PRIVACY POLICY

Last updated April 24, 2026

This Privacy Policy for Skyly Technologies LLC (doing business as Skyly) ("Skyly," "we," "us," or "our") describes how and why we access, collect, store, use, and share (collectively, "process") your personal information when you use our services ("Services"), including when you:

  • • Download and use our mobile application (Skyly) on iOS or Android, or any other application of ours that links to this Privacy Policy.
  • • Use Skyly. Skyly is a social networking and dating platform for the aviation community that enables users to create profiles, discover and match with others, and communicate through in-app messaging, with optional identity verification and paid subscription features.
  • • Engage with us in other related ways, including customer support, marketing, or events.

Questions or concerns? Reading this Privacy Policy will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our practices, please do not use our Services. If you have questions, please contact us at contact@skylyapp.com.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Policy. For more detail, use the table of contents below to find the full section. What personal information do we process? When you visit, use, or navigate our Services, we process personal information depending on how you interact with us, the choices you make, and the features you use. Do we process any sensitive personal information? Yes. With your consent, or as otherwise permitted by applicable law, we process sensitive personal information, including precise geolocation, information about sexual orientation, and the contents of in-app messages you send to other users. Where required, we also process government-issued identification and aviation credential documents that you submit for identity verification. Do we collect information from third parties? We collect limited information from authentication providers (Google Sign-In and Apple Sign-In) when you choose to register or log in using those services, and from service providers that support verification, messaging, and payment functions on our behalf. How do we process your information? We process your information to provide, maintain, and improve the Services; to facilitate matches and messaging between users; to prevent fraud and enforce our terms; to communicate with you; and to comply with law. We do not use your personal information for cross-context behavioral advertising. When and with whom do we share personal information? We share personal information with service providers that support our infrastructure, authentication, verification, messaging, push-notification, and billing functions; in certain legal or corporate-transfer circumstances; and, for public profile content, with other users of the Services. How do we keep your information safe? We maintain administrative, technical, and organizational safeguards designed to protect personal information. No electronic system is perfectly secure; we do not guarantee absolute security. What are your rights? Depending on where you reside, applicable privacy law gives you rights over your personal information, including rights of access, correction, deletion, portability, and, in certain circumstances, the rights to opt out of processing and to limit our use of sensitive personal information. How do you exercise your rights? You may email us at privacy@skylyapp.com, delete your account from within the app, or contact us at the address provided at the end of this Policy. We will consider and respond to your request in accordance with applicable law.

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you provide to us when you create an account, use the Services, or contact us. We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our Services, participate in activities on the Services, or otherwise contact us. Personal information provided by you. The personal information we collect depends on the context of your interactions with us and the Services, the choices you make, and the features you use. The personal information we collect includes:

  • • name;
  • • email address;
  • • mobile phone number;
  • • username;
  • • date of birth (used to confirm that you meet our minimum age requirement and for matching);
  • • gender and visibility settings;
  • • sexual orientation (where you choose to provide it);
  • • profile photos;
  • • profile details including bio, interests, languages spoken, and dating mode preference;
  • • aviation-related profile information including professional role, airline or employer, and base city;
  • • lifestyle preferences (available on higher-tier subscriptions), including preferences regarding smoking, drinking, children, and relationship type;
  • • discovery location and passport-mode location preferences you set within the app;
  • • user-to-user chat messages (content and any attachments) between you and other users;
  • • user interaction data, including likes, matches, blocks, and reports;
  • • feedback you submit to us; and
  • • records of your acceptance of our Terms of Service and this Privacy Policy, including timestamps.

Authentication information. When you create an account, we collect credentials used to authenticate you. Password credentials are handled by our authentication provider (Supabase) and are not stored by Skyly in plain text. Where you choose to register or log in using Google Sign-In or Apple Sign-In, we receive authentication tokens and limited profile information as described in Section 6. Identity verification information. Where you voluntarily participate in identity verification, we collect government-issued photo identification, FAA documentation (where applicable), airline or crew employment documentation, and airline or crew badge imagery. Verification documents are reviewed by authorized Skyly personnel only and are not visible to other users. Sensitive personal information. With your consent, or as otherwise permitted by applicable law, we process the following categories of sensitive personal information:

  • • precise geolocation (see "Application data" below);
  • • information about your sexual orientation;
  • • government-issued identification documents and aviation credential verification documents that you submit for verification purposes; and
  • • the contents of in-app messages you exchange with other users.

