Privacy Policy
Who we are
SkyOS is a personal AI assistant at app.skyos.ink, operated by
Gennadii Kosaryntsev, an individual developer based in
Kazakhstan. For anything in this policy — a copy of your data, deletion, a
complaint — write to
byerhovbiz@gmail.com. Under EU/UK
law we are the data controller for everything described here.
What we store
| Data | Why | When |
|---|---|---|
| Your email address | Your account and sign-in link | Always |
| Your messages and SkyOS's replies | To hold the conversation and sync it across your devices | Always |
| Memory notes written from your conversations | So SkyOS remembers what you have told it | Always |
| Files and images you upload | So SkyOS can read them | When you attach something |
| Name, nickname, occupation, interests | To personalise answers | If you enter them at onboarding |
| Your settings and project list | To restore the app on any device | Always |
| Message counts | To enforce usage limits | Always |
| Approximate city, from your IP address | So answers match where you are | While the time and location permission is on |
| Precise coordinates, from your device | Nearby places and directions | Only if you grant the browser location permission |
| Local time and timezone | So SkyOS knows the date and time for you | While the time permission is on |
| Voice recordings | Converted to text, then discarded | While you dictate or use voice mode |
| Feedback and bug reports you send | To fix what you told us about | When you submit one |
We do not run advertising or tracking pixels, and we do not sell your data or share it with anyone for marketing.
It is not end-to-end encrypted
Your data travels over HTTPS and sits on providers that encrypt their disks. That protects it in transit and against someone stealing a hard drive. It does not mean only you can read it.
Your messages, memory notes and files are stored so that our operator, and staff at the providers listed below, are technically able to read them. There is no key that only you hold. Someone with access to our database console can open a record and read it as ordinary text.
On our side that is one person: SkyOS is run by a single operator, and nobody else holds credentials to the database. It is not a team, and there is no support desk with a view of your account. What follows is the limit that person works to.
When a human looks at your data
Being able to read something is not permission to. We open the contents of your account — your messages, memory notes and uploaded files — only when one of these applies:
- You ask for help and we need to see what went wrong.
- Debugging a fault — a bug we can only reproduce from the affected record.
- Abuse or security — investigating misuse, fraud, or a threat to the service or to someone's safety.
- The law requires it — a valid legal demand. Where we are allowed to tell you, we will.
We do not read your conversations to improve the product, to train models, or out of curiosity.
Usage counters are separate and are looked at routinely. How many messages you sent, how many tokens they cost and what the bill came to are numbers, not text — they carry nothing you wrote. Watching those is how the service is kept running and inside its limits, and it needs no reason from the list above.
Where your data is held
| Provider | What it holds or does | Where |
|---|---|---|
| Upstash (Redis) | Your messages, memory notes, uploaded files, settings and usage counts | United States |
| Supabase | Your account and sign-in | United States (North Virginia) |
| Resend | Sends your sign-in emails; sees your email address and the sign-in link | United States (North Virginia) |
| Only if you choose “Continue with Google”: confirms who you are and gives us your email address and name | United States | |
| OpenAI | Generating replies; speech-to-text; text-to-speech | United States |
| Vercel | Hosting, server logs, the IP-based city lookup, and usage analytics | United States |
| esm.sh | Serves the sign-in library to your browser; sees your IP address | Global CDN |
| OpenStreetMap (Nominatim) | Turns coordinates into a district name | Europe |
| Paddle | Sells and bills SkyOS+ as the merchant of record; sees your name, email, billing address and payment details. We never see or store your card number. | United Kingdom / United States |
Your conversation is sent to OpenAI to produce each reply. That includes the message you just typed, recent messages from that project, a small number of older messages from the same project when what you asked plainly refers back to them, your memory notes, and any file you attached. We switch off their request logging, so your conversations are not stored in our account there and do not appear on any dashboard we can browse. OpenAI may still retain a copy for a limited period to monitor for abuse, under their own terms, and that copy is outside what our delete function can reach. It is not used to train their models.
Each of these providers uses its own sub-processors — hosting, infrastructure
and support companies working on their behalf — under contracts that pass on
the same obligations. They publish their own lists; OpenAI’s is at
platform.openai.com/subprocessors.
Signing in
There is no password. Signing in with your email sends a one-time link that
works once and expires after an hour. To deliver it we hand your email
address and that link to Resend, our mail provider. Resend
can see both, and keeps a delivery record — that the message was sent, and
whether it arrived. Sign-in mail comes from hello@skyos.ink,
which is send-only: replies to it bounce rather than reaching us.
If you choose “Continue with Google” instead, Google tells us your email address and name so we can recognise your account. Google will know you signed in to SkyOS, and their own privacy policy covers what they do with that. We never see your Google password. This route is optional — the email link does the same job without involving Google at all.
Feedback you send us
When you submit feedback or a bug report, we store what you wrote along with your app version, which screen you were on, your browser and your account id. Your messages and memory notes are not attached. The one exception is reporting a specific reply: that report includes the reply being reported, and the composer shows it to you before you send.
Reports are emailed to us through Resend, the same provider that sends your sign-in link, and your email address travels with them so a reply reaches you. Nothing new is collected: it is the address already on your account.
Server logs
Our host keeps ordinary server logs — timestamps, error messages, and the internal key of a record when a storage call fails. That key contains your account id, but not your name or email. We deliberately do not write the contents of your messages or notes into logs.
