Privacy Policy
Effective Date: July 20, 2026
Floating Point Applications ("Company", "we", "our", or "us"), a business organized under the laws of the Commonwealth of Pennsylvania, is committed to protecting your privacy and safeguarding your personal information. This Privacy Policy explains how we collect, use, store, disclose, and protect your information when you use our mobile applications, including Fold, Stashly, and Blip Bluetooth Finder Tracker, and any future applications we may release (collectively, the "Apps"), as well as our website located at floatingpointapps.com (the "Site").
Our Core Commitment: Floating Point Applications is built on a local-first, privacy-by-design architecture by default. This means your data stays on your device by default. Apps like Fold and Blip do not operate user accounts, cloud databases, or server-side storage for your personal data. Stashly supports complete offline local storage without an account, while offering optional cloud synchronization via Firebase Authentication and Firestore for users who choose to sign in and sync their catalog across devices.
Our Apps are classified as follows:
| App | Category | Cloud Accounts & Sync | Contains Ads? |
|---|---|---|---|
| Fold | Ad-Free | No (Local-First Only) | No |
| Stashly | Ad-Free | Optional (Firebase Sync for Signed-In Accounts) | No |
| Blip Bluetooth Finder Tracker | Ad-Supported | No (Local-First Only) | Yes (Google AdMob) |
Any future Apps we release will be classified as either Ad-Free or Ad-Supported. The classification of each App will be identified within the App itself and updated in this policy. All advertising-related disclosures in this policy apply to Ad-Supported Apps. Ad-Free Apps do not contain advertisements, advertising SDKs, or any form of ad-supported monetization.
Please read this Privacy Policy carefully. By downloading, installing, accessing, or using any of our Apps or visiting our Site, you acknowledge that you have read and understood this Privacy Policy. This Privacy Policy should be read in conjunction with our Terms of Service.
1. Information We Collect
We categorize the information associated with our Apps into information stored locally on your device, optional cloud data (Stashly signed-in users), and information we may collect with your consent. The table below provides a detailed breakdown:
| Data Type | Collected by Us? | Stored Where | Purpose |
|---|---|---|---|
| Bet logs, odds, bankroll data (Fold) | No | Your device only | App functionality |
| Fabric, pattern, notion catalogs & photos (Stashly - Offline Users) | No | Your device only | App functionality & offline storage |
| User catalog data (Stashly - Signed-In Users) | Yes (cloud sync) | Google Firebase Firestore | Multi-device catalog sync across devices |
| Email address (Stashly - Signed-In Users) | Yes (authentication) | Google Firebase Authentication | User sign-in, authentication, and session security |
| Crowdsourced Community Barcodes (Stashly) | Non-personal pattern specs only | Shared Firebase Firestore lookup (global_barcodes) |
Commercial pattern barcode auto-lookup for all sewists |
| Bluetooth scan results & signal data (Blip) | No | Your device only (in memory / local database) | Device detection & tracking |
| Saved device preferences & AirTag logs (Blip) | No | Your device only (Room database) | Device management |
| Location data (Blip, Android 11 and below only) | No | Your device only (in memory) | Required by Android OS for Bluetooth scanning on older devices |
| On-device AI processing (Fold, Blip) | No | Your device only (processed locally by AI model) | AI-powered analysis & assistance |
| AI model files (Fold, Blip) | No | Your device only | Enables on-device AI features |
| Advertising data (Ad-Supported Apps - Blip) | Yes (via Google AdMob SDK) | Google servers | Serving personalized or non-personalized advertisements based on user consent |
| Anonymous crash reports | Yes (with consent) | Third-party service | App stability improvement |
| Anonymous usage analytics | Yes (with consent) | Third-party service | Feature improvement |
1.1 Information Stored Locally (Not Collected by Us)
By default, data generated through Fold and Blip, as well as offline catalog data in Stashly, is stored exclusively on your device using local database architecture. This data is never transmitted to our servers, and we have no ability to access, view, or retrieve it. This includes:
- Fold: Bet logs, odds entries, bankroll history, and all tracking data you enter.
