Legal
Privacy Policy
Draft — pending operator and contact details
Prepared October 3, 2026. Values shown as highlighted placeholders — operator name, contact email, minimum age, and province or territory — are being confirmed and will be filled in before launch. This document has not been legally approved.
Stiitch is a social video app where friends build connected video stories together. This policy describes, in plain language, what the app and this website do with your information.
01Who we are and how to reach us
This Privacy Policy applies to the Stiitch mobile app and this website, operated by [LEGAL OPERATOR NAME] ("Stiitch", "we", "us"). It explains what personal information we collect, why, how long we keep it, who can see it, and the choices you have.
For any privacy question or request — access, correction, withdrawal of consent, deletion, safety reports, or complaints — contact us at [PRIVACY EMAIL]. Accepting our Terms & Conditions is not blanket consent to optional processing: where the law requires separate consent, we ask for it separately.
02Information we collect
We collect the following categories of information when you use Stiitch:
- Account information: your name, email address, username, user and provider identifiers, avatar, bio, authentication information processed by our authentication provider, and account dates and preferences. If you sign in with Google, Google supplies the identity and profile details you authorize; Stiitch does not receive your Google password.
- Content: the short video stories and connected video replies you post (with audio), their thumbnails, profile images, direct messages and attachments, plus identifiers, timestamps, duration, size and format, the conversation relationships between stories and replies, the audiences you select, and location information stored with a story.
- Social activity: friendships and friend requests, invite and QR codes, discovery and search interactions, reactions, views, saves, messaging activity, blocks and mutes, and notification settings.
- Safety and support: reports you submit, the content and account identifiers involved, your descriptions, relevant evidence, moderation actions, and our correspondence with you.
- Technical data: IP addresses and request/security logs, platform, device and app information, installation identifiers, and push notification tokens.
- Analytics and diagnostics: Stiitch includes Firebase Analytics, which records interactions such as sign-in, signup, taps, sharing, and story and reply submissions. Automatic SDK events, identifiers, device characteristics, and approximate geography may also be processed. Diagnostic capabilities included in builds may process crash, device, and app context. We do not represent this data as necessarily anonymous.
- Local storage: sessions, settings, cached media, drafts, and pending or retried uploads are stored on your device. This website uses browser storage for preferences, and our hosting provider keeps standard hosting logs.
03Location information
Location is optional on Stiitch. If you grant location permission, signup can obtain and store a location name and latitude/longitude on your profile. The recording preview can obtain your coordinates to generate a city or region label that is stored with a posted story and visible to its permitted viewers; your operating system's geocoding service processes those coordinates to produce the label.
Refusing location permission does not prevent you from signing up or posting. Current Stiitch features do not require continuous background location tracking. Turning the permission off stops future collection but does not erase location data already stored. Keep in mind that the media itself — what is visible or audible in a video — can reveal where it was recorded.
Friend discovery on Stiitch works through profiles, mutual connections, QR codes, invite links, and the system share sheet. Stiitch does not upload your device address book, and we do not request a contacts permission.
04How we use information
We use the information above to:
- authenticate you and maintain your profile;
- upload, store, and play back your media and connect replies to stories;
- power friends, saves, reactions, and direct messages;
- enforce the audiences you select and the blocks you set;
- send notifications you have enabled;
- remember your preferences;
- troubleshoot problems and understand how the app is used;
- provide support and protect safety, including fraud and abuse prevention; and
- meet legal obligations.
Optional location information is used only for the purposes described in the Location section above: your profile location and the city/region label stored with a posted story.
We send promotional communications only with the consent or authorization the law requires. If we ever want to use your information for a materially new purpose, we will explain the new purpose and seek your consent where the law requires it.
05Device permissions
Stiitch asks for the following device permissions. Each is used only for the feature listed, declining one limits only the related features, and you can revoke any permission in your device settings at any time. Revoking a permission stops future collection but does not erase data you have already uploaded. Available permissions vary by device and app build.
| Permission | What it is used for | If you decline |
|---|---|---|
| Camera | Recording video stories and replies, and scanning a friend's QR code. | You cannot record video or scan QR codes in the app. |
| Microphone | Recording the audio that is part of your video stories and replies. | Recording features that require audio may be unavailable. |
| Photos / media | Selecting media to upload, attach to messages, or use as your avatar. | Selecting existing media may be limited; your device may offer a system picker or limited selection. |
| Save to photos / storage | Exporting media you choose to save to your device (legacy Android storage). | You cannot export media to your photo library from the app. |
| Location | Optional profile location at signup and the city/region label stored with a posted story. | Stories post without a location label; signup and posting still work. |
| Notifications | Alerts for stories, replies, friends, reactions, and messages you allow. | You will not receive push notifications. |
| Network / background data | Finishing uploads you started, even if you leave the screen. | Uploads may pause or fail until you return to the app. |
Camera
Recording video stories and replies, and scanning a friend's QR code.
If you decline: You cannot record video or scan QR codes in the app.
Microphone
Recording the audio that is part of your video stories and replies.
If you decline: Recording features that require audio may be unavailable.
Photos / media
Selecting media to upload, attach to messages, or use as your avatar.
If you decline: Selecting existing media may be limited; your device may offer a system picker or limited selection.
Save to photos / storage
Exporting media you choose to save to your device (legacy Android storage).
If you decline: You cannot export media to your photo library from the app.
Location
Optional profile location at signup and the city/region label stored with a posted story.
If you decline: Stories post without a location label; signup and posting still work.
Notifications
Alerts for stories, replies, friends, reactions, and messages you allow.
If you decline: You will not receive push notifications.
