Privacy Policy.
A clear, plain-English account of what the Makerly app collects, why, who we share it with, and the choices you have. Built so you can read it, not skim past it.
Plain-English summary
Your stash, your palettes, your projects, and your photos — they’re yours. We don’t sell your data. We don’t run advertising SDKs. The app asks for camera, photo, file, location, and notification access only when you use a feature that needs it, and you can revoke any of those permissions at any time in your device settings.
App identity & contact
App: Makerly (the “App”), an app for quilters, embroiderers, and sewers, published by SUPPLYNSERVICE LLC, a Washington limited liability company (“Makerly,” “we,” “us,” “our”).
Privacy contact: contact@getmakerly.com. You can also reach us through the in-app support flow or the contact form on getmakerly.com. We aim to respond within one business day.
Who controls your data
SUPPLYNSERVICE LLC is the data controller for the personal data described in this policy. The App stores account, profile, and project data in Supabase (Postgres database, authentication, storage, and edge functions) on our behalf. Our Supabase project is hosted in the United States; the Supabase URL used by the App is configured at build time via the EXPO_PUBLIC_SUPABASE_URL environment variable. Supabase processes your data under its own Privacy Policy and a Data Processing Addendum with us.
Account & profile
To use most features you create an account using your email address and a password. Authentication is handled by Supabase Auth, and your session is stored on your device using secure key–value storage (AsyncStorage) so you stay signed in between launches.
Your profile in the profiles table can include:
- Email address — your sign-in identifier and the address we use for service emails.
- Display name — optional, used in the app and (if you post) in community features.
- Profile picture URL — optional, points to an image you uploaded to Supabase Storage.
- Subscription & trial fields — trial start/end dates and current subscription status, used to gate Pro features.
- Stripe customer linkage — the Stripe customer ID and subscription IDs associated with your account, so we can match billing events back to you.
- Expo push token — only if you enable push notifications (see “Push & local reminders” below).
- Admin flag — an internal boolean used by edge functions to grant moderation/admin tooling to staff accounts. Most users have this set to
false.
Camera
android.permission.CAMERA on Android, and the NSCameraUsageDescription entitlement on iOS.The App uses the device camera only when you tap a feature that needs it, for example to:
- Scan and photograph fabric to add it to your stash.
- Capture quilt blocks, embroidery hoops, or in-progress projects.
- Photograph designs or printed patterns to attach to a project, troubleshoot a problem, or send to an AI feature you initiated.
Camera frames are processed locally on your device. They are not streamed to a remote server in real time, and we do not access the camera in the background. A photo only leaves your device if you save it, attach it to a project, send it to an AI feature, or post it to the community. The App does not record audio with the camera unless an explicit audio feature is later added and separately disclosed.
You can revoke camera access at any time in your device settings. Without it, camera-driven features are disabled but the rest of the App continues to work.
Photo library
The App can read from and write to your photo library when you use features that need it:
- Read: picking fabric photos, project photos, or reference images via
expo-image-picker. - Write: saving quilt previews, recolored designs, or rendered embroidery layouts back to your photo library via
expo-media-library.
We only access photos you explicitly choose. The App does not browse, index, or upload your library in the background.
Files & documents
For features such as importing embroidery files, the App uses the system document picker (expo-document-picker) to let you pick a specific file. Only the file you choose is imported. We don’t scan your file system or other documents.
Photos & files we host
Images and files you choose to attach to a project, post, or stash entry are uploaded to Supabase Storage. Depending on the feature, your upload lands in either:
- A public bucket with a public URL (for example, profile pictures or community post images), or
- A private bucket accessed via short-lived signed URLs (for example, embroidery files or stash photos that should not be publicly browsable).
You can delete uploads at any time from inside the App; deleted files are removed from Supabase Storage. Background backups may retain residual copies for up to 30 days — see “Retention & deletion” below.
Device location
The App can request foreground device location (via expo-location) for one purpose only: the “Find local shops” flow on the shops screen. When you tap that flow we use your coordinates to:
- Build a map or directions URL (Google Maps / Apple Maps).
- Filter or sort the shop list by distance.
