Uzora

Privacy policy

Last updated: 11 September 2026

Uzora is a local-first cross-stitch companion. It has no advertising and does not track you across other companies’ apps or websites. No account is required for core use. Your private library stays separate from anything you choose to publish in the optional community pilot. When automatic safety checks are enabled, they send your chosen public name and selected community text and photos through OpenRouter to the model provider described below; the same route translates approved community text into the pilot’s other language. If you allow notifications, Apple delivers short community notifications to your device.

Data stored on your device

Imported pattern files and derived thumbnails, stitching progress, sessions, notes, journal attachments, and app preferences are stored in the app’s private storage. They may be included in your device backup according to Apple’s backup settings. Backup files you export go only where you choose to share them. Optional sync, diagnostic uploads and community publications make the separate copies described below only when you use those features.

Uzora also stores the access tier, subscription expiry, elapsed paid subscription coverage, and recent Plus PDF-import timestamps locally so it can enforce the features shown in the app.

Purchases and subscriptions

Apple processes all in-app purchases and subscription payments. Uzora requests localized product information and verified transaction history from StoreKit to unlock and restore a subscription and to determine whether it is currently active. Uzora does not receive or store card or bank details, your Apple Account password, or a full purchase receipt.

Apple handles subscription renewal, management, cancellation, and refunds under your Apple Account. A failed or cancelled purchase does not upload payment data to Uzora.

Optional sync

A build may offer opt-in cloud sync. It remains inactive until you sign in and enable it. Your email address and any linked sign-in provider identify your account, which can also be used for community participation. When sync is enabled, chart and progress data is stored so your own devices can restore it. Joining the community does not make these private sync records visible to other members. You can sign out at any time.

Optional community pilot

The community is an invitation-only TestFlight pilot for people aged 18 or older. It requires sign-in and acceptance of the displayed rules. The accepted rules version and acceptance time are recorded; the pilot does not request your date of birth. Local stitching remains available without joining, and community participation does not require product analytics to be enabled.

You choose a public display name. While the pilot's automatic checks are enabled, the name check runs before a new public profile is created. If the name is rejected, the result is unclear, or the check cannot be completed, no new public profile is created. You can choose another name, retry later, or contact support for help.

When submitting a post or reply, you supply its text, a selected photo if any, and any project title or progress percentage you wish to include. Uzora stores these with the posting time and your account identifier. Your public profile and approved posts and replies are visible to other invited members. In manual moderation mode, new submissions wait for a human moderator. When automatic checks are enabled, ordinary content that passes the check is published automatically; clear rule violations can be rejected automatically with a reason. Unclear results and checks that fail or are unavailable leave the submission pending for a human moderator. You and moderators can see your pending or rejected submissions and the relevant moderation reason. Contact support to ask a human to review a decision. Your email, sign-in details, private notes, original chart files and unselected journal photos do not become public.

Reactions and follow relationships support the feed and following features. Block relationships, abuse reports with the reporter’s identity, and moderation decisions support safety and rule enforcement. Reports and block lists are not published to other members; moderators can access the reports they review. Recent action timestamps are stored to limit repeated requests and spam.

When you report a problem, you receive a receipt and can see the status and recorded decision in My reports. This private inbox does not reveal the reported content or another person's identity. A report, its complaint text and decision can remain after the reported content or account is removed, for the retention period below. Deleting your own account removes reports you made.

We also use grouped counts from existing community records to understand whether people post again, receive replies and continue conversations during the pilot. Small groups are suppressed and larger counts are reported in ranges. This does not add app tracking events or connect community records to product-analytics identifiers.

When automatic safety checks are enabled, our server sends your chosen public display name, the post or reply text you selected, any included project title, post category and progress percentage, and any selected photo through OpenRouter to its model provider. Photos sent for checking have already been decoded for validation and stripped of metadata. Larger or incompatible images are resized or re-encoded when needed. We do not attach your account identifier, email, sign-in provider details, authentication credentials, private notes, chart files or unselected journal photos to these requests. Personal information you type into the chosen name or text, or include in a selected photo, remains part of that content and is sent with it.

Model inference requests are restricted to the Google Vertex EU route (google-vertex/eu), with fallback to other model providers disabled. This describes the inference route, not a promise that all processing happens in the EU: OpenRouter’s platform services may process data elsewhere. Requests require zero-data-retention (ZDR) routing, disallow routes marked as collecting data (data_collection: deny), and do not opt in to prompt logging. These are request and routing controls, not a blanket guarantee that every service or operational record has no retention. OpenRouter and the model provider’s stated data-handling policies and routing capabilities govern their processing. These controls do not remove the community records stored by Uzora as described below.

Posts and replies share one feed in every pilot language. The server records the language it detects for each post and reply. When automatic checks are enabled, the text of an approved post or reply and its project title are also sent through OpenRouter, on the same route and with the same controls, to be translated into the pilot’s other languages (currently Russian and English). Translations are stored with the post or reply and shown to readers who use another app language, with the original available under Show original. A reader can also request the translation of a single post or reply, which sends that text the same way. Automatic translation and posts in other languages can be turned off in the community preferences. Translations never change your original text and are removed together with it. Photos are not sent for translation.

