Legal

Privacy Policy

Last updated: September 30, 2026

This policy explains what information Skanza ("we," "us," "our") collects through the Skanza iOS app and the skanza.app website, why we collect it, who handles it for us, and what you can ask us to do about it. We have written it the way we would explain it to you in person, because a policy you cannot follow protects nobody. A scan of your home is sensitive, and we would rather tell you exactly what happens to it than leave you to guess.

The short version: scanning happens on your iPhone, but Skanza is an account-based app. You need to sign in with Apple to save a scan, to open its floor plan, to build a virtual view, or to export or share it, and a saved scan is backed up to our servers. The app asks you to sign in at the moment a scan finishes. If you decline, that scan is discarded and nothing about it is uploaded or kept. If you delete your account, we delete your data, from inside the app.

What Skanza uses on your iPhone

Skanza needs your camera and your iPhone's LiDAR sensor to scan a room. The camera lets the app see the room and track how your phone moves through it. The LiDAR sensor measures real distances to the walls, which is what makes a Skanza floor plan true to scale: the dimensions are measurements, not estimates from a photo. A device without LiDAR cannot scan.

Skanza does not use your microphone and records no audio. It never asks for access to your photo library, and it does not read, add to, or scan your photos. It collects no device identifier, advertising identifier, or fingerprint of your phone.

Why an account is required

You can start and carry out a scan while signed out, and the live preview you see while walking the room is produced entirely on your device. What needs an account is the result. When a scan finishes, the app asks you to sign in with Apple before it turns that scan into a saved floor plan, because a saved scan has to belong to someone: it is stored against your account so it survives a reinstall or a new phone, and so your scan allowance can be counted fairly.

That prompt is a real choice. If you decline it, the scan is discarded on the spot: no floor plan is created, nothing is written to our servers, and there is nothing left for us to hold. The practical consequence is worth stating plainly, since it is easy to misread: without signing in, you cannot view, keep, export, or share a scan at all.

Sign in with Apple is handled for us by Supabase, our backend provider. From it we store the account identifier Apple issues for Skanza and basic account timestamps (when the account was created and when it was last seen). We do not separately collect your name or email address, and if you used Apple's private email relay, we never see your real address.

Location and true north

Skanza asks for location access ("while using the app") for two purposes, both tied to the scan you have just finished. It labels the scan with an approximate street address, so a list of floor plans is something you can actually recognise months later, and it works out which way is north so the floor plan can be oriented correctly.

To do that, the app takes a single location fix when a fresh scan completes. It does not track you, does not follow you between scans, and does not ask for location in the background. The coordinates of that fix and the address derived from them are saved with the floor plan, and because they are part of the floor plan record, they are included in the backup that goes to our servers. Turning the address into readable text is done by Apple's geocoding service, which receives the coordinates for that lookup.

This is optional. If you deny location access, or turn it off later in iOS Settings, scanning and floor plans work exactly as before; the scan simply carries no address, and north is estimated from the sensor data alone. If a scan already carries an address you would rather not keep, delete that scan.

What we store when you save a scan

Each scan you save is uploaded in the background to our cloud storage (Cloudflare R2), and a record of it is written to our database (Supabase). The uploaded data is the raw material of the scan: the camera images captured while you walked the room, LiDAR depth and confidence data, the camera position for each frame, the resulting 3D point cloud and mesh, and the floor plan derived from them, including any room names you typed and walls you chose to hide.

This backup is how the app works rather than an extra we bolted on: it is what lets a scan come back after a reinstall, and what the virtual view is built from. There is no setting to save a scan without it. Your control over it sits one step earlier, at the sign-in prompt when the scan finishes, and afterwards in deleting the scan.

Once a scan's backup has actually reached our storage, the bulky raw dataset (the camera images, depth data, and mesh) is deleted from your phone; the floor plan itself stays available locally. If the upload cannot finish, because you are offline for instance, the raw data stays on your phone and the upload is retried the next time you open the app.

Deleting a scan in the app deletes its floor plan on your phone, its raw data in our cloud storage, its virtual view panoramas, and its database record. We have no tool for browsing or exporting your scans outside the app, and we do not look at your scan content except where you have asked us to help with a specific problem and it is necessary to answer you.

Virtual view scans

A virtual view is a walkthrough built from panoramas captured during your scan. Stitching them takes more computing power than a phone can reasonably provide, so it runs on our servers. When you ask for a virtual view, the data already backed up for that scan is processed in the cloud and the finished panoramas are stored alongside it under your account. The app downloads them for viewing and keeps a cached copy on your phone so it can show them again without re-downloading.

Panoramas are treated exactly like the rest of a scan's backup. Deleting the scan, or a single viewpoint inside it, deletes them from our storage too. A virtual view is private to your account; the app has no feature that publishes one to the web or hands anyone else a link.

Notifications

Processing a virtual view can take a while, so the app offers to tell you when it is ready. If you allow notifications, Apple issues a device token that we store with your account and use for that one purpose. We do not use notifications for marketing. Turning notifications off in iOS Settings stops them, and deleting your account deletes the stored token.

Exporting and sharing

Once a scan is saved, you can export its floor plan as CAD (DXF), PDF, PNG, or SVG. The file is produced on your phone and handed to the standard iOS share sheet, so where it goes next is your decision: AirDrop, email, Messages, a cloud storage app, or anywhere else you pick. That transfer is between you and the destination you chose. We are not a party to it and receive no copy of what you shared or of where you sent it.

