Who we are
Skyro Cloud is the service at www.skyrocloud.com and the Skyro Cloud Android app (com.skyro.cloud). For the data described here, the controller is:
- Legal entity
- FILL IN: registered company name
- Registered address
- FILL IN: registered address
- Contact
- support@skyrocloud.com
What we collect
Because you have an account
- Email address. Required. It identifies the account and is where service messages go.
- Name. Only if you enter one.
- Profile photo. Only if you upload one. It is stored in our database and shown only to you.
- How you sign in. A password stored as an Argon2id hash (never the password itself); or a link to your Google account, which is Google's opaque account identifier plus the email address Google tells us; or passkeys, where we store the public credential your device registered, never anything that could sign in as you elsewhere.
- Two-factor settings, including an authenticator secret if you enable one.
- Sign-in sessions. For every signed-in device: the browser or app identifier it reports, the IP address it connected from, and when it was last seen. This is what powers the list of sessions you can review and revoke.
- Security events. When your password or two-factor settings change, we record the event and notify you. The notification includes the IP address and app or browser identifier that made the change, so you can spot one you did not make.
- Failed sign-in attempts and any resulting lockout, to slow down people guessing at your account.
Because you use cloud phones
- Your phones: the name you gave each one, its plan, region, Android version, current state and when it was last used.
- Its history: a record of state changes, such as starting, stopping, resetting or being destroyed, and why.
- Usage measurements taken from the phone itself: processor load, memory in use, how much storage is occupied, network throughput and video frame rate. These are numbers about the machine. They do not describe what you were doing.
- Streaming records: when a viewing session opened and closed, and network quality measurements for it such as round-trip time, jitter, packet loss and bitrate. We do not record the video or audio of your session. The stream is forwarded live and never written down.
- Screenshots of the phone's screen taken automatically at a few moments, when a viewing session ends, when the app refreshes the picture, and when a phone is first provisioned, so the app can show a thumbnail of each phone in your list. These are pictures of your screen and may contain whatever was on it. They are stored privately, shown only to you and anyone you have shared that phone with, and deleted when the phone is deleted.
- File names and paths for files you upload to a phone or screenshots you take through the app. The file contents stay on the phone; we record only the path and size.
- Proxy settings, if you route a phone's traffic through your own proxy. The password is encrypted before it is stored and is never shown back to you or to us.
Because you share or transfer a phone
If you invite someone to a phone, or transfer one to them, we store the email address you typed, the invitation itself, and any message you wrote with it. That address belongs to another person, who may not be a Skyro Cloud customer. Only invite people who expect to hear from you.
Because you pay us
- Invoices: amount, currency, what it was for, when, and whether it was refunded.
- Wallet: your balance and a ledger entry for every movement in or out.
- Payment methods: the card network and the last four digits, plus the reference our payment provider uses. We never receive or store your full card number, expiry date or security code. Those go straight from your device to the payment provider.
- Purchases made through Google Play carry a Play purchase token, which we send to Google to check the purchase is real.
Because you asked for early access
If you apply for early access from a download page we store the email address you gave, which platform you asked about, anything you wrote in the optional box, and the IP address and browser the request came from. The last two are kept only to spot one person applying a thousand times; they are not used for anything else.
We use the address for one message, telling you the app is ready. Ask us and we will delete the entry, and we do that whether or not you ever become a customer.
Because you contacted support
Your support tickets, everything written in them, and any file you attached.
What we do not collect
- No advertising identifiers, no cross-site or cross-app tracking, no data brokers.
- No analytics or crash-reporting service in our backend. There is no Google Analytics, Sentry, Mixpanel, Segment or equivalent collecting from our systems.
- No recording of your screen or audio.
- No location data beyond what an IP address implies.
What is on your cloud phone
Your cloud phone is a real Android device with its own storage. Whatever you put on it, apps, the accounts you sign into, files, photos, messages, lives in that storage, which is yours for as long as you rent it.
We treat the contents of your phone as yours:
- It is not read, indexed, scanned or analysed by us.
- It is not used to train anything.
- It is not shared with anyone, except where the law compels us and we are permitted to comply.
Two honest qualifications:
- A phone's storage is encrypted at rest, in its own container with its own key, using AES-XTS. What that does and does not protect against is set out in section 8: it is not a defence against someone who already has administrative access to the running machine. See also section 9.
- Your phone's internet traffic leaves our network. By default it goes out through our data centre's connection. If you configure a proxy for a phone, it goes through the proxy you chose, and that provider sees the traffic. Either way, the sites and services your phone talks to receive whatever your apps send them, exactly as on a physical phone.