Location
Two separate levels, both controlled in Settings → Permissions:
- City from your connection. Worked out from your IP address by our host. No browser prompt. Turning off the time and location permission stops it.
- Precise position from your device. Only after your browser asks and you allow it.
Coordinates are turned into a district name by OpenStreetMap. That lookup is cached for seven days by coordinate, not by user. Your position is never written into your memory notes.
Voice
When you dictate or use voice mode, the recording goes to OpenAI, is turned into text, and is discarded. SkyOS does not keep the audio. The resulting text is treated like anything else you type.
Web search and links you paste
When SkyOS looks something up, the search query — which may contain part of what you asked — goes to the search tool. When you paste a link, our server fetches that page so SkyOS can read it. Turning off Web search in Settings → Permissions stops both.
Usage analytics
We use Vercel Web Analytics to count visits and which screens are opened. It records the page, the referrer, and rough device and country information. It sets no cookies, stores no identifier that follows you between visits, and cannot be tied back to your account. Your messages, notes and files are never sent to it.
We also count how far people get through sign-up — how many reached the welcome screen, how many signed in, how many finished. This is our own counting, not a third party’s, and it is a running total per step per month: one number each, with no visitor identifier attached, so it can say how many got somewhere and can never say who. Your browser remembers which steps it has already counted, purely so one person reloading a page is not counted twenty times; that marker stays on your device and is never sent.
Once you have an account we also keep the furthest step you reached on your usage record, beside the message counts. It is a single word, such as “name” or “done”.
How long we keep it
- Messages, settings and usage counts: until you delete them or delete your account. Nothing expires on its own.
- Memory notes: until you delete them or delete your account, with one exception — when a note repeats another word for word, or a newer note replaces an older one outright, SkyOS removes the line it no longer needs. It only ever deletes a whole line; it never rewrites what a note says. Everything still on file is wording your own conversations produced.
- Uploaded files: capped per account. Once you pass the cap, the oldest files are deleted automatically to make room.
- Voice recordings: not kept.
- Server logs and analytics: kept by our host for their standard retention period.
Deleting everything
Profile → Delete Account removes your messages, memory notes, uploaded files, settings and usage counts, and deletes your login. It takes effect immediately and cannot be undone. You can also delete individual memory notes at any time from the memory screen, using the ⋮ menu on each one.
Backups held by our providers may keep copies for a short period before rolling off, and anything already sent to OpenAI is subject to their retention, not ours.
If you are in the EU, the EEA or the UK
Your data is processed in the United States. Our database (Upstash), our host (Vercel), our account and sign-in provider (Supabase), our mail provider (Resend), our model provider (OpenAI), and Google if you sign in with it, all process it there. The United States is not covered by an EU adequacy decision for all of these providers, so the transfers rely on the European Commission’s Standard Contractual Clauses in each provider’s data processing terms. One exception, stated plainly: our hosting provider’s data processing addendum covers paid plans only, and SkyOS is currently on their free tier, so that addendum is not in force for the processing they carry out as our host. Authorities in the United States may also be able to compel disclosure under their own law in ways that differ from EU law.
Why we are allowed to process it (legal basis):
- Performing our contract with you — your account, your messages, your memory notes, your files, and the message counts that keep you inside your plan’s limits. Without these the app cannot work.
- Your consent — precise location, the microphone, and web search. Each is a permission you switch on, and you can switch it off at any time.
- Legitimate interests — keeping the service running and secure, and reading per-account usage counts to watch cost and capacity.
Your rights. You can ask us to:
- give you a copy of your data, or correct it
- delete it — you can do this yourself from Profile → Delete Account
- restrict or object to how we use it
- export it in a portable form — do this yourself from Profile → Export my data, which downloads a JSON file of your profile, projects, messages, memory notes, usage and your attachments themselves — pictures and documents travel inside the file as base64, so it stands on its own. Very large attachments are listed but not embedded, because one response can only carry so much; those stay downloadable from Library
- withdraw a consent you gave, without affecting what came before
Write to byerhovbiz@gmail.com and we will answer within one month. You also have the right to complain to your national data protection authority.
We do not use your data for automated decisions that produce legal or similarly significant effects about you.
If you are in California
This section covers the CCPA as amended by the CPRA. In the last 12 months we have collected these categories of personal information:
| Category | Examples |
|---|---|
| Identifiers | Email address, account id, IP address |
| Internet activity | Pages opened in the app, approximate city from IP |
| Geolocation | Precise coordinates, only if you allow it |
| Audio | Voice recordings, converted to text and discarded |
| Other information you provide | Your messages, memory notes and uploaded files |
We collect it for the purposes described above, from you directly and from your device. We disclose it to the service providers listed under “Where your data is held”, for those purposes only.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the past 12 months, including for anyone under 16.
Your rights: to know, to access, to correct, to delete, and to limit the use of sensitive personal information. We do not use sensitive personal information to infer characteristics about you. Exercise any of these by writing to byerhovbiz@gmail.com, or delete everything yourself from Profile → Delete Account. We will not treat you differently for exercising them.
Security
Traffic uses HTTPS. Our providers encrypt data at rest. Access to the production database is limited to the operator. As set out above, this is not end-to-end encryption, and we cannot promise that no incident will ever happen. If a breach affects your data we will tell you and the relevant authority as the law requires.
Children
SkyOS is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
If this policy changes in a way that matters, we will say so in the app before the change takes effect. The date at the top always shows the current version.
← Back to SkyOS