We do not process biometric information for the purpose of uniquely identifying a consumer, and we do not collect Social Security numbers. We do not use sensitive personal information for the purpose of inferring characteristics about you. Where our use of sensitive personal information goes beyond the purposes permitted under 11 C.C.R. § 7027(m), California residents may exercise the Right to Limit described in Section 13. Social media login information. If you register using a social login, we collect limited profile information from the provider as described in Section 6. Application data. If you use our mobile application, we may collect the following information with your permission:

  • • Geolocation information. We request permission to access precise location data from your mobile device when the application is in use, in order to provide location-based features including discovery and matching. We do not track your location in the background. You may revoke permission at any time in your device settings; note that certain Services will be unavailable without it.
  • • Mobile device access. We request access to your device camera and photo library so that you may upload profile photos and verification documents. You may grant or revoke these permissions in your device settings.
  • • Mobile device data. We collect limited device information, including device type (iOS or Android), operating system and version, device identifiers, application version, IP address or proxy server, and limited system-configuration data, which we use to operate and secure the Services.
  • • Push notifications. With your permission, we send push notifications regarding your account and Services activity. You may disable push notifications in your device settings at any time.

All personal information you provide must be true, complete, and accurate, and you must notify us of any material changes.

Information automatically collected

In Short: When you use the Services, we automatically collect certain technical and usage information. We automatically collect limited technical and usage information when you access or use the Services. This information is used to operate, secure, diagnose, and improve the Services. It includes:

  • • Log and usage data. Service-related, diagnostic, and performance information that our servers record when you access the Services, including IP address, date and time stamps, application events, errors and crash reports, pages and screens viewed, searches run, and features used.
  • • Device data. Device type, operating system and version, device identifiers, application version, hardware model, network carrier (where applicable), and locale.
  • • Location data. As described above, we collect precise location data only while the application is in use and with your permission. We do not track location in the background.
  • • User-interaction and behavioral-event data. Information generated by your activity within the application, including swipes, likes, matches, blocks, reports, chat activity, feedback submissions, banner dismissals, and similar in-app events.

Information collected from other sources

In Short: We collect limited information from authentication providers and from service providers that assist us with verification and communications. We do not purchase personal information from data brokers. Where you register or log in using Google Sign-In or Apple Sign-In, we receive authentication tokens and limited profile information (name, email address, and a unique identifier) from the provider, as further described in Section 6. We also receive information from service providers that support phone verification (Twilio), subscription management (RevenueCat), push notifications (OneSignal and Firebase Cloud Messaging), and city-level location autocomplete (Google Places).

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, maintain, and improve the Services; to facilitate matches and messaging; for security and fraud prevention; and to comply with law. We process your personal information for the following purposes, depending on how you interact with the Services:

  • • To create, authenticate, and administer your account. Including password authentication and sign-in through Google or Apple.
  • • To deliver and operate the Services. Including presenting profiles, generating matches, enabling in-app messaging, and providing location-based discovery.
  • • To provide optional identity verification. For users who submit verification documentation, we review and, where appropriate, mark verified status on the profile.
  • • To enable user-to-user communication. Including routing messages, notifying you of matches and activity, and processing blocks and reports.
  • • To process payments for subscriptions. Through Apple App Store (StoreKit), Google Play Billing, and RevenueCat. Skyly does not receive or store your payment card or financial-account information.
  • • To send administrative communications. Including changes to our terms and policies, service announcements, and responses to your inquiries.
  • • To protect the Services and our users. Including fraud detection, abuse prevention, enforcement of our Terms of Service, content moderation, and the handling of reports and blocks.
  • • To maintain security. Including detecting and responding to security incidents, preserving the integrity of the Services, and protecting against illegal activity.
  • • To understand usage and improve the Services. Including product analytics we conduct ourselves using data stored in our backend; we do not use third-party advertising or behavioral-analytics software development kits.
  • • To protect vital interests. Where necessary to protect the life or physical safety of a person.
  • • To comply with legal obligations. Including responding to lawful requests from public authorities.

