Skyl Privacy Policy
This Privacy Policy describes how Vestgaard Construction Ltd. ("Skyl," "we," "us," or "our"), operating as Skyl, collects, uses, discloses, and protects your information when you use the Skyl mobile application (the "App") and any related services (together, the "Service"). The Service is a social and professional network for construction-trade professionals to share work, find jobs, message peers, build a portfolio, and join crews and clubs.
By creating an account or using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, do not use the Service.
1. Information We Collect
1.1 Information you provide
- Account credentials. Email address and/or phone number, and a password. Phone-number sign-up uses SMS one-time passwords (OTP) sent via Supabase Auth.
- Profile information. Username, full name or company name, bio, trade, location (free text), years of experience, hourly rate, profile image, banner image, account type (personal or company), and badges.
- About-me / business-card details. Optional work experience, languages, trade school, certifications (issuer, dates, credential ID, image), and optional contact email/phone that you choose to display on your portfolio or business card.
- Company / business profile. Company name, logo, profession, company size, hiring status, description, website, social links, services, and team members.
- User-generated content. Posts (text, images, videos), comments and replies, direct messages, crew chat messages, job-application messages, job listings, portfolio items (photos, PDFs, descriptions, tools, skills, project location), club posts, and feedback you submit through the in-app form.
- Job-related information. Job title, description, requirements, pay, location, and any cover message you submit when applying.
- Support information. Subject, category, message body, and contact email when you contact Skyl support.
1.2 Information collected automatically
- Usage and engagement data. Likes, comments, saves, follows, friend/crew memberships, job applications, post views, feed impressions, video watch events, and search queries (recent queries are stored only on your device).
- Presence data. A
last_seentimestamp updated approximately every two minutes while the App is in the foreground, when you have "Show Online Status" enabled. - Push notification token. A device token issued by Apple Push Notification service or Firebase Cloud Messaging, relayed through Expo Push, so we can deliver notifications.
- Approximate or precise location. When you enable Location Services in Settings, the App uses your device GPS to fetch weather (OpenWeatherMap) and to display job sites on the map. Coordinates are used transiently; a city-level cache is stored on your device for performance.
- Device and log data. App version, OS version, device model, language, and crash/performance logs that may be produced by the operating system or by Expo.
- Moderation records. When content is reported or scanned, we store the report reason, automated decision and scores, and any appeal you submit.
1.3 Information stored on your device
The App stores the following on your device using AsyncStorage:
- Your Supabase session tokens (access and refresh tokens) for login persistence.
- For multi-account switching: the user ID, email, display name, avatar, and session tokens for each saved account.
- Your per-user settings (notification preferences, privacy flags, location-services toggle, language, online-status toggle).
- Cached weather and news data, recent search queries, hidden message threads, and showcase layout preferences.
1.4 Sensitive information
We do not knowingly collect sensitive personal data such as government IDs, racial or ethnic origin, religious beliefs, health data, or biometric data. If you include such information in posts, messages, or your profile, it is treated as general user-generated content under this policy.
2. How We Use Your Information
We use your information to:
- Operate the Service. Create and authenticate accounts, display profiles, show feeds, reels, jobs, clubs, and crews, and sync content across devices.
- Enable communication. Deliver direct messages, crew chat, job-application threads, mentions, comments, and notifications.
- Personalize and rank content. Use your trade, follows, crew memberships, location, and engagement signals to rank feed posts, reels, jobs, and news.
- Provide hiring features. Display job listings, accept and track applications, and let employers contact applicants.
- Show weather and maps. Use your location (when enabled) to fetch weather from OpenWeatherMap and to geocode locations via OpenStreetMap Nominatim.
- Send push notifications. Notify you about likes, comments, mentions, follows, friend/crew/team invites, direct messages, job applications, and moderation actions. You can adjust or disable these in Settings.
- Maintain safety and enforce guidelines. Automatically scan text and media for policy violations, review reported content, warn, suspend, or ban accounts that violate our Community Guidelines, and respond to appeals. Child-safety reports may be reported to the National Center for Missing & Exploited Children (NCMEC) where required by law.
- Provide support. Receive and respond to support tickets and feedback, including by email.
- Aggregate analytics and product improvement. Analyze engagement patterns (post views, feed events, watch time) to improve ranking, surface bugs, and decide product direction. We do not use a third-party analytics SDK.
- Prevent fraud and abuse. Detect duplicate accounts, suspicious activity, and policy violations.
- Meet legal obligations. Comply with law enforcement requests where legally required, and meet tax and accounting obligations.
3. How We Share Your Information
3.1 With other users
- Public profile data (username, full name, profile image, banner, trade, bio, badges) is visible to authenticated users.