We do not collect location in the background, build a continuous location history, or use location to target advertising. Coordinates used for these flows are processed in memory and not stored long-term on our servers.
Stash “purchase location” text
When you save fabric to your stash you can optionally type where you bought it (a shop name, city, or note). This is plain text you enter, not GPS, and it is stored alongside your stash entry in our database. Leave the field blank if you don’t want to keep that information.
Push & local reminders
If you grant notification permission, the App registers an Expo push token and stores it on your profile so we can send you remote notifications — for example, replies to a community post, project reminders, or service announcements.
The App also schedules local notifications (no server involved) for things like trial expiration reminders. These are surfaced by your operating system at the time we scheduled them.
You can disable notifications system-wide in your device settings, or sign out to unregister the push token from your profile.
Payments & subscriptions
Pro subscriptions and trials are processed through Stripe. The App opens a Stripe Checkout or Customer Portal session served by our edge functions. Card numbers, CVCs, and expiration dates are entered directly into Stripe’s hosted UI — we never see or store your card details. Stripe handles payment data under PCI-DSS and its own privacy policy.
What our database stores is limited to: your Stripe customer ID, subscription IDs, plan, status, current period end, and trial dates. Receipts are emailed by Stripe to the email associated with the purchase.
AI features & third-party AI providers
Several features — craft advice, fabric rating, troubleshooting, design and color suggestions — are powered by these generative-AI models. When you use one of these features:
- What is collected: the prompt or question you type, and any photos, images, or files you choose to attach (for example, a photo of your fabric, quilt block, or project).
- How it is collected: your signed-in app sends that content to our Supabase Edge Functions (for example,
ai-gemini), which act as a secure relay. - How it is shared: our backend forwards your text and images to the third-party AI provider used by that feature — Google’s Gemini API and/or OpenAI’s API — so the provider can process them and return a result.
- How it is used: solely to generate the AI response you requested (craft advice, ratings, troubleshooting, design/color suggestions), and to store a short usage record (for example, in an
ai_usagetable) tied to your account so we can enforce fair-use limits and trial/paid quotas. - Third-party terms: your content is processed by Google under Google’s Generative AI terms and by OpenAI under OpenAI’s Privacy Policy and usage policies.
- No training on your content: we do not use your AI prompts, photos, or attachments to train AI models, and we use these providers’ APIs under terms that do not train their models on your content.
AI disclosure & limitations
In keeping with U.S. Federal Trade Commission (FTC) guidance on the use of artificial intelligence, we want to be clear and not overstate what these features do:
- AI output can be wrong. Generative AI can produce inaccurate, incomplete, or “hallucinated” information. Treat every suggestion — including yardage math, color matches, fiber/thread guidance, and troubleshooting steps — as a starting point, and verify anything important before you cut fabric, buy materials, or operate equipment.
- Not professional advice. AI features do not provide professional, safety, medical, legal, or financial advice and are not a substitute for a qualified professional.
- No guaranteed results. We do not promise any specific outcome, accuracy rate, or that an AI feature will be suitable for your particular project.
- AI-generated content is labeled. Output produced by these features is identified in the App as AI-generated so you always know when a response came from a model rather than a person.
- No significant automated decisions. We do not use AI to make automated decisions that produce legal or similarly significant effects about you, and we do not use your prompts or attachments to train AI models.
- Human help is available. You can always reach a real person at contact@getmakerly.com instead of relying on an AI feature.
On-device & server ML
Some craft features run machine-learning models on your device — for example, ML Kit-based vision tasks, background removal, and ONNX/SAM-style image segmentation used in quilting and embroidery flows. The image data for these on-device models stays on your device.
A small number of advanced features (where shipped to you) call our segment-shape edge function, which uses Replicate to run heavier segmentation models server-side. In that case, the image you submit is sent to Replicate for the duration of the request. Replicate processes data under its own privacy policy.
Community / My Shop
If you opt in to community features (for example, “My Shop” profiles, the public feed, comments, hearts, or shop follows), the content you post — text, images, profile information — is stored in Supabase and shown to other users. Posting is always your choice, and you can edit or delete your posts at any time. We may also remove content that violates our community guidelines, and we keep limited records of moderation actions and reports.
