Privacy Policy

Skomi is an analytics company, so this document has to be better than most. It says what is collected, where it goes, who else can see it and when it is deleted, both for you as a customer and for the people who visit your sites.

Last updated 10 September 2026

Skomi is operated by Skomi OÜ, registered in Estonia. Where these documents say "we", "us" or "Skomi", they mean that company.

There are three different relationships here

Most privacy policies describe one. This one has to describe three, and mixing them up is what makes an analytics company's policy unreadable.

  1. You, browsing skomi.com. We are the controller. Covered in section 1.
  2. You, as a Skomi customer. We are the controller for your account and billing. Covered in section 2.
  3. The people who visit your sites. You are the controller and Skomi is your processor. We hold that data on your instructions, and it is your privacy notice that has to describe it to them. Covered in section 3.

1. When you browse skomi.com

This marketing site does not track you. There is no analytics script on it, no advertising pixel and no third-party tag.

Three cookies can be set, all first-party:

Cookie When Lifetime Why
skomi-theme You choose light or dark Persistent So the page does not flash the wrong theme on your next visit
skomi_ref You arrive from an affiliate link (?a=…) 60 days So the affiliate who referred you is credited if you sign up
Session cookies You sign in Session or as chosen Authentication on app.skomi.com and admin.skomi.com

skomi_ref is the only one that is not strictly necessary. It records a referral code, never who you are, and it is set only if you arrive through a link that carries one.

If you write to us through the contact form we keep your message and address so we can answer it.

2. When you are a customer

What we hold. Your name and email address, the sites and apps you have registered, your settings, your plan and its history, and the records of what you have been billed. If you join the affiliate programme, we hold your referral code and what it has earned.

Payment details we do not hold at all. Paddle is the merchant of record and takes payment; card numbers never reach us. We receive the outcome and nothing more: that a payment succeeded, the amount, and the country used for tax.

Email. We send you what the service needs: confirmation, security notices, billing, and the reports you asked for. Every report email can be unsubscribed from, and doing so is one click.

Server logs. Warnings and errors from all four Skomi hosts are stored so we can find faults. They can incidentally include an IP address or a URL.

Why we are allowed to. Running your account and taking payment is performance of our contract with you. Keeping the service secure and finding faults is our legitimate interest. Records we keep for accounting are a legal obligation.

3. What Skomi collects on your sites

Here we act on your instructions. What follows is what the software does, so that you can describe it accurately in your own privacy notice.

The visitor's IP address is stored. It is used when a hit arrives, to derive an identifier, to look up an approximate location, and to apply any traffic exclusions you set. It is then kept alongside the rest of the visit for your plan's retention period. It appears in no report, no breakdown and no export, and it is never shared with anybody. There is one place you can see it: when a single address sends implausibly high volume, a traffic alert shows you that address so you can exclude it. Showing it there is the reason it is kept.

Identity is derived on our server, not stored on the device. By default Skomi sets no cookie and stores no identifier in a visitor's browser. The only things it ever writes there are a visitor's own choices, such as that a feedback widget was dismissed or that a comment was already sent, so that the site does not ask again. Nothing is written unless the visitor acts, and none of it identifies anybody. A visitor is identified by a one-way hash of the site, the address and the browser string under a random salt that is never written down and is replaced every day. Yesterday's salt no longer exists, so yesterday's visitors cannot be linked to today's by anyone, including us. That is the property that makes the identifier not ordinary personal data, and the reason most sites need no consent banner for Skomi.

The cost of that is real and we would rather state it than hide it: the same person on two days counts as two visitors, and cohort retention reporting cannot work at all. A site that needs those can switch a site to device identity, which stores an identifier in the browser. At that point consent is required and getting it is your job.

What is stored for a page view. The URL and page title, the referrer, UTM and ad-click parameters, an approximate location from the IP (country, region and city, never the address itself), the browser, operating system and device type, the screen and window size, and timing and engagement figures. The browser's user-agent string is kept alongside the parsed values.

Custom properties and events hold whatever you send. You decide what that is; see section 3 of the terms.

Session recordings and heatmaps (the Behavior product, off unless you switch it on) record what happened on the page so it can be replayed. Input contents are masked by the recorder and that is not configurable; you can block further elements by selector. Recording honours the Global Privacy Control browser signal when you switch that on for a site.

Feedback submissions hold the rating and the comment a visitor chose to write, and the page element they pointed at.

4. Who else is involved

Who What for Where
Hetzner Hosting, databases and object storage Germany
Paddle Payments, invoicing and tax, as merchant of record EU / UK
MaxMind The geolocation database Queried locally, so no visitor data leaves our servers
Google reCAPTCHA, which checks that a sign-in or sign-up form was filled in by a person Only on the sign-in and sign-up pages of app.skomi.com

Your data is stored in the EU. If you connect Google Search Console or Bing Webmaster Tools to a site, that is you instructing us to fetch data from them on your behalf, and their own terms apply to what they hold.

We do not sell data, we do not share it with advertisers, and we do not use it to train models.

Attribution. This product includes GeoLite2 Data created by MaxMind, available from https://www.maxmind.com. The wording is MaxMind's own, which is why it stays in English.

5. How long things are kept

Measurement data is deleted automatically on a schedule set by your plan:

Plan Analytics Session replays Feedback
Hobby 90 days 30 days 90 days
Beginner 1 year 90 days 1 year
Advanced 2 years 180 days 2 years
Business 5 years 1 year 5 years

Nothing is kept beyond five years in any case. That is the ceiling on the storage itself, not only a policy.

Account and billing records are kept while your account is open, and afterwards for as long as accounting law requires. Server logs are kept for a short operational window. Deleting a site deletes its measurement data across every store, and that is permanent.

6. Your rights

If you are in the EU or UK you have the right to see the personal data we hold about you, to correct it, to have it deleted, to restrict or object to how we use it, and to receive a copy in a portable form. Ask through the contact page and we will answer within one month.

If you are a visitor to a site that uses Skomi, ask that site's owner, not us. We hold their data on their instructions and they are the controller; we will help them answer you. Given section 3, we usually cannot identify which records are yours without their help.

You can also complain to your national data protection authority.

7. Security

Traffic is encrypted in transit. Passwords are hashed and two-factor authentication is available on every account. Access to production systems is limited to the people who need it. Session recordings are stored in object storage that is not publicly addressable, and a replay is only served against a short-lived grant.

No system is perfect. If we discover a breach affecting your data, we will tell you and the relevant authority as the law requires.

8. Children

Skomi is a business tool and is not directed at children. Do not use it to collect data about children where your law does not allow it.

9. Changes

We will update this page when what we do changes, and the date at the top says when. For a change that materially affects you, we will email the account address.