Last updated: 13 June 2026
Privacy Policy for Smula
Last updated: 2026-06-13
Your privacy matters to us. This policy describes the personal data we collect when you use Smula (app and website, including the forum, tips, newsletter and beta programme), why we collect it, and the rights you have under the General Data Protection Regulation (GDPR). We only collect what we need and aim for data minimisation.
1. Data controller
Smula is the controller for this processing. Contact: rickard.jutegrim@dromverket.com.
2. What data we collect
- Email address — when you sign up for the newsletter, join the beta, contact us or create a forum account (sign-in uses a one-time code). Email addresses are stored encrypted (see section 6).
- Contact details — your name, an optional phone number, the type of help your enquiry concerns and your message when you fill in a contact form. Phone numbers are stored encrypted.
- Beta profile — if you join the beta you can share details such as your parenting role, whether you are expecting or have children, number of children, children's age groups, where you live and what matters most to you.
- App account — a device-based account with a device identifier and the choices you make during onboarding (e.g. profile preferences, saved places, accepted terms). You can connect an email to sync and use the forum.
- Location data — with your permission, the app may use your device's approximate or precise location locally on your device to show nearby places, calculate distances and provide directions. We do not store your ongoing location on our servers. If you submit a place yourself, the coordinates and details you provide are saved.
- User content — places you suggest, edit or report, tips, uploaded images, and forum threads, replies and likes. Images may contain metadata; only upload images you have the right to share.
- Push token — if you allow notifications, we store a push token (via Expo) and platform so we can send notifications.
- Usage and analytics data — pseudonymous data about how the service is used: an install/client identifier and session identifier, platform, app version, which screens and events occur, plus timestamps and session length. On the web we may log technical information such as browser type (user agent), e.g. to measure campaign links.
- App feedback and bug reports — if you rate the app or send a bug report, we store the rating, any comment, platform, app version and an install identifier, along with any technical diagnostics you provide.
3. Why we process the data and legal basis
| Purpose | Legal basis |
|---|---|
| Providing and operating the service (account, saved places, forum, push) | Performance of a contract |
| Sending newsletters and beta information | Consent |
| Handling contact requests and support | Legitimate interest / consent |
| Showing nearby places and directions (location data) | Consent (device location permission) |
| Improving, measuring and debugging the service (analytics, feedback, bug reports, campaign measurement) | Legitimate interest |
| Moderating content and preventing abuse | Legitimate interest / legal obligation |
You can withdraw consent at any time, for example by unsubscribing from the newsletter or turning off the location permission in your device settings. Withdrawal does not affect processing that has already taken place.
4. Notifications
If you allow push notifications, we may send notifications, e.g. about replies and activity in the forum. You can turn notifications off in the app or device settings. Forum users without the app may receive at most one summary email per day about unread activity.
5. How long we keep the data
We keep data for as long as it is needed for the purpose: account data while you have an account, newsletter data until you unsubscribe (unsubscribe is handled via a signed link), and analytics, feedback and campaign data for a limited period. After that it is deleted or anonymised. Backups may persist for a short time.
6. Security and encryption
We protect your data with technical and organisational measures. Sensitive data such as email addresses and phone numbers is stored encrypted at rest using AES-256-GCM. To enable lookups and avoid duplicates we also store a one-way hash (HMAC-SHA-256). Authentication uses encrypted tokens in secure httpOnly cookies, with protection against forged requests (CSRF) and rate limiting. However, no transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Sharing of data
We never sell your personal data. We may share data with trusted providers (data processors) who help us operate the service and only on our instructions, for example for hosting, maps and directions (Google), push notifications (Expo) and email delivery (SendGrid). We may disclose data where required by law or to protect our or others' rights.
8. Transfers outside the EU/EEA
If any provider processes data outside the EU/EEA, we ensure appropriate safeguards are in place, such as the European Commission's standard contractual clauses.
9. Your rights
Under the GDPR you have the right to request a copy of your data, have inaccurate data corrected, have data erased ("the right to be forgotten"), restrict or object to processing, receive your data in a portable format, and withdraw consent. Contact us at rickard.jutegrim@dromverket.com to exercise your rights. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
10. Children
Smula is intended for parents and carers, i.e. adults. The service is not intended for use by children, and we do not knowingly collect data about children beyond what a parent chooses to provide.
11. Cookies
Information about cookies and similar technologies is available in our cookie policy.
12. Changes
We may update this policy. The latest version is always available here, and we will notify you of material changes.
13. Contact
Questions about your personal data? Contact us at rickard.jutegrim@dromverket.com, via https://smula.app/sv/kontakt or through our social channels (Instagram, Facebook and TikTok).