Privacy policy
What information Wevy handles, why it is used, where it goes, and the choices you have.
Last updated: September 27, 2026
1. Scope and controller
This Policy applies to Wevy’s website, accounts, editor, pattern library, Make mode, exports, and public read-only pattern links. It does not apply to websites that Wevy links to.
Volodymyr Boiarinov, the developer who operates Wevy, is the controller of the personal data described in this Policy. You can contact the controller at volodymyrboiarinov@gmail.com.
2. Information Wevy processes
The information processed depends on the features you use:
- Account data includes your email address, optional display name, interface language, an approximate country that the hosting provider derives from your Internet Protocol address, account dates, authentication records, session identifiers, and account status. Supabase Auth handles your password. The app database does not store your plain-text password.
- Saved work includes pattern names and canvas data, thumbnails, folders, color sets, custom beads, stamps, personal bead corrections, view and export settings, reference images, and related dates and metadata.
- Billing data includes Mono subscription identifiers, payment amounts, currency, payment dates and statuses, and paid access and renewal dates. Card details are handled by plata by mono on its checkout page; Wevy does not store card numbers or security codes.
- Plan and product data includes your Free, Hobby, or Pro status, cloud pattern count, monthly export and image-tracing counts, onboarding progress, when a pattern was created, updated, or opened, and in-app events such as finishing onboarding, opening a plan dialog, starting checkout, or completing an export.
- Sign-up source data includes the first Wevy page you opened in that browser, the external site that referred you, any campaign tags in the link you followed, and the last page you viewed before the sign-up form. It is stored with the account so the operator can see which pages and channels bring people to Wevy.
- Sharing data includes the random token for a read-only link and the pattern data returned to a person who uses that link.
- Communications include your email address, message, and any files or details you send when you contact support or submit a privacy, legal, or copyright request.
- Technical data can include your Internet Protocol address, browser and device information, requested pages, timestamps, cookie and session data, request logs, diagnostics, and security events. Wevy’s infrastructure providers process this data when they deliver and protect the service.
3. Information kept on your device
Wevy uses browser storage for your language and theme, account-scoped open tabs, export header and footer presets, Make mode progress and appearance, temporary local pattern imports, and the sign-up source described above (the first landing page and referring site for the browser, the last page viewed for the tab). Session storage normally clears when the browser session ends. Local storage remains until you clear it or the browser removes it.
Image tracing runs in your browser. Wevy converts the selected image into pattern cells without uploading that source image as part of tracing. PDF, image, and pattern-file exports are also generated in your browser before download.
4. Sources of information
Wevy receives information from you when you create an account, edit or upload content, share a pattern, choose settings, or contact support. It also receives technical and account information from your browser and the service providers used to run Wevy. Wevy does not buy personal data from data brokers.
An email address and password are required to create an account and use cloud features. The display name is optional. Pattern content, reference images, public links, and support messages are optional, but Wevy cannot provide the feature you request without the data that feature needs.
5. Purposes and legal bases
Where data-protection law requires a legal basis, Wevy relies on the following bases:
- Contract: create and secure your account; save, sync, organize, render, export, and share patterns; apply plan limits; and provide requested support.
- Legitimate interests: operate, diagnose, secure, and improve Wevy; prevent fraud and abuse; protect users and legal rights; and understand service reliability and where people stop before choosing a plan, using Wevy’s own event records, without advertising profiles.
- Legal obligations: keep or disclose information when applicable law, a valid legal process, or tax and accounting duties require it.
- Consent: process information for an optional purpose when the law requires consent. You can withdraw consent for future processing at any time.
6. Cookies and similar storage
Wevy uses essential Supabase authentication cookies to keep you signed in and protect your session. It also stores a language cookie for up to one year. Browser storage supports the device-local features listed above.
The public marketing pages ask whether you accept Google Analytics 4 before any analytics script loads. If you accept, Google sets its own cookies, such as _ga and _gid, which can last up to two years, and receives your Internet Protocol address, the pages you view, and an approximate location. Google LLC processes that data in the United States and other countries. If you decline or make no choice, no analytics script loads and no Google cookie is set. Your choice is kept on your device, and the “Cookie choice” link in the footer lets you change it at any time.
The signed-in app loads no analytics script at all. Wevy uses no advertising cookies and no cross-site tracking, and relies on its own event records, described above, to understand how the service is used.
