Last updated: 30 August 2026
This Privacy Policy explains how the Stichbook applications — Stichbook, which carries both the Workforce and Production sides of the product, and Stichbook Staff for workers (Android, iOS and web) — collect, use and protect information. Stichbook is a business tool used by factories and workshops to manage their own staff and production. In most cases the people whose details are recorded (workers, supervisors, designers and other staff) are entered by an organization's administrators, who act as the data controller for that information; Stichbook acts as a data processor on their behalf.
1. Who we are
Stichbook is operated by 16 Pixel ("we", "us"), a sole proprietorship registered in India (proprietor: Jatin Jivarajbhai Lathiya), with its registered office at Gr Flr, Plot No-75, Amardeep Soc, Nana Varachha, Surat 395006, Gujarat, India. GSTIN 24AGGPL3574N1Z0. If you have any questions about this policy or your data, contact us at hello@16pixel.design.
2. Information we collect
Stichbook only collects the information needed to run your organization's workforce and production records. We do not collect location data, we do not run advertising, and we do not use third-party analytics or tracking SDKs.
| Category | Examples | Why |
|---|---|---|
| Administrator account | Phone number and password used to sign in. For authentication, the phone number is mapped to a synthetic internal email address (e.g. <phone>@apex.local). |
To sign administrators in and identify their organization. |
| Staff records | Name, an optional employee code, role/category (worker, supervisor, designer, other), the department they work in, wage/salary details and phone number, as entered by your admins. | To manage your workforce. |
| Attendance | How much of a day each person worked — absent, half a day, one, one and a half or two days — recorded per person per date, either a day at a time or across a month. | To track attendance (hajari) and calculate salary. |
| Advances (Upad) | Advance amounts, dates and related notes. | To track advances and generate receipts. |
| Salary reports | Calculated monthly pay, deductions and saved payroll history. | To produce salary reports and slips. |
| Machine and production records | The machines your organization sets up (number, type and settings), and per-machine production for the day and night shift, with the karigar credited, the date and the figures your organization has chosen to record on an entry. | To record machine output and auto-mark operator attendance. |
| Job-slip photos | Photos of machine job slips captured through the app, and any additional photo attached to a production entry. | So authorized users in your organization can review them. Kept in private storage (see §5) for a maximum of 3 months, after which they are removed (see §3 and §8). |
| Details read from a photo (OCR) | The values read from a job slip by on-device text recognition — for example design number, stitch count and quantity — which fill in the production entry and can be corrected by hand. | To save re-typing what is already printed on the slip. The recognition itself happens on your device (see §3). |
| Worker (Karigar) login | The worker's phone number and a 4-digit PIN, created for them by their organization's owner. The PIN is never stored as typed — only a one-way hash of it is kept, so it cannot be read back by us or by anyone with database access. | To sign a worker in to the Stichbook Staff app and identify which organization and machines they belong to. |
| Worker uploads | A photo of the worker's finished production for a shift, plus the details read from it. | So the organization's owner can review what was produced on each machine, each shift. Retained on the same terms as job-slip photos (see §3). |
| Voice notes (optional) | Short audio recordings a worker or operator can attach to a production entry or upload, instead of typing a note. | To let staff add a spoken note when typing is impractical. Recorded only when you press record; stored privately (see §5). |
| Operator and department access | Which administrator logins are operators rather than owners, and which departments each one is allowed to see. | So an operator's view of the floor can be limited to their own department. |
| Entries waiting on your device | Production entries, attendance and uploads captured while the phone had no signal, held in the app's own private storage on that device until they sync. | So work recorded in a dead zone is not lost. See §4. |
| Subscription record | Your organization's plan, status, seat count and trial or renewal date. | To know whether the organization is on a trial, active, or read-only. We do not store card or bank details. |
Whose information this is
Most records in Stichbook are about employees of the organization using it — entered or uploaded by that organization's administrators, not by the employee themselves. The organization is responsible for the accuracy of those records and for informing its staff that it keeps them, and for obtaining any consent its local law requires. We process that information on the organization's behalf, only to provide the service.
3. Camera, photos and voice notes
Photos and OCR
Stichbook allows authorized users to photograph machine job slips for production and machine tracking purposes. Both apps use your device camera (and, on iOS, your photo library) for this, and the camera is only used when you actively take a photo. In Stichbook it is reached only from the Production side; nothing on the Workforce side asks for it.
OCR processing is performed on the device to extract the relevant information from the job slip and fill in the entry. The image is not sent to us, or to any third party, for text recognition — the apps use the operating system's built-in on-device text recognition.
Captured job-slip photos are then uploaded to private storage tied to your organization (see §5), so authorized users within that organization can review them when needed alongside the entry they belong to. Job-slip photos are retained for a maximum of 3 months and are not kept beyond that retention period. Your organization can also remove them sooner using the deletion controls described in §8.
The same private storage and the same 3-month limit apply to the other photos the apps capture: a worker's upload of their finished production, and any extra photo attached to a production entry as a note.
Stichbook does not use these photos for advertising, marketing, or to train AI models.
Voice notes
Both apps can use your microphone to record a short voice note on a production entry or upload — an alternative to typing for staff who find that easier. Recording happens only while you hold or press the record control; there is no background or continuous listening, no speech is sent anywhere for transcription, and the recording is stored privately alongside the entry it belongs to. Voice notes are optional; the apps work fully without them.
Neither permission is requested until you first use a feature that needs it, and an organization that never records production is never asked for either.
