message.
Your choices
- Export a backup from Settings and keep it wherever you choose.
- Disable future analytics events in Settings.
- Sign out to stop sync.
- Send a failed chart only after reviewing its separate confirmation.
- Delete the app to remove its local data from the device.
- Contact support to request deletion of sync data or a failed-file report.
- Ask to be removed from the launch waiting list, at any time.
Contact
Privacy questions and deletion requests: uzora@rozhnov.me.