Privacy Policy
Plain-English summary of what we collect, why, and what your rights are. The full legal text is below.
1. Who we are
SKILLFLIRT is operated by SkillFlirt AB ("we", "us"), a Swedish entity registered at Stockholm, Sweden. This Privacy Policy covers the SKILLFLIRT mobile apps (iOS, Android), the web experience at skillflirt.com, and the admin tooling at skilldash.skillflirt.com.
For privacy questions or to exercise your rights, contact us at privacy@skillflirt.com.
2. Data we collect
You give us
- Account details — email, password (hashed with scrypt + per-user salt; we never see the plaintext), display name, username.
- Profile information — avatar, gallery photos, age, interests, location query, gender preference.
- Content you create — quizzes, comments, messages (including voice and image attachments), reactions.
- Payment data — handled by Stripe; we receive a customer ID and the last 4 digits of your card. We never store full card numbers.
We collect automatically
- Device push token — for sending notifications you've opted into.
- Usage events — what features you use, sent through PostHog (EU region). Anonymised after 90 days.
- Crash reports — via Sentry, scrubbed of personal identifiers before submission.
- Approximate IP-based location — for rate-limiting abuse, not for advertising.
3. Why we collect it
- Run the service — match you with people, deliver messages, count XP and coins.
- Process payments — verify charges, prevent fraud, send invoices.
- Keep you safe — detect spam, block abusive accounts, moderate user-generated content.
- Improve the app — see which features land, fix bugs faster.
- Comply with the law — respond to lawful requests from authorities (we publish a transparency report annually).
4. Legal basis (GDPR Art. 6)
- Contract — for delivering the service you signed up for.
- Legitimate interest — for fraud detection, abuse prevention, security telemetry.
- Consent — for marketing emails and optional analytics. Withdrawable any time in Settings → Notifications.
- Legal obligation — for tax records and law-enforcement responses.
5. Who sees your data
- Other SKILLFLIRT users — only what you choose to share on your profile + the content you publish.
- Stripe (Ireland) — payment processing.
- Firebase / Google Cloud (EU regions) — push notifications.
- Convex (eu-west-1, Ireland) — primary database + realtime sync.
- PostHog (EU region) — product analytics.
- Sentry (EU region) — crash reporting.
We sign Data Processing Agreements with each. No data is sold to advertisers, brokers, or insurance companies.
6. Your rights
Under GDPR you have the right to:
- Access — download everything we hold via Settings → Export my data (returns a JSON file).
- Delete — wipe your account permanently via Settings → Delete account. Cascades to messages, matches, push tokens, and Stripe customer.
- Correct — edit your profile any time, or email us if a field is locked.
- Object / restrict — opt out of marketing emails and analytics in Settings; we won't ban you for it.
- Portability — the export above is a machine-readable JSON. Import to a competitor is at their discretion.
- Complain — to your local Data Protection Authority (in Sweden: IMY, imy.se).
7. Retention
- Account data — kept until you delete the account or are inactive for 24 months.
- Messages — kept until you delete the conversation or your account.
- Payment records — kept 7 years for tax compliance.
- Audit & security logs — kept 90 days unless tied to an active investigation.
- Anonymised analytics — kept indefinitely (no link back to you).
8. International transfers
All primary infrastructure lives in EU regions. Stripe processes some data in the US under Standard Contractual Clauses (the post-Schrems-II safeguard). If we ever move infrastructure outside the EU, you'll be notified by email at least 30 days before the move.
9. Children
SKILLFLIRT is rated for 18+. We do not knowingly collect data from children under 18. If you believe a minor has an account, email safety@skillflirt.com and we'll investigate within 24 hours.
10. Changes
We'll email you and post a notice in-app at least 14 days before meaningful changes take effect. Minor wording fixes are made silently.
Related: Cookies Policy · Terms & Conditions · Privacy & Security · Tips