In Short: We process personal information only where we have a valid legal basis under applicable law. If you are located in the EEA, the United Kingdom, or Switzerland The General Data Protection Regulation (Regulation (EU) 2016/679) and the UK General Data Protection Regulation require us to identify a valid legal basis for processing personal information. We rely on the following legal bases:

  • • Performance of a contract (Art. 6(1)(b)). To provide the Services you request, authenticate you, facilitate matching and messaging, process subscriptions, and perform our Terms of Service.
  • • Consent (Art. 6(1)(a) and, for special categories, Art. 9(2)(a)). For processing of sensitive personal information that you voluntarily share, including information about sexual orientation, and for access to precise location and device features. You may withdraw your consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • • Legal obligation (Art. 6(1)(c)). To comply with applicable law, including responding to lawful requests from public authorities and retaining records where required.
  • • Vital interests (Art. 6(1)(d)). To protect the life or physical safety of you or another person.
  • • Legitimate interests (Art. 6(1)(f)). To secure the Services, prevent fraud and abuse, enforce our Terms of Service, analyze usage to improve our product, and conduct ordinary business administration. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms; you may object to this processing as described in Section 11.

If you are located in Canada We may process your personal information with your express or, where permitted, implied consent. In limited circumstances set out in the Personal Information Protection and Electronic Documents Act and provincial equivalents, we may process personal information without consent, including where processing is clearly in your interest and consent cannot be obtained in a timely manner, where necessary to investigate a breach of contract or a contravention of Canadian law, where required by subpoena, warrant, or court order, or where the information is publicly available in the manner specified by regulation.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We share personal information with service providers that support the Services, with other users for public profile content, and in limited legal or corporate-transfer circumstances. Service providers. We share personal information with third-party service providers that perform functions on our behalf under written contracts that restrict their use of the information to the services they provide to us. Our current service providers include:

  • • Supabase — database, authentication, file storage (including profile photos and verification documents), and server-side application logic.
  • • Google Sign-In — optional OAuth-based account registration and sign-in.
  • • Apple Sign-In — optional OAuth-based account registration and sign-in.
  • • Apple App Store (StoreKit) and Google Play Billing — in-app subscription billing on iOS and Android respectively.
  • • RevenueCat — subscription-state management and entitlement tracking linked to your account identifier.
  • • Twilio — SMS delivery for phone-number verification.
  • • OneSignal — mobile push-notification delivery.
  • • Firebase (Google) — push-notification delivery (Firebase Cloud Messaging) and hosting for our landing page and administrative panel.
  • • Google Places API — city-level location autocomplete in profile and discovery fields.
  • • Google Maps Platform — mapping and location services where you interact with map-based features.

Other users. Information that you include in your public profile, and information you share in public areas of the Services, is visible to other users and may remain visible after you leave the Services. Messages you send to other users are visible to the intended recipient. Reports you submit about other users are reviewed by Skyly personnel; your identity as the reporter is not disclosed to the reported user. Legal process and public authorities. We may disclose personal information where we believe in good faith that disclosure is required or permitted by law, including to comply with a subpoena, court order, or other lawful request; to cooperate with law enforcement; to establish or defend our legal rights; or to protect the rights, property, or safety of Skyly, our users, or others. Business transfers. We may share or transfer personal information in connection with a merger, acquisition, financing, reorganization, sale of company assets, or due-diligence activity. Where such a transfer occurs, we will take reasonable steps to ensure the recipient is bound by privacy obligations consistent with this Policy, and we will notify affected users where required by applicable law. With your consent. We may share personal information for any other purpose disclosed to you at the point of collection with your consent. Google Maps Platform. When you use map-related features, we transmit limited location information to Google Maps Platform APIs. Your use of Google Maps features is subject to Google's terms and privacy policy. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

In Short: Our mobile application uses limited on-device storage to operate. We do not use third-party advertising cookies, behavioral advertising software development kits, or cross-context behavioral advertising. Skyly is distributed as a mobile application. The application uses limited on-device storage and device identifiers provided by the operating system to maintain session state, manage push-notification tokens, cache location data briefly for performance, and operate security and fraud-prevention functions. Third-party software development kits used by the Services (for example, the authentication, push-notification, and billing kits identified in Section 4) may store tokens or identifiers on your device for the purposes of those functions. We do not serve behavioral or targeted advertisements within the Services, and we do not use third-party advertising or behavioral-analytics kits. We do not engage in cross-context behavioral advertising as that term is defined in the California Consumer Privacy Act, and we do not engage in targeted advertising as that term is defined in the state privacy laws of Virginia, Colorado, Connecticut, Oregon, Texas, or other states. Our landing page and administrative panel, hosted separately, may use strictly necessary and limited analytics cookies; where applicable, a cookie notice on those surfaces describes this use.

