Carol

Privacy Policy

Carol, knitting app for iPhone

Last updated: 19 July 2026

In short

Carol processes all of your data only locally on your iPhone. The app sends no data to any server, uses no trackers, shows no ads, and has no accounts. Carol offers an optional one-time in-app purchase (Carol Pro) and any paid knitting patterns in the pattern shop, all handled entirely through Apple; the app itself receives no payment data. There are no third-party SDKs, no analytics, and no crash reporters beyond Apple's standard features. If you do not want to read on, that is the essence of it.

1. Controller within the meaning of the GDPR

The controller for data processing in connection with Carol is:

Nordic App Studio
Owner: Ferdinand Drobik (sole proprietorship, Enkeltmandsvirksomhed under Danish law)
Bordeauxgade 4, 2.th
2150 Copenhagen
Denmark

CVR: 45328120
Email: info@nordicappstudio.dk

No data protection officer is appointed, as the conditions under Art. 37 GDPR and section 38 BDSG are not met.

2. Principle of data minimisation

Carol was built on the principle of maximum data minimisation. The app works fully without an internet connection. It does not collect, store, or transmit any personal data to the developer or to external servers. All data stays only on your device.

3. What data the app processes

Carol processes only the content that you enter yourself in order to plan and follow your knitting projects. This includes:

This content is stored locally in an app-owned database on the device (Apple SwiftData) and does not leave the device through the app.

4. What is stored on the device

Project database

Your projects, counters, swatches, reminders, pattern adjustments, and any project photo are held in a local SwiftData store on your iPhone. iCloud synchronisation is not enabled. The provider has no access to this data.

App settings

A few settings are stored locally via @AppStorage (equivalent to UserDefaults), such as your saved own swatch, knitting-mode options (left-hand mode, haptics), whether you have seen the onboarding, the unlocking of Carol Pro, and the IDs of patterns already purchased. These values do not leave your device.

Project photos

When you add a photo to a project, you select it through the iOS system image picker. The image is stored locally with the project. Your original photo in your library is not changed, and nothing is uploaded.

Reminders

Carol can remind you at specific rounds. Such reminders are scheduled by iOS as local notifications on the device. There is no push server and no transmission to third parties.

Backup and export

You can create a backup as a JSON file yourself, or export a single project as readable text, and share it through the iOS share menu. Where that file goes is entirely up to you; the app does not send it anywhere on its own.

5. What the app does not do

The following list is deliberately explicit, because that is the heart of this app.

6. Permissions

Carol requests as few permissions as possible. Access to a project photo runs through the system image picker, which does not grant the app lasting access to your library but only passes along the specific image you selected. For round reminders, iOS asks once for your consent to notifications when needed. You can withdraw this consent at any time in the iOS settings.

7. No third-party SDKs

Carol uses no external software SDKs or tracking libraries and no external package dependencies. The entire source code of the app was written by the developer. There are no hidden data transfers to third parties.

8. Apple App Store and purchases

You obtain Carol through the Apple App Store. When you purchase, install, and run it, Apple processes data under its own responsibility (Apple ID, payment data, device identifiers, and optionally diagnostic data if you have enabled that in the iOS settings). The optional one-time Carol Pro purchase and any purchases of individual knitting patterns are handled entirely through Apple's in-app purchase. The app only learns whether an unlock exists and receives no name, card, or account data. That processing sits with Apple, not with the provider of this app.

Apple's privacy policy: apple.com/legal/privacy

If you have enabled sharing under "Settings, Privacy & Security, Analytics & Improvements, Share with App Developers" in iOS, Apple may pass anonymised crash reports to us. We do not actively enable this channel and do not systematically evaluate the reports. You can withdraw this sharing at any time in the iOS settings.

9. Legal basis

Where personal data within the meaning of Art. 4 GDPR arises at all in an individual case, for example because a project photo shows people, the processing takes place only on your device and by you yourself in the course of your use of the app. No transmission to the provider of this app or to third parties takes place.

Legal bases, where applicable:

10. Retention period

Local data (projects, swatches, settings, project photos, backups you create) remains stored for as long as you do not delete it, do not uninstall the app, and do not reset your device. The provider has no access to this data and can neither view nor delete it. When you uninstall the app, iOS removes the app's local storage.

11. Data recipients

There are none. Carol transmits no data to processors, no data to third parties, and no data to third countries. The only data flow that takes place at all runs between Apple and you (purchase, installation, in-app purchase, and diagnostics if applicable).

12. Your rights

Because the provider does not collect, store, or otherwise process any personal data, most GDPR rights to access, rectification, and erasure have practically nothing to act on. You have the following rights nonetheless:

If you wish to exercise one of these rights, please contact the address named in section 1. We usually answer questions about privacy and legal matters within three business days, and in any case within the legal deadline under Art. 12(3) GDPR.

13. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority in Denmark is:

Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark
datatilsynet.dk

14. Security

The processing of your entries happens on your device. The app uses the standard iOS security mechanisms (app sandbox, local app storage). No further security model of our own is required, because no data leaves the device.

15. Children

The app is intended for a general audience and collects no data at all, neither from adults nor from children. There are no accounts, no profiles, and no communication features in which children could disclose personal data.

16. Changes to this privacy policy

If the features of the app change so that this policy no longer fits, we update the text and the date above. Noticeable changes, such as the introduction of a cloud feature or a third-party SDK, are clearly marked in the app's changelog and in the App Store release notes.

17. Contact

Email: info@nordicappstudio.dk

About this website

The policy above describes the app and its on-device data handling. This policy is itself published as a page on nordicappstudio.dk, which is hosted by Simply.com A/S on servers within the EU. As with any website, viewing this page generates standard server access logs (for example your IP address, browser type, and time of access) for the secure operation of the site, on the basis of legitimate interest (Art. 6(1)(f) GDPR). This applies only to viewing this web page and does not affect how the app works. Full details and your rights are in our Website Privacy Policy.