Shopping list
Your shopping list is stored locally on the device using AsyncStorage, keyed by your user ID after sign-in. It is not synced to our servers. Signing out or uninstalling the App clears the list from the device.
Quilt & design data
Projects, quilt designs, blocks, palettes, fabric stash entries, and similar craft data you save in the App are stored in Supabase tables (for example, quilts, fabrics, and related tables) so they sync across your devices. You remain the owner of this content. You can edit, export, or delete it from inside the App, or request full deletion (see “Retention & deletion”).
Email from the app
The App sends a small number of transactional emails through Supabase Auth: account-confirmation links on signup, password-reset links, and email-change confirmations. These emails route the user back to the App via a getmakerly.com redirect URL. We do not subscribe you to marketing emails by default; any newsletter is opt-in.
Links to third parties
The App can open external apps and websites — for example, Google Maps or Apple Maps for directions to a shop. When you follow such a link, the destination service receives a normal browser/app request (URL, IP address, user agent). We don’t share your Makerly account data with them, and they handle that visit under their own privacy policies.
Children
Makerly is a general-audience craft app and is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has created an account, email contact@getmakerly.com and we will delete the account and associated data.
Retention & deletion
You can request deletion of your account and associated personal data at any time from Settings → Account in the App, by visiting your account page on getmakerly.com, or by emailing contact@getmakerly.com. We delete account data, profile fields, projects, and your uploads from production systems within 30 days of a verified request.
Limited records may be retained longer where required — for example, billing/tax records held by Stripe, abuse-prevention logs, or encrypted backups. Encrypted database backups roll off on a 30-day cycle. Anonymized aggregates (such as feature-usage counts that no longer identify you) may be kept indefinitely.
International users
The App is operated from the United States. Supabase, Stripe, Expo, Google, OpenAI, and (where applicable) Replicate process your data on servers primarily located in the United States. If you use the App from outside the US, you understand that your data will be transferred to and processed in the US under this policy. Where required, our processors offer appropriate transfer mechanisms (for example, Standard Contractual Clauses).
App updates
The App uses Expo’s OTA update service (expo-updates) to deliver bug fixes and small improvements between full app-store releases. When the App checks for an update, Expo sees a normal request from your device. Expo processes that request under its own privacy policy.
No advertising SDKs
We do not include third-party advertising SDKs in the App, do not show third-party ads, and do not sell your personal information. If we ever change that, we will update this policy and notify users in advance.
Security
All traffic between the App and our servers, Stripe, Expo, Supabase, Google, and OpenAI is encrypted in transit (HTTPS/TLS). Database access is gated by Supabase row-level security so signed-in users can only read and write their own rows except where features (such as the public feed) explicitly allow shared access. Passwords are never stored in plain text. No internet service can be guaranteed 100% secure, but we work to keep your data safe and we will notify affected users in line with applicable law if a security incident occurs.
Terms of service
Use Makerly for your craft. Don’t abuse the community. Don’t scrape our libraries. We’ll keep the lights on.
By using Makerly you agree not to use the service for illegal activity, to attempt to breach our security, or to scrape our block, shop, or community databases. We may suspend or terminate accounts that violate these terms.
Subscriptions
Maker Pro subscriptions and trials are billed through Stripe. Trials end silently — we never auto-enroll you into a paid plan unless you explicitly start a paid subscription. You can cancel any time from Settings → Subscription (which opens the Stripe Customer Portal) and keep your Pro features until the end of your paid period. Stripe stores your payment details under PCI-DSS standards; we never see or store your full card number.
Your content
You own what you make in Makerly. We get a limited license to store, sync, and display your content back to you (and, for content you choose to post publicly, to other users who can see it). That’s it.
Acceptable use
You agree not to, and not to help anyone else: (a) use Makerly for any unlawful purpose or in violation of these terms; (b) upload, post, or share content that infringes intellectual-property rights, or that is defamatory, harassing, hateful, obscene, or otherwise objectionable; (c) impersonate any person or misrepresent your affiliation; (d) attempt to breach, probe, or circumvent our security, rate limits, or authentication; (e) scrape, harvest, or bulk-export our block, shop, brand, or community databases; (f) reverse-engineer the App except where that restriction is prohibited by law; or (g) interfere with or disrupt the service or the servers and networks behind it. We may remove content and suspend or terminate accounts that violate this section, with or without notice.
