←BackSkiftyStart a project

Privacy Policy — Skifty

Effective date: 2026-08-07 Data controller: Acoid HB, Hallebergsvägen 15, 167 37 Bromma, Stockholm, Sweden. Contact: hello@acoid.com.

Skifty ("we", "us") is a mobile app for lending, borrowing, and giving away items within circles — small groups of neighbours, called cirklar in the app. This policy explains what personal data we process, why, the legal basis, how long we keep it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR).

We are committed to data minimisation: we collect only what the app needs to work. We do not sell your data, do not use it for advertising, and do not track you across other apps or websites.

1. Who this applies to

Users of the Skifty mobile app. Our launch market is Sweden; the service and this policy are governed by EU/Swedish law. You must be at least 16 years old to use Skifty. That is a condition of using the service that we set ourselves — it is not a statement about the age at which Swedish law lets you consent to data processing, which is lower.

2. What we collect, why, and the legal basis

DataExamplesWhy we process itLegal basis (GDPR Art. 6)
Account identifiersYour account id, email address (or the private relay email you choose to share via Apple), and — if you sign up with email — a password; handled by our authentication provider (Clerk). If you sign in with Apple or Google, we also receive your name (if you choose to share it), a unique identifier from that provider, and — from Google — your profile photo.To create and secure your account and sign you inContract (Art. 6(1)(b))
ProfileDisplay name, profile photo (avatar)To identify you to others in your circlesContract
Circle dataCircle names, invite codes, which circles you belong to, and — for an open circle — its approximate area, coverage radius, and member countTo run circles and show you the right contentContract
PostsItem titles, descriptions, categories, additional info, the photos you upload, and which of your circles you shared the item withTo let you offer (to lend or give away) or request itemsContract
RequestsBorrow and give-away requests and their status/timestampsTo run the lend, borrow, and give-away flowContract
MessagesMessages you send in a one-to-one chat about an item, and messages you post in a circle's group chat (visible to every current member of that circle)To let you arrange a loan or hand-over, and to let a circle talk togetherContract
Social graphCircle membership, requests to join an open circle, and which chats you are a party toTo enforce who can see whatContract
Notification tokensDevice push token, platform (iOS/Android), and the sign-in session that registered itTo send you transactional notifications (e.g. a new message or a request update)Contract. Your device's notification permission controls delivery — that is a device setting, not a separate consent we hold
Approximate location (optional)An approximate area, never a precise position: a grid cell roughly 150 metres tall and about 80 metres wide at Swedish latitudes, and the centre point of that cell. You choose to save one or more areas ("Hem", "Sommarstugan"). We store the cell and its centre — never a raw coordinate from your device, and never an address.To show roughly how far away an item is, and to help you find open circles near youConsent (Art. 6(1)(a)) — optional, opt-in, withdrawable at any time
BlocksWhich users you have blockedTo hide the two of you from each other, because you asked us toContract
ReportsWhat you reported (a user, post, or circle), a reason category, and up to 1 000 characters of free text you write — which may describe another userTo review and act on abuse, and to be able to explain and defend a moderation decisionLegitimate interests (Art. 6(1)(f)) — keeping the service safe for its users
Deletion requestsThe email address, and any reason you give, when you ask us to delete an account without signing inTo identify the account and carry out the deletion, and to record that we didLegal obligation (Art. 6(1)(c), Art. 17) / Contract
Abuse-preventionYour IP address, transiently, as a rate-limit counter on a few endpointsTo prevent abuse (e.g. invite-code guessing, spam)Legitimate interests (Art. 6(1)(f))
Audit logsRecords of meaningful actions: the action, who did it, when, and the identifiers of the items and accounts involvedSecurity, debugging, and integrity of the serviceLegitimate interests
Diagnostics (optional, opt-in)Crash reports and error breadcrumbs, linked to a pseudonymous account identifier, with your email address removed and identifiers strippedTo detect and fix crashes and bugsConsent (Art. 6(1)(a)) — optional, opt-in, withdrawable at any time
Usage / product analytics (optional, opt-in)Information about which features and screens you use, linked to a pseudonymous account identifier — no name, email, or message contentTo understand what is useful and improve the appConsent (Art. 6(1)(a))

You can create an account and sign in with an email and password, or by using Sign in with Apple or Google Sign-In. These sign-in options are optional alternatives to email/password — you choose which to use, and we only receive the data described above for the method you pick.

