Privacy and cookies
Last updated: 30 September 2026 · A draft awaiting legal review.
Who we are
Skydust is run by IADL ("we"). We are responsible for the information the service keeps about you.
What Skydust stores
- Your account: name, email address, and how you sign in (an emailed code, Google, Apple, GitHub or a passkey). If your sign-in provider has a profile picture, its address is kept to show it in your account menu.
- What is made about your businesses: ideas, plans, tasks, metrics, your conversations with Sky, and a log of every change.
- The line: your email address, how it was confirmed, your number, your share link and how many joined through it, and any places bought.
- Emailed codes are kept only as a keyed hash and stop working after ten minutes. To prevent abuse, a keyed hash of the network a request came from is kept too — never the address itself.
- Skydust uses no passwords. Credentials for accounts you connect to a business (a payment provider's key, for example) are stored encrypted, and no AI model ever sees them.
- The business's phone: when Sky answers a call to a business's number, the call goes through Twilio, and hearing and speaking are done by Google (through Twilio). What is said on the call is kept encrypted; a short summary goes into the business's customer list, with the caller's number. Card numbers, passwords and ID numbers are never asked for on the phone.
- Live View: if you turn on a camera in a business, Sky looks at a still every so often. The still is sent to Cloudflare's AI models (Workers AI), read and dropped — it is never stored anywhere. Only the words and numbers of what was seen are kept (how many people, who is waiting, who is working, what needs attention). No one is identified, faces are never described, and no sound is recorded. Before a camera runs, whoever turns it on confirms there is a sign at the entrance, the staff know, and it faces nothing private.
Why, and what not
To provide the service: to open and run your account, to have Sky work on your businesses, to send the sign-in codes and messages you asked for, and to protect the service from abuse. We don't sell your information, use it for advertising, or share it beyond what is written here.
You are under no legal obligation to give us information. Without a verified email address, an account can't be opened.
Who processes your data
- Cloudflare: hosting, the database, background work, sending email, and AI models (Workers AI).
- Anthropic: the Claude model, which receives the relevant business context while Sky works, through Cloudflare AI Gateway.
- Google, Apple and GitHub: they authenticate you when you choose to sign in with them.
- Hugging Face: Sky's Hebrew voice is a model that runs in your browser (Kyutai's Pocket TTS with a Hebrew adapter by thewh1teagle, licensed CC BY 4.0). The first time, your browser downloads it (about 200 MB) from Hugging Face, which sees your IP address as any website does. What Sky says is made on your device and sent nowhere.
- Morning (Green Invoice): if a business connects it, Skydust reads the receipts the business issues, its unpaid invoices and the expenses recorded there, to know what it earned, what it is owed and the VAT for the period, and to remind the owner when the VAT report is due. If the owner allows it, Sky can also ask a customer to pay: once the owner approves each request, Skydust gives Morning the customer's name, email and phone, the amount and what it is for, and Morning sends the customer a payment page and issues the receipt when they pay. Skydust never sees a card or holds the money, and never changes or cancels a document.
- Stripe: it takes the payment when you pay to move up the line; Skydust never sees your card.
Some of these providers process data outside Israel.
Cookies
Skydust sets only essential cookies. There are no advertising or tracking cookies.
| Cookie | Purpose |
|---|---|
skydust_session | Keeps you signed in. 30 days, renewed while you use Skydust. |
lang | Remembers the language you chose. One year. |
world_gate | Remembers the door opened for this browser while Skydust isn't open to everyone. 180 days. |
skydust_oauth | Ties a Google, Apple or GitHub sign-in to the browser that started it. 10 minutes. |
skydust_passkey | Ties a passkey sign-in to the browser that started it. A few minutes. |
skydust_start | Holds where you said you're starting from while you sign in. One hour, removed once used. |
sd_line | Remembers which place in the line this browser shows. Signed, one year. |
Your rights
You can ask to see the information kept about you, to correct it, or to delete your account and businesses (sections 13 and 14 of the Privacy Protection Law). You may also complain to Israel's Privacy Protection Authority.
Requests: through whoever runs Skydust, until a dedicated address is published here.
Security and retention
Credentials are stored encrypted (AES-256-GCM), sessions and codes only as hashes, and every change is logged. Information is kept while your account exists and deleted on request.