- Stashly (Offline Mode): Fabric details, pattern records, notion inventory, images, tags, notes, categories, and all catalog information stored locally on your device.
- Blip: Bluetooth device scan results, signal strength measurements, proximity data, saved device preferences, and AirTag logs. Scan data exists in active memory during use; saved devices and logs are stored in a local Room database on your device.
1.2 Stashly Cloud Synchronization & Accounts (Signed-In Users)
Stashly offers an optional account creation and cloud synchronization feature powered by Google Firebase services:
- Authentication Data: When you create a Stashly account, your email address is collected via Firebase Authentication to secure your account, authenticate your login sessions, and support password resets.
- Cloud Catalog Sync: For signed-in users, pattern names, fabric inventory details, notion records, project tracking entries, notes, tags, and categories are synced to Google Firebase Firestore so you can access your sewing catalog across multiple devices.
- Photos: Images you take or attach to pattern, fabric, notion, or project entries remain stored locally on your device's internal storage.
1.3 Crowdsourced Community Barcode Catalog (global_barcodes)
To enable automatic barcode auto-lookup when adding commercial sewing patterns, Stashly maintains a shared community barcode lookup database (global_barcodes). When a user scans or adds a commercial sewing pattern with a UPC barcode, non-personal commercial pattern specifications (brand name, pattern number, title, garment type, and fabric yardage requirements) are contributed to this shared lookup database so other sewists scanning the same barcode can auto-fill pattern information.
Community Barcode Privacy Safeguard: Personal notes, purchase prices, personal photos, fabric stash items, user names, email addresses, and account IDs are NEVER contributed to or shared with the community barcode catalog. Only non-personal public commercial pattern specifications are shared.
1.4 Information We May Collect (With Your Consent)
With your explicit, opt-in consent, we may collect the following limited, anonymized information:
- Crash Reports: If you opt in, we may collect anonymous crash data including stack traces, device model, operating system version, and app version. This data does not contain any personally identifiable information (PII) and is used solely to diagnose and fix technical issues.
- Anonymous Usage Analytics: We may collect aggregated, non-identifiable usage data (such as which features are most used, session duration, and screen navigation patterns) to improve our Apps. This data cannot be used to identify you personally.
- Advertising Data (Ad-Supported Apps Only): In Apps that display advertisements (e.g., Blip), the Google Mobile Ads SDK (Google AdMob) automatically collects certain information to serve and measure ads. This includes:
- IP Address: Used to estimate approximate (city-level) location for contextual ad serving, fraud prevention, and security.
- Ad Interaction Data: Information about your interactions with advertisements, including ad impressions, clicks, and video views.
- App and Device Information: App version, device model, operating system version, and mobile network information.
In Ad-Supported Apps, Google AdMob uses your device's Advertising ID (such as Google Advertising ID on Android or IDFA on iOS) to serve personalized advertisements tailored to your interests, unless you decline consent or opt out. We implement the Google User Messaging Platform (UMP) SDK to gather and manage your consent choices. You can learn more about how Google uses data at How Google uses data when you use our partners' sites or apps.
