Privacy Policy (WebApp and App)

PatternScan Pro Desktop and Mobile

This Privacy Policy applies to PatternScan Pro Desktop at app.patternscan-pro.com and to PatternScan Pro Mobile for iOS and Android. If you only visit our marketing website at patternscan-pro.com, additional website-specific notices apply, especially for hosting through Webflow.

We want this policy to be concrete. PatternScan Pro digitizes sewing patterns. To do that, we need to process photos, contours, calibration data and account data. We do not use this data for advertising, tracking, data brokerage or AI model training.

1. Controller

The controller responsible for data processing is:

Rasmus Liebscher
Findelsgrund 68
32457 Porta Westfalica
Germany

Email: mail@patternscan-pro.com
Phone: +49 157 827 58542

This contact applies to privacy requests for PatternScan Pro Desktop and PatternScan Pro Mobile for iOS and Android.

2. Short Version

We process data so you can use PatternScan Pro:

  • Account and sign-in: email address, Firebase UID, sign-in provider and technical login data.
  • Pattern processing: photos or files you upload or capture in the mobile app, generated SVG, PNG, DXF and PACX files, thumbnails, contours, measurements and editing data.
  • Calibration: calibration profiles, Reference Tile detection, camera parameters and technical measurements required for perspective correction and measurement accuracy.
  • Subscription and payment: subscription status, plan, Stripe customer ID, checkout and portal sessions. We do not store full credit card details.
  • Diagnostics: Firebase Crashlytics crash and diagnostic reports in the mobile app, if you are signed in and actively enable crash reports in Settings.
  • Communication: the content of emails you send us.

We do not use advertising tracking, data brokers, Google Analytics inside the apps or cross-app tracking for advertising. The iOS privacy manifest sets tracking to false.

3. Account and Sign-in Data

When you create an account or sign in, we process, depending on your sign-in method:

  • email address
  • Firebase UID as internal user identifier
  • password hash for email and password sign-in. We do not see your plain-text password.
  • sign-in provider, for example email, Google or Apple
  • technical authentication data such as session tokens, IP address, timestamps and security events
  • for Apple or Google sign-in: profile data shared by the provider, usually email address and sometimes name

Purpose: create your account, enable login, secure your account, reset passwords and connect your data to your account.

Legal basis: Art. 6(1)(b) GDPR for providing the account and Art. 6(1)(f) GDPR for security, abuse prevention and error analysis.

If you use "Sign in with Apple" or "Sign in with Google", Apple or Google also process data under their own responsibility. Their own privacy notices apply.

4. Photos, Files and Patterns

PatternScan Pro processes photos or files that you deliberately upload or capture in the mobile app.

Mobile App Camera

In PatternScan Pro Mobile, the camera is active only inside the in-app capture screen. Live camera frames are processed locally on your device so the app can show quality, stability, alignment and Reference Tile feedback. Your device's motion sensors (gyroscope and accelerometer) are also used locally only, to measure shake and capture angle.

Only the photo you explicitly capture is stored or uploaded for further processing. Camera frames that are not captured are not uploaded, not permanently stored, not used for marketing and not used for training.

Optionally, you can enable a toggle in Settings that additionally saves original captures to your photo gallery (Photos library on iOS, gallery on Android). This is off by default and uses add-only access. The app does not read your photo gallery.

Upload and Processing

When you upload a photo or file, we process:

  • the uploaded image file or source file
  • filename, file type, pixel dimensions and creation time, where available
  • the generated pattern as SVG
  • thumbnails and background images for the Pattern Library
  • export files such as PNG, DXF and PACX, when you generate them or the app prepares them for preview
  • contours, control points, measurements, scale, Reference Tile detection and editing data
  • technical upload data such as upload ID, app version, build number, device model (for example "iPhone16,1" or "SM-A528B"), platform and client capabilities
  • capture quality values such as sharpness, brightness, motion, surface angle, ISO and shutter speed, where the app determines them for processing
  • camera parameters and calibration data required for undistortion, perspective correction and measurement

Purpose: digitize, sync, show, edit and export your sewing patterns across your devices.

Legal basis: Art. 6(1)(b) GDPR, because this processing is required for PatternScan Pro's core functionality.

Storage

Your uploaded patterns, photos, thumbnails, SVGs and export files stay in your Pattern Library until you delete the individual pattern, delete your account or we have another lawful reason to delete them.

Stored patterns are not automatically deleted after a few days, because Desktop and Mobile use a synchronized Pattern Library.

We do not use your patterns for advertising, data sales, AI training or public examples unless you explicitly allow us to do so.

5. Calibration and Reference Tiles

PatternScan Pro uses Reference Tiles and calibration data to correct perspective and improve measurement accuracy.

Depending on the workflow, we process:

  • Reference Tiles detected in the image
  • camera parameters and correction values
  • calibration profile ID, profile name and device model
  • technical calibration quality data

When you create a calibration profile in the mobile app, the calibration photos stay on your device. The app analyzes them locally and only transmits the detected checkerboard corner points, image dimensions and quality values to our server, which computes the calibration profile from them.

