Legal
Privacy Policy
Effective: August 5, 2026 · Last updated: August 5, 2026
This Privacy Policy explains how SkyPath VPN ("SkyPath", "we", "us", or "our") handles information when you use the SkyPath VPN Android application (the "App") and the website at skypath.cloud (the "Website"). It is written to meet Google Play's User Data and VpnService policy expectations, and to match what the App and our servers actually do.
If you do not agree with this policy, please do not use SkyPath.
1. The Short Version
- You do not need an account, email, phone number, or any personal profile to use SkyPath.
- We do not log the websites you visit, your DNS queries, or the content of your internet traffic.
- We do not sell, rent, or trade user data.
- We do not use Android's
VpnServiceto inspect, modify, inject into, or monetize other apps' traffic. - To run the VPN we store a WireGuard public key, an assigned tunnel IP, and related device-registration metadata.
- The App uses Google Firebase Crashlytics and Firebase Analytics for stability and product improvement.
- You can request deletion of data we hold about you at any time (see Section 12).
2. Who Controls Your Data
The data controller for information collected through the App and Website is:
- Legal entity: Servicios De Informática y Diseño, S.P.A.
- Product / brand: SkyPath (Google Play package
cloud.skypath.vpn) - Address: Morande 835 P 5 Of518, 8340155 Región Metropolitana, Chile
- Privacy contact: privacy@skypath.cloud
- Support: support@skypath.cloud
If you are in the European Economic Area (EEA) or the United Kingdom, you may contact us at the same privacy address for matters relating to the EU General Data Protection Regulation (GDPR) or the UK GDPR.
3. Our VPN Service Commitment (Google Play VpnService)
SkyPath is a VPN app. Providing a VPN is the App's core functionality. The App uses Android's VpnService API solely to create an encrypted device-level tunnel to our VPN servers when you choose to connect.
In line with Google Play's VpnService policy, we commit that:
- The VPN connection is used solely to provide the VPN service you request when you tap Connect and grant Android's system VPN permission.
- All data from the device to the VPN tunnel endpoint is encrypted using the WireGuard protocol.
- We do not inspect, read, modify, rewrite, or redirect the content of your traffic for advertising, affiliate, tracking, or other monetization purposes.
- We do not collect personal or sensitive information from the contents of your VPN traffic.
- We do not use the VPN tunnel to inject advertisements, affiliate links, tracking scripts, or to alter data that passes through it.
- We do not redirect or manipulate traffic from other apps on your device for monetization (including relocating ad traffic to another country).
- Use of
VpnServiceis documented in our Google Play listing, and the first connection requires Android's standard VPN permission prompt.
These commitments also appear in our Terms of Use.
4. Data Safety Summary
This summary is intended to align with Google Play's Data Safety form. Declarations in Play Console must match this policy. "Shared" below means transfer to a third party for that party's own purposes — not processing by a service provider acting on our instructions (see Section 9).
| Data type | Collected | Shared | Purpose | Optional |
|---|---|---|---|---|
| Personal info (name, email, phone, address) | No | No | — | — |
| Email address (only if you contact support) | Yes | No | Respond to your message | Yes — only if you email us |
| Financial info | No | No | — | — |
| Precise or approximate location | No | No | — | — |
| Photos, videos, audio, files, contacts, calendar, SMS, call logs | No | No | — | — |
| Web browsing history, search history, DNS queries, traffic content | No | No | — | — |
| App activity (in-app events, e.g. connect attempt, server selected) | Yes | No | Analytics & product improvement (Firebase Analytics) | No — collected while the App is installed |
| Crash logs and diagnostics (device model, OS version, app version, stack trace) | Yes | No | Fix bugs and improve stability (Firebase Crashlytics) | No — collected while the App is installed |
| Device or other IDs (Firebase installation ID; WireGuard public key used as device identity) | Yes | No | Operate VPN registration; analytics and crash attribution | No — required for the VPN to work / diagnostics |
| VPN device registration (WireGuard public key, assigned tunnel IP, device id, created time) | Yes | No | Provision WireGuard peers, route traffic, operate and secure the service | No — required to provide the VPN |
| Connection diagnostics (optional connect-failure reports: server id, stage, error code, app version) | Yes | No | Detect broken paths and improve reliability | Generated only when a connection attempt fails |
Data encryption in transit: yes — VPN traffic is encrypted via WireGuard from the device to the VPN tunnel endpoint; App-to-API calls use HTTPS.
Data deletion requests: yes — see Section 12. SkyPath does not use accounts; deletion covers device registration and other data we can locate.
Children / Families: SkyPath is not directed at children and is not enrolled in Google Play's Designed for Families program. See Section 13.
5. Details of What We Collect
5.1 Information you provide
You do not need to create an account or provide personal information to install or use the App. If you email us for support or privacy requests, we receive your email address and message content so we can reply.
