Last updated
August 2026

Privacy Policy

Welcome to Coutto Pattern (“we”, “our”, or “the App”). We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, share, and safeguard information when you use our mobile application (iOS and Android), website at coutto.app, and related services.

By using the App, you acknowledge that you have read and understood this policy. If you do not agree, please do not use our services.


1. Information We Collect

1.1 Information You Provide

  • Account information: Email address, username, password (stored encrypted), profile photo, and other registration details
  • Third-party login information: Account identifiers provided by the login provider when you sign in with WeChat or Sign in with Apple (WeChat openid / unionid, Apple’s unique user identifier), plus the name and email you choose to share
  • User content: Pattern files you import, create, or upload (PDF, SVG, DXF, PLT, PNG, JPEG, WebP, etc.), annotations, categories, and preference settings
  • Shared content: Pattern files you share with or receive from other users
  • Feedback and support: Questions, suggestions, or complaints submitted via email or in-app channels

1.2 Information Collected Automatically

  • Device information: Device model, operating system version, unique device identifiers, screen resolution, language, and regional settings
  • Usage data: Feature usage frequency, crash logs, performance data, session duration, and interaction behavior
  • Network information: IP address and connection type (Wi-Fi / cellular)
  • Diagnostic data: Error reports and crash stack traces to troubleshoot issues and improve stability

1.3 Information from Third Parties

  • App stores: Purchase history, subscription status, and anonymous identifiers from Apple App Store or Google Play (we do not directly collect payment card details)
  • Analytics providers: Aggregated usage data from third-party SDKs (see Section 4)
  • Cloud sync services: Session and storage information from backend services used for account login and data synchronization
  • Login providers: Login identifiers, name, and email (if you choose to share) returned by WeChat / Apple

1.4 Sign in with Apple

When you sign in with Apple, we receive Apple’s unique user identifier (sub), the name and email you choose to share (including the relay address in “Hide My Email” scenarios), used solely to create or sign into your account and for account lifecycle management. Identity tokens issued by Apple are verified server-side only and are not delivered to or persisted on your device. To meet Apple’s account-deletion authorization requirements, we store the Apple-issued refresh token in encrypted form on the server. It is used solely to revoke Apple authorization when your account is deleted, is never used to access your Apple data or for any other purpose, and is revoked and removed together with your account data when the account is deleted.


2. How We Use Your Information

Purpose Description
Core functionality View, project, cut, stitch, print, store, and manage sewing patterns
Account & sync Create and manage accounts; sync patterns and settings across your devices
Product improvement Analyze usage trends to optimize features and user experience
Security Detect abuse, fraud, and unauthorized access
Customer support Respond to inquiries and complaints
Legal compliance Fulfill obligations under applicable laws
Notifications Send feature updates and subscription reminders when you opt in


3. Personal Information Inventory

Data Type Purpose Required? Collection Method
Email address Registration, login, password recovery Required for account Provided by you
Apple user identifier (sub) Third-party login, account mapping Required when signing in with Apple Provided by Apple
WeChat identifier (openid / unionid) Third-party login, account mapping Required when signing in with WeChat Provided by WeChat
Apple refresh token (encrypted) Revoking Apple authorization on account deletion Generated automatically when signing in with Apple Stored server-side
Password (encrypted) Account authentication Required for account Provided by you
Display name / avatar Profile display Optional Provided by you
Pattern files & metadata Core features: storage, projection, printing, stitching Required for related features Provided by you
Device identifiers Analytics, crash diagnostics, fraud prevention Automatic System collection
Device model & OS version Compatibility and troubleshooting Automatic System collection
IP address Security auditing, regional statistics Automatic System collection
App usage logs Product improvement, feature analysis Automatic System collection
Crash & diagnostic logs Bug fixes, stability improvements Automatic System collection
Purchase / subscription records Verify in-app purchase entitlements When using paid features App store


4. Third-Party SDKs and Sharing

To enable app functionality and ensure secure, stable operation, we integrate third-party software development kits (SDKs) and cloud services. We assess partners for security and require them to protect your data in accordance with applicable law.

