Legal
Privacy Policy
Last updated: 19 July 2026
Skoft is an independent software studio based in the Netherlands. This policy explains what personal data we collect through this website (skoft.app), through the tools we operate, and through the Skoft Files desktop app, why we collect it, and the rights you have over it. If anything here is unclear, contact us at privacy@skoft.app.
Who is responsible
The controller for the personal data described here is:
- Skoft Software (eenmanszaak, Netherlands)
- Loosduinseweg 297a, 2571 AD Den Haag, Netherlands
- KvK 42097143
- privacy@skoft.app
Data we collect
- Waitlist email address. If you join a product waitlist, we store the email address you submit so we can notify you when that product ships. You may also tick an optional box to hear about other Skoft products now and then. Whether you ticked it is the only other thing we store, and it stays off unless you tick it.
- Social publishing credentials. Skoft operates first-party tools that publish posts to social accounts we own (including Instagram, Facebook, X and Bluesky). When such an account is connected, the platform issues us an access token, which we store only to publish the content we author. We do not collect, store, or process the personal data of other users of those platforms.
- Technical logs. Cloudflare, which hosts this site, records standard request metadata (such as IP address, timestamp, and user agent) to serve and secure it. Our own waitlist service additionally keeps a per-IP submission counter for 60 seconds to slow down abuse; it deletes itself after that minute. We do not use any of this for advertising or profiling.
The Skoft Files app
Skoft Files is built to keep your files and activity on your machine. The only data that leaves it:
- License checks. When you activate the app, and roughly once a week afterwards, it contacts our license service and sends your license key, an install id, your machine's hostname and its operating system. The service stores the buyer's email address and, per machine, the hostname, operating system and a last-seen date. This is what enforces the machine limit and keeps a refunded license from staying active.
- Feedback you send. If you use the in-app feedback form, the report contains your message, the app version and your operating system, plus, only if you choose to attach it, a log file that may contain file names. Reports go to a private issue tracker that only Skoft can read.
- Update checks. The app checks our servers for signed updates.
No other data leaves your machine: no usage analytics, no tracking, no file contents. The retention and rights sections below apply to this data like everything else.
How we use it
We use the waitlist email to tell you when the product you signed up for launches. If you ticked the optional box, we may also email you now and then about other Skoft products. You can ask us to stop at any time, and we never run a recurring newsletter. We use social access tokens solely to publish posts to our own accounts. We use technical logs solely to operate and secure the service. We use license data solely to deliver and enforce the license you bought. We do not sell your data, and we do not share it except with the processors listed below.
Legal basis
- Consent for the waitlist and the optional cross-product emails. You can withdraw it at any time, with effect for the future, by using the unsubscribe link in any email or by emailing us.
- Performance of a contract for license activation, license checks and delivering your purchase.
- Legitimate interest for security logs and the brief per-IP rate-limit counter described above: keeping the service up and abuse out, with minimal data held for the shortest workable time.
Meta Platform data
Where our tools connect to Instagram or Facebook through the Meta Platform, any data obtained via Meta is used only to publish and manage content on the Skoft-owned accounts we have connected. This data is never sold, shared, or used for any other purpose. Access can be revoked at any time from your Meta account settings, or by contacting us. On revocation or on request, the associated token and any cached account metadata are deleted.
Processors we rely on
- Cloudflare (US) hosts this site and our services, and stores waitlist entries and license records. See Cloudflare's privacy notice for how they handle infrastructure data.
- Resend (US) delivers our emails, such as the waitlist confirmation and license keys.
- Stripe (US) processes payments once Skoft Files is on sale. Card details go to Stripe, never to Skoft.
- GitHub (US) stores feedback reports sent from the app, in a private repository.
- Meta Platforms and other social networks, only where we have connected an account we own, for the sole purpose of publishing our own content.
International transfers
The processors above are US companies, so some data is transferred to the United States. Those transfers rely on the EU-US Data Privacy Framework where the provider is certified, with EU Standard Contractual Clauses as fallback. For UK visitors, the UK Extension to the Data Privacy Framework and the UK Addendum to the Standard Contractual Clauses apply.
Retention
We keep waitlist emails until the product launches and you have been notified, or until you ask us to remove you, whichever comes first. We keep social access tokens only while the connection is active. Technical logs and the rate-limit counter are retained for a short operational window and then discarded. License records are kept while the license exists; purchase records are kept for the seven years Dutch tax law requires. Feedback reports are kept while we work on the issue.
Your rights
Under the GDPR you have the right to access, correct, or delete the personal data we hold about you, to object to or restrict its processing, and to data portability. Where processing rests on consent, you can withdraw that consent at any time without affecting what happened before. To exercise any of these, email privacy@skoft.app and we will respond within the statutory time limits. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Data deletion
To have your data deleted, email privacy@skoft.app with the request. We remove waitlist entries and any connected-account tokens on request and confirm once done.
Changes
If this policy changes we update the date at the top of this page. Continued use of the site after a change means you accept the revised policy.
Contact
Questions about privacy or this policy: privacy@skoft.app.