1.5 Information We Do NOT Collect
For clarity, we want to explicitly state what we do not collect:
- Financial information, payment card details, or banking information (handled directly by Google Play Store)
- Precise or approximate geolocation data outside local Bluetooth scanning on your device
- Contacts, call logs, SMS messages, or calendar data
- Videos or audio recordings
- Advertising IDs or cross-app tracking identifiers for the purpose of interest-based advertising or user profiling in Ad-Free Apps (Fold and Stashly contain zero advertising SDKs)
- Health, fitness, biometric, or genetic data
- Browsing history or search history
- Device identifiers for the purpose of cross-app tracking or behavioral profiling
2. Device Permissions
Certain Apps require specific device permissions to function. We follow the principle of just-in-time permissions — we only request access when a feature requires it, not at app startup. Below is a complete list of permissions our Apps may request:
| Permission | App | Purpose | Data Leaves Device? |
|---|---|---|---|
| Notifications | Fold | Send daily check-in reminders at your chosen time and optional jackpot updates | No |
| Microphone | Fold | Voice-to-text input for the AI assistant; audio is processed on-device and never recorded or stored | No |
| Internet Access | Fold | Fetch publicly available lottery jackpot estimates for display, download the optional AI model, and transmit anonymous crash/usage data only if you opt in | Only with opt-in consent (crash/usage data) |
| Photos / Files (via system picker) | Fold | Import bet history from images (on-device text recognition), CSV, Excel, or PDF files you select, and save exported files — only files you explicitly choose are accessed | No |
| Bluetooth / BLE Scanning | Blip | Scan for and detect nearby Bluetooth-enabled devices | No |
| Bluetooth Connect | Blip | Connect to detected Bluetooth devices for identification and tracking | No |
| Location (Android 11 and below only) | Blip | Required by Android OS for Bluetooth scanning on older Android versions (API 30 and below); not requested on Android 12 and above | No |
| Internet Access | Blip | Load advertisements via Google AdMob, process optional premium billing, download the optional AI model, and transmit anonymous crash/usage data only if you opt in | Yes (advertising data to Google AdMob; crash/usage data only with opt-in consent) |
| Foreground Service | Blip | Run Bluetooth scanning in the background for continuous device tracking | No |
| Notifications | Blip | Display persistent scanner service alerts and scan result notifications | No |
| Camera | Stashly | Used solely for barcode scanning (e.g., scanning pattern or fabric barcodes) and capturing photos of fabrics, patterns, notions, or projects for your catalog | No (processed and stored locally on your device) |
| Storage / Media Access | Stashly | Select, save, and display pattern and fabric photos within your catalog | No (stored locally on your device) |
| Internet Access | Stashly | User account authentication, password reset, and cloud catalog sync via Firebase Firestore for signed-in accounts | Yes (encrypted Firebase auth and Firestore sync for signed-in accounts only) |
You may revoke any permission at any time through your device's system settings. Revoking a permission may limit the functionality of the associated feature but will not affect other features of the App.
3. How We Use Your Information
We use information associated with our Apps strictly for the following operational and service purposes:
- Stashly Catalog Services: To store, organize, and sync your sewing patterns, fabrics, notions, and projects across your devices via Firebase Firestore (for signed-in users), and authenticate user accounts via Firebase Authentication.
- Community Barcode Auto-Lookup: To enable commercial sewing pattern barcode auto-fill via the non-personal
global_barcodesdatabase. - App Improvement & Maintenance: To identify and fix bugs, crashes, and performance issues based on opt-in crash reports.
- Feature Development: To understand which features are most valuable to users and prioritize future development.
- Compatibility: To ensure our Apps function correctly across different device models and operating system versions.
- Security: To detect and address potential security vulnerabilities and protect user account access.
- Advertising (Ad-Supported Apps Only): To display advertisements within Ad-Supported Apps (such as Blip). Advertising data collected by the Google Mobile Ads SDK is processed by Google AdMob to serve, personalize (based on your consent), measure, and improve advertisements.
We do not use any information for:
- Advertising, ad targeting, or ad personalization in Ad-Free Apps (Fold and Stashly). In Ad-Supported Apps (Blip), advertisements are served by Google AdMob and personalized based on your consent as described in Section 14
- User profiling or behavioral tracking across third-party services
- Selling, renting, or trading personal data to third parties
- Marketing communications (we do not send marketing emails, push notifications, or SMS)
4. How We Share Your Information
We do not sell, rent, trade, or otherwise share your personal information with third parties for their own commercial purposes.
We share information only in the following limited and transparent circumstances:
- Cloud Infrastructure & Service Providers: We use Google Firebase (Firebase Authentication and Firebase Firestore) to process authentication credentials and sync catalog data for signed-in Stashly users. We may also use third-party crash reporting and analytics services (such as Firebase Crashlytics) to process anonymous crash reports. These providers are bound by strict data protection contracts.
