Craftinery Privacy Policy

Effective date: 25 August 2026 Last updated: 15 September 2026

This policy describes personal-data processing for craftinery.com, applications to test Craftinery App, the separate sign-up for Craftinery App updates, and Craftinery App. Craftinery Lab is a separate product and is not covered by this document.

1. Controller and contact

The controller is Dietetyk JULIA NOWAK, a sole proprietorship under Polish law, ul. gen. Tadeusza Bora-Komorowskiego 20/57, 03-982 Warsaw, Poland, Polish tax ID (NIP) 5222814473, REGON 520926090, referred to as “Craftinery”, “we” or the “Controller”.

General contact: hello@craftinery.com
Support: support@craftinery.com
Privacy and account deletion: privacy@craftinery.com

2. Website and testing applications — data we process

In connection with the website and the testing-application form, we may process:

  • email address, communication language, sign-up date/source, double-opt-in status, consent and unsubscribe history;
  • message content and contact details you provide;
  • IP address, request date/time, visited URL, browser/device information, server responses and security events;
  • email events such as delivery, bounce and unsubscribe, plus aggregate open/click data under the current Brevo configuration;
  • cookie and similar-technology choices where a consent mechanism is required and used.

The testing-application form is not intended to collect special-category data, documents or detailed craft-project data.

3. Website and testing applications — purposes, legal bases and retention

PurposeLegal basisRetention
Handling testing applications and sending information about Craftinery recruitment or testingconsent — Article 6(1)(a) GDPR and applicable electronic-communications rulesuntil withdrawal, unsubscribe or the end of testing-related communications; the need to retain an active entry is reviewed periodically
Recording consent and handling legal claimsArticle 6(1)(f) GDPRuntil the relevant limitation period expires or proceedings end
Responding to messagesArticle 6(1)(b) or (f) GDPR depending on the matteruntil the matter ends, then for the period needed to defend claims
Security, diagnostics and website maintenanceArticle 6(1)(f) GDPRfor the period made available under the hosting provider’s current operational and security policy; specific data may be retained longer only when needed for a security incident, legal duty or claim

Providing an email address in a testing application is voluntary, but we cannot send information related to the application and testing without it. Consent may be withdrawn at any time through the unsubscribe link or by contacting us.

3a. Separate sign-up for Craftinery App updates

The separate App Updates list is used to send emails about the development, new features and availability of Craftinery App. We process your email address, language, sign-up date and source, double opt-in status, and evidence of consent and its withdrawal. Brevo manages this sign-up. Sending emails is based on voluntary consent — Article 6(1)(a) GDPR and the applicable electronic communications rules. An active subscription requires clicking the confirmation link in an email.

An active entry is retained until you unsubscribe, withdraw consent or this communication purpose ends; the need to retain it is reviewed periodically. Evidence of consent and withdrawal follows the consent documentation and legal claims rules in section 3. Providing an email address is voluntary. Not subscribing does not prevent you from reading the website or app guide and does not affect an earlier testing invitation. This sign-up is not an application for the closed first group or a guaranteed place. Earlier applications and consents remain separate and are not automatically moved to App Updates. You can withdraw consent using the unsubscribe link in an email or by contacting privacy@craftinery.com.

4. How a testing application works

The PL and EN forms use double opt-in. The application and consented communication become active only after the confirmation link in the email is clicked.

Applying records your wish to test Craftinery App. It does not guarantee a place in a specific testing round.

5. Craftinery App — storage model

Craftinery App is local-first: a working copy of data is stored in the App’s private area on the device. After sign-in, account data and selected content are synchronised with Craftinery’s private cloud infrastructure based on Supabase.

The current technical model uses Supabase Auth, PostgreSQL with row-level access controls, private Storage and Realtime. Primary Supabase project data is stored in region eu-west-3.

An exported backup is saved through the Android system picker to a location chosen by the user. Available save locations may depend on the device and Android version; Craftinery does not promise that every backup can always be written directly to the root Downloads folder. Exported backups remain under the user’s control.

Backups are account-bound. Restore rejects a backup belonging to another account. Backups are used to restore Craftinery data and do not grant or transfer account access, trial status, premium status or other account entitlements between accounts. Uninstalling the App is not the same as deleting the account and cloud data.

6. Craftinery App — data categories

We may process:

  • account and access: email, user ID, Supabase-managed authentication data, access status/expiry, login/password-recovery events, accepted Terms version and language, and confirmation that the user is 18 or older;
  • device and synchronisation: App-specific device ID, platform, App version/build, last-seen time, change IDs, conflict information and sync status;
  • user content: projects, folders, stages, parts, statuses, tags, notes, counters, work/session history, materials, tools, catalogue data, saved links, shopping records, calendar entries, project costs, material prices, hourly rates and saved measurements in centimetres with names or notes for creative projects;
  • files: photos, PDF, TXT, DOC and DOCX files and related metadata to the extent actually used by the App;
  • settings: language, interface size, local-notification preferences and other App settings;
  • support and security: correspondence, diagnostics voluntarily sent to support, cloud-provider logs, authentication errors and security events. Infrastructure logs may include IP address, request time/path, response status and approximate country, region or city derived from IP; the App does not obtain precise GPS location;
  • ML Kit technical data: device, App and installation identifiers, feature-usage and performance metrics, and diagnostic errors associated with Google ML Kit;
  • optional product-code lookup: a product barcode (GTIN/UPC/EAN) submitted to UPCItemDB at the user’s request, with technical request metadata such as IP address and request time.