6. HOW DO WE HANDLE YOUR SOCIAL LOGINS?

In Short: If you choose to register or log in using Google Sign-In or Apple Sign-In, we receive limited profile information from the provider. The Services offer the option to register and log in using your Google or Apple account. Where you choose to do so, we receive an authentication token and limited profile information from the provider, which may include your name, email address, and a unique identifier. We use this information to authenticate you and to create or link your Skyly account. We do not control, and are not responsible for, other uses of your personal information by Google or Apple. We recommend that you review their privacy notices to understand how they process your personal information and to manage your preferences on their services.

7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

In Short: We are based in the United States. Where permitted by law, we transfer personal information to the United States and to other countries where our service providers operate. Our servers are located in the United States. Regardless of where you reside, your information may be transferred to, stored in, or processed in the United States and in other countries where our service providers operate. These countries may have data-protection laws that differ from those of your country. Transfers from the European Economic Area, the United Kingdom, and Switzerland. Where we transfer personal information from the EEA, the United Kingdom, or Switzerland to a country that the European Commission, the United Kingdom, or the Swiss Federal Data Protection and Information Commissioner has not determined to provide an adequate level of protection, we rely on appropriate safeguards, including the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914, Module 2 for controller-to-processor transfers and, where applicable, Module 3 for processor-to-processor transfers), the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner's Office (or, where applicable, the UK International Data Transfer Agreement), and analogous Swiss protections. Copies of these safeguards are available on request by writing to privacy@skylyapp.com. Skyly is not currently certified under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or the Swiss-U.S. Data Privacy Framework, and we do not currently rely on binding corporate rules. If this changes, we will update this Policy.

8. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We retain personal information only for as long as necessary to provide the Services, to comply with law, and to exercise or defend legal rights. We retain personal information only for as long as necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law. The following retention practices apply to our core data categories:

  • • Account and profile data. Retained while your account is active. When you delete your account, we promptly initiate deletion of your account and profile data from our active systems.
  • • Verification documents. Deleted promptly upon account deletion.
  • • Profile photos. Deleted promptly upon account deletion.
  • • Phone-verification records (including one-time passcodes). Deleted promptly upon account deletion; one-time passcodes are retained for only as long as needed to complete verification.
  • • Messages and match records. Retained while your account exists; deleted upon account deletion.
  • • Reports and safety records. Retained for as long as reasonably necessary to maintain the integrity of the Services, investigate abuse, enforce our Terms of Service, and defend legal claims.
  • • Billing and subscription metadata held by Skyly. Retained for as long as reasonably necessary to manage the subscription relationship and to comply with tax, accounting, and audit obligations. Payment card and financial-account information is not held by Skyly; that information is processed and retained by Apple, Google, and RevenueCat under their own policies.
  • • Security, fraud-prevention, and legal-compliance records. Retained for as long as reasonably necessary to fulfill those functions.

Where we no longer have a legitimate business need to process your personal information, we will delete or de-identify it, or, where that is not immediately possible (for example, where information has been stored in backup archives), we will isolate it from active processing until deletion is possible.

9. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We maintain administrative, technical, and organizational safeguards designed to protect personal information. We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption in transit, logical segregation of sensitive data such as verification documents, and operational practices for authentication, incident response, and vendor management. No electronic transmission over the Internet and no method of information storage can be guaranteed to be entirely secure. We do not guarantee absolute security, and transmission of personal information to and from the Services is at your own risk.

10. DO WE COLLECT INFORMATION FROM MINORS?

In Short: The Services are not directed to, and not intended for use by, anyone under 18 years of age. We do not knowingly collect personal information from anyone under 18. The Services are intended for adults only. Our Terms of Service require that all users be at least 18 years of age. We do not knowingly collect personal information from individuals under 18, and we do not direct our Services to anyone under 18. If we learn that we have collected personal information from a user under 18, we will deactivate the account and take reasonable steps to delete the information from our records. If you believe we may have collected personal information from a person under 18, please contact us at privacy@skylyapp.com. Because the Services are not directed to users under 13 and we do not knowingly collect information from users under 13, the Children's Online Privacy Protection Act does not apply to our processing. For the same reason, the California Consumer Privacy Act's opt-in requirement for the sale or sharing of personal information of consumers under 16 is not engaged; we do not in any case sell or share personal information, as described in Section 13.

11. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: Depending on where you reside, applicable privacy law gives you rights over your personal information. This section describes your rights and how to exercise them. Rights under EEA, UK, and Swiss law If you are located in the EEA, the United Kingdom, or Switzerland, applicable data-protection law gives you the following rights, subject to the conditions and limitations set out in law:

  • • the right of access to the personal information we hold about you;
  • • the right to rectification of inaccurate or incomplete personal information;
  • • the right to erasure of personal information in certain circumstances;
  • • the right to restriction of processing in certain circumstances;
  • • the right to data portability in respect of personal information you have provided to us, where we rely on consent or contract and processing is carried out by automated means;
  • • the right to object to processing carried out on the basis of legitimate interests;
  • • the right to withdraw consent at any time where processing is based on consent; and
  • • the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.

You may exercise these rights by contacting privacy@skylyapp.com. You also have the right to lodge a complaint with your local data-protection authority. A list of EEA supervisory authorities is maintained by the European Data Protection Board at edpb.europa.eu. UK residents may contact the Information Commissioner's Office at ico.org.uk. Swiss residents may contact the Federal Data Protection and Information Commissioner at edoeb.admin.ch. Automated decision-making We use algorithmic matching to suggest profiles that may be relevant to you. These suggestions do not produce legal effects or similarly significant effects and do not constitute solely automated decision-making within the meaning of Article 22 of the GDPR. We do not otherwise make decisions about you based solely on automated processing that produce legal or similarly significant effects. If our use of automated decision-making changes, we will update this Policy and, where required, provide additional information and choices. Withdrawing consent Where we rely on your consent, you may withdraw consent at any time by adjusting your settings in the application, revoking device permissions, or contacting privacy@skylyapp.com. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, and it does not affect processing conducted on other lawful bases. Account information You may review or update the information in your account at any time through the application settings. You may delete your account from within the application. On deletion, we deactivate the account and promptly initiate deletion of your account information from our active systems. We may retain limited information as necessary to prevent fraud, enforce our Terms of Service, resolve disputes, or comply with applicable law. Cookies and tracking technologies As described in Section 5, we do not use advertising or behavioral-analytics cookies or kits in the application. On our landing page and administrative panel, where applicable, you may use your browser settings to manage cookies. If you have questions about your privacy rights, you may email us at privacy@skylyapp.com.

12. CONTROLS FOR DO-NOT-TRACK FEATURES AND GLOBAL PRIVACY CONTROL

In Short: Because we do not engage in cross-context behavioral advertising or sell personal information, opt-out preference signals do not presently result in a change to our processing. Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") setting. At this time, there is no uniform technical or legal standard for recognizing and responding to DNT signals. We do not currently respond to DNT signals. We also recognize the Global Privacy Control ("GPC") signal and Universal Opt-Out Mechanism signals required by the privacy laws of California, Colorado, Connecticut, Oregon, Texas, Montana, and other states. Because we do not sell personal information, do not share personal information for cross-context behavioral advertising, and do not engage in targeted advertising as defined in those laws, a GPC or Universal Opt-Out Mechanism signal does not presently result in a change to our processing. If our practices change such that an opt-out would be meaningful, we will honor opt-out preference signals in accordance with applicable law and update this Policy.

13. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

In Short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you have rights under your state's comprehensive privacy law. Those rights are described below. Categories of personal information we collect The following table identifies the statutory categories of personal information we have collected from or about consumers in the preceding twelve months, with illustrative examples. This table reflects the structure of the California Consumer Privacy Act; other states use similar categorical structures. Category Examples Collected A. Identifiers Real name, alias, online identifier, IP address, email address, account name, unique personal identifier YES B. Customer-records categories (Cal. Civ. Code § 1798.80(e)) Name, telephone number, and similar personal information YES C. Protected-classification characteristics Age, gender, sex, sexual orientation YES D. Commercial information Records of subscriptions purchased or considered YES E. Biometric information Biometric identifiers used to identify a consumer NO F. Internet or other similar network activity In-application activity, interactions with Services, device and session information YES G. Geolocation data Precise device location when the application is in use; city-level location YES H. Audio, electronic, visual, or similar information Profile photos and images users upload; in-app messages (including any attachments) YES I. Professional or employment-related information Aviation professional role, airline or employer, and base city that users voluntarily share YES J. Education information Non-public education records NO K. Inferences drawn from collected information Matching relevance scores derived from profile and interaction data YES L. Sensitive personal information Precise geolocation; information about sexual orientation; government-issued identification (for verification); contents of in-app messages YES We collect sensitive personal information as permitted by applicable privacy law or with your consent. The purposes for which we process sensitive personal information are described in Section 1 and Section 2. Our use of sensitive personal information may in some circumstances extend beyond the purposes enumerated in 11 C.C.R. § 7027(m); California residents accordingly may exercise the Right to Limit, as described below. Sources of personal information The categories of sources from which we collect personal information are (i) consumers directly, (ii) authentication providers (Google Sign-In and Apple Sign-In, where a consumer elects to use them), and (iii) service providers identified in Section 4 that assist with verification, communications, and billing functions. How we use and share personal information The business and commercial purposes for which we process personal information are set out in Section 2. We disclose personal information to the categories of service providers and other recipients identified in Section 4. Sale and sharing of personal information We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We have not sold or shared personal information, as those terms are defined in the California Consumer Privacy Act, within the preceding twelve months. We do not engage in targeted advertising as that term is defined in the comprehensive privacy laws of Virginia, Colorado, Connecticut, Oregon, Texas, Utah, Delaware, Maryland, Minnesota, Montana, Tennessee, Indiana, Iowa, New Hampshire, New Jersey, or Kentucky. Because we do not sell, share, or engage in targeted advertising, no "Do Not Sell or Share My Personal Information" link is required or provided. If our practices change, we will update this Policy before beginning any such processing and will provide the disclosures and opt-out mechanisms then required by law. Your rights Subject to the limits set out in applicable law, residents of the states listed above may have the following rights:

  • • the right to confirm whether we are processing their personal information and to access it;
  • • the right to a copy of their personal information in a portable, readily usable format;
  • • the right to correct inaccuracies in their personal information;
  • • the right to request deletion of their personal information;
  • • the right to opt out of the sale of personal information, the sharing of personal information for cross-context behavioral advertising, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects (rights that, as described above, are not presently exercisable because we do not engage in any of these activities);
  • • the right of California residents to limit our use and disclosure of sensitive personal information to the purposes permitted under 11 C.C.R. § 7027(m);
  • • the right to non-discrimination for exercising any of these rights; and
  • • the right, under the laws of certain states, to obtain a list of the categories or specific third parties to which personal information has been disclosed.

How to exercise your rights You may exercise your rights by (i) emailing privacy@skylyapp.com, (ii) using the in-app account-deletion feature for deletion requests, or (iii) writing to us at the address set out in Section 15. To submit a request to limit our use or disclosure of sensitive personal information, email privacy@skylyapp.com with the subject line "Right to Limit." We will acknowledge receipt of your request within ten business days and will substantively respond within forty-five days (extendable by an additional forty-five days where reasonably necessary, with notice to you). Authorized agents You may use an authorized agent to submit a request on your behalf. We may require written proof of the agent's authority (for example, a signed permission or a power of attorney) and verification of your identity. Verification We will verify your identity before responding to a request. We will use information you provide in your request, together with information we already maintain, and may ask for additional information reasonably necessary to verify your identity consistent with applicable privacy-law regulations. Appeals If we decline to take action on your request, you may appeal by emailing privacy@skylyapp.com with the subject line "Privacy Appeal." We will respond to your appeal within the time required by applicable law, with an explanation of the action taken or not taken. Where your appeal is denied, you may contact your state attorney general; Colorado residents may also contact the Colorado Department of Law, and Connecticut residents may contact the Connecticut Attorney General's Privacy and Data Security Section.

14. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: We will update this Policy from time to time to reflect changes to our practices and to comply with applicable law. We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this Policy. Where a change is material, we will notify you through the Services or by other reasonable means before the change takes effect. We encourage you to review this Policy periodically to remain informed of our privacy practices.

15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this Policy or wish to exercise any of the rights described above, you may contact us at: Skyly Technologies LLC 1063 North Cypress Point Drive Venice, FL 34293 United States Email: privacy@skylyapp.com EU representative. Skyly has not appointed an Article 27 representative in the European Union or the United Kingdom. If our Services are determined to be directed to the Union or the United Kingdom in a manner that triggers the Article 27 requirement, we will appoint a representative and update this Policy accordingly. EEA, UK, and Swiss residents may contact us in the meantime at privacy@skylyapp.com.

16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Depending on the applicable laws of your country or state of residence, you may have the right to request access to, correction of, or deletion of the personal information we hold about you, or to withdraw consent to our processing. You may submit a request by emailing privacy@skylyapp.com or by using the in-app account-deletion feature for deletion requests. We will respond in accordance with applicable law.