- Community Barcode Catalog (global_barcodes): Non-personal commercial pattern specifications (brand name, pattern number, title, garment type, yardage requirements) contributed when adding a commercial pattern with a barcode are shared in the global lookup database to enable automatic pattern lookups for all users. Personal notes, photos, fabric stashes, and user identifiers are never included.
- Advertising Partners (Ad-Supported Apps Only): In Ad-Supported Apps (Blip), the Google Mobile Ads SDK transmits certain data (including IP address, device advertising identifier, and ad interaction data) to Google and its ad partners for ad serving, subject to your consent choices. See Google's Privacy Policy.
- Legal Requirements: We may disclose information if required to do so by law, court order, subpoena, or legal process, or if we believe in good faith that disclosure is necessary to comply with applicable law, protect our rights or property, or ensure public safety.
- Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, any information held may be transferred as part of that transaction with notice provided on our Site.
5. Data Security
We implement comprehensive administrative and technical safeguards to protect your information:
- Local-First Architecture: Storing data locally on your device for Fold, Blip, and offline Stashly minimizes exposure to remote server breaches.
- Encryption in Transit: All data transmitted between our Apps and backend infrastructure (including Stashly Firebase sync and crash reports) is encrypted using Transport Layer Security (TLS 1.2 or higher).
- Cloud Data Security & Rules: Stashly cloud data stored in Firebase Firestore is encrypted at rest by Google Cloud infrastructure. Firebase Security Rules enforce strict access controls ensuring that only authenticated account owners can read or write their personal catalog data.
- Secure Development Practices: We follow secure coding practices, code obfuscation, dependency management, and periodic security reviews.
- Minimal Data Collection: Our core strategy is data minimization — collecting only what is strictly necessary for functionality.
While we maintain high security standards, no method of electronic transmission or storage is 100% secure. We encourage users to maintain secure device passcodes and account credentials.
6. Data Retention
- Locally Stored Data: Data stored on your device persists until you delete it manually within the App, clear App storage via device settings, or uninstall the App.
- Stashly Cloud Catalog Data: Cloud catalog records and user account data in Firebase Firestore are retained as long as your account remains active. Upon account deletion, all personal catalog data under
users/{uid}and authentication records are permanently deleted within 30 days. - Community Barcode Data (global_barcodes): Entries in the crowdsourced community barcode catalog consist exclusively of non-personal, public commercial pattern specifications (brand, pattern number, title, garment type, yardage) and contain zero personal identifiers, user IDs, or usernames. These community reference records remain in the shared database to support barcode scanning auto-lookup for all users even if an individual user deletes their personal account.
- Anonymous Crash Reports & Analytics: Anonymized crash and usage data is retained by service providers for a maximum of 24 months, after which it is automatically purged.
7. Data & Account Deletion
Because our Apps prioritize user autonomy and local-first design, you maintain direct control over your data at all times:
7.1 Stashly In-App Account Deletion (Settings → Delete Account)
Stashly provides a direct, self-service account and data deletion mechanism within the App:
- Open Stashly and navigate to Settings.
- Tap Delete Account.
- Confirm account deletion when prompted.
Executing Delete Account immediately and permanently deletes:
- Your local Room database cache and stored settings on your device;
- All Firestore cloud data associated with your user ID (including patterns, fabrics, projects, notions, tags, and profile);
- Your Firebase Authentication account.
7.2 Stashly Email Deletion Request (Fallback)
If you cannot access the App or wish to request manual deletion, you may email support@floatingpointapps.com with the subject line "Stashly Account Deletion Request". Please send your request from the email address registered with your Stashly account. We will permanently erase your account credentials and Firestore cloud records within 30 days and confirm in writing.
7.3 Local Data Deletion (All Apps)
To delete locally stored data for any of our Apps:
- In-App: Use available in-app clear/delete options (e.g., deleting individual entries).
- Device Settings: Go to Settings > Apps > [App Name] > Storage > Clear Data.
- Uninstallation: Uninstalling the App permanently removes all locally stored data from your device.