Account and profile data is needed to use Skifty at all; if you do not provide it, we cannot give you an account. Everything marked optional above is genuinely optional — the app works without it.

Location is optional, and it is approximate by design. Skifty never asks for or stores your exact position. If you use your GPS position or drop a pin on a map, your device works out which grid cell you are in — roughly 150 metres tall and about 80 metres wide at Swedish latitudes — and sends only that cell — the coordinate never leaves your phone. If you type a postnummer instead, the postnummer is sent to our servers and we look up the matching cell there; we keep the cell, not the postnummer. Either way we store the cell and its centre point, which is simply the middle of that cell and tells us nothing more than the cell does.

You control this in two places: your device's location permission, and Skifty's own setting under Inställningar → Plats. Turning Skifty's setting off stops us saving new areas and stops us using your saved areas to show you distances or to find circles near you. Two things it does not do: it does not delete the areas you saved — you can delete each one in the app — and it does not remove an area you already attached to one of your items, which stays with that item until you edit or delete it. Everything else in Skifty works without location.

Crash reports and analytics are both off unless you turn them on. If you turn crash reporting on, technical reports are sent when something goes wrong so we can fix it. We remove your email address and strip identifiers from them, and we do not send your name or the contents of your messages. In pre-release test builds, crash reporting is always on so we can find problems before release. If you turn analytics on, we collect which features and screens you use — linked to a pseudonymous account identifier so we can see how the same account uses the app over time, but containing no name, email, or message content, and never used to track you across other apps or websites. Analytics is processed in the EU by PostHog. You can switch either one off at any time in Inställningar → Integritet, and the app works exactly the same with both off.

What to write in a report. Describe what happened and where. Please do not include information about health, religion, sexual life, political opinions or ethnicity, and do not make accusations of criminal conduct — if you believe something is a crime, report it to the police. We use reports only to decide whether someone has broken our Terms, and we remove free text that goes beyond what we need for that.

What we do NOT collect

We do not collect your precise location, your contacts, financial information, health data, biometric data, browsing history, or search history. Skifty has no payments in this version. We do not make any decision about you by automated means that produces legal effects or similarly significantly affects you.

3. How we share data (processors and recipients)

We do not sell personal data. We use the following processors, who process data on our behalf under data-processing agreements:

ProcessorRoleData it receives
ClerkAuthenticationEmail, password (hashed), account id, session metadata
SupabaseDatabase + file storage hosting (EU region)All app data listed in §2
Expo / Apple APNs / Google FCMPush-notification deliveryPush tokens and short notification text — which can include a display name, an item title, or a circle name, but never the contents of your messages
SentryCrash and error monitoringStack traces and breadcrumbs, with your email address removed, linked to a pseudonymous account identifier. Only active if you have turned crash reporting on — except in pre-release test builds, where it is always on.
PostHog (EU region)Product analyticsUsage events (which features and screens you use), linked to a pseudonymous account identifier so we can analyse how an account uses the app over time. No name, email, or message content is sent. Only active if you have opted in to analytics.

We do not send your posts, photos, or messages to any artificial-intelligence service. If that ever changes, we will update this policy and tell you in the app before it does.

If you choose to sign in with Apple or Google, that provider authenticates you and passes a limited set of account data to us. For this sign-in step, Apple and Google act as independent controllers under their own privacy policies for the processing they carry out in their own systems; towards Skifty they are recipients of the data they pass to us, not our processors. They only receive the data needed to authenticate you and never see your posts, messages, or circle activity.

Sign-in providerData it shares with us
Apple (Sign in with Apple)Your name (if you allow it) and email (or the private relay email Apple generates for you), and a unique account identifier — only if you choose to sign in with Apple
Google (Google Sign-In)Your name, email address, and profile photo, and a unique account identifier — only if you choose to sign in with Google

Maps. Where Skifty shows a map, it uses the maps built into your device (Apple Maps on iOS). We do not send Apple your account data or your list of saved areas. When you open a map it opens centred on the relevant area, so Apple receives the map view being drawn, as it would for any map you scroll to, under Apple's own privacy policy.

