1. Who we are
FriSki (“we”, “us”) is a group ski-tracking app: members of a private, invite-only group share their live position on a resort map, receive proximity audio alerts, and coordinate meeting points.
FriSki is operated by Morel Avraham. For any privacy question, or to exercise the rights described in section 7, contact support@friski.co.
2. Data we collect
| Category | What exactly | Where it lives |
|---|---|---|
| Account | Sign-in identity (Sign in with Apple, Google, an email one-time code, or email and password), display name, avatar colour, optional profile photo | Supabase |
| Live location | Latitude and longitude, altitude, battery level, timestamp. Only your most recent fix is stored on our servers: one row per person, overwritten on each update. Collected in the background during an active group session. | Supabase |
| Preferences | The choices you make in the app, such as skill level, ski or snowboard, pace, alert distance, and audio and navigation settings. Synced to your account so they follow you to a new phone. | Supabase |
| Ghost mode | Whether ghost mode is on. While it is, your phone sends no position to your group, and the position it last shared is deleted from our servers. | Supabase |
| Messages | Group chat messages and quick signals, and the photos and voice notes you send, which are stored privately and readable only by your group’s members. Also which messages you have read, shown to your group as “seen”. | Supabase |
| Groups | Group name, membership, invite code, meeting points, and the email address of anyone you invite by email | Supabase |
| Push token | A device token used to deliver notifications | Supabase |
| Safety reports | If you report a message: the reported text, who sent it, who reported it, and the reason you chose. Kept even if the message is later deleted, so a report can still be acted on. | Supabase |
| Day statistics | Distance, vertical drop, top speed, runs, time moving and time spent near each friend, for one ski day. Computed on your device, then saved to your account when the day ends so it survives a new phone and can be shared later. It is an aggregate: no coordinates, no route, no map. Your group sees it only after you choose to share that day, which is enforced by a database rule and not only by the app. | Supabase |
| Product analytics | Counted events, attributed to your account: opening the app (with the app version and the number of days since you last opened it), creating or joining a group, starting a ski day, starting navigation (to a friend, a meeting point or a place), setting a meeting point, sending a help alert, and sending a message (whether it was text, a photo, a voice note or a shortcut, never what it said). Also the Day Summary steps: day ended (with how the day ended, your group’s size and how many location updates your phone sent and received), summary viewed, share preview opened, photo added, friends tagged, share completed and caption copied. Counts and choices only, never coordinates, photos or message text. Deleted after 90 days. | Supabase |
| Crash data | Crash reports and diagnostic breadcrumbs, and a sample of the app’s performance timings. Identifiers are removed before anything is sent. No clipboard contents and no location payloads. | Sentry |
| Feedback | Optional in-app survey answers and anything you write in them, with the context that makes them useful: app version, your phone’s model and operating system, that day’s aggregate ski statistics (resort, distance, vertical, runs, time moving), your group’s size, how many friends were online, whether you used navigation or a watch, and how many times the app lost GPS, rerouted or could not find a route. No coordinates. | Supabase |
| Abuse protection | Counters of how often your account sends messages, joins groups and creates groups, used to enforce limits. On this website: a shortened one-way hash of your IP address and of the email address you submit, used to stop repeated signups. | Supabase |
| Waitlist | If you sign up for beta access on this website (not the app): your email address, whether “skier”, “snowboarder” or “other” best describes you, and any short text you enter for “Other” | Supabase |
| Website analytics | On this website only (friski.co), not in the app: visit statistics. The page viewed and when, the website you came from, your approximate location (country, region and city, worked out from your IP address), device type, and browser and operating system with their versions. No cookies are used and no individual profile is built. A visit is counted with a hash of the request (your IP address and browser details) that Vercel discards after 24 hours and that cannot link your visits across days or across other websites; the IP address itself is not stored. | Vercel |
The public website uses no advertising or analytics cookies. Its visit statistics are collected without cookies (see “Website analytics” above). The restricted administrator area uses a strictly necessary sign-in cookie so only approved moderators can review safety reports.
3. Real-time location sharing, and how it works
- Sharing runs only during an active group session. It starts when you enter one of your groups and stops when you leave, or when you turn sharing off in Settings.
- On Android a persistent notification (“FriSki is tracking your location”) is shown the entire time tracking runs.
- Your position is visible only to members of groups you joined by invitation. Access is enforced on the server with row-level security, and the real-time channel carrying positions is authorised per group member. Leaving or being removed from a group ends access immediately.