8. Children's Privacy
Floating Point Applications is committed to protecting the privacy of children. Our Apps are not directed at children under the age of thirteen (13), and we do not knowingly collect personal information from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA).
If we become aware that we have inadvertently collected personal information from a child under 13, we will take immediate steps to delete such information from our systems. If you believe that a child has provided personal information to us, please contact us immediately at support@floatingpointapps.com.
9. Third-Party Services & SDKs
Our Apps may integrate with third-party infrastructure and service providers as outlined below:
| Service Provider | Purpose | App(s) | Data Shared / Handled |
|---|---|---|---|
| Firebase Authentication (Google) | User authentication & sign-in security | Stashly (Signed-In) | Email address, authentication tokens |
| Firebase Firestore (Google) | Cloud database & multi-device catalog sync | Stashly (Signed-In) | User pattern, fabric, notion, and project catalog entries |
| Crash Reporting (e.g., Firebase Crashlytics) | App stability monitoring & bug diagnosis | All Apps (Opt-in) | Anonymous crash stack traces, device model, OS version |
| Analytics (e.g., Firebase Analytics) | Aggregated usage trends | All Apps (Opt-in) | Anonymous usage events (Ad ID collection disabled) |
| Google Play Billing | Processing in-app purchases | Fold, Blip | Handled entirely by Google Play — we never receive billing or payment card details |
| Google AdMob | Serving advertisements | Blip (Ad-Supported) | IP address, ad interactions, device info (subject to UMP consent flow) |
Ad-Free Apps (Fold and Stashly) do not integrate advertising SDKs or ad networks. Across all Apps, we do not integrate social media tracking SDKs, data brokers, or cross-app tracking tools. Review Google's Privacy Policy for information on Google services.
10. On-Device Artificial Intelligence
Certain Apps incorporate artificial intelligence ("AI") and machine learning ("ML") features powered by on-device models. This section explains how AI is used in our Apps and how it relates to your privacy.
Key Privacy Commitment: All AI processing in our Apps occurs entirely on your device. Your personal data is never transmitted to our servers or any third-party servers for AI processing. The AI models run locally using your device's hardware, consistent with our local-first architecture.
10.1 AI Features by App
| App | AI Feature | Data Processed by AI | Data Leaves Device? |
|---|---|---|---|
| Fold | AI-powered betting analysis assistant (Google Gemma 4 E2B) | Bet logs, odds, bankroll history, sports/platform data, app settings | No |
| Blip | AI-powered Bluetooth analyst and security assistant | Bluetooth scan results (RSSI, MAC addresses, device categories), saved device history | No |
| Stashly | None | N/A | N/A |
10.2 How On-Device AI Works
Our Apps use Google Gemma 4 E2B, an on-device large language model optimized for mobile devices. The AI model:
- Runs locally: All AI inference and processing occurs on your device's processor. No internet connection is required for AI features to function.
- Processes data in real-time: The AI reads your locally stored data only when you actively use AI features. It does not continuously monitor or process your data in the background.
- Has tool-calling capabilities: The AI assistant can read from and write to your local app database (such as logging bets in Fold or toggling the Bluetooth scanner in Blip) based on your conversational instructions. All such actions occur exclusively on your device.
- Does not learn from your data: The on-device model does not train, fine-tune, or update itself based on your personal data. The model is static; new model versions are obtained only when you choose to download them or through app updates.
10.3 User Consent and Control
AI features in our Apps are entirely opt-in. You must actively download the AI model within the App, open the AI assistant interface, and accept the in-app AI disclaimer before any AI processing begins. If you choose not to use AI features, no AI processing occurs.
10.4 AI Model Storage
The AI model files are downloaded directly to your device from a trusted public model repository (currently Hugging Face) only when you choose to enable AI features. The download is a one-way transfer: the model file is fetched to your device, and no personal data, identifiers, or usage information is sent in return.
10.5 What the AI Does NOT Do
For clarity, our on-device AI does not transmit prompts or queries to external servers, share betting or Bluetooth data with third parties, process biometric data, or profile users.