What other people can see

Other members of a circle you are in can see your display name and avatar, the posts you share to that circle and their photos, and your messages in that circle's chat or in a one-to-one chat you are a party to. You can share one post to several of your circles; it is visible to the members of each circle you chose.

  • Private circles are invite-only. Only someone with the invite code can join. Bear in mind that anyone you give the code to can pass it on, and other members can share it too.
  • Open circles are public within the app. Any Skifty user can find an open circle by name, or by searching near themselves, and can see its name, its member count, and its approximate area — never a street address. Depending on the setting the circle's owner chose, they can either join immediately or ask to join. If they ask, the owner sees their display name and avatar, and keeps a record of the request, in order to decide. Once someone is a member, they see the posts, photos, display names, and avatars in that circle like any other member. Treat an open circle as visible to people you do not know, and do not post anything there you would not want a stranger to see.
  • Distances. If you have saved an area and attached one to a post, other members see roughly how far away the item is — never where you are, and never your area, coordinates, or address. In a private circle we do not show anything below 200 metres as a distance; in an open circle we do not show anything below 1 kilometre. An open circle's own area is stored and shown more coarsely than your own saved area — a cell of up to roughly 1.2 km, and around 600 metres across at Swedish latitudes.
  • Blocking. Blocking hides the two of you from each other's feeds and stops new direct messages and new requests in both directions. A one-to-one conversation you already had stays visible to both of you — neither of you can write in it any more. If you are both members of the same circle, you will still see each other's messages in that circle's group chat.

Apart from an open circle's public listing described above, people who are not in a circle or a chat with you cannot see your posts, photos, or messages. One exception worth naming: any signed-in Skifty user can load any profile picture.

We may disclose data if required by law or to protect the rights, safety, or security of our users or the service.

4. Where your data is stored

Your posts, photos, messages and other app data are stored in the European Union (Supabase), and product analytics are processed in the EU (PostHog). Other recipients may process data outside the EU: our authentication provider (Clerk), crash reporting (Sentry), push delivery (Expo with Apple APNs and Google FCM), and Apple or Google if you use their sign-in. Those transfers rely on appropriate safeguards — EU-US Data Privacy Framework certification and/or Standard Contractual Clauses, as applicable to each provider. Email hello@acoid.com for a copy of the safeguards that apply.

5. How long we keep it (retention)

  • Account and profile data: for as long as your account exists. Deleted when you delete your account (see §7).
  • One-to-one conversations and their messages: kept up to 12 months after the request is closed, then deleted automatically.
  • Circle group chats: messages posted in a circle's group chat are kept for as long as the circle exists. If you delete your account, your own messages are deleted; messages other people wrote stay — unless the circle is one you created, which is deleted along with everything in it (see §7).
  • Saved areas (location): kept until you delete them in the app or delete your account. Turning the location setting off stops us using them, but does not by itself delete them.
  • Blocks: kept until you unblock the person, or until either account is deleted.
  • Reports: while we review a report we keep what you wrote. Once the report is closed we delete the free text automatically, and keep only the category, what was reported, and the outcome. We keep that closed record for 12 months from the date of the report, or 24 months if we took action such as removing content or suspending an account, so that we can explain and defend the decision if it is challenged (Art. 17(3)(e)); then we delete it. If a report is still open, we keep it until we have reviewed it. A report you filed is deleted when you delete your account. A report someone filed about you is kept for the period above even if you delete your account, because it is the record of our decision rather than a file on you.
  • Deletion requests: kept until we have carried out the deletion, and for 90 days afterwards as a record that we did, then deleted.
  • Audit logs: application activity records are kept for 12 months, then deleted. Lower-level database and infrastructure logs are kept for 90 days.
  • Abuse-prevention IP counters: up to 7 days.
  • Backups: we do not keep separate backup copies of the database. When your data is deleted, there is no backup copy for it to survive in, and the retention periods above are the whole picture rather than the part you can see.

