Skip to content
FeaturesFAQDownload now

Privacy Policy for the Skandineer app

Version: privacy_v3 · Last updated: 6 September 2026

This policy describes how Skandineer AB processes your personal data when you use the Skandineer app. This is an English translation of the Swedish original; in case of any discrepancy, the Swedish version prevails.

The short version

  • Your exact location is never shown to others. We store your most recent position on our server so we can calculate distances and derive which approximate area your pin should show. What others see is an approximate area of roughly 5 km, never your exact location. Location sharing is entirely optional, and if you turn off your map visibility the stored position is deleted.
  • We do not read your messages in the ordinary course. If a conversation is reported a moderator may read it, and opening the conversation beyond the reported message is logged together with the reason.
  • We never sell your data and show no ads. We make money from optional Plus subscriptions, nothing else.
  • All core data is stored within the EU (Frankfurt, Germany).
  • You can download your data and delete your account directly in the app, without contacting us.
  • Skandineer is for adults (18 or older).

Data controller

Skandineer AB, Swedish company reg. no. 559579-5435, Stockholm (“Skandineer”, “we”) is the data controller for the processing of your personal data in the Skandineer app.

Contact for privacy matters: hello@skandineer.se

What data we collect

We process no special categories of data under Art. 9 GDPR (health, religion, sexual orientation, ethnicity, etc.). What we do process:

  • Account: email address and password (always stored encrypted), or your Apple identity if you use Sign in with Apple.
  • Profile: display name, date of birth, gender (including “prefer not to say”), home country, current country and city, languages, profile picture, bio and interests. Your date of birth is never shown to others, at most your age or an age range.
  • Location: if you choose to appear on the map, we store your most recent position on our server, along with how accurate the measurement is and which country and city it falls in. We need it to calculate distances and to derive which approximate area your pin should show. The position is never shown to other users. What others see is an approximate area of roughly 5 km derived from the position, and that area is stored as a separate record. Your position is only updated while you are using the app (never in the background) and always replaces the previous one. If you choose “Profile only” on the map, or delete your account, the stored position is deleted.
  • Content: chat messages, posts, comments, images, and the groups and activities you create or join. Images are automatically stripped of hidden metadata (such as GPS coordinates in photo files) at upload.
  • Social connections: groups you have joined, activities you have signed up for, and users you have blocked.
  • Device: device model, operating system version, app version and a push notification address (token), so notifications reach the right device.
  • Purchases: payment is handled entirely by Apple. We never see your card details, only the subscription's status.
  • Usage statistics: which screens and features are used, tied to an internal ID and never to your name or email address. Never contains your messages, your exact location or any free text. To find usability problems we may also record how the app is used on screen, with automatic masking: text you type and images are hidden in the recording. All of this can be turned off at any time in settings (“Share usage statistics”).
  • Crash reports: technical error reports without personal data (such data is scrubbed automatically).
  • Reports and moderation: reports you make or are affected by, a copy of reported messages, decisions and their reasoning, and a log of when a moderator read a conversation and why.

Why, and on what legal basis

We process the data to provide the service, keep it safe and comply with the law. We send no marketing, only messages that belong to the service. Legal basis under Art. 6 GDPR per area:

  • Account, profile, content, groups and chat: contract (6.1.b).
  • Location (approximate): consent (6.1.a), voluntary and revocable.
  • Device data: contract (6.1.b) and legitimate interest (6.1.f) to prevent abuse.
  • Usage statistics and session recordings: legitimate interest (6.1.f); you can object at any time by turning it off in settings (Art. 21).
  • Crash reports: legitimate interest (6.1.f).
  • Purchase data: contract (6.1.b).
  • Moderation and security log: contract, legitimate interest and legal obligation (6.1.b, 6.1.f, 6.1.c).
  • Review of reported conversations and spam protection: legal obligation under the EU Digital Services Act (6.1.c) and legitimate interest in a safe service (6.1.f). The spam protection counts patterns (volume, recipients, whether messages are identical) without anyone reading the content.
  • Accounting records for purchases: legal obligation (6.1.c, the Swedish Bookkeeping Act).

Location sharing in detail

The map is the heart of Skandineer, so we want to be extra clear:

  • Location sharing requires two active choices: the iOS permission and your choice inside the app.
  • Your pin marks an approximate area of roughly 5 km, never your exact location. The area is derived on our server from your position, and the area is the only part other users ever see.
  • Your exact position is stored on our server for as long as you are visible on the map. We need it to calculate distances and to know which area your pin should show. It is never disclosed to other users and it is not visible anywhere in the app.
  • If you choose the “Profile only” mode, your pin disappears from the map, the stored position is deleted, and you no longer see other people's pins either (reciprocity).
  • Your position is only read while you are using the app, never in the background.
  • If you delete your account, your position and pin are deleted.

