SkyORM
Legal notice Privacy Terms of use Support
ES EN

Privacy policy

Version 2026-09-16. The Spanish version is the reference text.

In two lines. SkyORM processes two different things. Data about its own platform (your account, your sign-ins, technical logs) it processes as controller. What is filled in each ORM it processes on behalf of whoever publishes it, who is its controller: there SkyORM is a processor and does not use those responses for anything of its own.
  1. Who the controller is
  2. Two different roles
  3. What data SkyORM processes as controller
  4. Who else receives data
  5. Transfers outside the European Union
  6. How long data are kept
  7. Your rights and how to exercise them
  8. Minors
  9. Cookies and browser storage
  10. Security
  11. The mobile app
  12. Changes to this policy

1. Who the controller is

Privacy emailprivacy@skyorm.com
Pending publicationname or company name, tax ID (NIF) and address
Data protection officerNone appointed.

This is the service holder. Its identifying details are pending publication, in the legal notice too. In this policy we call it SkyORM.

2. Two different roles

2.1 What SkyORM processes as controller

Your account, signing in and its security, the platform's technical logs, internal messaging and notices, the assistant, support, and the responses sent to platform templates. What, why, on what basis and for how long is in section 3.

2.2 What SkyORM processes as processor: what is filled in each ORM

Each ORM is published by an organisation or a person (a club, a school, a company, a unit) that decides what it is used for and what it asks. That is the controller of what is filled in it. SkyORM processes it only on their behalf and following their instructions, under the processing agreement in the terms of use. Before an ORM is published, the platform requires whoever publishes it to declare who the controller is, on what legal basis they process the responses and what rule they cite, and to accept that agreement. An ORM without that declaration, or whose declaration has not accepted that agreement in any version, only accepts anonymous responses, and the form says so.

Each ORM has its own privacy page, at the ORM's address followed by /privacidad (for example, /orm/name-of-the-orm/privacidad). It can be read without the fill password and the form links to it. It states who the controller is and how to contact them, the legal basis and the rule they cite, what is stored in each of the three ways of answering (anonymous, alias or signed), who else sees the data (including whether its controller has switched on artificial intelligence), the rights and how long the identity is kept.

What they all have in common: the response itself (scores, risk band and scored answers) is never deleted, because it is the prevention statistics; what expires is the identity. The name or alias and the signature stay readable for 5 years; they are then blocked, available only to courts and authorities, until 10 years; and they are then removed, leaving the response like an anonymous one: no identity, no free text and times rounded down to the hour. Each controller may extend those periods if their rules require it, and their page says so. In an anonymous response the platform does not store who you are, your account, your network address or your browser.

To exercise your rights over a response to an ORM, contact its controller using the contact on its privacy page; they handle it from the platform itself. If you write to us, we will pass the request on and help them answer it. If the ORM belongs to a club and you signed while signed in, you can also withdraw your consent yourself from your response's result, in "My ORMs".

2.3 Platform templates

SkyORM offers a few reference ORM templates for everyone to use: anyone can fill them in directly, without an account or a password, and any account can copy and adapt them. The examples on the home page lead to them. Whatever is sent to a platform template is only accepted anonymously: who you are, your account, your network address, your browser, free text and signatures are not stored, and times are rounded down to the hour. SkyORM processes it as controller, so that anyone can do their assessment with them and to keep the responses, without identity, as usage statistics; there is no organisation behind them receiving them. Because the response does not store who you are, it is no record for your organisation that you did it: for that, use the ORM your organisation publishes. For the same reason, SkyORM cannot tell which response is yours to give you access to it or erase it (art. 11 GDPR). A copy made from a platform template belongs to whoever publishes it, and its controller is whoever declares it. Each platform template has its own privacy page summarising this.

