1. Who operates SkyPad Social
SkyPad Social is operated by Original Gen Labs. References to “SkyPad,” “we,” “us” or “our” in this policy refer to SkyPad Social and Original Gen Labs.
SkyPad Social is an independent third-party client for the Bluesky network. It is not affiliated with, endorsed by, or sponsored by Bluesky Social, PBC.
2. Information SkyPad processes
To provide its features, SkyPad may process your Bluesky handle, decentralized identifier (DID), profile information, service provider and Personal Data Server address; OAuth session credentials; posts, media, reactions, relationships, Lists, Starter Packs, saved posts and messages available to your account; content you compose or publish; and app preferences.
SkyPad also processes operational information needed to load content and complete actions, such as record identifiers, pagination values, message and notification state, selected languages, content labels and upload status.
3. Authentication and account credentials
SkyPad uses Bluesky OAuth and does not ask for your app password. Access and refresh tokens, the OAuth PKCE verifier and the device's DPoP private key are stored using the iPhone Keychain. Short-lived OAuth state and account routing information are stored locally to complete sign-in.
SkyPad validates the authorization callback, service identity, token type and account binding before accepting a session. No security system can guarantee absolute protection.
4. Information stored on your iPhone
SkyPad stores preferences such as appearance, language, translation and notification choices in local app storage. It also maintains bounded local caches for feeds, news, profile information and media so content can load efficiently. These caches can include post text, authors, media references, labels, interaction state and account-linked identifiers.
Composer drafts may contain text, settings and media. Draft media is stored in the app's Application Support folder with complete file protection. Temporary composer files are periodically removed. Some short-lived translation and image caches remain in memory only.
Saved posts use Bluesky's bookmark service and are temporarily held in app memory while SkyPad is running. Local notification state, offline action records and other continuity data may also be retained on the device.
5. How SkyPad uses information
- Authenticate your account and maintain a secure session.
- Display Bluesky and AT Protocol content, profiles, feeds, notifications and conversations.
- Publish posts and media and complete likes, reposts, follows, saves and other requested interactions.
- Provide messaging, search, discovery, ranking, trends and news organization.
- Store drafts, preferences and bounded caches.
- Provide translation, moderation tools, content labels, safety checks and troubleshooting.
6. Bluesky and AT Protocol services
SkyPad sends account and content requests to the AT Protocol services associated with your account. Depending on the action, this can include your Personal Data Server, Bluesky AppView and chat services, public Bluesky APIs, Bluesky's video service and DID resolution services such as PLC Directory or your handle's domain.
Content you publish, messages you send and interactions you make are processed and retained by the relevant Bluesky or AT Protocol provider under its own policies. Review the Bluesky Privacy Policy and AT Protocol Network Services Privacy Notice.
7. GIF search, Apple features and external links
Online GIF search is provided through Bluesky's GIF service and KLIPY. Search terms, pagination values, device locale, IP address and selected GIF requests may be processed by those services. SkyPad does not require a separate KLIPY account. Review KLIPY's Privacy Policy.
SkyPad uses Apple system frameworks for language identification, translation, link previews, secure Keychain storage and local notifications. Text you choose to translate is provided to Apple's Translation framework. When both required languages are downloaded, translation is processed on the device; otherwise, the text may be sent to Apple for processing. Apple controls that processing and retention. Review Apple's Translation & Privacy notice and Privacy Policy.
Opening a publisher link or other external website sends a normal request to that site. Creating a link preview may cause iOS to contact the public URL. Handle verification may query Cloudflare's DNS-over-HTTPS service or the custom domain associated with a handle.
8. Analytics, advertising, tracking and diagnostics
The current SkyPad app does not include third-party analytics, advertising, crash-reporting or cross-app tracking SDKs. SkyPad does not request Apple's advertising identifier.
The release app's local diagnostic logger is disabled by default. Development or support diagnostics may record operational details such as request status, byte counts and public or pseudonymous identifiers. SkyPad's authentication diagnostics exclude access tokens, refresh tokens, authorization codes, PKCE verifiers, DPoP proof material and response bodies. Third-party services listed above may perform their own logging or analytics under their policies.
9. Retention, sign out and deletion
Cache duration and capacity are bounded by the app, while drafts remain until you delete them or remove the app. Signing out removes the active account's access and refresh tokens and current authentication identifiers. It does not automatically remove every cache, preference, draft or locally queued continuity record.
Deleting SkyPad ordinarily removes its application container, including drafts, preferences and caches, subject to iOS backup and restore behavior. Keychain items are managed separately by iOS and may persist until removed by sign-out, the app or the system.
Content already published to Bluesky, AT Protocol services or external sites is not deleted when you sign out of or delete SkyPad. Use your account provider's controls to manage or delete that content and account.
10. Your choices
You can sign out, delete individual composer drafts, unsave posts, change notification and translation preferences, and use mute, block and report controls. SkyPad does not currently provide one control that erases every category of local app data.
You can use your Bluesky or AT Protocol provider's account controls for authorization, content and account requests that are managed by that provider.
11. Children and eligibility
SkyPad is for people who are eligible to use the Bluesky or AT Protocol account they connect. Bluesky's current terms require users to be at least 13 and to meet any higher minimum age required by local law. Other providers may have different rules. SkyPad does not independently collect a date of birth or perform age verification.
12. International processing and security
Bluesky, AT Protocol providers, KLIPY, Apple and external websites may process information in countries other than your own. Their locations, safeguards and transfer practices are governed by their policies and applicable law.
SkyPad uses safeguards including OAuth, device-bound proof, Keychain storage, protected draft files, secure transport checks and bounded network responses. These measures reduce risk but cannot guarantee absolute security.
13. Policy updates and contact
We may update this policy as SkyPad, its services or applicable requirements change. Material updates will be posted on this page with a revised effective date and may also be communicated in the app when appropriate.
For privacy questions, email privacy@originalgenlabs.com. For product support, email support@originalgenlabs.com. Never send passwords, OAuth codes or authentication tokens.
