Table of Contents

Last updated: July 29, 2026

This Privacy Policy explains how Stash2Go ("we", "us", "our") collects, uses, and protects information when you use the Stash2Go mobile application and related services ("App").

By using the App, you agree to the practices described here.

1. Information We Collect

We collect account information, device data, advertising identifiers, preferences, analytics, and optional AI feature data.

1.1 Information You Provide

Account information if you log in using Ravelry (username, tokens).

If you use Google-only mode, we store the account information needed to provide your Stash2Go account and sync your Google-only content across devices.

Optional data you submit, such as notes, project details, pattern favorites, or library items.

In Google-only mode, this can include project data and stash data that you create or edit in the App.

We do not store your Ravelry password. Authentication is handled by Ravelry.

1.2 Automatically Collected Information

When you use the App, we automatically collect:

  • Device information: device type, Android version, language, screen size.
  • Log data: IP address, crash reports (sent to our self-hosted GlitchTip instance for error tracking), app performance data.
  • Usage data: features used, screens visited, session duration.

1.3 Advertising Data (Google AdMob & Unity Ads)

If you use the free / ad-supported version of Stash2Go:

Our app uses Google AdMob and Unity Ads (via AdMob mediation) to display advertisements. These services may collect certain information from your device to provide, personalize, and optimize ad delivery.

Information Collected by Google AdMob

Google AdMob may collect:

  • Advertising ID (
  • IP address and general location (country/region level)
  • Device information (model, Android version, language, network type)
  • Usage data related to ad interactions

How This Information Is Used

This data enables:

  • Personalized/non-personalized ads (based on your preferences)
  • Frequency capping (limiting repetitive ads)
  • Fraud prevention
  • Performance measurement
  • Ad relevance and optimization

Data Sharing

Google AdMob and Unity Ads may share aggregated, non-personally identifiable data with their advertising partners.

Third-Party Privacy Policies

For more details on data practices, users can review:

Opt-Out of Personalized Advertising

You have control over personalized advertising:

  1. In-App Setting: You can disable personalized ads directly in the app by going to Settings → Legal & Privacy → Personalized Ads. When disabled, you will still see ads, but they will not be personalized based on your interests.

  2. Device Settings: You can also limit ad tracking using your device settings:

    • Android: Settings → Google → Ads → Opt out of Ads Personalization

Note: Opting out of personalized ads does not stop ads from being displayed, but it may make them less relevant to your interests.

Ad-Free Version

You can upgrade to the premium version of Stash2Go to remove all advertisements, including Google AdMob and Unity Ads. The premium version provides an ad-free experience and additional features. When you upgrade, all advertising-related data collection by Google AdMob and Unity Ads will cease, as these services are completely removed from the premium version of the app.

1.4 Server-Stored Preferences

To enable synchronization of your app preferences across multiple devices, Stash2Go stores certain preference data on our servers. This includes:

  • Unit preferences (metric/imperial, weight units, length units)
  • Color theme preferences
  • Appearance settings
  • Other app configuration settings

Purpose: This data is stored solely to enable cross-device synchronization and to restore your preferences if you reinstall the app or use the app on a new device.

Data Storage: Preferences are stored securely on our servers and are associated with your Ravelry username. The data is encrypted in transit and stored in a secure database.

Your Rights:

  • You can export your preferences at any time via Settings → Legal & Privacy → Export Preferences (sends preferences as JSON via email)
  • You can delete all server-stored preferences at any time via Settings → Legal & Privacy → Delete Server Preferences
  • Deleting server preferences will remove them from our servers but will not affect your local device settings

Data Retention: Server-stored preferences are retained until you delete them or until your account is deleted.

1.5 Analytics Data

We collect anonymized usage events (screens viewed, features accessed, session duration, and interaction context) to understand and improve how the App performs for the community. These anonymized events are sent to https://api.stash2go.com/api/events for internal usage analysis and product quality reporting. The payloads do not include your name, email, credentials, or other direct identifiers; the data is aggregated to prevent identification of individual users.

Usage analytics are enabled by default (full tracking). You can opt out at any time from within the App by visiting Settings → Legal & Privacy → Usage Analytics. When you disable usage analytics, event reporting to api.stash2go.com stops immediately and no new usage events are sent while tracking remains turned off.

