Privacy Policy
Yarnini is built to collect as little as possible. Signing in is optional. As a guest, your progress stays on your device. This policy explains what data the Yarnini app (the “App”) handles, why, and the choices you have.
In short
- Signing in is optional. As a guest, your progress, favourites, preferences and profile name stay only on your device.
- If you choose to sign in with Apple or Google, we receive your email address (or an Apple private relay address), name and account ID, and your progress is synced to your Yarnini account so it is available on your other devices.
- Before you sign in, the App uses a random anonymous identifier that is not linked to you.
- No ads, no tracking, no analytics, no selling or sharing of your data.
- Apple handles all payments. We never receive your card details.
- You can delete your account and its synced copy at any time in the App: Profile → Account → Delete my account.
1. Who is responsible
Yarnini is developed and published by an individual developer based in Türkiye (the seller named on the App’s App Store page). The developer is the data controller (veri sorumlusu) for the personal data described here. Contact: support@yarnini.com.
2. Data stored on your device
The App saves the following information locally in its private storage on your iPhone or iPad, so you can continue where you left off:
- your language choice and whether you have completed the welcome screens;
- the profile name you choose to enter, if any, and the date you started using the App;
- patterns you have saved as favourites;
- project progress, including the selected size, completed steps, current step, row counter values and when you last updated them;
- a copy of the pattern version you started, so that later pattern updates do not change your rows;
- a cache of the pattern catalogue, images and lesson videos for faster and offline use.
If you use Yarnini as a guest, this information is never sent to us and is not synced to any server. If you sign in, the items described in Section 4 are synced to your account. Your profile name and start date always stay on your device only. Deleting the App removes it from your device. Depending on your Apple settings, iOS may include app data in your own iCloud or computer device backups, and may restore it if you set up a new device from such a backup. Those device backups are controlled by you and Apple, not by us.
3. Anonymous identifier
When you first open the App, it silently creates a random identifier using Firebase Anonymous Authentication, a service provided by Google. This identifier (a user ID, or UID):
- contains no name, email address or phone number;
- is not linked to your Apple ID, your purchases or to you as a person, unless you later choose to sign in (see Section 4);
- is used to secure the App’s access to our backend, for example to protect the pattern catalogue from abuse. It is not used for advertising, analytics or tracking.
When Firebase creates or refreshes this identifier, it processes the technical data needed to provide the service securely, such as your IP address and basic device and app information. As a guest, we do not store your progress or any other content under this identifier. If you want an unused anonymous identifier deleted from Firebase, email support@yarnini.com.
4. Optional sign-in with Apple or Google, and sync
You can use every feature of Yarnini as a guest. If you want your progress on more than one device, you can sign in with Sign in with Apple or Google Sign-In. Sign-in is handled by Firebase Authentication. We never see or store your Apple or Google password.
What we receive from Apple or Google
- Email address. With Sign in with Apple, you can choose Hide My Email. We then receive only a private relay address that forwards to you, and we never see your real address.
- Name (display name), if you choose to share it.
- Account identifier from Apple or Google, which links your sign-in to your Yarnini account.
Firebase also keeps your Yarnini user ID, the sign-in provider, account creation and last sign-in times, and technical data needed to keep sign-in secure. We do not receive your profile photo, contacts or any other data from your Apple or Google account.
How your account is created
When you sign in for the first time, your anonymous identifier is upgraded to a full account with the same user ID. If you have already used that Apple or Google account with Yarnini, for example on another device, the App switches to your existing account, merges this device’s progress into your account’s synced copy, and deletes the temporary anonymous identifier.
What is synced
While you are signed in, a compressed copy of the following is stored in Google Cloud Firestore in the europe-west1 (Belgium) region, in a single record linked to your user ID:
- your App preferences, including language and welcome-screen status. If you used an earlier version of the App, this may also include older preference fields such as experience level, preferred hand and craft interests;
- your saved favourites;
- your project progress (sizes, steps, row counts and timestamps) and the pinned pattern versions described above;
- the time of the last sync.
The copy is updated when you sign in, when the App moves to the background, and when you tap Sync now. Our security rules allow only you, when signed in, to read, change or delete your record. Your profile name, payment details, photos, contacts and location are not synced.
Signing out
You can sign out in Profile → Account → Sign out. Your synced copy stays in your account, and the data already on this device stays on this device. The App then uses a new anonymous identifier.
5. Content and media delivery
To show patterns, the App downloads the catalogue and pattern details from Google Cloud Firestore. It also downloads images and videos from our content delivery network at media.yarnini.com, which is operated by Cloudflare (Cloudflare R2). As with any internet request, these providers receive your IP address, the requested file, time, and basic device and app information (user agent). They may keep this information briefly in technical logs to deliver content and protect against abuse. We do not use this data to identify you or build a profile.
When you visit this website, Cloudflare processes similar technical request data to serve the pages. This website uses no cookies, analytics or tracking scripts.
6. Purchases and subscriptions
Yarnini Pro subscriptions are sold and processed by Apple through the App Store. Apple handles your payment information under the Apple Privacy Policy. We do not receive or store your card number, billing address or Apple ID password. The App receives purchase information from Apple on your device, such as the product purchased, purchase and expiry dates and a transaction identifier, so that it can unlock Pro features and restore your purchases. To manage your subscription or request a refund, please use your Apple ID settings or Apple’s refund process.
