What we collect, why, and what we deliberately don't.
Effective 17 September 2026 · Last updated 17 September 2026
The data controller is Anders Lassen Kamsvaag, an individual developer based in Norway, operating as SkiPhoria.
Contact for anything in this policy, including requests about your data: privacy@skiphoria.com.
| Data | Why | Legal basis |
|---|---|---|
| Email address, from Google or Apple when you sign in | To identify your account so your results follow you between devices | Performance of a contract |
| Racer name — a name you choose | Shown on leaderboards and to people who follow you | Performance of a contract |
| Session data — times, distance, power, ascent, splits, and which type of machine you used. Since September 2026 this includes your workouts and free-ski sessions, stored in your account (without heart rate) so your history follows you between devices. | To show your history, rank leaderboards, and award trophies | Performance of a contract |
| Training settings — your FTP anchor, training progress and XP | To set workout targets and track your progress | Performance of a contract |
| Who you follow | To show a friends leaderboard and activity feed | Performance of a contract |
| Heart rate (special category — health data) | Shown live during a session and stored with it, on your device | Your explicit consent, only where it leaves the device |
| Courses you import from a GPX file | So you can ski and share your own routes | Performance of a contract |
| Strava tokens, if you connect Strava | To upload your sessions to your Strava account | Your consent |
| Reports you file — what you reported (a racer, a race, a course or a lobby entry), the reason you chose, your optional note, and where in the app you were | To keep the service safe and fair: a person reads every report and may remove content or results | Legitimate interest — the reported person did not agree to it, and does not need to |
| Feedback you send — your words, and for a bug report the diagnostics you chose to attach: app version, device model, operating system, your erg's name and machine type, and the last few lines of the app's connection log (events like “connected” or “stream lost” — never the raw data and never your heart rate) | To fix what you report and build what you ask for | Your consent, given when you press Send |
| Push token — an identifier for your device with Expo's notification service, only if you turn notifications on | To deliver the notifications you chose | Your consent; removed when you turn notifications off or sign out |
If you never sign in, none of this is sent anywhere. The app records your sessions on your device and nothing else happens.
SkiPhoria is a competitive app, so some things are visible to other users by design:
You choose who may follow you: anyone, by request only, or nobody. You choose separately whether your verified times appear on public course leaderboards under your racer name, and you can mark any individual race “Only me”, which keeps it off every leaderboard and out of your followers’ feeds. These settings are stored with your account and enforced by the database, not only by the app. Your racer name remains visible in search, in live-race lobbies and on any board you have chosen to appear on.
Since September 2026 the people you have accepted as followers also see your workouts and free-ski sessions in their Recent activity feed — distance, time, average power, never heart rate — unless you mark a session “Only me” or your profile is private. Training sessions never appear on a leaderboard and are never shown to anyone who does not follow you.
Anyone who can see one of your sessions can leave a fist bump on it, and everyone who can see that session can see who bumped it — your name appears on their screen the same way theirs appears on yours. We store who bumped what and when, so that you can see it and they can take it back. That is the whole of it: there are no comments, and nobody outside your accepted followers can react to anything of yours.
Your heart rate is not part of that. It is removed from every result before it is uploaded, so it cannot appear on a leaderboard even in principle. Your email address is never public. Neither is anything else in your private profile.
Your racer name is a name you choose, and nothing is pre-filled from your Google or Apple account — deliberately, so you are never nudged into publishing your real name.
Heart rate is special-category data under Article 9 GDPR, and we treat it that way:
SkiPhoria does not request or use your device's location. It is an indoor app.
You can import a GPX route, which does contain real-world coordinates. A GPX file that starts at your front door reveals where you live, so:
| Service | What it does | Where |
|---|---|---|
| Supabase | Our database, authentication and backend. Our processor — they hold the data on our behalf. | European Union |
| Google / Apple | Sign-in only, if you choose that option. We receive your email address; we do not receive your contacts, calendar or anything else. | Their own terms apply |
| Strava | Only if you connect it. We send your sessions to your account. The permission we request includes reading your public activities, because Strava only lets an app set the sport type of an activity it can see; the only thing we ever read is whether a session we uploaded already exists, and we store nothing from Strava. | Their own terms apply |
| Expo | Delivers app updates and, if you turn notifications on, the notifications themselves: it receives your device's push token and the text of each message — a racer name and what happened, never session numbers and never heart rate. When you send us feedback, the first 120 characters of your text are delivered to the operator's own device the same way, so we see it arrives. | — |
| Sentry | Crash reporting. When the app crashes it sends the error and where in the app it happened, the device model, operating system and app version, and the addresses of the last few requests to our server — without their contents, so never what you searched for or who you looked at. No name, email or account id is attached, and IP addresses are not stored. | European Union |
| Cloudflare | Hosts this website and routes email sent to support@ and privacy@skiphoria.com to us. The contents of an email you send us pass through it. | Their own terms apply |
Your Strava access tokens are stored on our server and are never readable by any other user or sent to your device. You can disconnect Strava at any time in the app.
Bluetooth is used for one thing only: connecting to your ergometer and your heart-rate strap.
Under the GDPR you have the right to access, correct, delete, restrict and object to the processing of your data, and the right to receive a copy of it in a portable format.
If you believe we have handled your data wrongly, you can complain to your national supervisory authority. In Norway that is Datatilsynet.
SkiPhoria is not intended for children under 16, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will remove it.
All traffic is encrypted in transit. Access to your data is enforced at the database level, so one user cannot read another user's private data. Sign-in tokens are held in your device's secure keystore, not in ordinary app storage. Strava credentials never leave our server.
If we change this policy we will update the date at the top, and for any significant change we will tell you in the app before it takes effect.