1.6 Assisted Features Data (Opt-In)

Assisted features are AI features. Each one sends data through the Stash2Go server to OpenAI and receives the answer the same way; your device never contacts OpenAI directly. Every one of them is off until you switch it on, individually, in Settings → Assisted Features. Nothing sent may be used to train a model. Section 12 below states where we stand, and links our full AI policy.

Turning AI off completely. Settings → Assisted Features has a single switch that blocks the whole category: while it is on, no assisted feature runs or is offered, none can be switched on, and nothing is sent to OpenAI. Your earlier choices are remembered and return if you allow AI again. The switch is not engaged by default, because every feature is already off on its own.

What each feature sends when you use it:

  • Assisted Search: your search words and the other searches in that session. On first use it also builds a preference profile from the public side of your Ravelry profile (projects, favourites, queue, public bundles, library and stash). Private and friends-only bundles are excluded, and fields Ravelry shows only to you are removed before anything is sent. The profile can be deleted at any time.
  • Photo Stashing: the label photo you take while adding yarn to your stash.
  • Yarn Scanner: the yarn photo you take to identify it.
  • Yarn Estimator: the pattern and yarn details for the size you select.
  • Suggested Comments: the title, description, designer, craft, tags and yarn of the item you are commenting on, plus your country code.
  • PDF Pattern Translation: only the passage you ask about, with its title and page number. The PDF file itself is never sent.
  • PDF Auto-Setup: the pattern text, and an image of a chart area when you ask for that chart to be read. The PDF file itself is never sent.
  • Bobbin (craft assistant): your message and which screen you are on, and up to 25 recent entries from your stash, projects, queue, favourites, needles or library when your question requires them. Your Ravelry credentials are never sent: the App retrieves the data and passes on the result.
  • Magazine: nothing about you. The articles themselves are generated with a model.
  • Studio colour tools: the link to the yarn photo whose colours you ask about.
  • Video captions: the project details of the video you are creating, and only when you request captions.

Trending forum themes. The Discover screen shows what the Ravelry forums are discussing. Several times a day our server groups public Ravelry forum topic titles with an OpenAI model and names each group. This uses no personal data, produces the same result for everyone, and is the only assisted feature without an individual switch; turning AI off completely removes it as well.

On-device features are not affected. Features labelled OpenCV, such as chart detection in PDF patterns, analyse images on your device. They send nothing and continue to work when AI is switched off.

None of these features send your account credentials, your messages, or your full project or stash data beyond the specific items listed above.

1.7 Error Tracking Data (GlitchTip, self-hosted)

To help us identify, diagnose, and fix bugs and performance issues, our app uses GlitchTip (self-hosted at errors.stash2go.com) for error tracking and performance monitoring. Error data is stored on our own server and is not sent to any third-party error tracking service.

Information Collected:

When error tracking is enabled (enabled by default), the following data may be collected:

  • Error messages, stack traces, and crash reports
  • Device information (model, Android version, language, screen size)
  • App version and build information
  • User context (if you are logged in): username, first name, last name, location (city/region level)
  • Breadcrumbs (user actions leading to errors, such as navigation events and API calls)
  • Performance data (10% sample rate in production for performance monitoring)
  • Session information (session duration, app state)
  • IP address (for approximate region)

How This Information Is Used:

This data enables us to:

  • Identify and fix bugs and crashes
  • Improve app stability and performance
  • Understand error patterns and prioritize fixes
  • Monitor app health and performance metrics

Data Storage:

Error tracking data is processed and stored on our own self-hosted GlitchTip instance at errors.stash2go.com. No error data is sent to third-party error tracking services. The @sentry/react-native SDK is used for data collection, but all data is transmitted directly to our own server.

Opt-Out of Error Tracking

Error tracking is enabled by default to help us improve the app. You can disable error tracking at any time by going to Settings → Legal & Privacy → Error Tracking. When disabled, no error reports or performance data will be sent to our server. Note that disabling error tracking may prevent us from identifying and fixing issues that affect your app experience.