The community keeps a private inbox of events about your own content and profile: replies to your posts, support reactions, new followers and the outcome of automatic or human moderation of your submissions, with the recorded reason. Each entry stores the event type, the accounts involved, references to the post or reply, and the times it was created and read. Entries are removed 90 days after creation, when the related post, reply or account is deleted, and when you delete your account.

If you allow notifications on your device, the app stores that device’s push token with your community profile, and Apple delivers short notification texts through the Apple Push Notification service: the event type, the other member’s public display name, an excerpt of the reply or post or the moderation reason, and your unread count. Apple processes delivery under its own terms; we use no third-party push provider. You can turn each notification type off in the community preferences, or all of them in the device settings. The token is removed when you sign out, delete your account, or when Apple reports it as no longer valid. Delivery of an individual notification is not guaranteed; the inbox and unread count refresh when you open the app.

Your community preferences (the language used for the feed and notifications, whether posts in other languages are shown, automatic translation, and which notification types are on) are stored with your community profile.

Supabase provides authenticated access, the community database and photo storage. The current project region is Ireland (eu-west-1). This describes the primary project location; it does not promise that every authentication email, provider log or support operation is processed only in the EU. The server validates submitted photos and removes metadata such as EXIF and GPS before storage. Suitable JPEG image data is preserved; other images are resized or re-encoded when needed. The original upload is processed in memory and is not retained as a separate stored original. Photos are delivered through temporary links to authorized viewers. People who have already viewed or downloaded a photo may retain their copies.

Posts and replies remain until removed by their author, during moderation, or through account deletion. Rejected submissions remain private to their author and moderators until deleted. Deleting a post also deletes its replies. Photo removal is queued and retried if storage is unavailable; the cleanup job also removes abandoned uploads. Resolved reports are removed 90 days after resolution; unresolved reports remain available for investigation. Moderation decision records are removed after 90 days from creation. A ban remains until it is lifted or the account is deleted; deleting the decision log does not lift the ban. Technical records preventing duplicate automatic checks remain until the related submission is deleted. Temporary name-check records expire after five minutes and are removed when used or by maintenance. Request-rate records are removed after they are more than two days old. These active-system cleanup rules do not recall downloaded copies or promise immediate erasure from every backup.

Delete your own post or reply from its menu. Settings → Account → Delete account starts removal of the account, private cloud data and associated community data, including your profile, authored posts, replies and photos. Storage failures can require a retry. Your local library remains on the device. Signing out or uninstalling the app does not delete previously published content. Contact support to request access to or export of community data, or if you cannot use the in-app deletion path.

Optional failed-file diagnostics

If Uzora cannot open a supported chart, the error screen may offer Send file to the developers. A failed import never uploads anything automatically. Uzora first asks you to confirm that the original file may contain copyrighted or personal information.

If you confirm, the original file, its filename, the app version and build, operating-system version, and technical import error are uploaded to a private Supabase Storage bucket. App clients have write-only access: they cannot list, download, replace, or delete reports. Uzora’s developers and diagnostic tools use a report only to reproduce the failure and improve file compatibility. Reports are not published, shared with other users, used for advertising, or added to a permanent test corpus without separate permission. They are deleted when no longer needed and always within 90 days.

The app shows a diagnostic ID after sending. Email that ID to support to request earlier deletion.

Product analytics

Product analytics is on by default for new installations and can be turned off at any time in Settings. If you installed Uzora while analytics was opt-in, it stays off until you answer the one-time question the update shows you. It sends a small allowlisted set of product events: for example whether onboarding or an import succeeded, whether the first stitch was marked, which tools and broad feature actions get used, the install channel and platform, the device language, and coarse session ranges. An installation and session receive random pseudonymous identifiers so return use can be understood.

Analytics never contains pattern titles or contents, filenames, chart coordinates, notes, photos, email addresses, raw error messages, receipts, or payment information. It is not sold, used for advertising, combined with third-party data, or given to data brokers. Supabase processes these events on Uzora’s behalf. Disabling Share private usage analytics clears queued events and the random identifier from the device and stops future collection. The random identifier itself is replaced with a new one after 13 months, so it cannot follow an installation indefinitely. Previously delivered pseudonymous events are kept for no more than 13 months, then deleted or aggregated without the installation identifier.

Crash reports

Some builds may include crash reporting. If enabled, it contains technical crash information such as a stack trace, device class and OS version, but no chart content, photos or personal data. Builds without a configured crash-reporting service send no crash reports.

The launch waiting list (website only)

The website offers a form to be told when Uzora reaches Google Play and the App Store. It collects the email address you type, the platform you pick, and the language the page was in — nothing else, and no part of it comes from the app. The address is used for exactly one message, the one announcing the public release; it is not a newsletter, it is never sold or passed to anyone else, and it is not linked to any analytics identifier. Signing up again from another device updates your platform choice instead of adding a second entry. Ask us to remove your address at any time and we will, before or after that message.

Your choices

Contact

Privacy questions and deletion requests: uzora@rozhnov.me.

Uzora support