SkiPhoria Privacy Policy

What we collect, why, and what we deliberately don't.

Effective 17 September 2026 · Last updated 17 September 2026

The short version

Who is responsible

The data controller is Anders Lassen Kamsvaag, an individual developer based in Norway, operating as SkiPhoria.

Contact for anything in this policy, including requests about your data: privacy@skiphoria.com.

What we collect, and why

DataWhyLegal basis
Email address, from Google or Apple when you sign in To identify your account so your results follow you between devices Performance of a contract
Racer name — a name you choose Shown on leaderboards and to people who follow you Performance of a contract
Session data — times, distance, power, ascent, splits, and which type of machine you used. Since September 2026 this includes your workouts and free-ski sessions, stored in your account (without heart rate) so your history follows you between devices. To show your history, rank leaderboards, and award trophies Performance of a contract
Training settings — your FTP anchor, training progress and XP To set workout targets and track your progress Performance of a contract
Who you follow To show a friends leaderboard and activity feed Performance of a contract
Heart rate (special category — health data) Shown live during a session and stored with it, on your device Your explicit consent, only where it leaves the device
Courses you import from a GPX file So you can ski and share your own routes Performance of a contract
Strava tokens, if you connect Strava To upload your sessions to your Strava account Your consent
Reports you file — what you reported (a racer, a race, a course or a lobby entry), the reason you chose, your optional note, and where in the app you were To keep the service safe and fair: a person reads every report and may remove content or results Legitimate interest — the reported person did not agree to it, and does not need to
Feedback you send — your words, and for a bug report the diagnostics you chose to attach: app version, device model, operating system, your erg's name and machine type, and the last few lines of the app's connection log (events like “connected” or “stream lost” — never the raw data and never your heart rate) To fix what you report and build what you ask for Your consent, given when you press Send
Push token — an identifier for your device with Expo's notification service, only if you turn notifications on To deliver the notifications you chose Your consent; removed when you turn notifications off or sign out

If you never sign in, none of this is sent anywhere. The app records your sessions on your device and nothing else happens.

What is public

SkiPhoria is a competitive app, so some things are visible to other users by design:

Who can see your races

You choose who may follow you: anyone, by request only, or nobody. You choose separately whether your verified times appear on public course leaderboards under your racer name, and you can mark any individual race “Only me”, which keeps it off every leaderboard and out of your followers’ feeds. These settings are stored with your account and enforced by the database, not only by the app. Your racer name remains visible in search, in live-race lobbies and on any board you have chosen to appear on.

Who can see your training

Since September 2026 the people you have accepted as followers also see your workouts and free-ski sessions in their Recent activity feed — distance, time, average power, never heart rate — unless you mark a session “Only me” or your profile is private. Training sessions never appear on a leaderboard and are never shown to anyone who does not follow you.

Anyone who can see one of your sessions can leave a fist bump on it, and everyone who can see that session can see who bumped it — your name appears on their screen the same way theirs appears on yours. We store who bumped what and when, so that you can see it and they can take it back. That is the whole of it: there are no comments, and nobody outside your accepted followers can react to anything of yours.

Your heart rate is not part of that. It is removed from every result before it is uploaded, so it cannot appear on a leaderboard even in principle. Your email address is never public. Neither is anything else in your private profile.

Your racer name is a name you choose, and nothing is pre-filled from your Google or Apple account — deliberately, so you are never nudged into publishing your real name.

Heart rate and health data

Heart rate is special-category data under Article 9 GDPR, and we treat it that way:

Location and routes

SkiPhoria does not request or use your device's location. It is an indoor app.

You can import a GPX route, which does contain real-world coordinates. A GPX file that starts at your front door reveals where you live, so:

Who else processes your data

ServiceWhat it doesWhere
Supabase Our database, authentication and backend. Our processor — they hold the data on our behalf. European Union
Google / Apple Sign-in only, if you choose that option. We receive your email address; we do not receive your contacts, calendar or anything else. Their own terms apply
Strava Only if you connect it. We send your sessions to your account. The permission we request includes reading your public activities, because Strava only lets an app set the sport type of an activity it can see; the only thing we ever read is whether a session we uploaded already exists, and we store nothing from Strava. Their own terms apply
Expo Delivers app updates and, if you turn notifications on, the notifications themselves: it receives your device's push token and the text of each message — a racer name and what happened, never session numbers and never heart rate. When you send us feedback, the first 120 characters of your text are delivered to the operator's own device the same way, so we see it arrives.
Sentry Crash reporting. When the app crashes it sends the error and where in the app it happened, the device model, operating system and app version, and the addresses of the last few requests to our server — without their contents, so never what you searched for or who you looked at. No name, email or account id is attached, and IP addresses are not stored. European Union
Cloudflare Hosts this website and routes email sent to support@ and privacy@skiphoria.com to us. The contents of an email you send us pass through it. Their own terms apply

Your Strava access tokens are stored on our server and are never readable by any other user or sent to your device. You can disconnect Strava at any time in the app.

What we do not do

Bluetooth is used for one thing only: connecting to your ergometer and your heart-rate strap.

How long we keep things

Your rights

Under the GDPR you have the right to access, correct, delete, restrict and object to the processing of your data, and the right to receive a copy of it in a portable format.

If you believe we have handled your data wrongly, you can complain to your national supervisory authority. In Norway that is Datatilsynet.

Children

SkiPhoria is not intended for children under 16, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will remove it.

Security

All traffic is encrypted in transit. Access to your data is enforced at the database level, so one user cannot read another user's private data. Sign-in tokens are held in your device's secure keystore, not in ordinary app storage. Strava credentials never leave our server.

Changes to this policy

If we change this policy we will update the date at the top, and for any significant change we will tell you in the app before it takes effect.