Privacy Policy
Last updated: 6 September 2026
This policy explains what happens to your information when you use the Quilta app or visit quilta.app.
The short version. There are no accounts. Your photos, your projects and your exports stay on your device, and there is no way for us to see them, because the app has no code that uploads them anywhere. What does leave your device is a small amount of information about how the app is running and which features get used, and this policy describes all of it by name.
Who is responsible for your data
Quilta is responsible for the information described here. Write to us at [email protected] about anything in this policy, including a request to see or delete what we hold. That address is the only contact you need, and it reaches a person.
Your photos and your work
When you add a photo, you pick it through your device's own photo picker. Quilta copies what you picked into its own storage on your device so it can edit the photo and open it again later. Those copies stay on your device.
Grids, carousels, layouts, text and edit history are saved in a database and a folder that belong to Quilta on your device. Deleting a project removes it. Deleting the app removes all of it.
Quilta does not read your photo library in the background and does not look at photos you have not chosen. There is no upload in the app. Not a disabled one, not one behind a setting: the code that would send a photograph to a server does not exist.
When you export, you choose where the result goes. Save to Photos writes the image into your photo library, and on iOS this is add only, so Quilta can put images in but cannot browse what is already there. Share hands the image to whichever app you pick from your device's share sheet, and from that moment the receiving app's privacy policy applies instead of this one.
When the app uses the network
Quilta goes online for four things, and none of them carry your photos, your projects or your exports.
Templates and presets. The Explore page fetches its catalogue, preview images and filter data from our own storage at api.quilta.app. Those requests say which version of the app you are running and which platform you are on, so a template your version cannot open is never offered to you. They also carry a random identifier that your installation makes for itself the first time the app runs. It is sixteen random bytes. It is not built from your device, your hardware or anything about you, it is given to nobody else, and reinstalling the app throws it away and makes a new one. It exists so the server can count requests per installation rather than per network, because otherwise everyone in one office or on one mobile network would share a single budget, and so a new template can be shown to a fraction of installations before all of them. Our own traffic statistics leave it out. Those statistics record the app version, the platform, what kind of thing was asked for, whether it was served from cache, and which of our three regional stores answered. Like any web request, these also tell the server your IP address, which is used to apply the same limits and is not written into the statistics either.
Fonts. The caption typefaces in the editor come from the Google Fonts library. When you use a typeface that is not already bundled with the app, Quilta downloads that font file from Google and keeps it on your device so it is not downloaded twice. Like any web request, that download tells Google your IP address and basic device information. We never see it. Google explains its handling at https://policies.google.com/privacy
Purchases. Described under Paying for Pro below.
Diagnostics. Described in the next section.
Nothing else in the app sends anything. There is no telemetry outside what is written here.
Crash reports and usage analytics
Settings, then Privacy, has two switches. They are independent, they take effect the moment you touch them, and no relaunch is needed.
Both are on by default. The app does not ask you first. If you would rather it collected nothing, turn both off and it stops from that moment.
Crash reports go to Firebase Crashlytics, which is run by Google. When the app fails, Crashlytics receives a description of the failure: the error, where in the app's code it happened, and the device model, operating system version and whether the device is physical, all of which are needed to reproduce it. It also receives the app's recent log messages, which is worth being precise about, because some of those messages contain the file path of an image the app was working on at the time. Those paths point inside Quilta's own private storage and are made of an identifier your operating system assigns and a name the app generated. They are not names from your photo library and they are not the image itself. No photograph is ever sent.
Usage analytics go to Firebase Analytics, which reports into Google Analytics 4, and to PostHog. Both receive the same thing: a count of which features get used. The events are a fixed list written into the app, such as a template opened, a project created, an export finished, or the paywall shown, and each carries only values from a fixed list too, such as which preset, how many slides, which aspect ratio, or how long an export took. Two facts about you are attached: whether a Pro subscription is active, and whether it is monthly, yearly or lifetime.