Please keep in mind that an exported floor plan can carry the address label and the room names you gave it. Once you have sent a file to someone, what they do with it is outside our reach and outside this policy.

Purchases and subscriptions

Skanza Pro is sold by Apple through the App Store using StoreKit. Your payment details go to Apple and never to us; Apple's own privacy policy governs them. So that your subscription works across your devices and after a reinstall, the app sends us the signed transaction record Apple produces, which contains the product identifier, Apple's transaction identifier, the start and end of the current billing period, and whether the purchase was made in Apple's sandbox. We store that against your account and use it for one purpose: deciding whether your Pro access is currently valid and how many of the period's scans remain.

Counting scans

Both plans include a limited number of scans, a small allowance on the free plan and a larger one per billing period with Skanza Pro. We count your completed scans against your account so the allowance survives a reinstall or a new phone. What we keep is a count and a timestamp. Never scan content.

One detail deserves stating plainly, because it is the only thing that outlives your account: when you delete your account, we keep a record of how many scans it had used, stored under a one-way hash of your Apple account identifier rather than the identifier itself. It exists so that deleting and re-creating an account does not hand out a fresh free allowance. The record contains nothing but that hash, the number, and the date of deletion. It cannot be used to identify you, to contact you, or to recover anything you scanned.

What the app does not do

  • No third-party analytics, crash-reporting, or advertising SDKs in the app
  • No background location, and no continuous location tracking of any kind. One fix, at the end of a scan, only if you allow it
  • No microphone access and no audio recorded, at any point during a scan
  • No access to your photo library, which the app never asks for
  • No device, advertising, or tracking identifiers, and no fingerprinting of your phone
  • No selling of personal data, and no sharing of it for anyone else's advertising
  • No training of models on your scans
  • No payment or billing details reaching us at any point

The skanza.app website

If you email us for support, we receive what you send: your email address and your message. We use it to answer you.

The website uses cookie-less, privacy-focused analytics (Vercel Web Analytics) to see aggregate traffic, such as which pages people visit. It is not tied to your identity and does not follow you elsewhere. The website sets no advertising cookies.

Who handles data for us

We use a small number of service providers, each for a narrow purpose, and each permitted to handle your data only on our instructions:

  • Supabase: authenticates Sign in with Apple and stores your account, scan records, usage count, subscription status, and notification token.
  • Cloudflare R2: stores the raw data backup of your scans and the panoramas produced for a virtual view.
  • Google Cloud: runs the server-side processing that turns a scan into a virtual view walkthrough.
  • Apple: provides Sign in with Apple, turns coordinates into a readable address, delivers notifications, and processes Skanza Pro purchases.
  • Vercel: hosts skanza.app and provides the anonymized, cookie-less traffic analytics described above.

None of them may use your data for their own purposes, track you across other apps or websites, or use it for advertising. They operate data centers in several countries, so your data may be stored or processed outside the country you live in, under contractual protections requiring it to be handled to the standard described here.

How long we keep things

A scan you declined to save leaves nothing behind, on your phone or with us.

For a scan you did save, your account record, the scan's raw backup and floor plan, its virtual view panoramas, your usage count, your subscription status, and your notification token are kept for as long as your account exists. Deleting a scan removes that scan's data promptly. Deleting your account removes all of it, apart from the hashed scan-count record described above.

Support emails are kept only as long as we need them to answer you, and you can ask us to delete the correspondence sooner.

Signing out, and deleting your account

These two are different, and the difference matters:

  • Signing out clears this phone. Every scan, floor plan, and download on the device is erased, so a signed-out phone is not left showing an account's private data. Anything already backed up returns automatically when you sign in again. Anything that had not finished uploading is gone for good. Signing out does not delete what is on our servers.
  • Deleting one scan, from the app, removes it both locally and from our servers, including its virtual view.
  • Deleting your account, from the account screen in the app, removes everything: your account record, every scan backup and virtual view, your usage history, your subscription records, and your notification token. It also revokes Skanza's Sign in with Apple token, so the app retains no connection to your Apple ID.

Account deletion is immediate and cannot be undone. It does not cancel an active App Store subscription, which only Apple can do, from your Apple ID subscription settings, so cancel there first if you intend to stop paying. If deletion fails for any reason, or you would rather we did it for you, write to info@skanza.app and we will take care of it.

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to receive a copy of it, and to object to how we use it. You are welcome to exercise those rights whether or not the law where you live grants them. Email info@skanza.app and we will respond within 30 days. We will not treat you differently, or degrade the app, because you asked.

We rely on your data for one reason only: to provide the app you asked for, including keeping your scans safe across devices, enforcing the scan allowance evenly, and keeping your subscription working. We do not use it for advertising or profiling, so there is nothing of that kind for you to opt out of.

Children's privacy

Skanza is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal data, email us and we will delete it.

Security

Your scan backups sit in access-controlled cloud storage, reachable only through short-lived links issued to your own signed-in session for one scan at a time, and our database restricts every row to the account it belongs to. Traffic between the app and our servers is encrypted in transit, and your sign-in session is held in the iOS Keychain on your phone. No system is perfect, and we will not pretend otherwise, but if a breach ever affects your data we will tell you and the relevant authorities as promptly as the law requires.

Changes to this policy

If this policy changes, we will update the "Last updated" date above, and where a change materially affects what we collect or how we use it, we will say so in the app before it takes effect. Continuing to use the app or the website after a change means you accept the updated policy.

Contact us

Questions, requests, or corrections to this policy are all welcome at info@skanza.app. A person reads that inbox.