6. Your rights under the GDPR

You have the right to: access your data, rectify inaccurate data, erase your data ("right to be forgotten"), restrict or object to processing, and data portability. You can exercise the main rights directly in the app:

  • Access / portability: export your data as JSON from within the app. The export includes your saved areas, your blocks, the reports you have made, and your requests to join open circles.
  • Erasure: delete your account from within the app. If you can no longer access the app, email us at hello@acoid.com to request deletion.
  • Rectification: edit your profile and your posts in the app.
  • Withdrawing consent: location, analytics, and crash reports are each opt-in and can be switched off at any time in the app's settings, without affecting the lawfulness of what we did before you switched them off.
  • Objection and restriction: for anything we do on the basis of legitimate interests — reports about you, audit logs, abuse prevention — email hello@acoid.com. We will stop unless we can show compelling grounds that override your interests.

Reports about you. If someone reports you, we do not tell you who reported you and we do not give you the text of the report. Doing so would reveal the reporter and would let people retaliate, which would defeat the purpose of having a reporting tool at all; we rely on Art. 14(5)(b) and Art. 15(4) for that. If we act on a report, we tell you which rule we found you had broken. You can object to this processing at hello@acoid.com and we will review both the report and our decision.

A completed give-away post is kept as a record of the hand-over and cannot be deleted individually while your account is active; it is erased when you delete your account (see §7).

For any request, or to contact our data protection point of contact, email hello@acoid.com. We have not appointed a Data Protection Officer; that address reaches the people responsible for this policy. We respond within 30 days as required by GDPR Article 12(3) (extendable by up to two months for complex requests, with notice). You also have the right to lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) or your local supervisory authority.

7. Account deletion — what happens

When you delete your account (in the app, or by emailing hello@acoid.com if you can no longer access the app), we permanently delete your profile, your posts and uploaded photos, your messages, your requests, your circle memberships, your saved areas, your blocks, your requests to join open circles, the reports you have made, and your notification tokens — and we delete your account at our authentication provider (Clerk).

Circles you created are deleted as well — and that takes the posts, photos and chats other members had in them, not merely their access. If you want a circle to survive you, transfer ownership to another member before you delete your account; you can do that from within the app. Deleting your one-to-one chats also deletes the messages the other person wrote in them.

If you have any in-progress loans or give-aways when you delete your account, we notify the other party so they are not left waiting on an item or a return; that notification includes the display name you were using and the item concerned.

If you signed in with Apple or Google, this also removes the associated link to that provider on our side; you can separately revoke Skifty's access from your Apple ID or Google Account settings at any time.

Three things outlive your account, all described in §5: a report someone else made about you, our internal activity log, and — if you asked us to delete by email — the deletion request itself. That log records that an action happened — what, and when. We remove your account identifier from the actor field when you delete your account, and some entries keep an account identifier inside the entry itself; those cannot be used to contact or identify you through Skifty, and every entry is deleted after 12 months. Everything else listed above is permanently deleted, not deactivated — we keep no hidden copy of your profile, posts, or messages.

8. Security

We treat the database as the security boundary: access is enforced by row-level security, so only people in your circles or chats can see your posts, photos, and messages. Two things are deliberately visible more widely, and are described in §3: open circles are discoverable by any signed-in user, and any profile picture can be loaded by any signed-in user. Data is encrypted in transit (HTTPS/TLS). Session tokens are stored in the device's secure storage (iOS Keychain / Android Keystore). We never ship administrative keys in the app.

9. Children

Skifty is not directed at children under 16. We do not knowingly collect data from children under that age. If you believe a child has provided us data, contact us at hello@acoid.com and we will delete it.

10. Changes to this policy

We may update this policy. We will post the new version with a new effective date and, for material changes, notify you in the app. We will not start processing your data in a materially new way — including sending your content to a new kind of recipient — before this policy says so.

11. Contact

Acoid HB, Hallebergsvägen 15, 167 37 Bromma, Stockholm, Sweden. Privacy contact: hello@acoid.com.

© 2026 Acoid — SkiftyTerms of ServicePrivacy Policy