What is deliberately not in there is worth listing. Not your photos. Not your text. Not your project names, which is why renaming a project records that a rename happened and never what you renamed it to. Not your file names. Not anything you typed. Not your email address, because the app never has one. The app also gives Firebase and PostHog no identifier of its own, so the only identity either one has is the anonymous id it generates for itself, and PostHog's screen recording feature is switched off in the app's configuration.
Turning usage analytics off stops collection and tells PostHog to throw away the anonymous id it was using. Turning crash reports off stops those.
Firebase Remote Config, also run by Google, is used to turn features on and off without shipping a new version of the app. It sends us nothing about you: the app asks for the settings and Google answers.
Google explains its handling of Firebase and Analytics data at https://policies.google.com/privacy and PostHog explains its own at https://posthog.com/privacy
Paying for Pro
Quilta Pro is sold by Apple's App Store and by Google Play. They take your payment and we never see your card, your billing address or your store account.
RevenueCat sits between the app and the stores, checks that a receipt is valid and tells the app whether a subscription is active. RevenueCat receives the purchase and receipt information the store provides, tied to an anonymous identifier that RevenueCat generates for the installation. The app gives RevenueCat no email address, no name and no device identifier, because it does not have any of them. RevenueCat explains its handling at https://www.revenuecat.com/privacy
We learn only whether an active subscription exists, and the app records the value and currency of a completed purchase in the usage analytics described above, so revenue can be counted.
Advertising
There is none. Quilta contains no advertising software, asks for no advertising identifier, and shows you no advertisements. On iOS the app never presents the tracking permission prompt, because there is nothing it would use the answer for.
Visiting quilta.app
The website loads nothing from anywhere else. No analytics, no tag manager, no embedded fonts, no social buttons, no third party anything. It sets no cookies and stores nothing in your browser. Its own content security policy blocks external resources outright, so this is enforced rather than promised.
The site is hosted on Cloudflare Pages, and our api.quilta.app service runs on Cloudflare too. As the company delivering the pages, Cloudflare processes the ordinary details of a web request, including your IP address, your browser's user agent string and which page you asked for. Cloudflare acts as our processor for this and explains its own handling at https://www.cloudflare.com/privacypolicy/
Where your data goes
The app's server storage is split across three regions, in North America, Europe and the Asia Pacific, and a request is answered by the one nearest you. That storage holds our templates and presets. It holds nothing about you.
Google, PostHog, RevenueCat and Cloudflare are companies based outside India, and the diagnostics and purchase information described above is processed by them on their own infrastructure, which for Google, PostHog and RevenueCat means principally the United States. Where the law requires a transfer safeguard, we rely on the standard contractual clauses those companies publish as part of their terms.
How long any of this is kept
Your photos and projects are kept on your device until you delete them, and are kept nowhere else.
Traffic statistics for api.quilta.app are aggregate counts and are kept for about three months.
Crash reports, usage analytics and purchase records are kept by Google, PostHog and RevenueCat under those companies' own retention settings, which is a matter of months rather than years. Ask us and we will tell you the current setting for each.
Your rights
You can remove any project from inside the app, turn either diagnostics switch off in Settings then Privacy, revoke Quilta's access to your photos in your device's system settings, and delete the app to remove everything it stored.
There is no account, no profile and no copy of your work, so for those there is nothing to export, correct or erase. For the diagnostics, analytics and purchase records that do exist, write to us and we will find what relates to your installation and delete it. Tell us as much as you can about when and on what device, because without an account there is no name to look you up by.
If you are covered by the GDPR, the UK GDPR, the CCPA or India's Digital Personal Data Protection Act, the rights those laws give you apply here, including access, correction, deletion, objection and complaint to your regulator. We do not sell personal information and we do not share it for cross context behavioural advertising, under any definition of those terms.
Children
Quilta is not directed at children under 13 and we do not knowingly collect information from them. If you believe a child has used the app and you want the diagnostics stopped, turn both switches off in Settings then Privacy and write to us.
India's Digital Personal Data Protection Act treats anyone under 18 as a child. If you are a parent or guardian in India and you have a question about a child's use of the app, write to us and we will answer it.
Changes
If this policy changes, the date at the top changes with it, and a change that matters will be called out in the app's release notes.