On Android devices whose camera interface does not report reliable camera parameters, the app reads these parameters locally through Google Play Services for AR (ARCore). No camera images are transmitted to us in this process; see Section 11 for details on ARCore.

Calibration profiles remain stored until you delete them or delete your account.

Legal basis: Art. 6(1)(b) GDPR.

Accuracy Test

In the mobile app, you can run an accuracy test to check the measurement accuracy of your device. The test photo is processed on our server like a regular scan, but it is not stored in your Pattern Library. For each test run, we store a result record with measurements, processing mode, calibration profile ID, device model, capture quality values and a timestamp. The test photo itself is not permanently stored. Test records are deleted when you delete your account.

Legal basis: Art. 6(1)(b) GDPR.

6. Local Data on Your Device

Mobile App

The mobile app stores data locally on your device:

  • app settings, for example language, development API environment, display options and crash report toggle
  • local gallery and upload queue data
  • local photo caches for faster display
  • device-specific calibration data
  • authentication state through Firebase

When you sign out, the app removes user-scoped local gallery and queue data. Device-specific calibration can remain locally stored so the same device can be used again after calibration.

Desktop Web App

The Desktop web app uses technically necessary local browser storage, for example for login state, language, settings and editor state. Without this storage, core functions such as sign-in, editing and sync cannot work reliably.

The legal basis for technically necessary local storage is Section 25(2)(2) TDDDG and Art. 6(1)(b) or Art. 6(1)(f) GDPR. If we introduce optional cookies or similar technologies for analytics or marketing in the future, we will ask for your consent first.

7. Subscription, Payment and Stripe

Payments and subscriptions for PatternScan Pro Desktop are processed through Stripe. In the mobile app, you cannot buy a subscription or make in-app purchases for PatternScan Pro. The mobile app can check your existing subscription status and open the Stripe Customer Portal for account management.

In connection with Stripe, we process:

  • Stripe customer ID
  • subscription status, plan, term, cancellation status and invoice status
  • checkout and portal sessions
  • payment and invoice events sent by Stripe to Firebase
  • email address, where required for checkout, invoices and subscription mapping

We do not store full credit card numbers, CVC codes or full payment details on our servers. Stripe processes this data directly.

Purpose: create subscriptions, check subscription status, unlock access, issue invoices and comply with statutory retention duties.

Legal basis: Art. 6(1)(b) GDPR for contract performance, Art. 6(1)(c) GDPR for legal obligations and Art. 6(1)(f) GDPR for fraud prevention, security and payment handling.

Stripe may process data as our processor and, in some cases, as an independent controller, for example for regulatory duties, fraud prevention and payment network rules.

8. Crash Reports and Diagnostics in the Mobile App

We use Firebase Crashlytics to detect and fix crashes and serious errors in the mobile app.

Crash reports may contain:

  • Firebase UID if you are signed in
  • Crashlytics installation ID and Firebase installation ID
  • app version, build number, operating system version, device model and technical diagnostic values
  • stack traces, error messages and technical logs
  • performance and other diagnostic data required for debugging

Crash reports are off by default. If you actively enable them in the app settings, they are not used for advertising, profiling or tracking across other apps and websites. You can disable crash reports there again at any time. According to Firebase, Crashlytics reports are generally retained for 90 days before removal from live and backup systems begins.

Legal basis: Art. 6(1)(a) GDPR if you enable crash reports. You can withdraw this consent at any time for the future by disabling crash reports again in the app settings.

9. Server Logs and Security

When you use the Desktop web app, the mobile backend endpoints and Firebase services, technical logs are generated. These may include:

  • IP address
  • date and time
  • requested URL or function
  • HTTP status, error messages and technical runtime data
  • browser, operating system, device type or app version
  • authentication status where required for security and debugging

Purpose: secure operations, find bugs, prevent abuse, improve performance and detect attacks.

Legal basis: Art. 6(1)(f) GDPR. In the default configuration, technical logs in Google Cloud are generally stored for 30 days unless a shorter or longer retention period is configured.

10. Email Contact

If you contact us by email, we process your email address, your message and any data you voluntarily include.

Purpose: answer your request, provide support, review student discount requests, process feedback or document legal communication.

Legal basis: Art. 6(1)(b) GDPR if your request relates to a contract or product use, and Art. 6(1)(f) GDPR for general communication and recordkeeping. Art. 6(1)(c) GDPR applies where statutory retention duties exist.

11. Hosting, Service Providers and Data Transfers

Firebase and Google Cloud

We use Firebase and Google Cloud for authentication, database, file storage, Cloud Functions, hosting and crash reports.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Depending on the service, Google LLC and other Google companies may also act as sub-processors.