7. Service providers and disclosures
Wevy shares information only as needed with providers that supply authentication, database and file storage, hosting, content delivery, email delivery, and web fonts. Supabase supplies authentication, database, and file-storage services, and Vercel supplies hosting and content delivery, including the country lookup described above. Providers process data under their own terms and contractual duties.
Your browser can connect to rsms.me to load Inter, and the canvas text tool can connect to Google Fonts for Pixelify Sans. Those font providers receive technical request data such as your Internet Protocol address and browser headers. Google Analytics receives the data described in the cookies section, and only after you accept it.
Wevy can also disclose information when required by law, to respond to valid legal process, to protect users or the service, or as part of a merger, financing, acquisition, reorganization, or sale of the service. Any successor must handle personal data under this Policy or give legally required notice of changes.
plata by mono processes payments and recurring subscriptions. Wevy receives payment and subscription status updates to manage paid access, renewals, cancellations, and billing support.
Wevy does not sell personal data and does not share it for cross-context behavioral advertising.
8. Public links and uploaded images
Patterns are private by default. A read-only link is a bearer link: anyone who has it can view the linked pattern without an account. The link has no automatic expiration. Delete the source pattern or contact support if you need the link disabled. A person who already downloaded, copied, or captured the pattern can keep that copy.
Reference images are stored in a public file bucket under hard-to-guess addresses. Anyone with an image’s direct address can access it, including through a shared pattern that contains the address. Do not upload confidential, sensitive, or unlawful images.
9. International processing
Wevy and its providers can process information outside your country. Those countries can have different data-protection laws. Where required, the controller or provider uses an approved transfer mechanism or another lawful safeguard. Contact volodymyrboiarinov@gmail.com for available information about those safeguards.
10. Retention and deletion
Account data, saved work, plan data, and sharing tokens remain while your account or the relevant content exists. Monthly export and image-tracing records and in-app event records can remain for the life of the account to enforce plan limits, resolve usage disputes, and improve Wevy; they are deleted with the account. Device-local data remains according to your browser’s storage rules.
Support and legal communications remain while a request is active and afterward for as long as reasonably needed to document the response or protect legal rights. Infrastructure providers retain technical logs under their retention settings and legal duties.
When you delete a cloud pattern, Wevy deletes its active database record and attempts to remove image files referenced by that pattern. Deleted information can remain temporarily in provider backups, logs, caches, or security records until those systems overwrite it. Wevy can retain limited information longer when law, fraud prevention, security, or dispute resolution requires it.
You can permanently delete your account in Settings, or email volodymyrboiarinov@gmail.com from the address connected to your account to request deletion of your account or other data. We may ask for information needed to verify the request.
11. Security
Wevy uses access controls, encrypted network connections, account-scoped database rules, and restricted storage paths to protect information. Public links and public image addresses are exceptions described above. No online service can guarantee absolute security, so protect your password, email account, device, and shared links.
12. Your rights and choices
Depending on where you live, you can have rights to know about and access personal data, correct it, obtain a portable copy, delete it, restrict or object to processing, and withdraw consent. You can also complain to the Ukrainian Parliament Commissioner for Human Rights or the data-protection authority where you live.
Email volodymyrboiarinov@gmail.com to exercise a right. Describe the account or information involved and the right you want to exercise. We may verify your identity and can decline or limit a request where applicable law permits.
13. Children
Wevy is not directed to children. You must be at least 16 to create an account, or older where local law sets a higher age to agree to the Terms, and Wevy does not knowingly collect personal data from anyone younger. A person who has not reached legal adulthood must use Wevy only with a parent or guardian’s permission. Contact us if you believe a child created an account or provided personal data without the required permission.
14. Automated decisions
Wevy automatically applies account entitlements, cloud-pattern and grid limits, and monthly export and image-tracing limits. These controls do not evaluate personal characteristics and do not produce legal or similarly significant effects. Wevy does not use personal data to train artificial-intelligence models or build advertising profiles.
15. Changes to this Policy
Wevy can update this Policy when the service, providers, or law changes. The date at the top identifies the current version. We will give additional notice before a material change takes effect when required by law.
16. Contact
Privacy questions and requests: volodymyrboiarinov@gmail.com