2. How We Use Your Information

We use your data to operate the app, provide Ravelry features, display ads, improve performance, and offer AI-powered features (if enabled).

Lawful Basis for Processing (GDPR):

We process your personal data based on the following lawful bases:

Purposes of Processing:

We use collected information to:

We do not sell your personal data.

3. Data Sharing

We share data with service providers (ad networks, analytics, AI services) and Ravelry. We do not sell your personal data.

3.1 Service Providers

Trusted providers who help us:

  • deliver ads (Google AdMob, Unity Ads)
  • provide analytics
  • track errors and monitor performance (self-hosted GlitchTip) - enabled by default, can be disabled
  • operate app functionality
  • provide assisted features (OpenAI) - only for the assisted features you switch on yourself, listed in section 1.6

These providers are required to protect your data.

3.2 With Ravelry

If you choose to connect your Ravelry account, data is exchanged according to Ravelry's API rules and their Privacy Policy.

3.3 Legal Requirements

We may disclose information if required by law, regulation, or court order.

We do not share personal information with advertisers directly.

4. Children's Privacy

The app is not intended for children under 13 (COPPA) or 16 (GDPR). We do not knowingly collect data from children.

The App is not intended for children under the age allowed by local regulations (e.g., 13 under COPPA, 16 under GDPR).

We do not knowingly collect data from children.

If you believe a child has submitted information, contact us and we will delete it.

5. Your Choices & Rights

You can opt out of personalized ads, disable AI features, and exercise GDPR/CCPA rights including access, deletion, and data portability.

5.1 Opt-Out of Personalized Advertising

You can disable personalized ads in two ways:

  1. In-App Setting: Go to Settings → Legal & Privacy → Personalized Ads to disable personalized advertising directly in the app.

  2. Device Settings: You can also limit ad tracking using your device settings:

    • Android: Settings → Google → Ads → Opt out of Ads Personalization

When personalized ads are disabled, you will still see ads, but they will not be tailored to your interests based on your activity.

5.2 Assisted Features Opt-Out

You do not have to opt out, because nothing is on to begin with: every assisted feature starts switched off and stays off until you switch it on.

To switch one off again, or to shut the whole category:

  • One feature at a time: Settings → Assisted Features, where each feature has its own switch and states what it sends.
  • All of them at once: the switch at the top of that screen turns AI off completely. While it is on, no assisted feature runs or is offered, none can be switched on, nothing is sent to OpenAI, and the trending forum themes card is not shown. Your earlier choices are remembered if you allow AI again.
  • The preference profile built by Assisted Search can be deleted separately, in the App.

When a feature is off, nothing is sent to OpenAI for it. A preference profile that was already generated remains stored until you delete it.

5.3 Opt-Out of Error Tracking

You can disable error tracking at any time:

  • In-App Setting: Go to Settings → Legal & Privacy → Error Tracking to disable error tracking directly in the app.

When error tracking is disabled, no error reports, crash data, or performance monitoring data will be sent to our server. This may prevent us from identifying and fixing issues that affect your app experience.

5.4 Data Rights (GDPR / CCPA)

If you are located in the European Economic Area (EEA), United Kingdom, or California, you have specific rights regarding your personal data:

Your Rights:

  • Right of Access: You can request a copy of the personal data we hold about you
  • Right to Rectification: You can request correction of inaccurate or incomplete data
  • Right to Erasure ("Right to be Forgotten"): You can request deletion of your personal data under certain circumstances
  • Right to Restrict Processing: You can request that we limit how we use your data
  • Right to Data Portability: You can request a copy of your data in a structured, machine-readable format
  • Right to Object: You can object to processing of your data for certain purposes
  • Right to Withdraw Consent: If processing is based on consent, you can withdraw it at any time (this does not affect the lawfulness of processing before withdrawal)

How to Exercise Your Rights:

To exercise any of these rights, please contact us at privacy@stash2go.com with:

  • Your name and contact information
  • A clear description of the right you wish to exercise
  • Any relevant details to help us process your request

We will respond to your request within one month (or two months for complex requests). We may need to verify your identity before processing certain requests.

