Privacy policy

Privacy policy

Last updated: July 17, 2026

Skoma ("we", "us") respects your privacy. This policy describes what we collect, why we collect it, and how you can control it. By using the app you agree to the practices described here.

1. Information we collect

Account. When you create an account we store your email address and name. If you register with a password, we keep a securely hashed version of it — never the password itself. If you sign in with Google, we receive your basic Google profile (name, email, and avatar).

Strava. When you connect Strava, we receive your public profile (name, city, country, avatar) and the activities you authorize us to read — distance, duration, elevation, heart rate, pace, routes, and photos attached to activities.

Content you create. We store the books you build, including the photos you add and any edits you make to pages.

Orders. When you buy a printed book, we collect the billing and shipping details needed to fulfil and deliver it, and we keep a record of your order. Card details are entered directly with our payment processor and are never seen or stored by us.

Communications. If you email us, join a waitlist, or submit an email address to hear about updates, we keep that message or address so we can respond or send what you asked for.

Technical.We collect basic technical information automatically — IP address, device type, browser, and usage metrics needed to keep the service running and understand how it's used.

2. How we use it

  • To build, display, and print your photobook.
  • To process orders, take payment, and ship your book.
  • To generate written captions and summaries for your book — to do this we may send a summary of your activity data to our AI text provider.
  • To save your edits and preferences between sessions.
  • To send transactional email (receipts, order updates) and, if you opted in, product updates.
  • To debug issues, secure the service, and improve the product.
  • If you accept marketing cookies, to measure which of our ads led to an order (see section 4).

We do not sell your data. We do not use your activities to train advertising models.

3. Share links

You can generate a public, read-only link to a book. Anyone with the link can view the book — including your name and the maps and stats on its pages — without signing in. They can't edit, download the print file, or order it.

To reduce what a shared link reveals, we trim the exact start and finish from route maps in the public view, so the link doesn't expose your likely home location. You control sharing: a link can be set to expire (or never), and you can revoke it at any time from the editor, after which it stops working.

4. Cookies, analytics & advertising

We use essential cookies required to sign you in and run the app. Everything else is opt-in, split into two separate choices you can accept or decline independently in our cookie banner:

  • Analytics— privacy-respecting product analytics so we can understand how the app is used and what's broken.
  • Marketing — lets our advertising partners measure which ads actually lead to an order. If you accept this, when you complete a purchase we share a hashed version of your email address with the advertising platform (currently Reddit) so it can match that order to an ad you saw. We share it only for measuring our own advertising, and we never send your training data or book contents to an ad platform.

Declining marketing does not affect your order, and you can change your mind at any time — withdrawing a category stops the relevant tags and clears the cookies they set.

5. How we share data

We share data only with the service providers needed to run the app, each bound to confidentiality and permitted to use your data only to provide their service to us:

  • Hosting and infrastructure.
  • Database and file storage.
  • Payments and printing/fulfilment.
  • Transactional email delivery.
  • Maps, to render your routes.
  • AI text generation, for book captions and summaries.
  • Product analytics.
  • Advertising platforms (currently Reddit), to measure ad conversions — only if you accept marketing cookies, and only the hashed identifier described above.
  • Strava and Google, for the integrations you choose to connect.

6. Strava data

Your use of Strava data within Skoma is additionally governed by Strava's own terms. We import your activities only to build your book and, once the import is complete, we revoke our Strava access so we hold no long-lived Strava credentials. You can also disconnect Strava at any time. Activity data already saved in your books remains until you delete the book.

7. Your rights

You can access, export, or delete your data at any time by emailing privacy@skoma.ai. If you are in the EU, UK, or another region with similar laws, you have additional rights under GDPR and equivalent regulations.

8. Retention

We keep your data for as long as your account is active, or as required to comply with legal obligations (for example, tax and order records). Deleted books are removed from our systems within 30 days.

9. Security

We use industry-standard safeguards — encryption in transit, access control, rate limiting, and regular reviews. No system is perfect, so we encourage you to use a strong password and keep your devices secure.

10. Changes to this policy

We may update this policy from time to time. When we do, we'll update the "Last updated" date above. Material changes will be announced in-app or by email.

11. Contact

Questions about privacy? Reach us at privacy@skoma.ai or via our contact page.