Privacy Policy — Skifty

Effective date: 2026-07-11 Data controller: Acoid HB, Hallebergsvägen 15, 167 37 Bromma, Stockholm, Sweden. Contact: hello@acoid.com.

Skifty ("we", "us") is a mobile app for lending, borrowing, and giving away items within invite-only groups of people you trust. This policy explains what personal data we process, why, the legal basis, how long we keep it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR).

We are committed to data minimisation: we collect only what the app needs to work. We do not sell your data, do not use it for advertising, and do not track you across other apps or websites.

1. Who this applies to

Users of the Skifty mobile app. Our launch market is Sweden; the service and this policy are governed by EU/Swedish law. You must be at least 16 years old to use Skifty.

2. What we collect, why, and the legal basis

DataExamplesWhy we process itLegal basis (GDPR Art. 6)
Account identifiersYour account id, email address (or the private relay email you choose to share via Apple), and — if you sign up with email — a password; handled by our authentication provider (Clerk). If you sign in with Apple or Google, we also receive your name (if you choose to share it), a unique identifier from that provider, and — from Google — your profile photo.To create and secure your account and sign you inContract (Art. 6(1)(b))
ProfileDisplay name, profile photo (avatar)To identify you to others in your groupsContract
Group dataGroup names, invite codes, and which groups you belong toTo run invite-only groups and show you the right contentContract
PostsItem titles, descriptions, categories, additional info, and photos you uploadTo let you offer (to lend or give away) or request itemsContract
RequestsBorrow and give-away requests and their status/timestampsTo run the lend, borrow, and give-away flowContract
MessagesMessages you send in chats about an itemTo let the two parties to a loan communicateContract
Social graphGroup membership and which chats you are a party toTo enforce who can see whatContract
Notification tokensDevice push token and platform (iOS/Android)To send you transactional notifications (e.g. a new message or a request update)Consent (you grant the OS notification permission) / Contract
Abuse-preventionYour IP address, transiently, as a rate-limit counter on a few endpointsTo prevent abuse (e.g. invite-code guessing, spam)Legitimate interests (Art. 6(1)(f))
Audit logsRecords of meaningful actions (action name, actor, timestamp)Security, debugging, and integrity of the serviceLegitimate interests
DiagnosticsCrash reports and error breadcrumbs, linked to a pseudonymous account identifier, with your name, email, and message content removedTo detect and fix crashes and bugsLegitimate interests
Usage / product analytics (optional, opt-in)Information about which features and screens you use, linked to a pseudonymous account identifier — no name, email, or message contentTo understand what is useful and improve the appConsent (Art. 6(1)(a))

You can create an account and sign in with an email and password, or by using Sign in with Apple or Google Sign-In. These sign-in options are optional alternatives to email/password — you choose which to use, and we only receive the data described above for the method you pick.

If you turn analytics on in Settings, we collect information about how the app is used — e.g. which features you open and how often — to understand what is useful and improve the app. These events are linked to a pseudonymous account identifier (so we can see how the same account uses the app over time), but they contain no name, email, or message content, and we do not use them to track you across other apps or websites. Analytics is processed in the EU by PostHog, is off by default, and you can toggle it any time in Settings → Integritet (Privacy).

What we do NOT collect

We do not collect your location, contacts, financial information, health data, biometric data, browsing history, or search history. Skifty has no payments in this version.

3. How we share data (processors and recipients)

We do not sell personal data. We use the following processors, who process data on our behalf under data-processing agreements:

ProcessorRoleData it receives
ClerkAuthenticationEmail, password (hashed), account id, session metadata
SupabaseDatabase + file storage hosting (EU region)All app data listed in §2
Expo / Apple APNs / Google FCMPush-notification deliveryPush tokens and templated notification text (never message contents)
SentryCrash and error monitoringStack traces and breadcrumbs, with personal identifiers scrubbed
PostHog (EU region)Product analyticsUsage events (which features and screens you use), linked to a pseudonymous account identifier so we can analyse how an account uses the app over time. No name, email, or message content is sent. Only active if you have opted in to analytics.

