Privacy Policy
Last updated: May 2025
1. Who we are
2. Data Protection Officer (DPO)
3. Data collected and purposes
3.1 Account holders
When you create an account, we collect:
- Email address — identification and account communications.
- Username and display name — for the public profile page.
- Bio, avatar, and social links — public profile content, voluntarily provided.
- Payment data — processed directly by Stripe; SKEEM does not store card data.
Legal basis: performance of a contract (LGPD Art. 7(V)) and data subject consent (Art. 7(I)).
3.2 Visitors to public profiles
When someone accesses a profile page (skeem.lol/username), SKEEM automatically collects, in an anonymised manner on the server:
- Country/region — derived from IP address, without storing the IP itself.
- Visit duration — approximate time spent viewing the profile.
- Link clicks — which links on the profile were clicked.
These data are used solely to provide performance metrics to the profile owner. They are not shared with third parties for advertising. Legal basis: legitimate interest (LGPD Art. 7(IX)).
4. Cookies
SKEEM uses only strictly necessary cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| sb-* (Supabase) | Authentication session | Session / 7 days |
We do not use tracking cookies, advertising, Google Analytics, social media pixels, or any other third-party tracking technologies. Legal basis for necessary cookies: legitimate interest (LGPD Art. 7(IX)).
5. Sub-processors and data sharing
SKEEM uses trusted vendors to operate the service. Personal data may be transferred to the following sub-processors, located in the United States:
| Vendor | Purpose | Safeguards |
|---|---|---|
| Supabase | Database and authentication | Standard Contractual Clauses (SCCs) |
| Stripe | Payment processing | PCI DSS certification / SCCs |
| Vercel | Hosting and CDN | Standard Contractual Clauses (SCCs) |
| Discord | Optional OAuth login | Discord Terms of Service |
We do not sell personal data to third parties.
6. International data transfers
7. Data retention
- Account data: retained while the account is active. Deleted after account deletion.
- Analytics data (visits, clicks, duration): retained for up to 12 months.
- Payment records: retained for the period required by law (5 years for tax purposes).
8. Your rights (LGPD Art. 18)
You have the following rights regarding your personal data:
- Confirmation of data processing
- Access to collected data
- Correction of incomplete or inaccurate data
- Anonymisation, blocking, or deletion of unnecessary data
- Data portability to another service provider
- Deletion of data processed on the basis of consent
- Information about sharing with third parties
- Withdrawal of consent at any time
- Opposition to processing in case of non-compliance with LGPD
To exercise any of these rights, contact our DPO at skeemlolhq@gmail.com. We respond within 15 business days.
You can also delete your account directly from account settings, which will immediately remove all your personal data from our systems.
9. Security
10. Changes to this policy
11. Contact
You can also reach us via our Discord server.