Right to Lodge a Complaint:

If you believe we have not addressed your concerns, you have the right to lodge a complaint with your local data protection authority:

6. Data Retention

We keep data only as long as necessary to provide the app, comply with legal requirements, or maintain legitimate business needs.

We keep data only for as long as necessary to provide the App, comply with legal requirements, or maintain legitimate business needs.

For Google-only accounts, project data and stash data stored by Stash2Go are retained until you delete them, request account deletion, or they are no longer needed to provide the service.

If you delete your Google-only Stash2Go account, the Google-only project and stash data associated with that account will be deleted from our servers, subject to any limited retention required by law or for security, fraud-prevention, or backup recovery purposes.

Ad identifiers and analytics data are retained according to the third-party providers' policies.

7. Data Security

We use encryption, secure authentication, access controls, and regular security assessments to protect your information.

We use reasonable technical and organizational measures to protect information, including:

No method of transmission or storage is 100% secure, but we aim to safeguard data to industry standards.

Data Breach Notification:

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (as required by GDPR) and inform affected users without undue delay.

8. Third-Party Services

The app integrates with Ravelry, Google AdMob, Unity Ads, and OpenAI. Their data practices are governed by their own policies.

The App may contain links or integrations with third-party services, including Ravelry, Google AdMob, Unity Ads, and OpenAI (for opt-in assisted features). Error tracking is handled by our self-hosted GlitchTip instance (errors.stash2go.com) and does not involve third-party services.

Their data practices are governed by their own policies.

Google AdMob Privacy Policy: https://policies.google.com/technologies/ads

Unity Ads Privacy Policy: https://unity3d.com/legal/privacy-policy

Ravelry Privacy Policy: https://www.ravelry.com/about/privacy

OpenAI Privacy Policy: https://openai.com/policies/privacy-policy

We are not responsible for third-party content or practices.

9. International Data Transfers

Your data may be transferred internationally. We use Standard Contractual Clauses and other safeguards for transfers outside the EEA.

If you are located outside the country where our servers are hosted, your information may be transferred internationally, including to countries outside the European Economic Area (EEA).

Safeguards for International Transfers:

When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, such as:

We process data in accordance with applicable laws, including GDPR requirements for international transfers.

10. Android-Specific Privacy Information

We may update this policy. Continued use means you accept the revised policy. The "Last updated" date reflects changes.

Google Play Data Safety Section

In accordance with Google's Play Store policies, we disclose our data collection, sharing, and security practices in the Data Safety section on our app's Play Store listing. This section provides transparency about:

  • What data we collect and why
  • How data is used and shared
  • Security practices we follow
  • Your data deletion options

Granular Permissions

Android allows you to manage app permissions individually. You can adjust these settings at any time through your device's settings menu (Settings → Apps → Stash2Go → Permissions). We request only the permissions necessary for our app's functionality and provide clear explanations for each permission request.

Google Advertising ID

On Android, we use the Google Advertising ID (GAID) for advertising purposes. You can reset or opt out of personalized ads through Android Settings → Google → Ads → Reset advertising ID or Opt out of Ads Personalization.

Google TV / Chromecast

If you are using Stash2Go on Google TV or Chromecast, please refer to our dedicated Google TV Privacy Policy. The Google TV version is a read-only companion app that does not display ads and only presents data from your Ravelry account.

11. Changes to This Policy

Luxx Yarns GmbH (LUXX) is the data controller. Contact privacy@stash2go.com for questions or to exercise your rights.

We may update this Privacy Policy from time to time.

When we update it, we will change the "Last updated" date at the top.

Your continued use of the App means you accept the revised Policy.

12. Data Controller & Contact Information

The app works without AI, every assisted feature starts off, AI-generated patterns are refused, and nothing sent may be used to train a model.

Data Controller:

Luxx Yarns GmbH (LUXX) is the data controller responsible for processing your personal data in connection with the Stash2Go app.

Contact Us:

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:

Email: privacy@stash2go.com

Website: https://stash2go.com

Company: Luxx Yarns GmbH (LUXX)

For GDPR-related inquiries specifically: Please include "GDPR Request" in your subject line to ensure prompt handling.

