Pulpo SVG — Privacy Policy
Last updated: 2 September 2026
Pulpo SVG is an SVG editor that runs entirely on your device. Your drawings, your project folder and your settings stay there. There are no accounts, no analytics, no advertising and no tracking of any kind. The app only sends something out when you ask it to — a bug report, or a commit to a GitHub repository you connected yourself — and this page explains exactly when that happens.
Who is responsible
Pulpo SVG is made by Collide Works. For anything related to this policy or to your data, write to iakl@collideworks.com.
What stays on your device
- Your files. The SVGs you open, edit and save, and everything in the project folder you grant access to — images, symbols, palettes, fonts and effects. The app reads and writes them locally. They are never uploaded anywhere.
- Your settings and recent work. Preferences, recent files, saved palettes, the last folder you mounted and the automatic recovery copy of unsaved work. All of it lives in your device's local storage, or in the project folder itself.
Access to a folder is granted by you, per folder, through the Android system picker. You can revoke it at any time from the app or from Android's settings. Uninstalling the app removes everything it stored locally; your SVG files remain where you saved them.
What the app sends, and only if you ask
Reporting a bug or requesting a feature
The “About” panel has a form for telling us what is broken or what you would like. It is the only feature that sends anything to us, and it does nothing until you press send. What it sends:
| Data | Why |
|---|---|
| The description you write | To understand and fix the problem, or to consider the request |
| Your email address — optional, only if you tick the box agreeing to be contacted | To reply to you. Leave it out and the report is anonymous |
| The app version and whether it is the app or the web version | Because it is the first thing any answer needs, and asking costs two emails |
Your document is never attached, and nothing is sent in the
background. In the Android app the report is handed to your own email application,
already written, and you are the one who presses send. In the web version it is
posted to our server at collideworks.com and delivered to our mailbox
by Resend, an email
delivery provider acting on our behalf.
Reports are kept in that mailbox for as long as they are useful for support, and are used for nothing else: no mailing lists, no profiling, no sharing or selling to anyone. Ask us at the address above and we will delete yours.
Connecting GitHub
Pulpo SVG can publish a mounted project folder to a GitHub repository you already own. This is off until you set it up, and it is the only feature that sends your drawings anywhere.
There is no Pulpo account and no sign-in through us. You create a fine-grained personal access token yourself on github.com, choose which repositories it may touch, and paste it into the app. We never see it: the token goes straight from your device to GitHub.
| Data | Where it goes |
|---|---|
| Your access token | Stored on your device only. In the Android app it is encrypted with the Android Keystore, outside the project folder and out of reach of the WebView. In the web version it is kept in that browser's local storage. It is sent to github.com to authenticate your own requests, and nowhere else. |
| The files you choose to commit | Sent to github.com, into the repository and branch you linked. Only the files you tick, and only when you press Commit and Push. |
| Repository, branch and commit information | Read from github.com to show you what changed and to keep the folder's own Git metadata up to date. Nothing is written outside your project folder. |
Nothing goes to Pulpo SVG's servers at any point: the app talks to github.com directly. “Disconnect account” deletes the stored token from the device, and you can revoke it at any time from your GitHub settings. What GitHub does with what you send it is covered by GitHub's privacy statement.
Purchases
Pulpo SVG Pro is a single in-app purchase handled entirely by Google Play. We never see or receive your payment details. The app asks Google Play whether the Google account on the device owns the product, and remembers that answer locally so it keeps working offline. That is the whole exchange. Google's handling of the transaction is covered by Google's privacy policy.
What the app never does
- No user accounts and no login of ours. Connecting GitHub uses a token you create and can revoke, and it never reaches our servers.
- No analytics, telemetry, crash reporting or usage statistics.
- No advertising and no advertising identifiers.
- No device identifiers, no location, no contacts, no camera, no microphone.
- No cookies for tracking, on the web version or anywhere else.
- No selling or sharing of personal data. There is nothing to sell.
Children
Pulpo SVG is a general-purpose design tool. It is not directed at children and we do not knowingly collect anything from them.
Your rights
Because the app collects nothing on its own, in most cases there is simply no data of yours in our hands. If you did send a report with your email address, you can ask us to show it to you or to delete it, and we will. Write to iakl@collideworks.com.
Changes to this policy
If the app ever starts doing something that is not described here, this page will say so before that version ships, and the date at the top will change.