When a phone is destroyed, its storage is erased. When a subscription simply lapses, we hold the storage for a while in case you renew, and how long depends on how much you had bought for that phone in total:
| What you bought, in total | Storage kept after it lapses |
|---|---|
| More than a month | 7 days |
| More than a day, up to a month | 1 day |
| A single day | Nothing. The storage is erased as soon as the rental ends. |
"In total" means everything you ever bought for that phone, not the last payment. Twelve monthly renewals count as a year, so they earn the same week as paying for a year up front.
When you delete your account, no grace copy is kept at all, whatever you had bought.
Why we hold it
| What | Why | Lawful basis |
|---|---|---|
| Email, sign-in credentials, sessions | To give you an account and keep other people out of it | Performance of our contract with you |
| Your phones and their state | To provide the thing you are paying for | Performance of our contract |
| Usage measurements | To run the fleet, size machines, and tell you when a phone is nearly full | Legitimate interests in operating the service |
| Streaming quality records | To diagnose bad connections and improve streaming | Legitimate interests |
| Thumbnails of your phone screen | So your device list shows what each phone was doing | Performance of our contract |
| Security events, failed sign-ins, IP addresses | To detect and stop account takeover and abuse | Legitimate interests in security |
| Invoices, wallet ledger, payment references | To take payment and to keep lawful accounting records | Performance of our contract, and legal obligation |
| Support tickets | To answer you | Performance of our contract |
| Early access requests | To tell you when an app is ready, and to stop one person flooding the list | Consent, which you may withdraw by asking us to delete the entry |
| Invitation and transfer email addresses | To deliver the invitation you asked us to send | Legitimate interests, at your request |
Where we rely on legitimate interests, we have weighed them against your privacy and limited what we hold accordingly. You can object; see your rights.
Who else sees it
We do not sell your data and we do not share it for anyone else's marketing. These are the only third parties that receive anything, and exactly what reaches them:
| Who | What reaches them | What for |
|---|---|---|
| Stripe | Your card details, sent straight from your device to Stripe and never through us. From us: the amount, the description of what you bought, your email address, and an internal account reference. | Card payments and refunds |
| Google (Play Billing) | The purchase token and the product identifier | Verifying purchases made through the Play Store |
| Google (Sign-In) | Only if you sign in with Google: the sign-in token from your device is sent to Google to verify. Google returns your account identifier and email address. | Signing you in |
| Google (Firebase Cloud Messaging) | Your device's push token, and the text of each notification we send you | Delivering push notifications |
| Cloudflare (Turnstile) | On the download pages only: your IP address and a signal about your browser, so the anti-spam check can tell a person from a script. Cloudflare states it does not use this to profile you or serve advertising. | Stopping the early access form being flooded |
| Our email provider (netcup, Germany) | The recipient address and the full message: verification and sign-in codes, receipts, security alerts, invitations you send | Sending email |
| A proxy provider of your choosing | All of that phone's internet traffic, including its DNS queries | Only if you configure a proxy for a phone. You choose the provider; we simply route through it. |
Each of these has its own privacy policy governing what it does with what it receives.
How long we keep it
Everything below is deleted automatically on this schedule, whether or not you ask:
| What | Kept for |
|---|---|
| Detailed per-minute usage measurements | 24 hours, then summarised |
| Summarised usage measurements | 7 days at one-minute detail, 90 days at hourly detail |
| Streaming network-quality measurements | 24 hours |
| Streaming session records | 30 days after the session closes |
| Revoked sign-in sessions | 30 days |
| Notifications you have read | 90 days |
| A phone's event history | 90 days |
| A lapsed phone's storage | 7 days, 1 day, or not at all, by total purchase (see section 4), then erased |
| Sign-in and verification codes | 10 minutes to 24 hours depending on the code |
| Access tokens | 15 minutes |
| Sign-in refresh tokens | 30 days |
The rest is kept while your account is open, and deleted when you delete it, except:
- Invoices, the wallet ledger and payment records which we keep as long as accounting and tax law require, even after you leave.
- Support conversations which are not deleted automatically with your account. Ask us and we will delete them.
- Records of staff actions on accounts which cannot be altered or deleted, because that is what makes them an audit trail.
How it is protected
- In transit: everything between you and us is encrypted with TLS. Connections between our own servers use mutual TLS with a private certificate authority, so a machine cannot join the fleet without a certificate we issued.
- Passwords are stored as Argon2id hashes. We cannot recover your password, and neither can anyone who steals the database.
- Sign-in tokens are stored only as hashes. Reusing an old refresh token outside a few seconds' grace is treated as theft and kills the whole session.
- Proxy passwords and emailed one-time codes are encrypted with AES-GCM before storage, so a database dump does not reveal them.
- Two-factor authentication is available by authenticator app, by email code, or by using passkeys to sign in.
- Rate limiting and lockout: sign-in attempts are rate limited per address, and ten consecutive failures lock the account for fifteen minutes.
