Privacy Policy
How SkyyCast handles your data
This page explains what information SkyyCast collects when you use the product, why it's collected, and how it's handled.
Last updated: August 31, 2026
Who operates SkyyCast
SkyyCast is operated by Sangay Choda as an individually operated business (sole proprietorship), based in Bhutan. This policy applies to anyone who creates a SkyyCast account, connects a Bluesky account, or otherwise uses the product.
Information we collect
SkyyCast collects only what's needed to operate the product:
- Account information. Your email address, received from Google when you sign in with your Google account (SkyyCast uses Google sign-in as its authentication provider).
- Bluesky connection information. When you connect a Bluesky account, we store your Bluesky handle and DID (decentralized identifier), and the authentication tokens needed to publish on your behalf — either through Bluesky's official OAuth flow or, for legacy connections, an app password you provide. These credentials are stored so SkyyCast can publish scheduled posts and read your post performance without asking you to sign in again every time.
- Content you create. The text and any images of posts you write and schedule through SkyyCast, along with their scheduled time, status (pending, published, or failed), and, when applicable, the error message explaining why a post failed.
- Subscription and billing information. If you upgrade to Pro, our Merchant of Record, Paddle, handles your checkout and stores your payment details. SkyyCast itself never receives or stores your card number or other payment credentials — we only receive and store your Paddle customer ID, subscription ID, plan, subscription status, and billing period dates, which we use to determine whether your account has Pro access.
- Post performance data. For posts published through SkyyCast (and, where you've connected your account, other posts on your Bluesky timeline), we fetch engagement counts — likes, reposts, replies, and quotes — directly from Bluesky's own public API, so you can review how your content performed inside SkyyCast.
- Technical information. Standard request logs generated by our hosting provider, and application logs used to diagnose failed scheduling or publishing attempts. These logs are written to exclude authentication tokens, passwords, and other credentials.
Cookies and local storage
SkyyCast's own use of cookies and local storage is limited to operating the product, not advertising or cross-site tracking. Your signed-in session is maintained through a secure, http-only session cookie that SkyyCast sets after you sign in with Google. SkyyCast also uses local storage for a small amount of purely functional data — such as remembering your Bluesky connection status and whether you've completed the onboarding walkthrough — so the app doesn't need to reload that information from the server every time you open it. Third-party advertising cookies are covered separately in the "Advertising" section below.
How we use this information
We use the information above only to operate SkyyCast, specifically to:
- Authenticate you and keep your account secure.
- Publish your scheduled posts to Bluesky at the time you chose.
- Show you your queue, publishing history, and post performance.
- Determine whether your account has Free or Pro access, and enforce the Free plan's limit of 15 successful publishes per calendar month.
- Process your subscription through Paddle and keep your subscription status up to date.
- Diagnose and fix failed scheduling or publishing attempts.
We do not sell your data, and we do not use your scheduled post content or Bluesky connection for advertising or profiling.
Third-party service providers
SkyyCast is built on a small number of third-party services, each handling a specific part of the product:
- Bluesky / the AT Protocol — to publish your posts and read post performance data, using the connection you authorize.
- Paddle — to process Pro subscription payments. Paddle acts as our Merchant of Record and handles payment processing, billing, and payment-related information. Your payment details are handled by Paddle, not by SkyyCast.
- Google — our authentication provider; you sign in with your Google account and we receive your email address.
- Render — our hosting and database provider, which serves the application, processes requests, and hosts the PostgreSQL database where your account, connection, and scheduled post data is stored.
- Cloudflare (R2) — our media storage provider, where images you attach to scheduled posts are stored.
Each of these providers has its own privacy policy governing how they handle data on our behalf. SkyyCast's blog content is managed through a separate content system (Sanity) used only to publish articles like the ones on this site — it does not process or store any of your account, connection, or scheduled-post data.
Data sharing
We share information only with the third-party service providers listed above, and only as needed for them to perform their role — for example, sharing your Bluesky authorization with Bluesky's own API to publish your posts, or your billing details with Paddle to process a subscription. We do not sell your information, and we do not share it with third parties for their own marketing purposes.
Advertising
SkyyCast is preparing to show advertising from Google AdSense on its public pages — the blog and informational pages like this one. Ads are not shown inside your signed-in dashboard, and SkyyCast does not use your account, your scheduled post content, or your Bluesky connection for ad targeting.
Once advertising is enabled, Google and its advertising partners use cookies and similar technologies to serve ads and measure their performance, and may show personalized ads based on your prior visits to this and other websites. You can review and control the ad personalization Google applies to you at myadcenter.google.com. Google describes how it uses cookies in advertising at policies.google.com/technologies/ads, and how it uses information from sites that use its services at policies.google.com/technologies/partner-sites. You can also opt out of personalized advertising from many other vendors at aboutads.info/choices.
Where the law requires consent for advertising cookies that are not strictly necessary — for example in the EEA and the UK — those cookies will only be used after you have given consent, and you can change or withdraw that consent at any time.
Data retention and deletion
We retain your account, connection, and scheduled post data for as long as your account is active, so the product keeps working the way you'd expect. If you disconnect your Bluesky account, we stop using that connection to publish or fetch data on your behalf.
To request deletion of your account and associated data, contact us at connect@skyycast.com. We don't yet offer a fully self-service account-deletion option inside the product.
How we protect your data
Access to your account data is restricted to your own signed-in session — other SkyyCast users cannot see your scheduled posts, Bluesky connection, or subscription details. Bluesky authentication tokens and Paddle webhook communications are never exposed to the browser or logged in readable form. The background process that publishes scheduled posts uses a separate, narrowly-scoped credential that can only perform that one task. No system can guarantee absolute security, but we design SkyyCast to limit what data is exposed and to whom.
Your rights
Depending on where you live, you may have rights to access, correct, or delete the personal information we hold about you. To exercise any of these rights, contact us at connect@skyycast.com and we'll respond as required by applicable law.
Children's privacy
SkyyCast is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at connect@skyycast.com so we can address it.
International data
SkyyCast is operated from Bhutan. The third-party providers we rely on — including Google, Render, Cloudflare, Paddle, and Bluesky — may store or process data in other countries as part of providing their services to us. By using SkyyCast, you understand that your information may be processed outside of your own country.
Changes to this policy
If we make a material change to how we collect or use your data, we'll update this page and change the "Last updated" date above.
Contact
Questions about this policy or your data can be sent to connect@skyycast.com.
SkyyCast