English version
1. About this policy
This Privacy Policy applies to the Craftime Android and iOS apps
(production application identifier
com.selfmade.craftime), Craftime websites and community
services, and other related services operated by Shanghai Xinliu Self
Made Information Technology Co., Ltd. (上海心流自造信息技术有限公司)
("Craftime", "we", "us", or "our"). It describes the personal data we
collect, why we use it, when it is shared, how long it is retained,
and the choices available to you.
Some Craftime features are available without an account. Account, publishing, messaging, social, points redemption, and personalized features may require additional data.
2. Data we collect
Depending on the features you use, Craftime may process the following categories:
| Category | Examples | Purpose |
|---|---|---|
| Account and authentication | Email address, password or authentication credential, verification code and flow ID, user ID, access/refresh token, and linked Google, Apple, Facebook, or Instagram account information you authorize. | Create and secure your account, sign you in, recover access, prevent abuse, and manage linked sign-in methods. |
| Profile and social graph | Username, display name, avatar, profile background, biography, gender or other optional profile details, interest tags, followers/following, blocked users, privacy preferences, badges, level, and invitation records. | Display and personalize your profile, connect you with the community, enforce privacy choices, and operate community features. |
| User content and communications | Posts, drafts, captions, images, videos, craft journals, comments, likes, collections, reposts, polls, reports, feedback, chat messages, group information, friend requests, typing/read status, and related metadata. | Publish, save, synchronize, moderate, deliver, and display content and communications you request. |
| Photos, videos, and camera content | Only photos or videos you select through the system picker, content you capture after granting camera permission, edits, thumbnails, and upload metadata. | Create posts, set avatars or collection covers, send media messages, maintain craft journals, and attach files to feedback. |
| Location and place data | Approximate or precise current latitude/longitude, accuracy, timestamp, selected nearby place, place name, and address when you grant location permission and use a location feature. | Show nearby places, notes or activities and optionally add a location to your content. The mobile apps request current or while-in-use location only and do not request background location. |
| Device, app, and network data | On Android: Android ID, a device fingerprint derived from hashed hardware characteristics, Widevine DRM device ID and screen parameters, advertising or attribution identifiers and Android Privacy Sandbox measurement signals where available, and Firebase installation/push token. On iOS: an app-generated UUID stored in Keychain. On the web: a hashed browser fingerprint/visitor ID, browser user agent, and browser-storage identifiers. Across platforms: Craftime server device ID, brand or device/browser model, OS and app/browser version, IP address, network type, language, region, and timezone. | Register the device, maintain sessions, deliver notifications, support login and OAuth, prevent fraud and abuse, diagnose compatibility issues, and measure service reliability. |
| Cookies and browser storage | On Craftime websites: sign-in token, app-generated client/device ID, verification-flow state, language or display preferences, and temporary navigation or feature state stored in cookies, local storage, session storage, or memory. | Keep you signed in, secure requests, remember settings, continue verification and navigation flows, and operate website features. You can clear these through your browser, but doing so may sign you out or reset features. |
| Activity and analytics | App opens, page views, clicks, feature usage, login method, publishing actions, permission choices, search queries/history, viewing history, content interactions, referral information, event time, and coarse service-log metadata. | Provide history features, understand usage, improve performance and product design, personalize content, measure notifications, and detect misuse. |
| Diagnostics | Crash stack traces, exception messages, app state, device/OS/app information, runtime and network status, timestamps, and pseudonymous diagnostic identifiers. | Detect, investigate, and fix crashes, security incidents, and performance problems. |
| Support and feedback | Your email, feedback text, survey answers, attachments, support history, and information needed to verify or investigate your request. | Respond to questions, resolve complaints, and improve Craftime. |
| Points redemption and delivery | Points records, redemption order, receiver email, delivery address, goods and logistics status. | Process a points-based goods redemption, arrange delivery, provide support, and prevent redemption fraud. |
3. Device permissions and platform controls
- Camera: the Android and iOS apps use it only after your action to take a photo for an upload.
- Photos and videos: Craftime uses system pickers or photo-library controls to access items you choose. On supported Android versions, it uses the system photo picker and blocks broad media-library access; legacy storage write access is limited to Android 9 and below.
- Approximate/precise or while-in-use location: used for current-location and nearby-place features. The mobile apps do not request background location. You may deny or later revoke access.