11. Your Privacy Rights
Depending on your location, you have rights regarding your personal information under applicable data protection laws:
11.1 Rights Under CCPA/CPRA (California Residents)
California residents have the right to request disclosure of collected personal information, request deletion of personal information, opt out of the "sale" or "sharing" of personal information (or targeted advertising in Ad-Supported Apps), and receive non-discriminatory treatment. We honor Global Privacy Control (GPC) opt-out signals.
11.2 Rights Under GDPR (EEA, UK, Switzerland)
Users in the EEA, UK, or Switzerland have rights of access, rectification, erasure, restriction, data portability, and consent withdrawal under the GDPR. Our legal basis for processing opt-in crash/analytics data or optional Stashly cloud sync is consent (Article 6(1)(a) GDPR) and contract performance for account sync. Contact support@floatingpointapps.com to exercise your rights.
11.3 Other U.S. State Privacy Laws
We respect privacy rights under state privacy laws (including VCDPA, CPA, CTDPA, TDPSA, OCPA, MTCDPA) allowing users to access, delete, or opt out of targeted advertising in Ad-Supported Apps.
12. Do Not Track & Global Privacy Control (GPC)
We recognize and honor Global Privacy Control (GPC) signals. When detected, GPC signals are treated as an opt-out of targeted advertising in Ad-Supported Apps (resulting in non-personalized ads only). Ad-Free Apps (Fold and Stashly) contain no advertising or cross-site tracking tools.
13. International Data Transfers
Floating Point Applications is located in Pennsylvania, United States. Any data transmitted to cloud services (such as Stashly Firebase sync or opt-in crash reporting) may be processed in the United States under standard security protocols and encryption.
14. Advertising & Tracking (Ad-Supported Apps Only)
Ad-Free Apps (Fold and Stashly) contain no advertisements or advertising SDKs. In Ad-Supported Apps (Blip), advertisements are served by Google AdMob. Users are presented with the Google User Messaging Platform (UMP) consent flow to manage personalized vs. non-personalized advertising preferences. Users can opt out via in-app privacy settings, device advertising settings, or GPC signals.
15. Data Breach Notification
In the event of a data breach affecting personal information held on cloud systems, we will notify affected users and regulatory authorities (including the Pennsylvania Attorney General) within 72 hours of verification, consistent with legal requirements.
16. Changes to This Privacy Policy
We may update this Privacy Policy periodically. Material changes will be accompanied by an updated "Effective Date" and prominent notices on our Site or within Apps.
17. Google Play Data Safety Compliance Summary
- Data Collection: Anonymous crash diagnostics and app performance data (with consent). For signed-in Stashly users, account email and catalog sync data.
- Data Sharing: No selling of data. Anonymous crash diagnostics shared with crash reporting tools. For Blip (Ad-Supported), ad interaction/device info processed by Google AdMob.
- Data Encryption: All transmitted data is encrypted in transit using TLS 1.2+. Cloud catalog data encrypted at rest in Firebase.
- Data Deletion: In-app self-service deletion in Stashly (**Settings → Delete Account**) and manual email deletion request process.
18. App Disclosures Comparison Summary
| Disclosure | Fold | Stashly | Blip Tracker |
|---|---|---|---|
| Contains advertisements | No | No | Yes (Google AdMob) |
| Advertising SDK integrated | No | No | Yes (Google Mobile Ads SDK) |
| Cloud account / sync support | No (Local-Only) | Optional (Firebase Auth & Firestore) | No (Local-Only) |
| In-app account deletion feature | N/A (No Accounts) | Yes (Settings → Delete Account) | N/A (No Accounts) |
| On-device AI assistant | Yes (Gemma 4 E2B) | No | Yes (Gemma 4 E2B) |
| Personalized ad opt-out support | N/A | N/A | Yes (UMP / Device Settings / GPC) |
19. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: support@floatingpointapps.com
- Phone: 1-410-343-7227
- Mailing Address: Floating Point Applications, 310 E South St, York, Pennsylvania 17403