Copyright & DMCA
Makerly lets users post images, text, and designs (“user content”). You are solely responsible for the content you upload, and you represent that you own it or have the rights to share it. We respect intellectual-property rights and respond to clear notices of alleged copyright infringement under the U.S. Digital Millennium Copyright Act (DMCA).
If you believe content on Makerly infringes your copyright, send a written notice to us at contact@getmakerly.com (subject line “DMCA Notice”) that includes: (1) your physical or electronic signature; (2) identification of the copyrighted work; (3) identification of the allegedly infringing material and where it appears in the App; (4) your contact information; (5) a statement that you have a good-faith belief the use is not authorized; and (6) a statement, under penalty of perjury, that the information is accurate and that you are the owner or are authorized to act on the owner’s behalf.
We will remove or disable access to material that is the subject of a valid notice and, in appropriate circumstances, will terminate the accounts of repeat infringers. If you believe your content was removed by mistake, you may submit a counter-notice to the same address.
Disclaimers
Makerly is provided “as is” and “as available,” without warranties of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement. We do not warrant that the App will be uninterrupted, error-free, or secure, or that calculators, AI suggestions, color matches, or other outputs will be accurate or suitable for your project. You rely on the App’s outputs at your own discretion. Some jurisdictions do not allow the exclusion of certain warranties, so some of the above may not apply to you.
Limitation of liability
To the maximum extent permitted by law, SUPPLYNSERVICE LLC and its owners, employees, and suppliers will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, data, goodwill, or materials, arising out of or related to your use of (or inability to use) Makerly — even if advised of the possibility of such damages. Our total aggregate liability for any claim relating to the service will not exceed the greater of the amount you paid us in the twelve months before the claim or USD $100. Some jurisdictions do not allow certain limitations, so some of the above may not apply to you.
Indemnification
You agree to indemnify and hold harmless SUPPLYNSERVICE LLC and its owners and staff from any claims, damages, liabilities, and expenses (including reasonable legal fees) arising out of your content, your use of the App, or your violation of these terms or of any law or third-party right.
Binding arbitration & class-action waiver
Please read this section carefully — it affects your legal rights.
Except for small-claims matters and requests for injunctive relief to protect intellectual property, you and SUPPLYNSERVICE LLC agree that any dispute arising out of or relating to Makerly or these terms will be resolved by binding individual arbitration rather than in court, in accordance with the following standard arbitration clause of the International Chamber of Commerce (ICC):
As recommended by the ICC when adopting its standard clause, the parties further agree that: (a) the place (seat) of arbitration is Seattle, Washington, USA; (b) the arbitration will be conducted in the English language; (c) the dispute will be decided by one (1) arbitrator; and (d) the law governing these terms is the law of the State of Washington, USA. The arbitrator, and not any court, decides all issues relating to the scope, applicability, and enforceability of this arbitration agreement.
Class-action waiver: you and SUPPLYNSERVICE LLC each agree to bring claims against the other only in an individual capacity, and not as a plaintiff or class member in any purported class, collective, or representative proceeding. The arbitrator may not consolidate more than one person’s claims. If this class-action waiver is found unenforceable as to a particular claim, that claim (and only that claim) will be severed and may proceed in court.
If you do not wish to be bound by this arbitration agreement, you may opt out by emailing contact@getmakerly.com within 30 days of first accepting these terms, stating your name and that you opt out of arbitration.
Governing law
These terms are governed by the laws of the State of Washington, without regard to its conflict-of-laws rules. Subject to the arbitration section above, the state and federal courts located in the State of Washington will have exclusive jurisdiction over any matters not subject to arbitration.
Changes to this policy
If we materially change this policy we will email signed-in users and post a notice in the App at least 30 days before it takes effect. Minor wording changes (typos, clarifications) are made in place with a new “Last updated” date.
Contact
Questions, requests, or concerns about this policy? Email contact@getmakerly.com or use the contact form. We’re happy to help.
For the Google Play “Data safety” breakdown of what is collected, shared, and why — see the Data Policy.