Who we share data with

We never sell your data. Beyond the providers below, we only disclose data where the law requires it (for example in a criminal investigation, after legal review). These providers process data on our behalf under data processing agreements:

  • Supabase: database, sign-in and file storage (EU, Frankfurt).
  • Sentry: crash reports (EU, Frankfurt).
  • PostHog: usage statistics and masked session recordings, can be turned off in settings (EU, Frankfurt).
  • RevenueCat: subscription management (USA, see next section).
  • Mapbox: the map imagery in the app (global CDN, see next section).
  • Resend: service emails such as confirmations and password reset (USA, see next section).
  • Expo: relays our push notifications to your device, and delivers app updates (USA, see next section).
  • Apple: payments, Sign in with Apple and push notification delivery.
  • Vercel: hosting of our internal administration tool (EU).

Transfers outside the EU/EEA

  • RevenueCat (USA): protected by the European Commission's Standard Contractual Clauses (SCCs). We minimize what is sent: subscription data and a customer ID, never your messages, your location or your content.
  • Resend (USA): sends our service emails and stores metadata and logs in the USA, protected by Standard Contractual Clauses (SCCs). Only your email address is involved.
  • Mapbox: when the app fetches map tiles, Mapbox sees your IP address, as does any web server you visit. Governed by a data processing agreement.
  • Expo (USA): our push notifications are relayed to your device via Expo's service. Expo receives and stores your push notification address (token), and receives the notification's title and body, which can contain another user's name and the beginning of a message. The notification text itself is not stored by Expo: it is passed on to Apple and discarded. The app also asks Expo whether a new app update exists, and Expo sees your IP address when it does. Expo participates in the EU-U.S. Data Privacy Framework, which covers the transfer to the USA. We never send your location, your password or whole conversations to Expo.
  • Apple: push notifications are delivered via Apple's servers. Push tokens cannot be linked to your identity without our database.

How long we keep your data

  • Account, profile and content: for as long as your account exists.
  • Location (exact, on our server): only the most recent position is stored, each new one replacing the previous. It remains for as long as you are visible on the map, and is deleted when you choose “Profile only” or delete the account.
  • Pin area (approximate, what others see): same as above, only the most recent one, deleted when your pin disappears or the account is deleted.
  • Deleted account: 30-day grace period, then permanent deletion.
  • Chat images: for as long as the chat exists. An image you delete is permanently removed 30 days later. Everything is deleted when the account is deleted.
  • Notifications: for as long as your account exists, and deleted with the account.
  • Crash reports: 90 days.
  • Usage statistics: up to 1 year.
  • Session recordings: up to 30 days.
  • Purchase/accounting records: 7 years (the Swedish Bookkeeping Act), anonymized if the account is deleted.
  • Copies of reported messages: deleted 90 days after the report is closed without action. If the report leads to a decision, the copy follows the moderation log.
  • Security and moderation log: 7 years, anonymized when the account is deleted.

What happens when you delete your account?

The account is deactivated immediately: your profile, your pin and your content stop being visible. For 30 days you can change your mind by signing in again. After that, your data is permanently deleted, including images and location.

Two things we must keep by law, in anonymized form with no link to your identity: accounting records for purchases and the security/moderation log. Copies of messages you sent that were reported are anonymized. If someone wrote your name in their own message (“hi Erik!”), it remains in that person's conversation, just as in email and text messages.

Your rights

Under the GDPR you have the right to:

  • Access and export your data: tap “Download my data” in the app's settings to receive everything you have provided, in machine-readable format (Art. 15 and 20).
  • Correct inaccurate data: most things you edit yourself in your profile; locked fields (such as name and date of birth) we correct by email (Art. 16).
  • Delete your account: directly in the app under Settings (Art. 17).
  • Restrict or object to processing: usage statistics and session recordings are turned off directly in the app's settings (Art. 21). For other objections, email hello@skandineer.se (Art. 18 and 21).
  • Withdraw consent at any time: location sharing is turned off in settings, without affecting the rest of the service.

Automated decisions and complaints

No decisions with legal or similarly significant effects are made about you in a fully automated way (Art. 22). Automated filters may temporarily hide content that violates our rules. Such actions are reviewed by a human, you receive a statement of reasons, and you can appeal in the app.

Complaints: you can always contact the Swedish Authority for Privacy Protection (IMY, imy.se), or the data protection authority in the EU country where you live.

Age limit

Skandineer is for adults. You must be 18 or older. This is verified at registration, and younger users cannot create an account.

Changes to this policy

For material changes we will notify you in the app before they take effect, and you can always choose to close your account. Each version of this policy is versioned (this one is privacy_v3), and we record which version you accepted.

If we want to engage a new provider that processes personal data, we will notify you 30 days in advance in the app and by email.

Contact

Skandineer AB · Company reg. no. 559579-5435 · hello@skandineer.se

The website waitlist has its own privacy policy: skandineer.se/integritet.