- Ghost mode hides you from your group completely: your phone stops sending your position and the last one it shared is deleted from our servers, while you can still see everyone else.
- While you share your location, the app also shares with your group your average speed on each slope difficulty, so that arrival times are more accurate; it never does this while ghost mode is on.
- We store only your latest position. We do not build a movement history on our servers.
4. Legal bases (GDPR Article 6)
- Performance of a contract: providing the map, chat, groups and meeting points.
- Consent: background location and push notifications, both granted through operating-system permissions you can revoke at any time.
- Legitimate interest: crash reporting, acting on abuse reports, and anonymous website visit statistics.
5. Retention
- Live location: your latest fix is kept until the next one overwrites it, or until you delete your account.
- Messages, groups, meeting points and profile: kept until you delete them or delete your account.
- Safety reports: kept while the report is open and for a reasonable period after it is resolved, so repeat behaviour can be recognised.
- Product analytics: deleted automatically after 90 days.
- Website analytics: the visit hash is discarded by Vercel after 24 hours. Visit records are kept for the Web Analytics reporting window of our Vercel plan, and Vercel may keep them longer.
- Lift status reports: deleted automatically one day after they expire. Answered or cancelled invites, and replaced meeting points: deleted automatically after 30 days.
- Crash data: retained under Sentry’s standard retention window.
- Waitlist signups: kept until the beta closes or you ask us to remove your email. Write to support@friski.co.
- Day statistics: kept until you delete your account. They are not purged on a timer. Sharing a day with your group cannot yet be undone in the app; write to support@friski.co and we will remove it.
- Unused groups: a group that never had a second member, a message or a meeting point is deleted automatically once it is 30 days old and nothing in it has been active for 30 days.
- Guest accounts: an account you never signed in to with an email, Apple or Google, that is in no group and has no saved ski day, is deleted automatically 30 days after it was last used, together with its profile.
- Website abuse-protection hashes: deleted automatically one day after the last attempt.
- Administrator activity log: 180 days. It records which administrator did what in the moderation and support tools, and holds no coordinates and no message text.
- Account media deletion jobs: the record that an account’s photos were deleted is kept for 90 days after the job finishes, so a restored backup can be reconciled against it and a deleted account is not brought back.
- The timed deletions above are the only automated purges we run; everything else is kept until you delete it.
One thing a deletion cannot reach: a database backup taken before you deleted something still contains it for as long as that backup is retained. That applies to your most recent location too. We keep no location history in the live database, and a backup is not one, but we will not claim that an overwritten position stops existing everywhere the moment it is overwritten.
6. Deleting your account
In the app: Settings → Account → Delete account. This immediately and irreversibly erases your profile and photo, your authentication record, your group memberships, your stored location, your push token, your preferences, your day statistics, and the photos and voice notes you sent.
Content you shared with a group (messages, meeting points and feedback) remains, but is detached from you so it can no longer be traced to your account. Removing one person’s messages would leave holes in a history the rest of the group still relies on. The deletion page lists exactly what is erased and what is detached.
If you cannot reach the app, see deleting your FriSki account for how to request deletion by email.
7. Your rights
You have the right to access, correct, erase, restrict and port your data, and to object to processing. You can exercise most of these in the app directly, through profile editing and account deletion, or by emailing us. You may also lodge a complaint with your local data protection authority.
If you live in California or another US state with a privacy law, you have the same rights to know what we hold, to correct it and to delete it, and you can use them by emailing us. We do not sell your personal information and we do not share it for cross-context behavioural advertising.
8. Sharing
We do not sell your data, and we do not share it with advertisers. We rely on these processors to run the service: Supabase (database, authentication, real-time), Sentry (crash reporting), Expo and EAS (build and push infrastructure), Mapbox (map tiles, which your phone requests directly as you pan the map; the map software’s own usage and location telemetry to Mapbox is switched off), Resend (the sign-in codes and the email we send when you join the beta waitlist), Vercel (hosting and anonymous visit statistics for this website), and Apple and Google (sign-in and push delivery). Your location and messages are shared only with your group members, as described in section 3.
9. International transfers
Data is hosted in the European Union (Supabase, eu-central-1). Processors may transfer data outside the EU under standard contractual clauses. Our website provider, Vercel, may process website data in the United States.
10. Children
FriSki is not directed at children under 13, or the higher minimum age your country requires. Signing up requires confirming that you are 13 or older.
11. Changes
We will post any changes on this page and update the date at the top. Material changes are announced in the app.