This privacy policy is applicable to the Knotty app for mobile devices, together with any related services operated by ponyokiki (collectively, the "Application"). ponyokiki is hereinafter referred to as the "Service Provider".
ponyokiki acts as the Data Controller responsible for the processing of your personal data.
For data protection inquiries and to exercise your GDPR rights, please contact the Data Controller using the contact information above.
The Application does not require an account or registration. The content you create in the Application — projects, chart images, calibration data, and knitting progress — is stored locally on your device and is not transmitted to the Service Provider.
The Application acquires the information you supply directly to the Service Provider, for example when you contact support by email or through the website contact form. The Service Provider may also use the information you provide to send important information, required notices, and, where permitted by law, marketing communications.
The Application offers a one-time, non-consumable in-app purchase that unlocks additional features. Payment is processed by Apple (App Store) or Google (Google Play) acting as the merchant of record; the Service Provider does not receive or store your payment card details.
Purchases are managed through RevenueCat, Inc., which acts as a processor on the Service Provider's behalf. To validate a purchase and restore it across your devices, RevenueCat assigns an anonymous app user identifier and processes purchase history together with technical device information (such as device identifiers, IP address, and country). This does not require an account. You can restore a previous purchase at any time from within the Application, and refunds are handled by the applicable app store in accordance with its policies. See RevenueCat's Privacy Policy for details.
With your consent, the Application uses Sentry (operated by Functional Software, Inc.) to collect anonymous crash and error diagnostics that help the Service Provider find and fix bugs. Crash and error reporting is off by default and sends nothing until you actively enable it — either through a one-time in-app prompt or the "Crash reporting" toggle in Settings → General. You can withdraw your consent at any time by turning that toggle off; from then on, no further crash reports are sent. The "Send feedback" screen described below is separate: it transmits only a message you write and send yourself, and is not governed by this toggle.
When enabled, a crash or error report contains only: technical diagnostic information about the error (such as the error type and a stack trace), your device model, your operating system version, and the app version. It does not include any account or personal identifiers (the Application has no accounts), advertising identifiers, device or installation identifiers, or any content you create (projects, chart images, photos, or notes).
Your IP address is not stored: Sentry is configured to discard it on receipt. Before it is discarded, Sentry uses it to derive an approximate location — for example the city and country you were in — and that approximate location is retained alongside the report. No precise location is collected, and the IP address itself is not retained.
Because no account, device or installation identifier is attached, the Service Provider cannot link a report back to you.
The legal basis for this processing is your consent (Article 6(1)(a) GDPR). Crash reports are retained by Sentry for a limited period (up to 90 days) and then deleted automatically. Crash data is stored in Sentry's European Union region (Frankfurt, Germany). Sentry is a US-headquartered company and may access data from outside the EEA in the course of providing and supporting the service; where that occurs, the safeguards described under "International Data Transfers" below apply. See Sentry's Privacy Policy for details.
Because these reports contain no information that identifies you, the Service Provider cannot link a specific report to an individual in order to action a targeted deletion request. Instead, the data is minimized by design (no identifiers, no IP) and deleted automatically after the retention period stated above.
With your consent, the Application uses PostHog (operated by PostHog, Inc.) to collect anonymous, aggregated usage analytics that help the Service Provider understand how the Application's features are used and improve them. This feature is off by default and shares the same consent control as crash reporting: it sends nothing until you actively enable it — either through the one-time in-app prompt or the "Help improve Knotty" controls in Settings → General. You can withdraw your consent at any time from Settings, after which no further analytics are sent.
When enabled, analytics record anonymous product-usage events (such as which screens you open and which features you use) together with basic technical context (your device model, operating system version, and app version). PostHog assigns a randomly generated, anonymous identifier so that events from a single installation can be grouped for aggregate analysis. The Application does not send your name, email, any account identifier (the Application has no accounts), advertising identifiers, or any content you create (projects, chart images, photos, or notes), and it does not use this data to identify you or track you across other apps or websites. PostHog receives your IP address in transit to deliver the service but is configured to discard the client IP address so that it is not stored with your events; before it is discarded, the IP may be used transiently to derive an approximate (country-level) location. No precise location is collected, and the IP address itself is not retained.
The legal basis for this processing is your consent (Article 6(1)(a) GDPR). Analytics data is processed by PostHog in the European Union (EU region). See PostHog's Privacy Policy for details.
The Application includes a "Send feedback" screen in Settings that lets you send a written message to the Service Provider. Nothing is sent unless you write a message and press Send. There is no background collection of any kind associated with this feature.
