Privacy Policy for Stoke

Last updated: September 29, 2026

This privacy policy describes how the app Stoke (the "app"), published by Snow Agency ApS, Denmark ("we", "us"), collects, uses and protects your information when you use it for wind and wave forecasts, spot alerts, community reports and session tracking on iPhone, Apple Watch, Android and Wear OS.

Stoke is free, has no advertising, no in-app purchases and no third-party tracking. We do not sell personal data.

1. Information we collect

Account

You can sign in with Apple, with Google or with an e-mail address and password. Authentication is handled by Firebase Authentication (Google). We store your user ID, e-mail address and display name so your spots, alerts and sessions follow you across devices. With Sign in with Apple you may hide your e-mail address; Apple then gives us a relay address instead.

We send a password-reset e-mail only when you ask for one. It is delivered through the e-mail service Resend from the address noreply@stoke.snowagency.com; Resend receives your e-mail address for that delivery only.

Location

With your permission, Stoke uses your device's location to:

Your current location is used on the device and is not stored on our servers. GPS tracks are stored only as part of sessions you save (see "Sessions").

Spots and alerts

Spots you create and the alert limits you set (wind range, directions, waves, temperature) are stored on our servers so the forecast can be checked for you and pushes sent. A spot you share appears on the community map with its name, position and photos, without your name. Spots that nobody follows are removed after 30 days.

Forecast data

Forecasts come from the Open-Meteo weather API. Only the coordinates of a spot are sent to Open-Meteo, never your identity or your own location. Forecast accuracy is checked daily against public weather stations (DMI, KNMI, Meteotrentino, NOAA); this involves spot coordinates only.

Push notifications

If you allow notifications, we store a push token for your device (Firebase Cloud Messaging) to send spot alerts, the daily briefing and community updates. You can turn notifications off at any time in the system settings.

Camera, photos and spot reports

With your permission, Stoke uses your camera or photo library so you can add a photo to a spot report or a spot. Reports and photos are shown to other users at that spot. Uploaded photos are automatically screened by Google Cloud Vision (safe-search) and removed if they are flagged. Spot reports are deleted automatically after 24 hours.

Sessions

When you log a session, we store its date, spot, gear, notes, rating, duration, distance, GPS track, top and average speed, run/gybe counts and, if you tracked it from a watch, average and maximum heart rate and calories. Sessions are private by default. If you mark a session as public, it is visible to other users; you can change this at any time.

Health data (Apple Watch and Wear OS)

On Apple Watch, and only with your explicit HealthKit permission, Stoke reads heart rate and active energy during a session you start on the watch, and writes the session as a workout to Apple Health. On Wear OS, with your permission, the watch app reads heart rate through Health Services while a session is running. Health data is used solely to show your own session in your surf log. We do not use it for advertising or marketing and we do not share it with third parties. The phone apps do not read Android Health Connect. You can revoke this access at any time in the Health or system settings; the rest of the app keeps working.

Strava (optional)

If you connect Strava, you authorise Stoke through Strava's own login. The access token is stored on your device only (iOS Keychain / Android encrypted storage); our server forwards the token exchange to Strava but keeps no copy of your token. Stoke then reads your recent activities and their GPS tracks so you can import them as sessions, and uploads a session to Strava only when you ask it to. You can disconnect Strava in the app menu or revoke Stoke in your Strava settings.

Usage and crash data

The apps include the Firebase SDK, which may report anonymous app-usage events and crashes to help us keep the app working. This data is not used for advertising and is not linked to your identity for tracking. The app does not track you across other apps or websites.

2. How we use the information

3. Who receives data

We use these processors to run the service. Each receives only what is needed for its purpose:

ServicePurposeData
Firebase / Google CloudAuthentication, database, photo storage, push notifications, hosting, backend functionsAccount data, spots, alerts, sessions, reports, photos, push tokens
Google Cloud VisionAutomatic safe-search screening of uploaded photosUploaded photos
Open-MeteoWeather, wave and ensemble forecastsSpot coordinates
ResendPassword-reset e-mailsYour e-mail address
StravaOptional import and export of sessionsSessions you import or export; only if you connect Strava
Apple, GoogleSign-in and push delivery on their platformsSign-in identity, push tokens

We do not sell or rent personal data, and we do not share it with advertisers.

4. Retention and deletion

You can delete your account at any time from the app menu ("Delete account"), or by following the steps on our account deletion page. Deletion permanently removes your profile, spots, alerts, sessions, reports and photos from our systems.

5. Your rights

Under the GDPR you can ask for access to, correction of, export of or deletion of your personal data, and you can object to or restrict its processing. Most of this you can do directly in the app; for anything else, contact us at the address below. You also have the right to complain to the Danish Data Protection Agency (Datatilsynet).

6. Children

Stoke is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.

7. Security

Data is transmitted over encrypted connections and stored on Google Cloud infrastructure with access rules that restrict each user to their own data. Strava tokens never leave your device's secure storage.

8. Changes

We may update this policy when the app changes. The date at the top shows the latest version; material changes are announced in the app's release notes.

Contact Us

Snow Agency ApS, Denmark. Questions about this policy or your data:

Email: anders@snowagency.com