12. AI Policy

The app works without AI, every assisted feature starts off, AI-generated patterns are refused, and nothing sent may be used to train a model.

This is our complete AI policy. Section 1.6 lists what each feature sends; section 5.2 explains how to switch them off.

12.1 In short

  • We never make patterns with AI. A knitting or crochet pattern must be made by a person. We will not add a feature that generates patterns.
  • Every AI feature is off when you install the App. You switch on what you want. One card on the Discover screen is the single exception, and it sends nothing about you.
  • One switch turns AI off completely, that card included. Then nothing runs and nothing is sent.
  • Nothing that is sent may be used to train AI. Not your data, not a designer's pattern, not even information that is already public.
  • The App works fully with AI switched off. Counters, charts, stash, projects, patterns: all normal.

12.2 AI-generated patterns: we say no

Stash2Go does not generate knitting or crochet patterns. We will not add a feature that does. We will not help publish or sell one. A pattern must be a real human creative act. Ravelry does not allow generated patterns in its database either.

A model has never held a needle. What it makes reads like a pattern: the numbers do not add up, the shaping does not work, and nobody ever made the thing in the photo. The seller does not pay for that. A beginner does, and a first project that was never possible can end someone's crafting before it starts.

Keeping this out of a pattern database is slow human work, and on Ravelry much of it is done by volunteers in their free time. Far more of it arrives than used to. That work deserves thanks, and we will not add to the pile. Stolen patterns are the same problem: if you find one, tell the designer and report it on Ravelry.

If you are a designer. Your pattern file is never sent to OpenAI. If a reader uses translation or Auto-Setup on their own copy, only the text needed for that one job goes out, and it may not be used for training. Both are off unless the reader switches them on. We do not sell, share or republish patterns, and we never generate them.

What our features actually do. They read a pattern a person wrote: counters from your own copy, one passage explained, some arithmetic. None of them writes a pattern, and none ever will. Search results come from Ravelry's own database, so nothing generated is added to what you see. The only text a model writes anywhere in Stash2Go is the beta Magazine's articles, which are off by default and labelled. Never patterns.

12.3 Where we stand

AI helps with a few boring jobs. It does harm when it is used for the creative work itself. So we keep those two apart.

What we use it for: reading a yarn label from a photo, explaining one passage of a pattern in a language you cannot read, estimating how many skeins a size needs, and grouping public forum titles for the Discover screen. Small, checkable jobs where you see the answer and judge it yourself.

Why we are careful with it:

  • It sounds just as confident when it is wrong. A stitch count it made up looks exactly like one a designer worked out.
  • The models were trained on craft work without asking the people who made it. We cannot undo that, and we will not pretend it did not happen.
  • It makes it cheap to mass-produce things that look like patterns. That is the real damage, and section 12.2 is our answer to it.
  • It is pushed at people who never asked for it. Many knitters and crocheters want none of it, and that is a fair position.

Controlled, or not at all. Our rule is: help the person doing the craft, never do the craft. Either each feature has its own switch and they all start off, or one switch in Settings → Assisted Features turns the category off entirely. There is no third way where we decide for you. Nothing is on by default, no update switches anything on, and your choices are remembered and follow your account.

12.4 Nothing that is sent may be used to train a model

Stash2Go reaches OpenAI through the paid API, where data sent through the API is not used to train OpenAI's models. We have not enabled anything that would allow it, we keep nothing in order to build a training set, and we pass nothing to anyone else for that purpose. OpenAI holds a request briefly for abuse monitoring under its own API terms, then deletes it.

This holds for public information as much as private. Your projects and favourites may be public on Ravelry, and a designer's pattern is a published work. Public does not mean free to train on. If this ever changed on the provider's side, we would change this policy and say so.

12.5 What AI never decides

No model decides anything about you. It does not judge your account, moderate your posts, set your price, rank you against other knitters, or make any choice that has a consequence for you. It answers the one question you asked and stops there.

Where a model does write something, it is marked as such: Bobbin says what it is, Magazine articles are labelled, and no answer is written into your Ravelry data unless you put it there. When something is wrong, and it will be, the designer's own words win.


Copyright © 2026 Stash2Go
Luxx Yarns GmbH (LUXX)