A feedback submission contains the message you write, together with basic technical context: your app version and build number, your device model, your operating system and its version, and the language the Application is set to. It does not ask for or collect your name, email address, or any other contact detail; it contains no account or advertising identifier (the Application has no accounts); and it does not include any content you create (projects, chart images, photos, or notes). No identifier is attached, so a feedback submission is not linked to you, to your device, or to your other submissions. As with crash reports, your IP address is not stored — Sentry discards it on receipt — but before it is discarded Sentry uses it to derive an approximate location, for example the city and country you were in, and that approximate location is retained alongside your message. No precise location is collected.
For that reason the Service Provider cannot reply to feedback sent this way. If you would like an answer, use the "email us" link on the same screen or write to knottyapp@gmail.com directly. An email you send is handled as described under "Developer Website" above, and can be deleted on request at any time.
The message field is free text. If you choose to write personal details into it — your name or your email address, for example — that information is transmitted with your message. The Service Provider does not ask for it and recommends that you do not include it. If you have included such details and would like the submission removed, contact the Service Provider at knottyapp@gmail.com quoting the message, so that it can be identified and deleted.
Feedback is delivered through Sentry (operated by Functional Software, Inc.), the same processor used for crash reporting, and is stored in Sentry's EU region (Frankfurt, Germany). It is retained for up to 90 days and then deleted automatically. This feature is not governed by the "Crash reporting" consent toggle. That toggle controls background collection, which requires your prior consent; sending feedback is instead a deliberate act you take each time, and if you never press Send, nothing is ever transmitted. The legal basis for this processing is Article 6(1)(b) GDPR (steps taken at your request) together with Article 6(1)(f) GDPR (the Service Provider's legitimate interest in receiving and acting on reports about the Application).
Where the GDPR applies, the Service Provider relies on one or more lawful bases to process your personal data, including:
The Application or its third-party SDKs may use cookies, SDKs, pixels, and similar technologies to support functionality, analytics, and service delivery. Where required by law, the Service Provider will obtain your consent before using non-essential tracking technologies.
The Service Provider's developer website, including this Privacy Policy, is hosted on GitHub Pages, a service operated by GitHub, Inc. (USA). When you visit the website, GitHub may process technical data such as your IP address, browser type, and access times as described in GitHub's Privacy Statement.
Where the website provides a contact form, the personal data you enter (such as your name, email address, and the content of your message) is processed for the purpose of handling your inquiry. The legal basis for this processing is Article 6(1)(b) GDPR (steps taken at your request prior to or in performance of a contract) or Article 6(1)(f) GDPR (the Service Provider's legitimate interest in responding to inquiries). Inquiry data is retained only as long as needed to handle your inquiry and any follow-up, and is deleted thereafter unless longer retention is required by law.
If the Application uses automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, you have the right to request human review, express your point of view, and contest the decision. Information about the logic involved and the likely consequences of that processing will be provided where required by law.
In its default state, the Application collects nothing automatically. It has no account system, assigns no advertising identifier, and stores the content you create — projects, chart images, calibration data and progress — locally on your device.
Where you have switched on one of the optional features described above, that feature collects only what its section states: crash and error reporting sends diagnostic information about an error together with your device model and operating system version; usage analytics sends anonymous product-usage events under a randomly generated identifier. Neither stores your IP address, and neither is linked to your identity. In-app feedback transmits only at the moment you write a message and send it, and carries no identifier either; like the other two it stores no IP address, though the approximate location derived from it before it is discarded is retained.
Separately, processing an in-app purchase transmits the technical device information described under "In-app purchases", which is necessary to validate a purchase and restore it across your devices.
This Application does not gather precise information about the location of your mobile device.
The Application does not use Artificial Intelligence (AI) technologies to process your data or provide features.
The Application transmits data only to the processors named in this Privacy Policy, and only for the purposes described here: RevenueCat (validating and restoring in-app purchases), Sentry (crash and error reporting, and any in-app feedback you choose to send), and PostHog (usage analytics). Each acts on the Service Provider's documented instructions under a data processing agreement and has no independent right to use the data.
The Service Provider does not sell your personal data and does not share it for advertising purposes. The circumstances in which data may otherwise be disclosed are listed below.
The Service Provider or its third-party service providers may transfer personal data outside the European Economic Area (EEA). Where such transfers occur, the Service Provider will use an appropriate transfer mechanism required by GDPR Chapter V.
Countries outside the EEA may not provide the same level of data protection as the EEA. Where required by law, the Service Provider will apply appropriate safeguards and obtain any consent required for the transfer.
