Privacy Policy
Last updated: 28 July 2026
This Privacy Policy explains how Beadium ("Beadium", "we", "us") collects and uses your personal data when you use the Beadium mobile app and website (the "Service").
1. Who we are (Data Controller)
The Service is operated by Tetiana Diachek, a sole trader trading as Beadium, based in the United Kingdom. Postal address available on request.
For any privacy question or to exercise your rights, contact: [email protected] (our postal address is available on request).
2. What data we collect
- Account data: email address, display name, and (optional) profile picture you upload.
- Authentication: Email/Password, Google and Apple sign-in. With Google or Apple we receive your basic profile (name, email); we never see your Google/Apple password.
- Your content: the patterns, colour palettes and bead inventory you create. When signed in, these sync to your account.
- Public sharing (optional): if you tap Share on a pattern, that pattern and your Display Name (or "Anonymous" if you have not set one) become publicly visible to everyone using the Beadium app and website, and other users can duplicate it. You control this — you can make a pattern private again at any time, though copies others already duplicated remain with them.
- Reference photos: a photo you trace is processed on your device only and is never uploaded — on the website it stays in your browser for that session, and in the mobile app it stays on your phone. Only the traced grid is saved, never the photo. Because we do not keep it, the photo is not there when you reopen the pattern; pick it again to carry on tracing.
- Subscription/purchase data: your plan status and purchase history (processed by Apple, Google Play and RevenueCat on mobile, and by Stripe for web subscriptions — we do not receive or store your card details).
- Preferences: language and app settings.
- Identifiers & technical data: a user ID and standard log/device data needed to run and secure the Service.
- Website analytics: aggregated, cookieless usage statistics via Cloudflare Web Analytics (no personal profiles, no cross-site tracking).
We do not sell your personal data, and we do not use it for cross-app advertising tracking.
3. How and why we use it (UK GDPR)
- To provide the Service — create your account, sync and store your patterns, run subscriptions and support (performance of a contract).
- To keep the Service secure and working — abuse prevention, debugging (legitimate interests).
- Website analytics — aggregated, cookieless statistics to understand usage and improve the Service (legitimate interests).
- Legal compliance — tax, accounting, lawful requests (legal obligation).
4. Who we share data with
We use trusted third parties that process data on our behalf:
- Google Firebase / Google Cloud — authentication, database, file storage (profile avatars).
- RevenueCat — subscription management.
- Apple App Store / Google Play — payment processing and subscriptions on mobile.
- Stripe — payment processing for web subscriptions.
- Google and Apple — sign-in providers.
- Cloudflare — website hosting and CDN, and cookieless website usage analytics (Cloudflare Web Analytics).
- SMTP2GO — transactional emails.
5. International transfers
Some providers process data outside the UK/EEA, including in the USA. Where this happens, transfers are protected by appropriate safeguards such as the UK International Data Transfer Addendum / EU Standard Contractual Clauses or an adequacy decision.
6. How long we keep it
We keep your account and content while your account is active. If you delete your account, we remove your personal data within a reasonable period (a 30-day cancellation window applies before permanent removal). Some data may be retained where required by law.
7. Your rights
Under UK GDPR you can: access your data; correct it; delete it; restrict or object to processing; data portability; and withdraw consent at any time. Manage your account and request deletion in Settings, or email [email protected]. You may also complain to the ICO (ico.org.uk).
8. Children
Beadium is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has provided us data, contact [email protected] and we will delete it.
9. Security
We use industry-standard measures (encryption in transit, access controls, managed cloud infrastructure with backups). No method is 100% secure, but we take reasonable steps to protect your data.
10. On-device storage & offline caching
To make the app fast and usable offline, some data is stored locally on your device rather than on our servers:
- Guest patterns: if you use Beadium as a guest (without an account), the patterns you draw are saved only on your device. They are not uploaded or synced, and they are lost if you delete the app or clear its data — unless you sign up, which migrates them to your account.
- Cache: your recent patterns, palettes and catalog data may be cached on your device so screens load quickly and keep working offline. You can clear this by signing out or reinstalling the app.
- Reference photos and any offline pattern files you export stay on your device under your control.
11. Cookies & similar technologies (website)
The Beadium website uses only strictly necessary and functional storage — nothing for advertising or cross-site tracking, which is why we do not show a cookie consent banner:
- Sign-in session: kept in your browser (IndexedDB/local storage) so you stay signed in. Essential.
- Preferences: your interface language, editor panel state and beading-row progress, stored in local storage on your device. Functional.
- One first-party cookie remembering whether the side panel is open. Functional.
- Security: our host Cloudflare may set a short-lived cookie to tell humans from bots. Essential.
- Payments: during checkout, Stripe sets cookies strictly for fraud prevention. Essential; only appears if you start a purchase.
- Analytics: Cloudflare Web Analytics is cookieless — it stores nothing on your device and builds no personal profile.
If we ever introduce non-essential cookies (e.g. advertising or third-party analytics), we will ask for your consent first.
12. Changes
We may update this policy; the "Last updated" date will change. Material changes will be notified in-app or by email where appropriate.
13. Contact
Email: [email protected] — Data Controller: Tetiana Diachek (sole trader), trading as Beadium, United Kingdom. Postal address available on request.