Privacy Policy
Effective date: 19 August 2026
About this policy
This policy explains how Stricknani handles information when you use a Stricknani web instance or the companion Android app.
Stricknani is self-hosted software. The operator of the instance you use is responsible for its deployment, configuration, backups, and legal obligations. This page describes the default behavior of the software and is not a promise about every deployment.
Who is responsible for your data?
For a self-hosted installation, the person or organization operating that installation is the controller of the data stored there. The Stricknani project does not receive data from independent self-hosted instances.
If you use an instance operated by somebody else, contact that operator about access, deletion, retention, or other privacy requests. Questions about the Stricknani software can be reported through the GitHub issue tracker.
Information handled by the web app
- Account information: your email address, a password hash, and account security state such as token version.
- Knitting content: projects, yarn entries, notes, instructions, categories, steps, attachments, profile images, and other information you choose to store.
- Authentication information: a session cookie for browser login and personal access tokens for API or Android access. Token values are shown only when they are created; the server stores a hash for later verification.
- Operational information: application and import logs may contain timestamps, routes, status information, error details, and identifiers needed to operate and troubleshoot the instance. The operator chooses log destinations and retention.
Why this information is used
The web app uses this information to authenticate you, provide project and yarn management, synchronize API clients, serve your authorized media, process imports, protect the service, and diagnose failures. It does not sell your information or use it for advertising.
Android app and offline data
The Android app connects only to the Stricknani server URL that you configure. It stores that URL and your personal access token locally, encrypted at rest, and does not ask for or store your Stricknani account password.
Projects, yarn entries, and their photos are cached on the device so the app can work offline. Offline edits may be queued locally and are sent to your configured server when synchronization resumes. Removing the app or clearing its application data removes the local cache according to Android behavior.
The Android app has no analytics, advertising, tracking, or crash-reporting service of its own. Data sent during synchronization goes to the server you configured.
Optional external services
A deployment may enable integrations that send limited information outside the Stricknani instance. For example, an AI provider may receive material submitted for AI-assisted pattern import, an archive service may receive a URL when you request an archive snapshot, and Sentry may receive diagnostic events when an operator configures it.
These integrations are optional and controlled by the instance operator. Their providers process information under their own terms and privacy policies; review those policies before enabling or using the related feature.
The web interface itself uses locally served assets and does not require an analytics or advertising network.
Storage, retention, and deletion
The instance stores account data and content in its configured database and media storage. There is no universal retention period: the operator determines retention, backups, log rotation, and whether deleted data remains in backups for a time.
You can manage your content and revoke personal access tokens through the available features. To request deletion or an export of account data, contact the instance operator. Deleting content or an account does not necessarily remove copies already retained in backups, logs, or external services.
Security
Stricknani uses password hashing, access checks, CSRF protection, upload validation, and security response headers. Operators should use HTTPS, protect application secrets, restrict access to the database and media volume, keep the software and host updated, and configure backups securely.
No software can guarantee absolute security. The security and confidentiality of a self-hosted installation also depend on the operator, hosting environment, network, integrations, and devices used to access it.
Your choices and contact
You may choose what to enter, upload, synchronize, or send to optional integrations. You may stop using the Android app, clear its local data, revoke API tokens, and contact the relevant instance operator about your rights under applicable law.
For software questions or privacy concerns that relate to the project, use the GitHub issue tracker.
Changes to this policy
This policy may be updated when Stricknani behavior or integrations change. The current version is published at this URL. Check the effective date above for the latest revision.