- Tenant isolation: phones cannot see each other on the network. A phone's storage is erased before that hardware is ever handed to another customer, and provisioning fails closed rather than hand over a phone that might still hold someone else's data.
Encryption of your phone's storage
Each cloud phone's storage is a separate encrypted container with a key of its own, using AES-XTS, unlocked only while that phone is running. One phone's key never opens another's.
What this protects against. Storage that leaves the machine: a disk that is decommissioned, replaced under warranty or reclaimed by the data centre; a copy of the image file taken off the host; a backup that goes somewhere it should not. In all of those the phone's contents are unreadable without its key.
What it does not protect against, said plainly. The key lives on the same server as the data, because your phone has to start without a human typing a passphrase. So this is not a defence against someone who already has administrative access to that machine while it is running, and it is not a defence against us. Encryption at rest is exactly that: protection for data at rest, not from the system that is using it. If what you plan to put on a cloud phone needs protection from the operator of the machine, encrypt it yourself, inside the phone, with a key we never see.
Deleting is a key destruction. When a phone is erased we destroy its key first. From that moment its previous contents cannot be read back, by us or anyone else, regardless of what remains on the disk before it is overwritten.
Encryption of everything else
The database is encrypted at rest too. It holds what a cloud phone does not: your email address, your invoices, your notification history and the thumbnails of your phone screens. It sits inside its own encrypted container rather than as a readable directory on the disk, and it is unlocked only while the service is running.
Inside that database, particular values get their own protection on top: passwords are Argon2id hashes we cannot reverse, sign-in tokens are stored only as hashes, and proxy passwords and emailed one-time codes are encrypted individually.
The same honest limit applies as for your phone. The keys live on the machine that uses them, because the service has to restart without a person typing a passphrase. This protects storage that leaves the machine. It does not protect against someone who already has administrative access to the running server.
No service can promise it will never be breached. If a breach affects your data, we will tell you and the relevant regulator as the law requires.
Who at Skyro Cloud can reach it
Being straight about this matters more than sounding reassuring.
The people who operate the service have administrative access to the machines your cloud phone runs on. The technical capability that keeps your phone working, starting it, streaming it, moving files to and from it, taking a screenshot of it, is the same capability that could be pointed at your phone without you. We do not do this, and it is not part of how the service is run, but we will not claim it is impossible.
What limits it in practice:
- The staff-facing admin panel deliberately has no ability to browse your files, take screenshots, read your clipboard or stream your phone. An operator can start, stop, restart, reset, destroy or migrate a phone, and nothing else.
- Destructive operator actions require an elevated role and a written reason, and every one is written to an audit trail that cannot be edited or deleted.
- Access to the underlying servers is limited to the people who run the infrastructure.
We access a phone's contents only when you ask us to for support, or where the law compels us. If we are ever legally compelled to hand over data, we will tell you unless we are forbidden from doing so.
Your rights
Depending on where you live, you have some or all of these rights. We honour them for everyone, wherever you are:
- Access: ask what we hold about you and get a copy.
- Correction: fix anything wrong. Your name and email address you can change yourself in the app.
- Deletion: delete your account and everything we are free to delete. You can do this yourself; see below.
- Portability: ask for your data in a machine-readable form.
- Objection and restriction: object to processing we base on legitimate interests, or ask us to limit it.
- Withdraw consent: where we relied on consent, withdraw it at any time.
- Complain: to your local data protection authority. We would rather you told us first, but it is your right either way.
Write to support@skyrocloud.com. We answer within 30 days. We will verify that a request really comes from the account holder before acting on it, because handing someone's data to an impostor would itself be a breach. We do not charge for this.
Deleting your account
You can delete your account yourself, from inside the app, at any time. It takes effect immediately: your cloud phones are destroyed, your credentials and personal details are erased, and you are signed out everywhere.
Step-by-step instructions, and exactly what is erased and what is kept.
Children
Skyro Cloud is not for children. You must be at least 16, or older if your country sets a higher age for agreeing to a service like this. We do not knowingly collect anything from a child. If you believe a child has an account, tell us and we will delete it.
Where the data lives
Our servers are in FILL IN: data centre country. Cloud phones run in the region you choose when you create them.
Some of the providers in section 6 operate internationally, so your data may be processed outside your country. Where that involves a transfer out of the European Economic Area or the United Kingdom, it is covered by the safeguards those laws require, such as the European Commission's standard contractual clauses.
Changes
If we change this policy we update the date at the top. If a change materially affects your rights or what we do with your data, we will tell you in the app or by email before it takes effect, not afterwards.
Contact
Questions, requests or complaints about privacy: support@skyrocloud.com.
Postal address: FILL IN: postal address