Last updated May 24, 2026

Privacy Policy

Skyline is a security product, so this policy is meant to be direct: what we collect, what the hosted service can see, what agents can see by default, what we share, and how approved secret use works.

What Skyline is

Skyline is a security product for letting agent tools ask to use your saved passwords and API tokens without making the agent a vault owner. This policy explains how Skyline Computer handles data for the Skyline app, hosted service, website, and related tools.

Skyline is designed so normal saved passwords and API tokens are encrypted before they are stored in Skyline's hosted service. The hosted service stores encrypted secret packages and metadata, not the normal secret plaintext or the private key material needed to decrypt those packages.

Data we collect

Vault data: encrypted secret packages, item type, account or service labels, usernames, service names, login URLs, short notes you choose to save, and other metadata needed to identify the right item.

Setup and device data: vault identifiers, device identifiers, requester or computer names, setup sessions, import sessions, approval requests, decisions, and audit history.

Account and service data: entitlement status, subscription or billing status from Apple where applicable, support messages, waitlist signups, and email addresses if you give them to us.

Security and abuse data: logs, rate-limit records, hashed IP or install identifiers, diagnostic events, and similar data used to protect the service.

App diagnostics and feedback: if you send feedback or if a crash is reported through app distribution, crash-reporting, or support tools, we may receive comments, screenshots, app version, device, operating-system, and diagnostic information.

Secret values and metadata

Passwords, API tokens, and similar secret values are treated differently from metadata. For normal vault items, Skyline's hosted service is built to receive encrypted secret packages, not plaintext passwords or API tokens.

Metadata such as service names, login URLs, usernames, labels, short notes, request summaries, device and requester names, decisions, and approval history can still be sensitive. We use it only to operate, secure, debug, and support Skyline.

Agents and local secret use

In normal Skyline flows, agents receive metadata, approval status, and action results, not raw passwords or API tokens in chat or tool output. Skyline can fill a browser password field, run a command with a secret as an environment variable, render a local config file, or capture a generated secret without returning the secret value to the agent.

Some approved uses happen on your trusted local device or in the destination you choose. If you explicitly approve a reveal-style fallback, render a secret file, run a command with secrets, copy a secret, or send a secret to a website or app, the value may exist on that approved local machine, in that browser page, child process, file, pasteboard, or destination service. Requester agents do not receive a vault-wide master key.

How we use data

We use data to create and run your vault, route approval requests, sync encrypted packages, show audit history, import selected records, manage devices and requesters, prevent abuse, provide support, and manage hosted access or billing.

When automatic policy review is enabled, Skyline may send non-secret request context, safe metadata, instructions, and recent request history to a model provider such as OpenAI so the policy system can help allow or deny routine requests. We do not intentionally send raw password or API-token values for this review.

What we do not do

We do not sell your personal data.

We do not use Skyline data for ads.

We do not track you across other companies' apps or websites for advertising.

We do not intentionally store normal saved passwords or API tokens as plaintext in Skyline's hosted service.

We do not intentionally put normal secret plaintext in analytics, logs, crash reports, support exports, or AI policy-review prompts.

Sharing with service providers

We share data with service providers only as needed to run Skyline. These may include app distribution, payment, notification, hosting, database, DNS, and security providers; model providers for automatic policy review; and support or email tools if you contact us.

We require providers that handle user data for Skyline to protect it consistently with this policy and to use it only for the service they provide to us.

Security

Skyline uses encrypted secret packages, local authentication, trusted local helpers, access controls, audit history, and log-redaction practices to protect user data.

Authorized apps and processes can use protected values through Skyline's local path, but agents do not get a synced local vault or reusable bearer token for the vault. When a use is allowed, Skyline releases an encrypted package to the selected trusted local helper or device.

Approved devices and destinations are part of your trust boundary. If a secret is revealed, copied, filled into a website, rendered to a file, provided to a command, or delivered to an approved local helper, plaintext may exist temporarily or persistently on that device or in that destination.

Retention and deletion

We keep data while needed to provide Skyline, protect the service, comply with law, resolve disputes, prevent abuse, and maintain business records.

If you delete your cloud vault from a paired Skyline app, Skyline is designed to remove hosted vault access and hosted vault data associated with that vault. Some limited records may remain for a time in backups, logs, security records, billing records, or legal records.

Your choices

You can choose what to import, which requests to approve, whether to allow notifications, and whether to send app feedback.

You can request help, correction, export, or deletion by contacting us. Some data may be retained where needed for security, legal, billing, backup, or abuse-prevention reasons.

Children

Skyline is not intended for children, and we do not knowingly collect personal data from children.

Changes

We may update this policy as Skyline changes. If changes are material, we will update the date below and provide notice where appropriate.