Skobka.Independent software studio
AboutOur appsContact
Reach the team

Privacy notice

Last updated 24 September 2026.

This notice covers skobka.eu and the applications published on it. It is given by «LEGAL_ENTITY is not set», at «LEGAL_ADDRESS is not set», which decides what is collected here and is therefore the data controller for it. Write to «LEGAL_CONTACT_EMAIL is not set» about anything on this page.

The short version

Three things are recorded, and they are listed below in order of how much they say about you. Nothing is sold, nothing is shared with advertisers, and there is no profiling and no automated decision-making.

1. Your account, if you have one

Signing in stores your email address, because it is how you sign in and how we reach you, and a session so that you stay signed in. Everything you then put into an application — your todos, your expenses, your recipes — is stored so the application can give it back to you. It is kept for as long as the account exists.

The lawful basis is the contract between us: without this the applications cannot work at all.

2. Visitor statistics

Pages are counted with GoatCounter, which runs on our own server rather than someone else's. It records the page visited, the page that linked to it, and a coarse description of the browser, the operating system, the screen size and the country. It sets no cookie, it does not store your IP address, and it cannot follow you to any other site. To recognise a repeat view within a day it keeps a one-way hash of your IP address and browser, made with a salt that is rotated; the address itself is never written down.

These counts are aggregate, they do not identify anyone, and they are kept for 12 months.

The lawful basis is our legitimate interest in knowing whether anything here is used. Because no cookie is set and nothing identifying is stored, this is not consent-gated — there is nothing meaningful to consent to.

3. Session replay, only if you agree to it

We intend to use Contentsquare, a third party acting as our processor, to record how a page is actually used: mouse movement, clicks, scrolling, the order pages are visited in, and the content of the pages as they appeared to you. That is considerably more than a page count, which is why it is treated differently.

It runs only with your explicit consent, and the code is not even sent to a browser that has not given it — the choice is made on our server rather than left to the tag to respect. You have not been asked yet: the consent banner is not live, and until it is, no session replay runs at all. Consent, once given, can be withdrawn at any time, and withdrawing it is as easy as giving it.

Server logs

The web server in front of everything writes an access log: the IP address the request came from, the time, the page asked for, the answer given, the browser's own description of itself, and the page that linked there. This is how a fault or an attack is investigated, and it is the legitimate interest the log is kept under.

It is kept for 90 days, then deleted by the server as it rotates. It is not used to build any picture of an individual.

Who else sees any of this

The platform runs on rented servers in the European Union, and the hosting provider is a processor acting on our instructions. Sign-in email is sent through an email provider, which necessarily sees the address it is sent to. Contentsquare, described above, sees only what you have consented to it seeing. Nobody else is given anything, and nothing is transferred outside the European Economic Area.

Your rights

Under the GDPR you may ask for a copy of what is held about you, ask for it to be corrected, ask for it to be erased, ask for it in a portable form, object to processing carried out under legitimate interest, and withdraw any consent you have given. Write to «LEGAL_CONTACT_EMAIL is not set» and you will have an answer within one month.

You may also complain to the data protection authority in the country you live in. You do not need to raise it with us first, though we would rather you did.

Deleting your account

Plainly: there is no button for this yet. Signing out ends a session, and an administrator can revoke your access, but neither of those erases what is stored. Automated self-serve deletion is not built, and this notice is not going to imply otherwise.

So it is done by hand, and it is done properly. Write to «LEGAL_CONTACT_EMAIL is not set» asking for your account to be deleted and everything held about you will be erased across every application within 30 days, with confirmation when it is finished. This is a gap we are closing, not a policy.

Cookies

Only two kinds are used, and neither is for advertising. A session cookie keeps you signed in. A preference cookie remembers a choice you made, such as a light or dark theme, or your answer to the consent question once there is one. The statistics described above set no cookie at all.

Changes

If this notice changes in substance the date at the top changes with it. It is a short document on purpose; if something here is unclear, that is worth telling us about at «LEGAL_CONTACT_EMAIL is not set».

Skobka.

© 2026 Skobka. Carefully made.

PrivacyTermsContact