Network / background data
Finishing uploads you started, even if you leave the screen.
If you decline: Uploads may pause or fail until you return to the app.
Background data sync is used to complete uploads you initiate — it is not used for background camera or microphone recording.
06Who can see your information
Your profile name, username, avatar, and bio may be discoverable beyond your friends — for example through search or mutual connections. Stories and replies follow the conversation's access rules: the audience selected for the story, friendships, and blocks all apply. Because replies connect to a story, participants in a conversation may not know everyone who is permitted to view it. Saving or sharing a thread never overrides these access restrictions.
Direct messages are intended for the conversation's participants, but they are not end-to-end encrypted. Authorized staff and service providers may process and access stored data as needed to operate, support, and secure the service, and to comply with the law. Notifications on a locked screen may expose message or story information to anyone holding your device. Other users can also make screenshots, downloads, or independent copies of content they can view, which we cannot erase.
We share information with service providers only as needed for their role:
- Supabase — authentication, database, storage, and backend services;
- Google / Firebase — analytics, push notifications, and diagnostics included in builds;
- Apple — notification infrastructure;
- Google — sign-in, when you choose it;
- your operating system — geocoding for location labels; and
- website hosting and operational communications providers.
We may also disclose information where the law or safety requires it, or as part of a business transfer, in each case with appropriate protections.
07How long we keep information
Ordinary threads that no one saves or shares normally leave the timeline 7 days after the root story was created. That is a visibility rule, not a promise of deletion at 7 days. After 30 days from the root story's creation, the thread becomes eligible for backend cleanup; media cleanup is queued and may take additional processing time.
Saved threads — including threads saved by another permitted user — and threads shared in direct messages can persist longer. Removing a direct message does not necessarily remove its retention marker. Access restrictions continue to apply for as long as a thread exists, and you can delete your own content or your whole account at any time.
Account, profile, and message data is kept as needed to provide the features or until you delete your account. Limited support, security, abuse-prevention, and legal records are kept only as needed or as the law requires. Backups, provider logs, and analytics follow separate deletion cycles and may be subject to lawful holds, so we cannot promise immediate or complete erasure from every system. We aim to minimize what we retain and to restrict its use to the purpose it is kept for. Uninstalling the app or signing out does not delete your account.
08Deleting your account and data
You can delete your account in the app via Menu → Settings → Account → Delete Account and confirming, or by emailing [PRIVACY EMAIL] with the subject "Delete my Stiitch account". Deletion is permanent — it is not a deactivation.
The process restricts further writes to the account, removes associated uploaded media, revokes sessions, and deletes the account and profile. It removes your own stories, replies, and media, and your account-linked social data. Current one-to-one messaging deletes the associated conversations and attachments from Stiitch, including for the other participant. Video replies that other people independently authored can remain, and minimal structural story records — with the account link and media removed — may remain to keep those replies connected, retaining only technical identifiers and timestamps.
Independent external copies made by other users, limited legal and security records, and backup and provider deletion cycles are exceptions. Deletion from service providers is subject to their applicable mechanisms, and deleting your Stiitch account does not delete your Google account. If deletion fails partway, the account may remain restricted pending retry or support. Full step-by-step instructions are on our Account & Data Deletion page.
09Reporting content and safety concerns
To report a story in the app: open the story's options menu, choose Report story, pick a reason, add any helpful details, and tap Submit Report. If you want to stop seeing someone, the Block option is also available.
For messages, profiles, or other concerns that do not have an appropriate in-app report control, email [PRIVACY EMAIL] with the subject "Stiitch safety report". Include the offending username, a story link or ID if available, the date, and an explanation. Please do not forward illegal imagery, and never send your password or verification codes — we will never ask for them. If someone is in immediate danger, contact your local emergency services first.
Reports, the identifiers involved, and our correspondence are handled as described in the Safety and support category above. How we investigate and act on reports is described in the moderation section of our Terms & Conditions.
10Your choices and rights
You control device permissions and notifications through your operating system settings. You can request access to, correction of, or deletion of your personal information, and withdraw consent, by contacting [PRIVACY EMAIL]; where applicable law provides portability or restriction rights, you can exercise them the same way. We apply proportionate verification to protect other people's information.
To stop marketing emails, use the unsubscribe link in the email or write to us with the subject "Stiitch opt out". Where Canada's Anti-Spam Legislation applies, we process marketing unsubscribes no later than 10 business days and keep a minimal suppression record so we do not contact you again. Essential security, account, and support messages may continue. For questions about optional processing, use the subject "Stiitch privacy opt out".
The current app has no in-app analytics toggle. Revoking permissions or notifications does not stop analytics collection, and emailing us does not instantly change settings inside an installed SDK — but we will explain the available options and their effects if you ask.
Under PIPEDA, access requests are normally answered within 30 days, subject to lawful extensions; that access deadline is separate from deletion timing, which depends on the cycles described above. You may also complain to the Office of the Privacy Commissioner of Canada or to your applicable privacy authority.
11Security and international processing
We use reasonable access controls and safeguards to protect personal information, but no system is perfectly secure, and we cannot guarantee absolute security. Please protect your own credentials and device.
Our service providers can process information outside your province or country, including in the United States and other jurisdictions, where it may be accessible to local lawful authorities. When information crosses borders, the laws of the place where it is processed may apply to it.
12Age, changes, and contact
Stiitch is intended for people aged [MINIMUM AGE] and older. If we learn that a child who does not meet the minimum age has provided us personal information, we will handle and delete that data as required once it is reported.
If we change this policy, we will update the effective date, give notice, and seek consent where the law requires it. Questions about this policy: [PRIVACY EMAIL].