Services used:

  • Firebase Authentication
  • Cloud Firestore
  • Firebase Storage / Google Cloud Storage
  • Cloud Functions for Firebase in europe-west3 (Frankfurt)
  • Firebase Hosting for the Desktop web app
  • Firebase Crashlytics for the mobile app

We have entered into the required data processing agreements with Google. Where data is processed outside the EU or EEA, Google relies on appropriate mechanisms such as EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

Stripe

We use Stripe for payments, subscriptions, checkout and the customer portal.

The provider for users in the EEA is generally Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Depending on the processing, Stripe, Inc. and other Stripe companies may also be involved.

Apple

If you use Sign in with Apple or install the iOS app through the App Store, Apple processes data under its own responsibility. Apple may send us an identifier, email address and sometimes name during sign-in. If you use Hide My Email, we receive the relay address provided by Apple.

Google Play and Google Play Services for AR (ARCore)

If you install the Android app through Google Play, Google processes data under its own responsibility, for example for downloads, updates and security checks.

The Android app also runs with Google Play Services for AR (ARCore), which is provided by Google and governed by the Google Privacy Policy (https://www.google.com/policies/privacy/). The app uses ARCore only to read validated camera parameters of your device locally when the Android camera interface does not provide them. Camera images from ARCore are never stored or uploaded by the app.

Google Sign-in

If you use Sign in with Google, Google processes data under its own responsibility and sends us the data required for sign-in, for example email address and identifier.

Webflow

Our marketing website and this Privacy Policy are hosted through Webflow. When you visit these Webflow pages, Webflow processes technical access data required for delivery, security and operation. The app itself does not run on Webflow.

Email

If you email us, your data is processed by our email provider. The specific provider depends on the configuration of our domain mailbox.

12. International Transfers

Some service providers are based outside the EU and EEA or use sub-processors outside the EU and EEA, especially in the United States. Where personal data is transferred to such countries, we use appropriate safeguards under Art. 44 et seq. GDPR, especially EU Standard Contractual Clauses, data processing agreements and, where applicable, the EU-US Data Privacy Framework.

Even with these mechanisms, there may be a risk that authorities in third countries access data under local law. We therefore limit such transfers to services required for operation, payment, security or app distribution.

13. Retention and Deletion

We store personal data only for as long as required for the relevant purpose or by law.

  • Account: until you delete your account or we lawfully delete it.
  • Patterns, photos, previews and exports: until you delete the pattern, delete your account or deletion is otherwise required.
  • Local mobile app data: until you delete it in the app, sign out, delete your account or the operating system removes local caches.
  • Calibration profiles: until you delete them or delete your account.
  • Accuracy test records: until you delete your account.
  • Payment and invoice data: according to contract handling and statutory retention periods, in Germany generally up to 10 years for tax-relevant records.
  • Support emails: as long as required for handling, evidence and possible claims.
  • Crashlytics data, if you enable crash reports: according to Firebase, generally 90 days.
  • Technical logs: in the default configuration, generally 30 days unless configured differently.

When you delete your account, we delete your Firebase Auth account, patterns, related storage files, calibration data, accuracy test records, user documents and Stripe extension data in Firestore, unless statutory retention duties prevent deletion. The Stripe customer itself and payment-related history may remain with Stripe where Stripe or we need them for billing, records, fraud prevention or legal obligations.

Backups and technical security systems may contain deleted data for a limited time. Such data is generally not used productively and is removed through regular backup rotation.

14. Account Deletion and Active Subscriptions

You can delete your account in the app. If a subscription still renews automatically, account deletion may be blocked until you cancel the subscription in the Stripe Customer Portal. This prevents a situation where your account is gone but billing continues.

If your subscription is already set to end at the period boundary, the app may ask you to confirm deletion again. If you delete before the paid period ends, you lose access immediately.

15. Security

We protect your data with technical and organizational measures. These include TLS encryption, Firebase Auth, user-scoped access rules, server-side ownership checks, private storage objects with tokenized URLs and backend access controls.

No system is perfectly secure. If you suspect your account or data may be affected, contact us at mail@patternscan-pro.com.

16. Your Rights

Under the GDPR, you have in particular the following rights:

  • access to your personal data
  • correction of inaccurate data
  • deletion of your data
  • restriction of processing
  • data portability
  • objection to processing based on legitimate interests
  • withdrawal of consent for the future
  • complaint with a data protection supervisory authority

You can contact us at any time at mail@patternscan-pro.com.

Competent supervisory authority for North Rhine-Westphalia:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Website: https://www.ldi.nrw.de

You may also complain to any other competent supervisory authority in the EU, especially where you live or where a possible infringement occurred.

17. No Automated Decisions

PatternScan Pro uses image processing to detect, correct and convert sewing patterns into editable files. We do not make automated decisions with legal or similarly significant effects under Art. 22 GDPR.

18. Changes

We update this Privacy Policy when PatternScan Pro, the services we use or legal requirements change. The current version is linked on our website and inside the app.