StencilStudio Privacy Policy

Effective Date: March 16, 2026

This Privacy Policy explains how StencilStudio (“we”, “us”, “our”) handles personal data when you use the StencilStudio iOS app and the related public pages hosted at beyondcal.com/stencilstudio (together, the “Service”).

StencilStudio is an AI-assisted stencil workflow app for tattoo artists, apprentices, and studios. Users can upload photos, references, and existing tattoo images, then generate stencil-style outputs more quickly than a fully manual tracing workflow. This policy is written for that product, not for a general image-sharing service.

1. Overview

We collect the data we need to run accounts, process uploaded files, generate stencil outputs, manage subscriptions and credits, provide support, and keep the Service secure.

We do not sell personal data. We do not share personal data for someone else's advertising.

You remain the owner of the images, references, prompts, and generated stencil outputs you submit or create in the Service, subject to the limited processing rights described here and in our Terms of Service.

2. Information We Collect

We collect the following categories of data.

2.1 Account and Authentication Data

  • Email address
  • Authentication data, such as a hashed password for email sign-in or identifiers returned by Apple or Google sign-in
  • Basic profile information you choose to add, such as a display name, artist name, or studio name

2.2 Uploaded Source Materials

To use the core stencil features, you may upload or capture:

  • Photos
  • Reference images
  • Existing tattoo images
  • Stencil-like source files
  • Text instructions, prompts, or editing choices you submit

These materials may include visible people, body parts, tattoos, copyrighted artwork, or other sensitive source material. Please upload only what you need for the requested job.

2.3 Generated Outputs and Project Data

  • Generated stencil outputs, previews, exports, and saved files
  • Generation history and job status records
  • Settings linked to a generation, such as mode, detail level, style preset, and similar processing metadata

2.4 Technical, Device, and Diagnostics Data

  • Device model, operating system, app version, and language
  • Basic log information such as timestamps and security events
  • Crash reports, error events, and performance diagnostics
  • Backend request data needed to operate the Service and investigate failures or abuse

2.5 Usage Data

  • Features used, screens visited, and basic in-app activity
  • Generation counts and credits consumed
  • Subscription-related state such as whether paid access is active and when credits refresh or expire

2.6 Communication Data

  • Your emails and support messages
  • Files, screenshots, or other attachments you send us
  • Any details you choose to include in a support or privacy request

2.7 Push Notification Data

In the current version of StencilStudio, push notifications are not active.

If we enable notifications in a later version, we may collect a device push token and notification preferences so we can deliver those alerts. If that happens, we will update this policy as needed.

2.8 Payment, Subscription, and Credit Data

If you buy a subscription or a one-time credit pack, we receive billing and entitlement information needed to unlock paid features and manage credits.

  • Plan or product identifier
  • Purchase, renewal, cancellation, and expiration status
  • Credit balances and credit-related events
  • Storefront or transaction reference data

Payments are handled by Apple and related billing providers. We do not receive your full payment card details.

3. How We Use Your Data

To operate your account

  • Create and maintain your account
  • Authenticate sign-in and secure access
  • Store your settings, projects, and generation history

To deliver the stencil features

  • Upload, store, retrieve, and display your source materials
  • Generate stencil outputs and save them to your account
  • Let you revisit prior generations, downloaded files, and related project data

To run AI-powered generation

  • Send uploaded images, prompts, and related metadata to AI providers such as OpenAI strictly to create or refine the stencil output you requested
  • Return the resulting output to your account and keep the generation record available inside the Service

We use this processing only to operate the feature. You remain responsible for making sure you have the rights and permissions needed to upload and use the source material you submit.

To manage subscriptions, purchases, and credits

  • Confirm paid access
  • Refresh monthly subscription credits
  • Apply top-up credits and track credit usage
  • Restore purchases and correct obvious billing or balance errors

To improve, maintain, and secure the Service

  • Monitor reliability, diagnose crashes, and fix bugs
  • Understand how core features are used
  • Detect fraud, abuse, scraping, and unauthorized access

To communicate with you

  • Reply to support and privacy requests
  • Send service emails about account, billing, or legal changes
  • Send other necessary operational messages

To comply with law

  • Keep records required for tax, accounting, or consumer law
  • Respond to lawful requests and enforce our terms

4. Legal Bases for Processing (GDPR)

If you are in the EEA or UK, we rely on the following legal bases:

  • Performance of a contract: to create your account, run stencil generation, store your files, and manage paid access.
  • Legitimate interests: to secure the Service, prevent abuse, investigate failures, improve product quality, and provide support.
  • Consent: where we ask for it for optional device or privacy settings.
  • Legal obligation: where processing is required to meet applicable legal, tax, accounting, or consumer protection duties.