- Your posts, comments, and likes are visible according to the audience you choose (public, followers, club members, or crew members).
- Direct messages and crew chats are visible to participants.
- Job applications and job-application threads are visible to the applicant and the job poster.
- Online status (green/red dot, "last seen") is shown to other users when "Show Online Status" is enabled.
- Mentions and tags notify the user you mention or tag and disclose your username to them.
3.2 With service providers and processors
We share data with the following third parties that process data on our behalf:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Authentication, database, realtime, edge functions, file storage | Account credentials, profile data, UGC, engagement, settings |
| Cloudflare (R2, Stream, Workers, Email Routing/Sending) | Media storage and CDN, video transcoding, transactional email | Media files, video files, email content, reply-to email |
| Expo (EAS Updates, Push) | OTA updates, push delivery | Push tokens, update metadata |
| OpenWeatherMap | Weather and geocoding | Coordinates or city name |
| OpenStreetMap Nominatim | Map geocoding | Location search strings |
| OpenAI | Automated text moderation (post, comment, profile text) | Text content |
| Sightengine | Automated image and video moderation | Media URLs |
| Google AdMob | Optional in-feed ads (where enabled) | Advertising identifier after App Tracking Transparency consent, ad interactions |
| Apple / Google | OS-level push delivery | Push tokens via APNs/FCM |
These providers process data under their own privacy policies and as our processors under appropriate data-processing agreements.
3.3 For legal and safety reasons
We may disclose information if we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation or law-enforcement request; (b) protect the safety, rights, or property of Skyl, our users, or the public; (c) investigate or respond to suspected violations of our Community Guidelines; (d) detect, prevent, or otherwise address fraud, security, or technical issues; or (e) enforce our Terms.
3.4 We do not sell your data
We do not sell your personal information to third parties. Where we serve ads through Google AdMob, that activity may be considered "sharing" or "cross-context behavioral advertising" under some state laws; in those cases we do so only after you have granted App Tracking Transparency permission.
4. Your Choices and Controls
You can manage your data through the App's Settings screen and through system-level controls:
- Push notifications. Toggle each notification type or disable all in Settings, or disable notifications at the OS level.
- Location services. Turn Location Services on or off in Settings; the App will not access GPS when off, and weather will display a "location services disabled" state instead of using a fallback.
- Online status. Toggle "Show Online Status" in Settings; when off, your
last_seenis cleared and not displayed. - Private account. Enable "Private Account" to require approval of new followers and limit who can see your posts.
- Hidden message threads. Hide specific DM or crew conversations from your list without deleting them.
- Block users. Block other users from contacting you or viewing your content.
- Ad tracking. Use Apple's App Tracking Transparency prompt or Android settings to deny or revoke advertising identifier access.
- Account deletion. You can request account deletion through the App or by contacting privacy@skylstudios.com. Deletion removes your profile, posts, comments, messages, and personal data, subject to legal retention requirements.
- Data export. You may request a copy of your personal data by emailing privacy@skylstudios.com.
- Withdraw consent. You can withdraw consent for optional data processing (location, push, online status, ads) at any time by adjusting the relevant setting.
4.1 How to turn off Push Notifications
Inside the App:
- Open the Skyl app.
- Tap your profile icon, then tap Settings (gear icon) in the top right.
- Under Notifications, toggle off any notification types you no longer want (likes, comments, mentions, follows, direct messages, crew messages, job applications, etc.).
- To disable all in-app push notifications at once, toggle off Push Notifications at the top of the Notifications section.
At the OS level (more thorough):
- iOS: Open the iOS Settings app → Skyl → turn off Notifications.
- Android: Open Settings → Apps → Skyl → Notifications → turn off Allow notifications.
4.2 How to turn off Location Services
Inside the App:
- Open the Skyl app.
- Tap your profile icon, then tap Settings.
- Under Privacy, toggle off Location Services.
- When off, the App will not access your GPS. The weather widget will display "Location services disabled" instead of showing weather, and the map will not center on your current location.
At the OS level (recommended as well):
- iOS: iOS Settings → Skyl → Location → select Never.
- Android: Settings → Apps → Skyl → Permissions → Location → Don't allow.
4.3 How to turn off Online Status (presence)
- Open the Skyl app.
- Tap your profile icon, then tap Settings.
- Under Privacy, toggle off Show Online Status.
- When off, your
last_seentimestamp is cleared and other users will not see a green/red presence dot on your profile, in the Crew list, or in direct messages. You will also stop seeing other users' online status if you have it disabled for yourself.
4.4 How to opt out of ad tracking
- iOS: When you first launch Skyl, you'll see an App Tracking Transparency prompt. Tap Ask App Not to Track to deny access to your advertising identifier. You can change this later in iOS Settings → Skyl → Tracking.