4.1 Third-Party SDK List

SDK Service Type Personal Data Collected Privacy Policy
Umeng+ SDK Mobile analytics & statistics Device info (IMEI / Android ID / IDFA / OPENUDID / GUID / SIM IMSI), network info, app usage; coarse location if authorized https://www.umeng.com/page/policy
WeChat Open SDK WeChat login Login identifiers (openid / unionid), name and avatar provided by WeChat (where applicable) https://privacy.qq.com/
Apple frameworks (iOS) Distribution, in-app purchases, crash reporting (if enabled) Device identifiers, purchase records, crash logs https://www.apple.com/legal/privacy/
Google Play services (Android) Distribution, in-app purchases, crash reporting (if enabled) Device identifiers, purchase records, crash logs https://policies.google.com/privacy

4.2 Other Third-Party Services

Provider Purpose
Cloud storage & sync Account authentication, cloud storage of patterns and user data, multi-device sync
App stores (Apple / Google) App distribution, subscriptions, and in-app purchase settlement

We do not sell your personal information. We may share information when:

  • You give explicit consent
  • Required to comply with law or valid government requests
  • Necessary to protect the rights, property, or safety of us, users, or the public
  • In connection with a merger, acquisition, or asset transfer (with prior notice where required)


5. Data Storage and Security

5.1 Location and Retention

  • Your data is primarily stored in data centers located in the People’s Republic of China and/or regions where our cloud providers operate
  • We retain personal information only as long as necessary for the purposes described in this policy. After account deletion, we will delete or anonymize your data within a reasonable period, except where retention is required by law
  • For users who sign in with Apple, the refresh token is used solely to revoke Apple authorization when the account is deleted; it is removed together with your account data after deletion

5.2 Security Measures

We use industry-standard safeguards, including:

  • Transport encryption (HTTPS / TLS)
  • Encrypted password storage
  • Access controls and auditing
  • Periodic security assessments

No method of transmission or storage is 100% secure. Please keep your account credentials confidential.


6. Your Rights

6.1 General Rights

Depending on applicable law, you may have the right to:

  1. Access and copy your personal information
  2. Correct inaccurate or incomplete data
  3. Delete your personal information where legally permitted
  4. Withdraw consent (without affecting prior processing based on consent)
  5. Close your account via in-app account deletion; for users who sign in with Apple, we will simultaneously revoke Apple authorization and delete the related data
  6. Lodge a complaint with a supervisory authority

6.2 European Economic Area (EEA) — GDPR

If you are in the EEA, you also have the right to restrict processing, data portability, and to object to processing based on legitimate interests, as well as to complain to your EU member state supervisory authority. Our legal bases include contract performance, legitimate interests, consent, and legal obligation.

6.3 California Residents — CCPA / CPRA

If you are a California resident, you have the right to:

  • Know the categories of personal information we collect, use, disclose, and sell
  • Request deletion of your personal information (subject to legal exceptions)
  • Correct inaccurate personal information
  • Opt out of the “sale” or “sharing” of personal information (we do not sell your personal information)
  • Non-discrimination for exercising these rights

To exercise these rights, contact us using the details in Section 10. We will respond within the timeframes required by law.


7. Children’s Privacy

The App is intended for users aged 13 or older (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe we have collected a child’s information without consent, please contact us and we will delete it promptly.


8. International Transfers

If your information is transferred outside your country, we implement appropriate safeguards (such as standard contractual clauses or equivalent measures) to ensure your data receives protection comparable to this policy.


9. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you via in-app notice, website announcement, or other appropriate means. The updated policy takes effect when posted; continued use of the App constitutes acceptance.


10. Contact Us

For questions, requests, or complaints about this Privacy Policy or your personal information:

We aim to respond within a reasonable time (typically within 15 business days).