4. Permissions we use
- Internet — all apps, to sync your data with our secure backend.
- Camera — to photograph job slips and finished production (the Production side of Stichbook, and Stichbook Staff).
- Photo library — on iOS only, to pick an existing photo instead of taking one.
- Microphone — only while recording an optional voice note on an entry or upload.
We do not request location, contacts, or push-notification permissions, and we do not collect location data of any kind. Photos are re-compressed before upload, which removes any embedded location (EXIF GPS) information they may have carried.
5. How your data is stored and secured
Stichbook is built on Supabase (a hosted platform providing a PostgreSQL database, authentication, real-time sync and file storage). Your organization's data is stored in this backend and protected as follows:
- Organization isolation: every record is scoped to your organization and enforced by database row-level security, so one organization cannot read or write another's data.
- Authentication: sign-in is handled by Supabase Auth using your phone number and password.
- Private file storage: production photos are kept in a private storage bucket and are only accessible through temporary, expiring signed links — they are not publicly browsable.
- Encryption in transit: all communication with the backend uses encrypted (HTTPS/TLS) connections.
On your device
Stichbook is built to keep working where there is no signal. Two kinds of data therefore sit on the phone itself, inside the app's own private storage — an area other apps on the device cannot read:
- An outbox of entries you saved while offline — production, attendance and worker uploads — which is emptied as soon as the device has a connection again, and cleared once the backend has accepted them.
- A cache of the records you last viewed, so lists still open in a dead zone.
- Your sign-in credentials, if you chose to stay signed in, so the app can renew its own session without asking you to type your password again.
Uninstalling the app removes all three. Anything still waiting in the outbox at that point is lost with it, because it has not reached our backend yet.
Some receipt/salary-slip images are generated on your device and shared by you (for example to WhatsApp). Sharing a slip is initiated by you, and any data you send is then handled by the app you share it to under its own terms.
6. How we use information
We use the information solely to provide the Stichbook service: authenticating administrators, storing and syncing your organization's workforce and production records, calculating salary, generating receipts/slips, and providing support. We do not sell your data, and we do not use it for advertising or profiling.
7. Third-party services
- Supabase — hosts our database, authentication, real-time sync and file storage. Data you enter is stored there on our behalf.
- WhatsApp (optional): if you choose to share a receipt, salary slip or report, your device opens WhatsApp to send it. We do not send your data to WhatsApp on our own.
- Google Fonts (this website only): the marketing site you are reading loads its typeface from Google's font servers, which makes your browser's IP address visible to Google as part of that request. The apps carry their fonts inside the installed package and make no such request.
Stichbook does not embed advertising networks, social-media trackers, or analytics SDKs.
8. Data retention and deletion
Your organization's records are retained for as long as your organization is active, so your history stays available. If a subscription lapses the organization becomes read-only rather than being deleted — your records stay where they are. Photos are the exception: job-slip photos, worker uploads and photo notes are retained for a maximum of 3 months and are not kept beyond that period, while the production figures read from them remain in your history. You are in control of removing anything sooner:
- Delete one record — deleting an employee, advance, machine, production entry, machine report or saved payroll hides it from your organization straight away and holds it in Recently Deleted for 7 days, so an accident can be undone. Any administrator can restore it in that window; a super-admin can destroy it immediately with Delete forever; and anything left is purged permanently by a nightly job once the 7 days are up.
- Erase your records, keep the organization — the Empty Database action inside the app permanently deletes operational records while leaving your logins and settings in place. It does not pass through Recently Deleted. Stored photos and voice notes are not reachable from the app afterwards, but the files themselves remain in private storage until the 3-month limit clears them; deleting the organization removes them at once.
- Delete the whole organization — the owner can do this themselves from the Stichbook web app at app.stichbook.in (Settings → Data → Delete Organization). This removes the organization, every staff record, all attendance, advances, salary and production history, anything held in Recently Deleted, every uploaded photo and voice note, and all administrator, operator and worker logins.
The last two are immediate and permanent — data is removed as you confirm, not queued for later, and cannot be recovered. Full instructions are on the Delete Account page. Removing a single administrator login, while keeping the organization running, is still handled by us on request.
9. Children
Stichbook is a workplace tool for businesses and their staff. It is not directed at children, is rated for users aged 18 and over, and we do not knowingly collect information from children. It should not be used to create records for anyone below the minimum working age set by your local employment law.
10. Your rights
Depending on where you live, you may have rights to access, correct, export or delete personal data. Because organizations control their own staff records, most requests should go to the organization's administrator. For requests about your administrator account, or where we act as controller, contact us at hello@16pixel.design. See also the Delete Account page.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
12. Grievances (India)
Stichbook is operated from India and most of the organizations using it are Indian businesses. Under India's Digital Personal Data Protection Act, 2023 we publish a point of contact for questions, complaints and requests about personal data:
- Grievance Officer, 16 Pixel (operator of Stichbook)
- Gr Flr, Plot No-75, Amardeep Soc, Nana Varachha, Surat 395006, Gujarat, India
- Email: hello@16pixel.design — write "Grievance" in the subject line
- Postal address available on request
We acknowledge grievances within 7 working days and aim to resolve them within 30 days. Note that for staff records the employing organization is the data fiduciary and decides what is stored — we act on its instructions — so complaints about a specific employee record are usually resolved fastest with that organization's administrator. If you are not satisfied with our response, you may approach the Data Protection Board of India.
13. Contact
Questions about this policy? Email hello@16pixel.design or visit our Contact page.