Legal
Privacy
The short version: we collect what the app needs to work, we never sell it, there is no advertising or analytics SDK in the app, and when you delete your account the data goes rather than resting somewhere for a month.
Last updated 31 August 2026. Skein is operated by Altros Studios.
What we collect
Things you give us
- Your email address, and a password we never see in plain text (authentication is handled by Amazon Cognito).
- Your date of birth, used to confirm you are 18 or over and to show your age.
- Your display name, pronouns, what you are looking for, your interests and your answers to prompts.
- Optionally, your gender identity, sexual orientation and relationship structure. These are sensitive and have their own section below.
- Photos you upload.
- Messages you send inside a Thread.
- The city you choose, and the coarse location cell described above.
- If you use a date check-in: the phone number of the trusted contact you nominate, and the plan text you want sent to them. See below — this is someone else's number, which is why it gets its own section.
Things the app produces
- A verification result: a boolean, a timestamp and a confidence score.
- Moderation results for photos you upload.
- Which people appeared in your daily set, and what you did about them.
- Tickets and RSVPs for Gatherings you attend.
- A record of what you have bought — Skein+, Spools packs and Gathering tickets — so we know what you are owed. Not a card number: see Who else touches your data.
Things we do not collect
- No advertising identifiers, and no third-party analytics or attribution SDK inside the app. Nothing measures what you tap.
- No contact list, no calendar, no browsing history.
- No raw GPS coordinates, no bearing, and no map position of any person. The API has no coordinate type on any readable field.
- No face template or biometric scan is kept. See below.
- Not your own phone number. You sign in with an email address. The only phone number Skein ever holds is one you type in for a date check-in, and it belongs to someone else.
Identifiers
Your account has an identifier — a random id issued by Amazon Cognito when you sign up. Everything of yours is stored against it, and it is what a moderator sees in a report. It is an account identifier, not a device or advertising one: it does not follow you to other apps, it is not derived from your hardware, and it is destroyed when you delete your account.
There are two device identifiers, and both exist to make a specific feature work rather than to recognise you:
- A push token, if you turn notifications on. It is issued by Apple or Google, it addresses one installation of the app on one device, and without it a notification has nowhere to go. Turning notifications off, signing out or deleting the app ends it.
- An identifier the RevenueCat SDK sends when it talks to the store on your behalf, so a purchase can be matched to the device that made it.
Neither is an advertising identifier, neither follows you into another company's app, and neither is used to build a profile of you. Apple's privacy label calls all of this “Identifiers”, and we declare both the account id and the device ids there. Earlier versions of this page said we held no device identifier at all; that was written before push notifications and purchases shipped, and this is the correction.
Sensitive information
Gender identity, sexual orientation and relationship structure are optional. You can use Skein without answering any of them, and you can remove an answer later from your profile.
If you do answer, those answers appear on your profile — that is what they are for, and it is the reason the fields exist rather than being inferred from anything. They are shown to the people your profile is shown to, and to a moderator reviewing a report about you.
On our side each of these is encrypted with its own key before it is stored, excluded from every log line, and excluded from every index key, by the same allowlist the logging and encryption code share. They are never used to target advertising, never sold, never shared with a data broker, and never used to build a profile of you anywhere outside Skein.
Your date of birth, your location cell, your verification record and the contents of your messages are held to the same standard, and by the same mechanism.
We are aware of what this data is. Skein is queer-built, and in much of the world an app knowing these three things about someone is a risk to them rather than a feature. Discreet mode exists for that reason, and so does deleting your account being immediate rather than a 30-day wait.
Phone numbers, and the date check-in
A date check-in works like this: you tell Skein where you are going, when to worry, and the phone number of someone you trust. If you do not check in by the time you set, we send that person a single SMS with your plan.
That number belongs to a third party who is not a Skein user and has not agreed to anything with us — so we hold it as narrowly as we can. It is encrypted with its own key, kept out of every log, used for nothing but that one message, and deleted with the check-in. So is the plan text, which is also sent in that SMS.
Only give us a number for someone who would expect to hear from you about this. We do not message them for any other reason, we do not keep them on a list, and we never contact them again.
Verification
Signing up includes a short liveness capture, which confirms a real person is holding the phone and compares against the photos on your profile. The capture and anything derived from it are deleted as soon as that comparison finishes. What remains is a boolean, a timestamp and a confidence score. The capture is never shown to another user, never used for advertising, and never used to identify you anywhere else.
Being plain about what that comparison is: it measures facial features in the capture against facial features in your photos, which makes it biometric processing, and we declare it as sensitive information on the app stores rather than leaving it implied. What we do not do is keep the result of that measurement. No face template, faceprint or embedding is stored, there is no gallery of faces to search, and your capture is deleted even when the comparison fails partway through. It is used once, to answer one question, and then it is gone.
The comparison runs on Amazon Rekognition inside our own AWS account.
Location, in detail
Your device applies a fixed offset of roughly 800–1200 m, derived from a per-account secret, then snaps the offset point to an H3 resolution-8 cell. Only the cell id and a coarse city label leave the device. Because the offset is fixed rather than random, taking many samples over time cannot average it away.
On our side the cell id is encrypted with a per-field key. A background job turns it into the cell's centroid so the app can work out who is nearby. Other people never see a distance in miles — they see a bucket (“under 2 mi”, “about 5 mi”, and so on), or nothing at all if you have discreet mode on.
Encryption and access
Messages, location cells, verification results and other sensitive fields are encrypted with AWS KMS at the field level, on top of the encryption the storage layer already applies. Those fields are excluded from every log line and from every index key by an allowlist the logging and encryption code share, so a stray log statement cannot leak one.
A moderator reviewing a report you or someone else filed can read the evidence attached to that report — up to the last 50 messages in the Thread and the reported profile. That is the only routine path by which a person at Skein reads a message, and it exists so reports can actually be acted on.
Who else touches your data
- Amazon Web Services — hosting, storage, authentication, and the image moderation and liveness services described above. Data stays in the US East region.
- Apple and Google — app distribution, push notification delivery if you turn notifications on, and payment. Everything you buy is bought from them, not from us, which is why we never see a card number: your card details go to Apple or Google and never reach Skein.
- RevenueCat — tells us what you have bought, so we can give it to you. They receive an account identifier and a device identifier, not your profile, your photos or your messages.
We do not sell your data, and we do not share it for advertising. There is no data broker in this list and there will not be one.
Deletion
Deleting your account starts the purge immediately. It removes your profile and settings, your photos, your messages, your location row, your sign-in account and your subscription alias. It is a real cascade across every store rather than a flag that hides you, and it is not held for a 30-day cooling-off period.
One exception, and it is deliberate: if you have been reported, the report and its evidence survive your deletion. Otherwise deleting an account would be a way to erase what you did to someone else.
Your rights
You can see and correct everything on your profile from inside the app, and you can delete your account from Settings without asking us. For a copy of your data, or anything else, write to support@skein.me and a person will answer.
Children
Skein is for adults. You must be 18 or over. If we find an account belongs to someone younger, we remove it.
Changes
If this policy changes in a way that affects what we collect or who sees it, we will say so in the app before the change takes effect, rather than silently updating the date at the top.