5.2 Information collected to operate the VPN
- Device registration. When you first connect, the App sends your WireGuard public key to our API. We assign a tunnel IP address (for example in a private VPN range), store a device id, and record when the device was created. This registry is required so VPN servers can accept your peer and route your encrypted traffic. We do not receive or store your WireGuard private key.
- Connect-failure diagnostics. If a connection attempt fails, the App may send the selected server id, failure stage, error code, timestamp, and app version so we can detect broken paths. These reports do not include browsing content or your WireGuard private key.
- Server-side operations. VPN servers and our control plane keep operational metrics needed to run the service (for example aggregated bandwidth and peer counts per server, and short-lived security/abuse signals such as request IP addresses). We do not build a browsing or DNS history from VPN traffic.
5.3 Crash reports and analytics
- Crash reports (Firebase Crashlytics). If the App crashes, diagnostic data such as device model, Android version, App version, stack trace, and a Firebase installation ID may be sent to Google Firebase Crashlytics so we can fix bugs.
- Product analytics (Firebase Analytics). Anonymous or pseudonymous product events (for example app open, connect attempt/success/fail, disconnect, server selected) may be sent through Firebase Analytics to understand aggregate usage.
These diagnostics help keep SkyPath stable. They are not used to build advertising profiles, and they are not derived from the contents of your VPN traffic.
5.4 Website
Our Website and free diagnostic tools may collect standard server logs (IP address, user-agent, request path) retained for security and abuse prevention, and may process IP addresses you look up when using geolocation tools. See Section 9 for MaxMind GeoLite2.
5.5 What we deliberately do NOT collect
- We do not keep logs of the websites you visit, the apps you use through the tunnel, your DNS query names, or any other content of your traffic.
- We do not require or collect name, email, phone number, or payment details to use the VPN.
- We do not request location, contacts, SMS, call log, microphone, camera, photos, files, or calendar permissions.
- We do not sell personal and sensitive user data.
- Advertising SDKs may be present in the App binary for future use, but ads are disabled in the current release. We do not use the Android Advertising ID for ads while advertising remains disabled. If we enable ads, we will update this policy and the Play Data Safety form before that change ships.
6. How We Use Information
- Operate the VPN — register devices, provision WireGuard peers, establish and maintain tunnels, and select or list servers.
- Keep it safe — detect and block abuse, DDoS, and attempts to disrupt the service.
- Fix bugs — reproduce crashes and failures using Crashlytics and connect-failure reports.
- Improve the App — analyze aggregate product events via Firebase Analytics.
- Answer support questions — if you email us.
- Comply with the law — if we receive a valid legal request. Because we do not log browsing activity, we typically have limited information to disclose.
We do not use your data for automated decision-making that produces legal or similarly significant effects on you. We do not engage in profiling for advertising.
7. Legal Bases (EEA / UK)
If you are in the EEA or UK, the legal bases on which we rely under the GDPR are:
- Performance of a contract (Article 6(1)(b)) — to provide the VPN service after you tap Connect and grant the system VPN permission.
- Legitimate interests (Article 6(1)(f)) — keeping the service secure, preventing abuse, diagnosing failures, and improving stability. These interests are balanced against your privacy, which is why we avoid traffic-content logging.
- Legal obligation (Article 6(1)(c)) — to comply with applicable law.
8. Sharing and Disclosure
We do not sell your data. We share or disclose data only in these limited cases:
- Service providers (processors). Providers who process data on our behalf under contractual terms — notably Google Firebase for crash reporting and analytics. See Section 9.
- Legal requirements. We may disclose information if compelled by valid legal process, or to protect our rights, safety, or those of our users.
- Business transfers. If SkyPath is acquired, merged, or reorganized, data may transfer as part of that transaction. We will notify users through the App or Website before any material change to how data is handled.
9. Third-Party Services (SDKs)
For transparency, here is every third party that may receive data from the App or Website tools, what they get, and why. We remain responsible under Google Play's User Data policy for third-party code included in the App.
| Provider | Purpose | Data processed | Policy |
|---|---|---|---|
| Google Firebase Crashlytics | Crash reporting | Device model, OS version, app version, stack trace, installation ID | Firebase Privacy |
| Google Firebase Analytics | Product analytics | Event names (e.g. connect), installation ID, coarse device metadata | Firebase Privacy |
| Google Play Services | App distribution, updates, security checks | Managed by Google Play on the device | Google Privacy |
| WireGuard (open-source library) | VPN protocol on-device | No browsing data leaves the device through WireGuard itself beyond the encrypted tunnel to our servers | WireGuard |
| MaxMind GeoLite2 | IP geolocation for Website tools | IP addresses you look up or that we resolve for tool results | MaxMind Privacy |
Website IP tools may use a limited fallback provider when local geolocation data is unavailable. Geolocation results may include attribution: “This product includes GeoLite2 data created by MaxMind, available from maxmind.com.”