5. Third-Party Providers and AI Processing

We use service providers that process data on our behalf.

  • Supabase for authentication, database services, file storage, and backend functions.
  • OpenAI and similar AI providers for image processing and stencil generation when you use AI-powered features.
  • RevenueCat for subscription entitlement and virtual currency management tied to in-app purchases.
  • Apple and other platform providers for app distribution, in-app purchase processing, and store-level billing.
  • Sentry for crash reporting and technical diagnostics.

If notifications are enabled in a future version, we may also use push delivery providers such as Expo or Apple push services.

We require processors to handle data only as needed to deliver their part of the Service and under appropriate security and confidentiality obligations.

6. Data Storage, Security, and Location

Account records, uploaded files, and generated outputs are primarily stored through Supabase-managed infrastructure and related cloud services selected for the project.

We use reasonable technical and organizational safeguards, including encryption in transit, access controls, credential protection, and least-privilege access where practical.

No service can promise perfect security. We work to reduce risk, but no system is completely immune from unauthorized access, outages, or data loss.

Some processing may happen outside your country of residence depending on the infrastructure used by our providers. More on international transfers appears below.

7. Data Retention

We keep personal data only for as long as we reasonably need it for the purposes described in this policy.

  • Account data, uploaded source materials, generation history, and generated outputs are generally kept while your account remains open, unless you delete them earlier.
  • Support and communication records are kept for as long as needed to handle the request and maintain reasonable records.
  • Diagnostic logs are usually kept for a shorter period, subject to what is needed for troubleshooting and security.
  • Subscription, purchase, anti-abuse, deletion, and compliance records may be retained longer where needed to verify purchases, defend chargebacks, enforce limits, prevent abuse, or comply with law.

You can delete your account inside the app. That is the standard account-deletion flow.

If you delete your account or ask us to delete your data, we will remove or anonymize personal data from active systems within a reasonable period, unless we need to keep limited data for legal, accounting, purchase-integrity, security, abuse-prevention, or dispute reasons.

Some data may remain in backups until those backups are overwritten. RevenueCat or platform purchase history may also remain subject to the retention rules of those providers.

8. Children and Age Limit

StencilStudio is not intended for users under 16, and we do not knowingly collect personal data from children under 16.

If you believe a child under 16 has provided us personal data, contact privacy@craftuplearn.com so we can review and delete the data where appropriate.

9. Your Rights

Depending on your location, you may have rights to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Request restriction of certain processing
  • Object to certain processing based on legitimate interests
  • Receive a portable copy of certain data
  • Withdraw consent where processing relies on consent

Many basic account actions can be handled inside the app, including account deletion.

For broader privacy requests, data-access requests, or help if you cannot access the app, email privacy@craftuplearn.com.

For general account or product support, you can also contact support@craftuplearn.com.

We may need to verify your identity before completing certain requests. If you are in the EEA or UK, you also have the right to complain to your local data protection authority.

10. International Transfers

Because we rely on cloud infrastructure and global service providers, personal data may be transferred to and processed in countries other than your own.

Where required, we rely on appropriate safeguards for those transfers, such as contractual protections and provider commitments designed to support lawful international processing.

11. Third-Party Links

The Service may include links to third-party sites or services. We are not responsible for their content, security, or privacy practices. Review their policies before you provide personal data to them.

12. Changes to This Policy

We may update this Privacy Policy from time to time, for example when the product changes, when we add or remove providers, or when the law changes.

If the change is material, we will post the updated policy here and may also notify you inside the app or by email. The new version becomes effective on the date shown at the top of the page.

13. Contact

Privacy requests: privacy@craftuplearn.com

General support: support@craftuplearn.com

Support page: /stencilstudio/support