- Notifications: used where enabled to show messages, social activity, publishing status, and service notices.
- Android phone/network/Wi-Fi state: used for device registration, network classification, reliability, and security.
- Android advertising and attribution APIs: Firebase/Google measurement components may access an advertising ID or Privacy Sandbox attribution/measurement signals where Android, your device settings, consent, and SDK configuration allow.
- Android foreground data sync: used for user-initiated or recoverable media publishing/upload work.
- Sign in with Apple: if you choose it on iOS, Apple provides an identity token and, when you approve and Apple makes it available, your name and email address for Craftime account authentication.
- Web cookies and storage: browser controls can block or clear Craftime cookies, local storage, and session storage. Required sign-in or security storage is necessary for authenticated website features.
Craftime does not request access to contacts, SMS, call logs, or microphone audio. Refusing an optional permission may disable the related feature but should not remove unrelated functionality. You can change permissions in Android or iOS system settings and manage third-party sign-in authorization through the relevant provider.
4. How we use data and our legal bases
We use personal data to:
- provide the features and transactions you request and perform our agreement with you;
- authenticate users, protect accounts, prevent fraud, enforce community rules, and comply with law;
- send transactional, security, social, and product notifications, subject to your notification choices;
- recommend and personalize content based on your settings and activity;
- measure, troubleshoot, secure, and improve Craftime; and
- handle support, legal requests, disputes, and business operations.
Where applicable law requires a legal basis, we rely on performance of a contract, your consent, our legitimate interests (such as security and service improvement, balanced against your rights), and compliance with legal obligations. You may withdraw consent for future processing where consent is the basis, without affecting processing that occurred before withdrawal.
5. When data is disclosed
We disclose data only as necessary for the purposes described above:
- Other users: when you publish content, communicate, join a group, or otherwise direct us to share it.
- Service providers: hosting, storage, authentication, analytics, crash reporting, maps/location, push notification, content delivery, and messaging providers acting for Craftime.
- Affiliates and business operations: to operate Craftime, or in a merger, financing, reorganization, or transfer, subject to appropriate safeguards and notice where required.
- Legal and safety: when reasonably necessary to comply with law, respond to lawful process, protect rights and safety, investigate abuse, or enforce our terms.
Current integrations by platform
| Provider / component | Role and possible data | More information |
|---|---|---|
| Craftime analytics (Android and Web); AnalyticsKit (iOS) | App or website opens, page views, feature events, page URL, event time, app/device or browser identifiers, app/OS/browser version, network and timezone metadata sent to Craftime-configured analytics services for product analytics and reliability. | This Privacy Policy |
| Google Firebase Authentication, Analytics, and Cloud Messaging; Google Play services, Google Sign-In, Maps and Location (Android) | Authentication data, analytics events, app/device, advertising, attribution or installation identifiers and measurement signals where available, push tokens, notification interaction, map requests, and location used for the feature you invoke. |
Firebase privacy and security Google Privacy Policy |
| Sign in with Apple (iOS) | Apple identity token and the name or email you authorize and Apple makes available, used to authenticate and link your Craftime account. | Apple Privacy Policy |
| Meta / Facebook Login and Instagram OAuth (Android, iOS, and Web where available) | Login/OAuth identifiers and the profile information you authorize Meta to provide. | Meta Privacy Policy |
| Tencent Bugly (Android) | Crash reports, device/app/network information, diagnostic identifiers, and runtime logs for stability monitoring. | Bugly SDK Privacy Statement |
| Alibaba Cloud Object Storage (OSS) (Android, iOS, and Web) | User-selected photos, videos, and other upload objects, plus upload metadata and network information. | Alibaba Cloud Privacy Policy |
| OpenIM client/server components (Android and iOS) | User ID, profile/avatar, messages, conversations, groups, friendships, read/typing state, and message media needed to provide Craftime messaging. Craftime connects the open-source client to Craftime-configured IM servers. | OpenIM documentation |
| FingerprintJS open-source library (Web) | Computes a hashed browser visitor ID from browser/device signals in the browser; Craftime stores and sends the resulting identifier to its device service for device recognition, security, and service operation. | FingerprintJS project |
We do not sell personal data, and the current Android and iOS apps do not display third-party ads. On Android, Firebase/Google measurement services may process advertising or attribution identifiers where available for analytics, attribution, security, and service measurement, subject to device controls and applicable consent. Aggregated or de-identified information that cannot reasonably identify you may be used for analytics and planning.
