Privacy Policy for the Nysta app

Last updated: 16 June 2026

This policy describes how we process your personal data when you use the Nysta app. The landing page at nystaknit.com has its own policy.

1. Data controller

StatLab (sole proprietorship)
Company reg. no. (CVR): 41068027
Alleen 39
8660 Skanderborg
Denmark
Privacy contact: hi@nystaknit.com

2. What data we process

When you use Nysta, we process:

  • Account data: your email address, and when you sign in with Apple or Google, the user ID they provide. Passwords are always stored encrypted (hashed).
  • Your yarn stash: the yarns you add (brand, colour, quantity, your own tags and notes) and any photos you upload.
  • Your preferences: e.g. selected brands, size and language.
  • Saved patterns: which patterns you save and the tags you put on them.
  • Subscription status: whether you are in trial, active or expired. The payment itself and your card details are handled by Apple/Google, not by us.
  • Technical usage data: error reports and pseudonymised usage statistics (see § 4) so we can fix bugs and improve the app.

We do not buy personal data about you from third parties.

3. Purpose and legal basis

Purpose Legal basis (GDPR)
Create and run your account and provide the app's features Performance of a contract, art. 6(1)(b)
Manage subscription and access Performance of a contract, art. 6(1)(b)
Send necessary operational emails (e.g. confirmation, account deletion) Performance of a contract, art. 6(1)(b)
Fix bugs and improve the app via pseudonymised statistics Legitimate interest, art. 6(1)(f)
Optional tracking/analytics beyond what is necessary Consent, art. 6(1)(a)

We do not make automated decisions with legal effect for you, and we do not profile you.

4. Tracking and consent

Pseudonymised product analytics (PostHog) run in the EU without cookies and without storing your full IP address. Where the law requires it, we ask for your consent before any non-essential tracking is enabled, and on iOS we show Apple's App Tracking Transparency prompt if we ever track across other companies' apps. You can always turn reminders and optional tracking off in the app's settings.

5. Recipients and processors

We share your data with the following processors. We have signed data processing agreements (DPAs) under GDPR art. 28 with those who process personal data on our behalf.

Processor What is processed Where Function Transfer basis
SupabaseAccount, stash, preferences, saved patternsEU (Frankfurt, AWS eu-central-1)Database and loginData resides in the EU. Supabase Inc. is US-based; any US support access happens under the European Commission's Standard Contractual Clauses (SCC).
Fly.ioAPI requests, temporary processing of stash/pattern data, IP in operational logsEU (Frankfurt)Hosting of our backend (api.nystaknit.com)Data is processed in the EU. Fly.io (US) may access under SCC.
RavelryTechnical queries about yarn and patternsUSSource of yarn and pattern dataRavelry is US-based. We do not send your email, account ID or other direct identity to Ravelry, only anonymous lookups of yarn and patterns. See note below the table.
RevenueCatPseudonymous subscriber ID and purchase status (not card details)USSubscription status managementRevenueCat Inc. is US-based. Transfers happen under SCC.
Apple / GooglePurchase, renewal, paymentEU/USPayment processing for App Store / Google PlayIndependent controllers for the payment itself under their own policies.
SentryError data, device type, stack traces (no personal content)EU (Frankfurt, sentry.io EU region)Error monitoringSentry (US) may access under SCC.
PostHogSession ID, screen views, eventsEU (Frankfurt, eu.posthog.com)Pseudonymised product analyticsPostHog Inc. is US-based; any US support access happens under SCC.

Note on Ravelry: When you look up a pattern or yarn, the app sends a technical query to the Ravelry API. We do not pass on your email, account ID or other direct identity to Ravelry, and we do not store the query together with your direct identity. Ravelry processes data under its own privacy policy (ravelry.com).

6. Transfers outside the EU/EEA

Data is processed primarily within the EU/EEA. For RevenueCat, processing takes place in the US, and for Supabase, Fly.io, Sentry and PostHog, US support access may occur. In these cases the transfer takes place under the European Commission's Standard Contractual Clauses (SCC), supplemented by technical and organisational measures in line with EDPB recommendations following Schrems II. Technical queries to Ravelry (US) happen without us passing on your identity (see the note under § 5).

7. How long we keep your data

Data Period Justification
Account, stash and preferences As long as your account is active Necessary to provide the service
After you delete your account 7-day grace period, then everything is permanently deleted within 30 days Protects against accidental deletion; see § 8
Error reports (Sentry) 90 days Time to find and fix errors
Pseudonymised statistics (PostHog) 12 months Comparison over time

8. Account deletion

You can delete your account in the app at any time. We keep the account for 7 days, during which you can undo the deletion via a link in an email. After the 7 days your data is permanently deleted (within 30 days). Note that you must cancel any subscription yourself via Apple/Google, since payment is handled there.

9. Your rights

Under GDPR, you have the right to:

  • Access (art. 15): get a copy of the data we hold about you.
  • Rectification (art. 16): have incorrect information corrected.
  • Erasure (art. 17): ask us to delete your data.
  • Restriction (art. 18): have processing paused during a dispute.
  • Data portability (art. 20): get your data in a common, machine-readable format.
  • Objection (art. 21): object to processing based on legitimate interest.
  • Withdraw consent (art. 7(3)): at any time, without affecting the lawfulness of processing before the withdrawal.

Write to hi@nystaknit.com. We respond within one month under GDPR art. 12(3). For particularly complex requests the deadline may be extended by up to two months, in which case we will inform you.

You can always complain to the Danish Data Protection Authority (Datatilsynet):

  • Address: Carl Jacobsens Vej 35, 2500 Valby, Denmark
  • Phone: +45 33 19 32 00
  • Email: dt@datatilsynet.dk
  • Web: datatilsynet.dk

10. Security

We have implemented technical and organisational measures under GDPR art. 32:

  • All communication between the app and our servers runs over TLS (HTTPS).
  • Data at Supabase is encrypted both in transit and at rest.
  • Passwords are stored hashed, never in plain text.
  • Access to the database is limited to people with a work-related need, through individual, encrypted keys.
  • Secrets (API keys, database credentials) are stored as encrypted environment and build secrets and are never included in the app bundle.
  • We review the setup on significant changes.

11. Data breaches

If we become aware of a breach likely to result in a risk to your rights, we report it to the Danish Data Protection Authority within 72 hours under GDPR art. 33. If the breach is likely to result in a high risk, we also notify you directly without undue delay under art. 34.

12. Data Protection Officer (DPO)

We are not required to appoint a Data Protection Officer, as our processing does not meet the criteria in GDPR art. 37. Enquiries about data protection go to hi@nystaknit.com.

13. Children

Nysta is not aimed at children. You must be old enough to create an account under the rules of your country. The age of consent for digital services is 13 in Denmark and may be up to 16 in other EU countries. We do not knowingly collect data about children below the applicable age. If you believe a child has created an account, please contact us and we will delete the information.

14. Changes

We may change this policy. The current version is always available at nystaknit.com/en/app-privacy with the date of the last update at the top. We give reasonable notice of material changes in the app or by email before they take effect.

15. Questions

Write to hi@nystaknit.com.