ML Kit text recognition, barcode recognition and translation process content on the device. Model downloads and technical usage/diagnostic reporting may require network access. Product-code lookup sends the product code, not the account email, private inventory records or project photos, to UPCItemDB.

The current App scope does not include advertising or marketing profiling. If the processing scope changes in the future, the relevant information and any required consent will be updated before such a feature is enabled.

7. Craftinery App — purposes, legal bases and retention

PurposeLegal basisRetention
Account, access control, App operation, synchronisation and user requestsperformance of a contract — Article 6(1)(b) GDPRwhile the account is active; after a valid deletion request active account data is deleted within 7 days, except data retained for a legal obligation, security reason or claim
User content and private-file synchronisationArticle 6(1)(b) GDPRuntil deletion by the user or account deletion; technical provider copies, where they exist, expire under the provider’s operational cycle
Security, sync integrity, diagnostics and legal claimsArticle 6(1)(f) GDPRunder the infrastructure provider’s current retention; evidence relating to a specific incident or claim may be retained until resolution or the relevant limitation period expires
Support and complaintsArticle 6(1)(b), (c) or (f), depending on the matteruntil resolved and then for the applicable legal or claims period

After the last successful access verification, the App may work offline for up to 24 hours. Internet access is then required to renew the entitlement check.

8. Terms, test access and access-status changes

Craftinery App records acceptance of Terms v1.0 together with the user, language and information needed to identify the accepted version. The user also confirms being at least 18 years old.

Access status is server-authoritative. Expiry or revocation does not automatically delete local device data. Access and account deletion are separate processes.

9. Backups, restore, data clearing and synchronisation conflicts

Cloud synchronisation and exported backups serve different purposes. Restoring from a valid backup may replace the current account dataset and then rebuild and synchronise the restored data with the cloud and other devices. The process may take several minutes when the backup contains many projects, history entries or files.

The App includes a separate Delete all Craftinery data operation. This removes Craftinery data associated with the account while keeping the account/Auth identity and its assigned access. It is separate from deleting the account itself.

If a data conflict is detected during synchronisation, Craftinery may stop automatic overwriting and ask the user to resolve the conflict. The exact behaviour depends on the type of changes and the devices’ connectivity.

10. Account and data deletion

Craftinery provides a public account-deletion route at https://craftinery.com/delete-account. Craftinery App also provides Settings → Account → Delete account; this flow has been physically tested in the current Android candidate.

After successful verification, active account data and related active Craftinery cloud data are deleted within 7 days, except information retained for a specific legal duty, security reason or legal claim.

Account deletion does not necessarily erase a local device copy or user-controlled exported backups stored outside the App.

11. Recipients and service providers

Data may be processed by:

  • Supabase for Auth, PostgreSQL, private Storage, Realtime and infrastructure logs;
  • Supabase infrastructure providers and current subprocessors under the applicable terms and DPA;
  • Google ML Kit for on-device recognition/translation and technical usage and diagnostics, as described in Google’s ML Kit data disclosure;
  • UPCItemDB for user-requested product-code searches and associated technical request metadata, under its privacy policy;
  • Zenbox for website, policy and account-deletion hosting;
  • Brevo — for testing application forms, the separate App Updates sign-up, and communications covered by the relevant, separate consent;
  • Google reCAPTCHA for protection of the website form against spam and abuse;
  • authorised support, maintenance, security, legal and accounting personnel/providers;
  • public authorities where required by law.

We do not sell user data or give it to advertisers for their own marketing.

12. Transfers outside the EEA

Some providers or subprocessors may process limited data outside the EEA. Where this occurs, appropriate Chapter V GDPR mechanisms are used, such as an adequacy decision or Standard Contractual Clauses together with any required supplementary safeguards.

Details can be requested from privacy@craftinery.com.

13. Cookies and similar technologies

Detailed information about technologies used by the website is provided on the Cookies and Similar Technologies page. The final list will reflect the live production audit performed before public testing recruitment.

14. Your rights

You may request access, correction, deletion, restriction and, where applicable, portability, and object to processing based on our legitimate interests. Consent can be withdrawn at any time without affecting earlier lawful processing.

You may lodge a complaint with the Polish supervisory authority at uodo.gov.pl.

15. Security

We use measures appropriate to risk, including encrypted transmission, private Storage, access controls, account separation, updates, backups and provider configuration. No transmission or storage method can guarantee absolute security.

16. Children

Craftinery App is intended for users aged 18 or older. Users under 18 must not create an account or use the App.

17. Changes

We may update this policy when the law, website, App or processing changes. The current version and effective date will remain available here. Where a change requires new consent, we will request it separately.