If you choose to sign in with Apple or Google, that provider authenticates you and passes a limited set of account data to us. For this sign-in step, Apple and Google act as independent controllers under their own privacy policies for the processing they carry out in their own systems; towards Skifty they are recipients of the data they pass to us, not our processors. They only receive the data needed to authenticate you and never see your posts, messages, or group activity.

Sign-in providerData it shares with us
Apple (Sign in with Apple)Your name (if you allow it) and email (or the private relay email Apple generates for you), and a unique account identifier — only if you choose to sign in with Apple
Google (Google Sign-In)Your name, email address, and profile photo, and a unique account identifier — only if you choose to sign in with Google

Other group members see the data you choose to share within a group: your display name and avatar, your posts and their photos, and your messages in a chat you are a party to. People you are not in a group or chat with cannot see your content.

We may disclose data if required by law or to protect the rights, safety, or security of our users or the service.

4. Where your data is stored

Your data is stored in the European Union. Notification delivery and crash monitoring may involve transfers to providers operating under appropriate safeguards (e.g. EU Standard Contractual Clauses) where applicable. Signing in with Apple or Google also involves a transfer to Apple Inc. and/or Google LLC in the United States, under appropriate safeguards (EU-US Data Privacy Framework certification and/or Standard Contractual Clauses, as applicable to that provider).

5. How long we keep it (retention)

  • Account and profile data: for as long as your account exists. Deleted when you delete your account (see §7).
  • Closed conversations and their messages: kept up to 12 months after the request is closed, then deleted automatically.
  • Audit logs: activity records (action name, actor, timestamp) are kept only as long as necessary for security, debugging, and the integrity of the service. Lower-level infrastructure logs are retained for a shorter period, according to our hosting plan.
  • Abuse-prevention IP counters: up to 7 days.
  • Backups: held under our provider's standard schedule. Backups are not exempt from your erasure rights — once you are erased from production, your data is not restored from backups into production.

6. Your rights under the GDPR

You have the right to: access your data, rectify inaccurate data, erase your data ("right to be forgotten"), restrict or object to processing, and data portability. You can exercise the main rights directly in the app:

  • Access / portability: export your data as a JSON file from within the app.
  • Erasure: delete your account from within the app. If you can no longer access the app, email us at hello@acoid.com to request deletion.
  • Rectification: edit your profile and your posts in the app.

A completed give-away post is kept as a record of the hand-over and cannot be deleted individually while your account is active; it is erased when you delete your account (see §7).

For any request, or to contact our data protection point of contact, email hello@acoid.com. We respond within 30 days as required by GDPR Article 12(3) (extendable by up to two months for complex requests, with notice). You also have the right to lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) or your local supervisory authority.

7. Account deletion — what happens

When you delete your account (in the app, or by emailing hello@acoid.com if you can no longer access the app), we permanently delete your profile, your posts and uploaded photos, your messages, your requests, your group memberships, and your notification tokens — and we delete your account at our authentication provider (Clerk). Groups you created are deleted as well, and their other members lose access — unless you transfer ownership to another member before deleting (you can transfer a group you own from within the app). If you have any in-progress loans or give-aways when you delete your account, we notify the other party that their counterpart in that exchange has left, so they are not left waiting on an item or a return. If you signed in with Apple or Google, this also removes the associated link to that provider on our side; you can separately revoke Skifty's access from your Apple ID or Google Account settings at any time. Audit-log entries are retained with your account identifier removed from the actor field; any residual references in historical entries are pseudonymous and are not linked back to an active account. Deletion is true deletion, not deactivation.

8. Security

We treat the database as the security boundary: access to your data is enforced by row-level security so that only people in your groups or chats can see your content. Data is encrypted in transit (HTTPS/TLS). Session tokens are stored in the device's secure storage (iOS Keychain / Android Keystore). We never ship administrative keys in the app.

9. Children

Skifty is not directed at children under 16. We do not knowingly collect data from children under that age. If you believe a child has provided us data, contact us at hello@acoid.com and we will delete it.

10. Changes to this policy

We may update this policy. We will post the new version with a new effective date and, for material changes, notify you in the app.

11. Contact

Acoid HB, Hallebergsvägen 15, 167 37 Bromma, Stockholm, Sweden. Privacy contact: hello@acoid.com.