Privacy Policy
STK - Style Tailors Kit
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Style Tailors Kit stores completed lessons and exercises, XP, skill scores and error counts, streak dates, earned badges, garment collection, activity history, and reminder preference on your iPhone. A random installation master secret is stored in this device's Keychain. When the app can reach its service, it sends an encrypted copy of the progress record for this installation. The service stores the latest encrypted copy and a SHA-256 hash of an authentication token derived from the installation secret. Requests to the service also expose ordinary network information such as IP address, request path, time, and user agent to Railway infrastructure and may appear in infrastructure logs. We do not require an account, name, email address, or precise location. The contact email below is for privacy inquiries, not an in-app messaging feature.
How we use information
The local record drives lessons, stage unlocking, personalized Focus Practice, Daily Stitch, garments, badges, and history. The encrypted server copy allows this same installation, while it retains its secret, to retrieve its most recent progress and check content versions. A requested local notification reminds you to practice. Network request information supports service delivery, availability, and security.
Service providers and sharing
The service is hosted on Railway, which processes network requests, hosts the PostgreSQL database, and may process infrastructure logs. Apple provides iOS storage, Keychain, device backup settings, and local notification delivery. We do not use advertising, analytics, email delivery, or social sign-in SDKs, and do not sell progress data. The server receives a derived authentication token but does not receive the separate derived encryption key; the stored snapshot is encrypted on the device.
Data retention
Progress remains locally until you clear it or remove the app, subject to your device backup settings. The service keeps only the latest encrypted snapshot for a given installation, replacing the preceding version. It remains until the installation requests deletion or the service is retired. We do not set an app-specific retention period for Railway infrastructure logs or possible provider backups; those are governed by the provider's configuration and practices. Clearing data deletes the active server row when the service is reachable. We cannot promise immediate removal from pre-existing device or infrastructure backups.
Deleting your information
Use Settings > Clear all data to erase the local progress record and request deletion of this installation's server snapshot. If offline, the app keeps only the installation secret and a pending-deletion flag so it can retry; local progress is already erased. Once deletion succeeds, the Keychain secret is removed. Removing the app before an offline deletion request can prevent that request from reaching the service. Without the installation secret, neither the app nor the operator can identify an encrypted snapshot as yours for recovery or targeted deletion. Contact alastair.abernethy@icloud.com with privacy questions; do not send a secret in email.
Permissions and your choices
The app may ask for notification permission only if you enable a Daily Stitch reminder. Reminders are scheduled on the device without remote push. You can turn them off in the app or iOS Settings; disabling permission stops delivery. The app does not request camera, microphone, location, photos, or contacts permission.
Your privacy rights
You can view your progress in the app, stop reminders, and clear local and server progress through Settings. For questions about access, correction, deletion, or applicable privacy rights, contact alastair.abernethy@icloud.com. Because there is no account and the service stores an opaque encrypted record keyed by an installation secret, recovery or identification after the secret is lost is not possible.
Security
The app uses HTTPS for service requests. It keeps a random installation master secret in the iOS Keychain with device-only accessibility and derives separate authentication and AES-GCM encryption keys from it. The encryption key is not transmitted. The service checks the derived authentication token on every private progress request, stores its SHA-256 hash rather than the raw token, and uses a PostgreSQL database. No security method eliminates all risk; device compromise, backups, and hosting infrastructure remain relevant.
Children’s privacy
Style Tailors Kit is designed for young adults learning sewing and is not directed to children under 13. It does not include accounts or social features. If you believe a child has used the app and need help with a privacy concern, contact alastair.abernethy@icloud.com.
Changes to this policy
We may update this policy when app or service practices change. The current version and effective date will be published at this page. Material changes will be reflected in the app and this policy before the changed practice is used. For questions, contact alastair.abernethy@icloud.com.