- Android: Open Settings → Ads → Reset advertising ID or Opt out of Ads Personalization.
5. Data Retention
We retain your information for as long as your account is active and for a limited period afterward to meet legal, safety, and accounting obligations:
- Account data. Retained until you delete your account. After you request deletion, your account is fully deleted within 30 days. Skyl also reserves the right to delete accounts that have been inactive for an extended period.
- User-generated content. Retained while your account is active. If your account has been inactive for 90 days, Skyl reserves the right to delete your user-generated content (posts, comments, messages, portfolio items). Deleted posts, comments, and messages are soft-deleted (content wiped, row retained for audit) and may be retained for up to 90 days for safety investigations before hard deletion.
- Messages. Direct messages and crew chats are retained until you delete them or your account is deleted.
- Push tokens. Removed when you sign out, delete your account, or disable notifications.
- Moderation records. Reports, scans, and enforcement actions are retained for up to 24 months for safety, audit, and legal-defense purposes.
- Engagement and analytics events. Aggregated and anonymized data may be retained indefinitely; identified
feed_eventsare retained for up to 24 months. - Support tickets. Retained for up to 24 months after resolution.
- Device logs. Retained for up to 90 days for debugging and security.
6. Security
We use industry-standard safeguards to protect your information, including encrypted transport (TLS), hashed passwords (managed by Supabase Auth), row-level security policies on the database, and access controls on internal systems. However, no system is perfectly secure, and we cannot guarantee absolute security.
Session tokens (including tokens for multi-account switching) are stored on your device using AsyncStorage. We recommend using a strong device passcode and biometric lock to protect local data.
7. Children's Privacy
The Service is intended for trade professionals and is not directed to children under the age of 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact privacy@skylstudios.com and we will delete it.
The App includes child-safety moderation: content that appears to involve the sexual exploitation of minors is escalated, removed, and may be reported to the National Center for Missing & Exploited Children (NCMEC) where required by law.
8. International Users
The Service is operated from Canada. Skyl's primary data infrastructure is hosted as follows:
- Supabase (authentication, database, file storage, edge functions): hosted in the CA-CENTRAL-1 region (Toronto, Canada).
- Cloudflare (media CDN, video transcoding, email): Cloudflare processes and stores data across its global network at the data center nearest to each visitor. Media files may be cached on edge servers worldwide for performance.
If you access the Service from outside Canada, your information will be transferred to and processed in Canada and on Cloudflare's global edge network. By using the Service, you consent to these transfers.
8.1 California Consumer Privacy Act (CCPA/CPRA)
If you are a California resident, you have the right to: know what personal information we collect, request deletion, request correction, opt out of the sale or sharing of your personal information, and not be discriminated against for exercising these rights. To exercise these rights, contact privacy@skylstudios.com. We do not sell personal information. We "share" personal information for cross-context behavioral advertising only when you grant App Tracking Transparency permission; you can opt out at any time in iOS Settings.
8.2 Other U.S. state privacy laws
If your state has a consumer privacy law (for example, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana CDPA, or others), you may have similar rights to access, correct, delete, or opt out of certain processing. To exercise these rights, contact privacy@skylstudios.com. We will respond within 30 days.
9. Third-Party Links and Content
The App may contain links to third-party websites or display content hosted by third parties (for example, news articles, weather data, or job postings that link to external sites). We are not responsible for the privacy practices of those third parties. This Privacy Policy does not apply to third-party services.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy in the App or on our website and, where appropriate, sending a notification. The "Effective date" at the top of this policy indicates when it was last updated. Your continued use of the Service after a change constitutes acceptance of the updated policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact:
Vestgaard Construction Ltd. (operating as Skyl)
- Mailing address: 115 Royal Birch Circle NW
- Privacy email: privacy@skylstudios.com
- Support and moderation: team@skylstudios.com
Please include a description of your request and, where relevant, the account email or user ID involved. We will respond within 30 days.
12. Summary of Data Categories
For your convenience, the categories of personal information we collect are:
- Contact info — email, phone number (account and optional display contact).
- Identifiers — user ID, username, push token, advertising identifier (when ATT granted).
- Account and profile data — name, bio, trade, location, image, banner, account type, badges, certifications.
- User-generated content — posts, comments, messages, job listings, portfolio items, club posts, feedback.
- Usage data — likes, follows, saves, post views, feed events, search history (on device).
- Location — GPS coordinates (when enabled), city cache, location text.
- Presence —
last_seentimestamp (when online status is enabled). - Device data — OS version, device model, app version, language, crash logs.
Each category is used for the purposes described in Section 2 and shared as described in Section 3.
Operated by Vestgaard Construction Ltd. · Terms of Service · privacy@skylstudios.com