6. Retention
We retain information only for as long as reasonably necessary for the feature, account, security, dispute, and legal purposes described in this policy. Retention depends on the data and context:
- Account/profile information is generally kept while your account is active.
- Published content, messages, drafts, history, and redemption records are kept until you delete them, close your account, or they are no longer needed, subject to legal and safety exceptions.
- Device, security, analytics, and diagnostic records are retained for a limited period appropriate to fraud prevention, audit, debugging, and service improvement.
- Local caches and databases may remain on your device until cleared, you sign out where the app supports cleanup, or the app is uninstalled. Website cookies or browser storage remain until they expire or you or Craftime clears them. An app-generated iOS device identifier stored in Keychain may persist across reinstall for device recognition and security; reinstalling the app is not an account- or server-data deletion request.
After a verified account-deletion request completes, we delete or de-identify associated personal data, except information that must be retained for legal obligations, fraud/security prevention, dispute resolution, or the protection of others. Such retained data is restricted from unrelated use. Residual copies may remain temporarily in protected backups until they are overwritten through the normal backup cycle. Third-party processors may apply the retention periods described in their policies.
7. Delete your Craftime account and data
In the app: sign in and go to Profile → Settings → Security → Delete Account. Complete password and email-code verification, review the notice, and confirm deletion.
On the web: visit Craftime Community Settings, sign in to your Craftime account, and use the account-deletion option in Settings.
If you cannot use the app or website: email [email protected] from your registered email, with the subject “Craftime Account Deletion Request.” Include your Craftime username/user ID if available. Do not send your password or verification code. We may request limited information to verify account ownership.
A confirmed in-app request starts a 15-day deletion period. Signing in during that period cancels the request and restores the account. After the period, the account can no longer be used and associated profile information, posts, comments, likes, collections, and message history are scheduled for permanent deletion or de-identification, except limited records we must retain for the legal, fraud, security, or dispute reasons described above.
You may also request deletion of specific data without closing the account by using available delete and history controls or contacting the email above. We will respond within the period required by applicable law after identity verification.
Deleting Craftime does not delete a separate Apple, Google, Facebook, or Instagram account. You can also revoke Craftime's authorization through that provider's account settings.
8. Your choices and privacy rights
Subject to local law, you may have the right to access, correct, export, delete, restrict, or object to processing of your personal data, and to withdraw consent or appeal a request decision. You can:
- edit profile information and visibility through profile and privacy settings;
- manage browsing history, collections, follows, blocks, linked sign-in methods, and notifications through available controls;
- change camera, location, notification, and media permissions in Android or iOS settings;
- clear or restrict cookies and browser storage through your browser settings, understanding that authenticated website features may stop working;
- delete content or request account deletion; and
- contact [email protected] for a request not available in the app.
We may verify your identity before fulfilling a request and may deny or limit a request where permitted by law, including to protect another person's rights or preserve required records. You may also complain to your local data-protection authority.
9. Security and international processing
We use administrative, technical, and organizational safeguards designed to protect personal data, including access controls, environment separation, authentication controls, and encrypted transport for supported production services. No internet transmission or storage system is completely secure. Please use a strong, unique password and do not share credentials or verification codes.
Craftime and its providers may process data in China, the United States, Singapore, or other locations where they or their infrastructure operate. Those places may have different privacy laws. Where required, we use consent, contractual safeguards, security measures, or other lawful transfer mechanisms.
10. Children
Craftime is not directed to children under 13. If the law where you live sets a higher age for valid consent to online services, you must meet that age or use Craftime only with authorization from a parent or legal guardian. We do not knowingly collect personal data from a child without required authorization. A parent or guardian who believes a child provided data without authorization may contact us to request review and deletion.
11. Changes to this policy
We may update this policy when Craftime, its SDKs, legal requirements, or data practices change. We will update the date above and, for material changes, provide an in-app notice or another notice required by law before the change takes effect. The archived or prior version may be requested by email.
12. Contact us
Data controller / developer: Shanghai Xinliu Self
Made Information Technology Co., Ltd.
(上海心流自造信息技术有限公司)
Apps and services: Craftime for Android and iOS
(com.selfmade.craftime), Craftime websites and community
services
Support, privacy, and account-deletion email:
[email protected]
Official website:
https://craftime.com/