Legal

Privacy Policy

Last updated: October 3, 2026

This policy explains what information Skovrum handles, why, who helps us run the service, and the choices you have. We have tried to write it plainly. If anything is unclear, email [email protected].

1. Who we are

Skovrum (“Skovrum”, “we”, “us”) is a note-taking workspace for corporate trainers, operated from the United States. You can reach us at [email protected].

2. Two roles

For organisations that use Skovrum (our “customers”), we process the information their trainers record about classes and learners on the customer’s behalf and on its instructions. The customer decides what is recorded and is responsible for having a lawful basis to do so and for telling its learners. If you are a learner and have a question about your information, please contact the organisation that runs your training; we will help them answer it.

For visitors to skovrum.com, people who contact us, and the people who sign in, we decide how the information described below is used.

3. What we collect

Accounts

For trainers and administrators: name, work email address, role, display colour, preferences (such as theme, the optional daily email digest and pinned items), and when you last signed in. Passwords are never stored, only a salted cryptographic hash of them.

Workspace content

What a customer’s trainers add, which can include:

  • learner names, work email addresses and employee IDs;
  • optional profile details: preferred name, pronouns, a manager’s name, title and email, and private context notes;
  • classes, sessions, curriculum, attendance, engagement ratings, notes and observations, tasks, questions and answers;
  • certifications, scores and issued certificates;
  • files uploaded to a note, reply or learner profile (images and PDFs);
  • development notes about trainers written by their coaches.

When a note is edited or deleted, the earlier version is kept as edit history so changes can be reviewed and restored.

Learner surveys

Survey responses are anonymous by default. A name is recorded only when a survey asks for it and the learner chooses their own name from the class list; self-assessment surveys are always named. We do not store IP addresses with survey responses.

Contact form

Your name, email address, team size (optional) and message, so that we can reply.

Demo requests

When you ask for the demo: your name, work email address and organisation; your role, team size and what you train, if you tell us; and whether you want launch news. We also note the campaign or website that brought you to skovrum.com (for example “newsletter” or “linkedin.com”, never the full address of the page), when we emailed your demo link, and when and how often the link was opened.

The shared demo workspace

The demo is one sample workspace shared by everyone with a demo link. Anything typed into it can be seen by other visitors until the daily reset at 00:00 UTC, when it is deleted, so please don’t enter real names or personal information. Your demo link tells the demo nothing about you except a random reference to your request, which is used to limit how many AI summaries each visitor can generate.

Usage and security information

  • Which screens and features are used, linked to the signed-in account, so we can run and improve the product.
  • Error reports from the app, with web addresses, email addresses, names and quoted text removed before they are stored.
  • IP addresses and email addresses used to limit repeated sign-in, password-reset, survey and contact attempts. These are kept for about a day.
  • An audit log of administrator actions (for example, changing a user’s role). It records who did what, not learner names.

Website analytics

skovrum.com uses Cloudflare Web Analytics to count page views. It does not use cookies or build a profile of you.

4. How we use information

  • To provide the service: storing, syncing and showing workspace content to the people the customer has given access to.
  • To send the emails you or your organisation turn on: password-reset links, the optional daily digest, survey invitations to learners, and replies to contact messages.
  • To send demo links, to follow up with people who ask for the demo, and to email launch news to those who ask for it.
  • To keep the service secure, prevent abuse, and investigate problems.
  • To provide support and improve the product.

We do not sell personal information, and we do not use it for advertising.

5. AI summaries

Some reports offer an optional written summary (for example, a weekly class summary, a learner handoff note, or the themes in survey comments). These are produced with Cloudflare Workers AI, which runs on Cloudflare’s network; no other AI company receives the data.

We send only what the summary needs: non-private notes and observations, attendance and certification figures, open tasks, and survey comments. Notes marked private and learners’ private profile context are never sent. Learner names are not sent as separate details, but a name typed inside a note or comment can be included. Skovrum does not keep the generated text unless you save it in a report you download. We do not use workspace content to train AI models.

6. Emails to learners

When a customer turns on survey emails, Skovrum emails the learners on the class list a link to the session survey, sent as “Trainer via Skovrum” with replies going to the trainer. Every survey email has an unsubscribe link; once used, Skovrum sends no further survey emails to that address.

7. Service providers

We use a small number of providers to run Skovrum. They process information only to provide their service to us.

ProviderWhat they do for us
Cloudflare, Inc.Hosting, database and file storage, sending email, AI summaries, website analytics
Google LLCWeb fonts (Google Fonts). Your browser loads them from Google’s servers, which receive your IP address.

We do not use any other providers to process workspace content. We may disclose information if the law requires it, or to protect the rights and safety of our users or the public.

8. Where information is stored

Skovrum is operated from the United States and runs on Cloudflare’s global network, so information may be stored and processed in countries other than yours. Where the law requires it, we rely on appropriate safeguards for international transfers, such as the standard contractual clauses in our providers’ data processing terms.

9. How long we keep information

  • Workspace content is kept while the customer’s workspace is active, until the customer deletes it. A manager can permanently erase a learner, which removes them and their records from the workspace.
  • Deleted files are removed from storage straight away.
  • The administrator audit log is kept for 365 days.
  • Error reports are kept for 30 days.
  • Security counters (IP and email attempt limits) are kept for about a day.
  • Password-reset links expire after one hour and work once.
  • Contact messages are kept while we need them to reply and to keep a record of the conversation.
  • Demo requests are deleted 24 months after your last request, or sooner if you ask. Demo links stop working after 7 days.
  • Anything entered in the demo workspace is deleted at the daily reset.

When a customer stops using Skovrum, we delete or return its workspace content on request.

10. Cookies and browser storage

Skovrum uses only cookies that are strictly necessary for the service:

  • skovrum_session keeps you signed in (up to 30 days). It cannot be read by scripts on the page. In the demo, the same cookie keeps you in the demo workspace.

The app also uses your browser’s local storage for preferences (such as theme), changes waiting to sync while you are offline, and an automatic backup copy of your workspace data on that device. These are cleared when you sign out. If you use a shared computer, please sign out when you finish.

On skovrum.com, your browser’s session storage keeps a note of the campaign or website that brought you, until you close the tab, so it can be sent with a demo request.

We do not use advertising or cross-site tracking cookies, so there is nothing to accept or decline.

11. Security

Information is encrypted in transit (HTTPS). Passwords are stored as salted hashes, sign-in cookies are protected from page scripts, repeated sign-in attempts are throttled, administrator actions are logged, and full workspace backups are encrypted with a passphrase only the administrator knows. No system is perfectly secure; if we learn of a breach that affects your information, we will tell the affected customers without undue delay.

12. Your choices and rights

  • Learners: please contact the organisation that runs your training. We will help them respond.
  • Account holders can update their name and password in Account settings, sign out of every other device, and turn the daily digest on or off. To close an account, ask your workspace administrator or email us.
  • Anyone can unsubscribe from Skovrum emails using the link in each email.
  • If you asked for the demo, email us to delete your request or to stop launch news.

Depending on where you live, you may have rights to access, correct, delete, restrict or object to the use of your personal information, and to complain to a data protection authority. To use them, email [email protected].

13. Children

Skovrum is built for workplace training and is not intended for children under 16.

14. Changes to this policy

If we change this policy, we will post the new version here and update the date at the top. If a change is significant, we will also tell customers’ administrators.

15. Contact

Questions or requests: [email protected].