Please note that the Application utilizes third-party services that have their own Privacy Policy about handling data. Below are the links to the Privacy Policy of the third-party service providers used by the Application:
Note: RevenueCat is active in the current release for in-app purchase processing. Sentry (crash and error reporting) and PostHog (usage analytics) are both integrated as optional, opt-in features that are off by default and process data only after you consent — see "Crash and error reporting" and "Usage analytics" above. Sentry additionally delivers in-app feedback, which is sent only when you write a message and press Send — see "In-app feedback" above.
The Service Provider may disclose User Provided and Automatically Collected Information:
Where the GDPR applies, the Service Provider enters into Data Processing Agreements (DPAs) with third-party service providers that process personal data on its behalf, as required by Article 28 of the GDPR. These DPAs impose the same data protection obligations on those service providers as described in this Privacy Policy.
You can stop further collection of information from your mobile device by uninstalling the Application. Uninstalling will stop the Application from collecting data from your device, but it does not automatically delete information that has already been transmitted to the Service Provider or to third parties.
To request deletion of your personal data, withdraw consent, or exercise any of your rights, contact the Service Provider at knottyapp@gmail.com.
The Service Provider retains personal data based on its necessity for the stated purposes:
Where a section above states a specific retention period for a particular feature, that period governs — crash reports and in-app feedback, for example, are deleted automatically by Sentry after up to 90 days.
You have the right to request deletion of your personal data at any time, except where retention is required by law. If you'd like the Service Provider to delete User Provided Data that you have provided via the Application, please contact them at knottyapp@gmail.com and they will respond within the time required by applicable law. Please note that some User Provided Data may be required in order for the Application to function properly.
You can request deletion of your personal data or account by contacting the Service Provider at knottyapp@gmail.com. The Service Provider will process your request within the timeframes required by applicable law.
Upon verification of your identity, the Service Provider will delete your personal data from its systems, except where retention is required for legal compliance or legitimate business purposes.
The Application is not intended for children under 16 years of age, or where a higher age of digital consent is established under applicable law. The Service Provider does not knowingly solicit data from children or market the Application to them.
Where parental or guardian consent is required under applicable law, the Application is not intended for use without that consent. The Service Provider does not knowingly collect personally identifiable information from children under 16 years of age, or where a higher age of digital consent is established by applicable law, in violation of applicable law. In the event the Service Provider discovers that a child has provided personal information, the Service Provider will immediately delete this from their servers. If you are a parent or guardian and you are aware that your child has provided the Service Provider with personal information, please contact the Service Provider (knottyapp@gmail.com) so that they will be able to take the necessary actions.
The Service Provider is committed to safeguarding the confidentiality of your information. The Service Provider implements physical, electronic, and procedural safeguards to protect information it processes and maintains. For example, access is limited to authorized employees and contractors who need to know that information to operate, develop, or improve the Application. However, no security system can prevent all potential security breaches.
In the event of a personal data breach that poses a risk to your rights and freedoms, the Service Provider will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by applicable law. Where the breach is likely to result in a high risk to your rights and freedoms, the Service Provider will also notify you without undue delay, providing information about the nature of the breach, the categories of data affected, and the measures taken or proposed to address the breach.
The Service Provider may update this Privacy Policy from time to time. The Service Provider will notify you of material changes by posting the updated Privacy Policy with an effective date. Where required by law, the Service Provider will seek your consent to material changes before they take effect.
Previous versions of this Privacy Policy will be maintained and made available upon request by contacting the Service Provider at knottyapp@gmail.com.
This privacy policy is effective as of 2026-08-29
Under the GDPR, you have the following rights:
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority. Contact details for each country's Data Protection Authority can be found at: https://edpb.ec.europa.eu/about-edpb/members_en
If you are located in the United Kingdom, you may contact the Information Commissioner's Office at https://ico.org.uk
If you are a resident of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information:
To exercise any of these rights, please contact the Service Provider at knottyapp@gmail.com. The Service Provider will verify your request using the information you provide and respond within the timeframes required by law. You may designate an authorized agent to make a request on your behalf.
Where processing is based on consent, you provide that consent by affirmatively opting in to the relevant feature or action. You may withdraw consent at any time without affecting processing carried out before withdrawal. Processing based on other lawful bases, including contract performance, legitimate interests, or legal obligations, is carried out as described above.
If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at knottyapp@gmail.com.
To request deletion of your personal data or to exercise any of your rights, contact the Service Provider using the details provided above. The Service Provider will respond within one month of receiving your request, extendable by up to two months where necessary due to the complexity or volume of requests, as permitted by applicable law.