7. Contacting support
If you email support@yarnini.com, we receive your email address and anything you include in your message. Emails to this address are forwarded to the developer’s inbox through Cloudflare Email Routing. We use this information only to answer you and to keep a record of the request.
8. What we do not do
- We do not show ads or use advertising identifiers (IDFA).
- We do not track you across other companies’ apps or websites, and we do not use tracking analytics. Firebase Analytics collection is turned off in the App.
- We do not sell, rent or share your personal data for advertising or for anyone else’s marketing.
- We do not access your contacts, photos, location, microphone or camera.
- We do not make automated decisions about you that have legal or similarly significant effects.
9. Service providers and international transfers
We use the following providers, which process data on our behalf under their data processing terms:
- Google (Firebase Authentication, Cloud Firestore, Google Cloud) for the anonymous identifier, accounts, synced progress and pattern catalogue delivery. Synced progress and the catalogue are stored in the EU (europe-west1). Authentication data may be processed by Google in other countries, including the United States.
- Apple (Sign in with Apple) and Google (Google Sign-In) verify your identity when you choose to sign in. They act under their own privacy policies.
- Cloudflare for media delivery (R2), this website and support email forwarding. Cloudflare operates a global network, so requests may be handled at the location nearest to you.
- Apple for App Store distribution and payments. Apple acts under its own privacy policy.
Some of these providers process data outside Türkiye and the European Economic Area. Where this happens, transfers rely on the safeguards offered by the providers, such as the European Commission’s Standard Contractual Clauses, the EU–U.S. Data Privacy Framework where applicable, and, for transfers from Türkiye, the safeguards in Article 9 of the Personal Data Protection Law No. 6698 (KVKK), such as standard contracts. We disclose personal data to public authorities only when required by law.
10. Legal bases
Under the GDPR and KVKK, we process personal data on the following bases:
- Performance of a contract (GDPR Art. 6(1)(b), KVKK Art. 5(2)(c)): to provide your optional account and sync your progress across devices, deliver patterns and content, and provide subscriptions you request;
- Legitimate interests (GDPR Art. 6(1)(f), KVKK Art. 5(2)(f)): to keep the service secure with the anonymous identifier, prevent abuse and answer support requests;
- Legal obligations (GDPR Art. 6(1)(c), KVKK Art. 5(2)(ç)): to keep records required by law.
Data processed through automated means is processed in line with these legal bases.
11. Retention
- Data on your device: kept until you delete it or delete the App.
- Account and synced copy: kept until you delete your account. Each sync replaces the previous copy. Signing out does not delete them.
- Anonymous identifier: replaced by your account when you sign in, or deleted when you sign in to an existing account. Otherwise it is kept until it is deleted at your request.
- After deletion, residual copies in our providers’ internal backups are removed according to their standard deletion schedules.
- Support emails: kept for as long as needed to handle your request, and normally no longer than 24 months, unless the law requires us to keep them longer.
- Technical request logs kept by Google and Cloudflare: kept for the limited periods set by those providers.
12. Deleting your data
- Account and synced copy: in the App, go to Profile → Account → Delete my account. You will be asked to confirm with Apple or Google again. The App then revokes the Sign in with Apple authorisation (if you used Apple), and permanently deletes your synced record and your Firebase account.
- Data on your device: account deletion and sign-out do not remove progress stored on your device. To remove it, delete the App.
- Anything else: if you can no longer sign in, or for any other privacy request, email support@yarnini.com. We may need to confirm that the account is yours before acting.
You can also remove Yarnini’s access in your Apple ID settings (Sign in with Apple) or your Google Account settings (Third-party connections). Doing this does not delete your Yarnini data, so please use the in-app deletion. Deleting your account does not cancel an Apple subscription. Please cancel it in your Apple ID settings.
13. Your rights
Under the GDPR (if you are in the EEA, the UK or Switzerland), you have the right to access your personal data, correct it, delete it, restrict or object to its processing, and receive a portable copy. Where processing is based on consent, you may withdraw your consent at any time. You also have the right to complain to your local data protection authority.
Under Article 11 of KVKK (Türkiye), you have the right to:
- learn whether your personal data is processed and request information about it;
- learn the purpose of the processing and whether the data is used for that purpose;
- know the third parties in Türkiye or abroad to whom your data is transferred;
- request correction of incomplete or inaccurate data, and request deletion or destruction of your data;
- request that these corrections or deletions be notified to the third parties who received your data;
- object to a result against you that arises solely from automated analysis;
- claim compensation for damage caused by unlawful processing.
To use any of these rights, email support@yarnini.com. We will reply free of charge within 30 days at the latest. If you are not satisfied with our response, you can complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) in Türkiye or to your local supervisory authority.
14. Children
Yarnini is made for adult makers who knit and crochet for babies. It is not directed at children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has created an account or provided personal data, please let us know and we will delete it. The App does not ask for information about the babies you make things for, so please do not enter it.
15. Security
Data is sent over encrypted HTTPS connections (TLS 1.2 or higher). Sign-in is handled by Apple, Google and Firebase Authentication, so we never handle passwords. Our backend security rules allow each signed-in user to access only their own synced record. No method of storage or transmission is completely secure, but we work to protect your data and limit what we collect.
16. Changes and contact
If our data practices change, we will update this policy and the “Last updated” date. If a change is material, we will notify you in the App, or by email if you have an account. For any privacy questions or requests, contact support@yarnini.com.