If we add a new SDK that collects or shares data (for example, ads), we will update this list and the Google Play Data Safety form before it ships.
10. Data Retention
- VPN device registration (public key, assigned tunnel IP, device id, created time) — retained while needed to provide VPN access for that device, and removed when you successfully request deletion or when we revoke inactive or abusive peers as part of operations.
- Connect-failure diagnostics — retained in limited form for reliability and abuse prevention, typically up to 30 days, then deleted or aggregated.
- Crash reports — retained for up to 90 days, then automatically deleted by Firebase Crashlytics (or sooner if you request deletion and we can locate the records).
- Analytics events — retained in Firebase according to our configured retention (typically up to 14 months in aggregated/pseudonymous form).
- Support correspondence — retained for up to 12 months after resolution, then deleted.
- Website server logs — retained for up to 30 days.
11. Data Security
We take reasonable technical and organizational measures to protect the data we handle, including:
- Encrypting VPN traffic with WireGuard from the device to the VPN tunnel endpoint (Curve25519, ChaCha20, Poly1305, BLAKE2s, SipHash24, HKDF).
- Using HTTPS for App-to-API and Website connections.
- Restricting server and console access to authorized administrators using strong credentials and multi-factor authentication where available.
- Applying operating system and library security updates on a regular schedule.
No system is ever 100% secure. While we work to protect information, we cannot guarantee absolute security.
12. Your Rights
Wherever you are, you can:
- Access — ask what data we hold about you.
- Correct or update — ask us to fix inaccurate data.
- Delete — ask us to erase data we hold that relates to you, including VPN device registration where we can identify it.
- Uninstall — at any time. Uninstalling stops further collection from your device, but does not by itself delete your device registration on our servers. Use the deletion request below for that.
To exercise these rights, email privacy@skypath.cloud with the subject line "Privacy Request". We will respond within 30 days. We may ask for details that help us locate records (for example device model, approximate install or first-connect date, or information shown in the App's About screen).
12.1 If you are in the EEA or UK (GDPR / UK GDPR)
In addition to the rights above, you have the right to: restrict processing; object to processing based on legitimate interests; data portability where applicable; and lodge a complaint with your national data protection authority.
12.2 If you are in California (CCPA / CPRA)
California residents have the right to know what personal information we collect, to request its deletion, to correct inaccuracies, and to opt out of the "sale" or "sharing" of personal information. SkyPath does not sell or share personal information as those terms are defined under the CCPA/CPRA. We do not use or disclose sensitive personal information for purposes that would trigger the right to limit under CPRA. We will not discriminate against you for exercising these rights.
12.3 No accounts — device and data deletion
SkyPath does not offer account creation, so Google Play's account-deletion requirements for account-based apps do not apply in the usual sense. To stay aligned with Play's User Data expectations for data control, we provide an external deletion path:
- Email privacy@skypath.cloud with the subject line "Delete My Data".
- Include your device model and approximate install or first-connect date (and any other detail that helps us find your WireGuard device registration).
- We will delete or irreversibly de-identify reachable records (including device registration where identified) within 30 days, except data we must retain for security, fraud prevention, or legal compliance, which we will explain if applicable.
This page (https://skypath.cloud/privacy) is the public web resource for privacy and deletion requests.
13. Children's Privacy
SkyPath is not directed at children under 13 (or the equivalent minimum age under your local law; for example, 16 in some EU member states). We do not knowingly collect personal information from children. SkyPath is not part of Google Play's Designed for Families program. If we learn that we have collected personal information from a child in violation of applicable law, we will delete it promptly. Contact privacy@skypath.cloud if you believe a child has provided us with personal information.
14. International Data Transfers
SkyPath operates VPN and control-plane infrastructure in multiple countries. When you connect to a VPN server, your encrypted traffic passes through that server's location. Crash reports and analytics are processed by Google Firebase, which may transfer data to the United States or other countries where Google operates, under transfer mechanisms described in Google's privacy documentation (including Standard Contractual Clauses where applicable). By using SkyPath you understand that data may be processed in countries different from your own.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will:
- Update the "Last updated" date at the top of this page.
- Notify you in the App (for example, via a banner) or by prominent notice on the Website before the changes take effect, where practical.
- Update the Google Play Data Safety form if collection, sharing, or purposes change.
Your continued use of SkyPath after changes are posted means you accept the updated policy. If you do not agree, please stop using the service and request deletion of your data.
16. Contact
- Privacy questions or deletion requests: privacy@skypath.cloud
- General support: support@skypath.cloud
- Google Play listing: SkyPath VPN