Your information
Privacy notice
Last updated: 7 September 2026
This notice explains how Knitglass, operated by Beeju, handles personal data when you use the Knitglass website and row companion. Knitglass is the data controller for this service. Privacy enquiries, support requests and data-rights requests can be sent through the contact form.
Information we collect
- Account information: your name, email address, profile image and provider account identifier supplied by Google or Microsoft when you sign in. We never receive or store your provider password.
- Preview access information: during a private preview, administrators may store the exact email address you will use to sign in so Knitglass can permit access.
- Pattern information: uploaded pattern files, converted instructions and charts, selected sizes, pattern families, processing status and recovery diagnostics.
- Reader information: current row, completed rows, gauge, measurements, notes and other settings needed to provide your row companion.
- Sharing information: shared-pattern access and promotion-code redemption records, including the account, pattern, code and redemption time. Administrators can see these records.
- Technical information: session identifiers, request and security information, device/browser information and operational error logs generated when the service is used.
- Support information: the subject and text of messages you send through the contact form, and a device diagnostic report only when you choose to include it.
- Device-only information: theme, reader settings, keep-awake preference, PWA prompt state, a recent incident journal, and an offline copy of the currently loaded pattern, all its parts and queued row-completion changes are stored locally in your browser.
Why we use information
| Purpose | GDPR legal basis |
|---|---|
| Authenticate your account and provide the pattern library, reader, progress and notes | Performance of our contract with you |
| Store and convert authorised pattern files, including AI-assisted transcription | Performance of our contract and steps you request |
| Secure, diagnose, maintain and improve the service; prevent misuse | Our legitimate interests in operating a safe and reliable service |
| Manage sharing, promotion access and administrator audit records | Performance of our contract and our legitimate interests in access control |
| Manage private-preview invitations and staged access to the service | Our legitimate interests in safely testing and operating the service |
| Send a one-time welcome email and respond to support requests | Performance of our contract and our legitimate interests in supporting users |
| Meet tax, regulatory, legal or enforcement obligations | Compliance with legal obligations |
Knitglass does not use your data for advertising, sell personal data, or make legal or similarly significant decisions about you using automated processing.
Who processes information
We disclose information only where needed to run the service:
- Cloudflare hosts the application, database, file storage, transactional email and operational security services. Cloudflare Turnstile processes browser and connection signals when you use the support form to distinguish people from automated abuse.
- Google and Microsoft provide passwordless account authentication when you choose their service.
- Google Gemini processes authorised pattern content to produce AI-assisted pattern transcriptions. Outputs can be inaccurate and are checked against the source within the application.
- Authorised Knitglass administrators can access account, pattern, processing, sharing and promotion information when needed to operate and support the service.
- Other authorised users can access patterns and processed sizes explicitly shared with them. This may include the associated source document.
The Buy Me a Coffee button is a normal external link. Knitglass does not load Buy Me a Coffee code or share browser data with it before you click. Once you leave Knitglass, that service’s own privacy terms apply.
International transfers
Our service providers may process information in the United States and other countries outside the UK or European Economic Area. Where data protection law requires it, transfers must use an approved safeguard such as an adequacy decision or standard contractual clauses. Provider details are available in the Cloudflare Privacy Policy, Google Privacy Policy and Microsoft Privacy Statement.
How long we keep information
- Account records are kept while your account is active and for the limited period needed to complete deletion, resolve disputes and satisfy legal obligations.
- Private-preview email addresses are kept until an administrator removes them, the preview access model no longer requires them, or you ask us to delete applicable data.
- Patterns, revisions, progress, notes and related records are kept until an administrator deletes the pattern or you ask us to delete applicable account data.
- Promotion audit records are kept while the relevant pattern and account exist, unless they must be retained longer to investigate misuse or meet a legal obligation.
- Security and operational logs are retained only for the period reasonably needed to protect and diagnose the service, then deleted or aggregated according to provider settings.
- Support emails are retained only as long as needed to answer the request, maintain a support history and meet legal obligations.
- The offline pattern snapshot, queued progress, incident journal and browser preferences remain on your device until replaced, cleared during sign-out where supported, or removed when you clear site data.
Security
We use passwordless OAuth, encrypted HTTPS connections, access controls and private storage to reduce risk. No internet service can guarantee absolute security. Keep your Google or Microsoft account secure and tell us promptly if you suspect unauthorised access.
Your data-protection rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, and to receive a portable copy of personal data. Where processing relies on consent, you may withdraw it. You can exercise these rights through the contact form. We may need to verify your identity before responding.
You may also complain to the data-protection authority where you live or work, or where you believe a breach occurred. EU authority contacts are listed by the European Data Protection Board.
Cookies and local storage
Knitglass uses the session cookie required to keep you securely signed in, IndexedDB and Cache Storage for the current pattern's offline reader, and local browser storage for the functional preferences and incident journal listed above. Offline row changes are sent to Knitglass only after your connection returns. We do not currently use advertising or analytics cookies. Because these technologies are necessary to provide settings or the service you request, they are active without an optional-cookie consent banner. If that changes, we will update this notice and request consent where required.
Children
Knitglass is not directed to children under 16. A parent or legal guardian should use the contact form if they believe a child has provided personal data without appropriate authorisation.
Changes to this notice
We may update this notice when the service or legal requirements change. The date above identifies the current version. Material changes will be communicated in the application where appropriate.