Privacy Policy
Last updated: August 27, 2026
How Snowly handles your data: what we collect, why, on what legal basis, for how long — and what you can do about it.
Data controller and contact
Snowly Technologies AB (Sweden) is the data controller. For questions, or to exercise your rights, write to [email protected] — we reply within one month at the latest.
- We have no data protection officer; all contact goes through the same address.
- If we change something material we update the date at the top, and for larger changes we notify you in the app.
Data, purpose, legal basis and retention
- Account data — email, name and a profile picture where the provider supplies one
- Creates your account and keeps you signed in. Basis: contract. If you use Apple’s "Hide My Email", we only ever see the relay address. Kept until you delete your account.
- Saved routes, history and travel preferences
- Lets you find your way back to your usual routes and sync them across devices. Basis: contract. Kept until you remove them or delete your account.
- Your location
- Used in the moment when you search from your position, appear on the map, or look up nearby departures. Basis: consent, given via the location permission and withdrawable in your phone settings. Never stored with us.
- Your search phrase
- Sent to Google Gemini to be interpreted into an origin, destination and time. Basis: contract. Also used for caching and analytics, see below.
- Get-off alerts — a random device id, push token, platform, language and the trip’s stops and times
- Lets the server watch the vehicle and notify you when it is time to get off. The device id cannot be traced back to you; if you are signed in, your account id is stored as well. Basis: contract and your consent to notifications. The row is deleted when the trip ends, and otherwise automatically shortly after its scheduled end time.
- Usage analytics and session replay
- Page views, clicks, errors, response times and device model, plus recordings of how the interface was used. The recordings show your search phrase — we need to see which searches fail. Password fields are masked. Basis: legitimate interest in finding and fixing faults. If you are signed in, the analytics can be linked to your account. Pruned on a rolling basis by PostHog.
- Anonymous search analytics
- Origin, destination, search phrase and whether the search succeeded. The table has no column for user or device, so the rows cannot be tied to you. Basis: legitimate interest in better search quality. Kept without a fixed end date.
- IP address
- Held briefly in memory to rate-limit requests, and used by Cloudflare to deliver and protect the service. Basis: legitimate interest in operational security. Not stored in our database.
- A debug recording you choose to share
- Only created when you actively tap to do so, and contains the trip’s stops, times and the app’s log lines. Basis: consent. Deleted once the fault is resolved.
Location data
The app cannot see where you are when you are not using it.
- We only request "while using the app" permission — the app has no background location.
- The get-off alert is based on timetable and real-time data on the server, not on your position. As a fallback an alarm time is booked locally on the phone so the alert works underground; it reads no location either.
- Coordinates we use in the moment are passed on to SL, Trafiklab/ResRobot, Google Places and OpenRouteService — only to those that need them. They are not stored with us and are not linked to your account.
Caching: why your search phrase can be reused
We store the interpretation of a search phrase so the next person who types the same thing does not cost another AI or maps call. None of these tables has a column for user, device or location.
- Interpreted phrases — which origin, destination and time a phrase meant — are stored with no fixed end date and reused for as long as the row exists, including when someone else types the same thing. Old rows are pruned by hand.
- Coordinates for named places ("Ikea Barkarby") are stored as well, but only reused for 30 days — after that we look the place up again, since a business may have moved.
- If you have given a place your own name in the app ("home"), your word is replaced by the stop or address it points at BEFORE anything is stored. So your word for the place never enters a cache — but the search is cached, with the real place instead.
What we do not do
- Sell, rent or trade personal data.
- Show advertising, or carry advertising and social media trackers.
- Profile you, or make automated decisions with legal effect for you.
- Collect sensitive data — please do not type health, religion or political opinions into the search field. The app is not directed at children.
Providers that process data for us
All are processors and may only do what we instruct them to do. Google and Apple process data in the USA under the Data Privacy Framework and the EU Standard Contractual Clauses, and Cloudflare may serve from a server outside the EU on the same basis. Account and route data at Supabase stays in the EU.
- Supabase (EU)
- Database and authentication: accounts, saved routes, history, preferences, cache tables, search analytics and alert rows.
- Cloudflare
- Delivers the app and runs the server functions, including the once-a-minute watch over trips in progress.
- Google Gemini (USA)
- Interprets your search phrase and translates disruption notices. Never receives your account id, name or email address.
- Google Places (USA)
- Resolves named places ("Ikea Barkarby") to coordinates.
- Google FCM and Apple APNs (USA)
- Deliver the notifications. Receive the push token and the notification text.
- PostHog (EU region)
- Usage analytics, error reports and session replay.
- Trafiklab/Samtrafiken, SL and ResRobot (Sweden)
- Timetables, real-time data, disruptions and stop lookups.
- OpenRouteService/HeiGIT (Germany)
- Computes the walking route for short legs.
Your rights
Exercising them is free and you do not have to give a reason.
- Access, correct or delete your data, and receive it in a machine-readable format. You can delete your account yourself in the app, under Account and the Danger zone section.
- Restrict processing while something is being looked into, or object to what we base on legitimate interest — the usage analytics, for instance.
- Withdraw consent: turn off location or notifications in your phone settings. This does not affect processing already carried out.
- Complain to the Swedish Authority for Privacy Protection (IMY). We would appreciate the chance to put it right first.
Swedish Authority for Privacy Protection (imy.se)Email [email protected]
Security and storage on your device
- All traffic runs over HTTPS, your database rows are protected by row-level security, and push tokens live in a table no client can read.
- We store no passwords — sign-in is handled by Google or Apple.
- Your device stores your sign-in session, language, theme, the device id for get-off alerts, a trip in progress and a short debug log. PostHog sets an identifier of its own. Clearing the app’s data removes all of it.
- No technical measure is perfect. If you find a vulnerability, please email [email protected] before telling anyone else.