3. What data SkyORM processes as controller

ProcessingDataWhat forLegal basis (GDPR)How long
User account Email, username, first and last name, password stored as a hash (never in clear), country and preferred language; phone if you give it. Only if you fill them in your profile: tax ID, date of birth, sex, address, notes and profile photo. The organisational unit and roles assigned by the administration. Giving you access to the platform, your ORMs and those shared with you, and identifying your account in the platform administration (its user search uses the tax ID, date of birth and sex if you gave them). If the administration has it enabled, it gets an email for each new sign-up with your name, email, phone, sign-up method and the network address you signed up from, and another for each ORM created with the name, email and network address of whoever creates it. Performance of the terms of use (art. 6(1)(b)); the notices to the administration, legitimate interest in the security of the service (art. 6(1)(f)). Where sign-up presents that acceptance, the platform stores the version of the terms you accepted and the date: today that is sign-up with Google; the email-and-password sign-up form does not yet show that tick box and so leaves no record (terms of use, section 3). While the account exists. Closing it also deletes its trusted devices, its sign-in log and its activity, except the record of rights handled (row "Activity log"). If you own any ORM, the closure is not carried out until its ownership moves to another account.
Emergency contact Name, email, phone and country of the person you name, only if you fill it in your profile. So the platform administration can alert someone if there is an emergency involving you. Legitimate interest, yours and that person's (art. 6(1)(f)). That person does not give us their data: you do, so tell them and point them to this policy. They can exercise their rights at the privacy email. While your account exists or until you delete it from your profile.
Signing in and account security The password (hash); one-time email codes for two-factor authentication, which expire after 10 minutes; SMS codes to verify your phone at sign-up and to recover your password by phone, which expire after 30 minutes; password recovery links by email, which expire after 6 minutes; and trusted devices: the name you give them and a fingerprint derived from a random identifier stored in a cookie, never the identifier in clear. Checking it is you and preventing unauthorised access. Performance of the terms (art. 6(1)(b)) for access; legitimate interest in the security of the service (art. 6(1)(f)) for the protective measures. Codes and links, until used or expired. Trusted devices, while the account exists.
Sign in with Google Email, name and Google identifier. Signing in without a password of your own, if you choose to. Performance of the terms (art. 6(1)(b)), at your choice. While the account exists.
Sign-in log For each sign-in: date and time, network address, browser and operating system, session identifier, sign-in method and result. Detecting and investigating unauthorised access. You can see yours in your profile, under "Security". Legitimate interest in security (art. 6(1)(f)). 365 days.
Request metrics Route, method, response code, duration and memory of each request, with your user identifier and a pseudonym of your network address (a hash with a secret key). When filling an ORM and on its privacy page, neither the user nor the pseudonym is stored. Knowing whether the platform is slow or failing. Legitimate interest in running the service (art. 6(1)(f)). 90 days.
Error log The technical error, the page address, the method, the referring page, your network address, your browser and your user identifier. When filling an ORM and on its privacy page the error is stored without any of that. Requests that look like security probes are also logged, with their network address. Some errors of signed-in users, and the probes, also trigger an email to the mailbox of whoever operates the platform, with the error and the page address and, outside ORM filling, your network address, your browser and your account details. Fixing faults and defending the platform. Legitimate interest in security and running the service (art. 6(1)(f)). 90 days, in the alert mailbox too.
Activity log Actions taken from the administration (changes to configuration, countries and users), those an ORM's owner takes to handle the rights over a response (access, rectification, restriction and removal of the identity) and the withdrawal of consent made by the person themselves: who, what, on which response and when, never the name of the response's person. Keeping a record of what is done with the platform and being able to show a right was handled (GDPR art. 5(2)). Legitimate interest in security and accountability (art. 6(1)(f)). 365 days; the record of rights handled, 1095 days, the limitation period of the LOPDGDD infringements.
Messaging and internal notices Messages, attachments, participants, notices and whether you have read them. Communication within the platform. Performance of the terms (art. 6(1)(b)). While the conversation or notice exists. If your account is closed, your messages stay in the conversation without your name.
Artificial intelligence assistant Your questions, the answers, the page you ask from, the language and your ratings; if you ask from your statistics or those of an ORM you have access to, those statistics, only from ORMs whose controller has switched artificial intelligence on; and a daily usage counter. The artificial intelligence provider only receives what the recipients section says: never your account or its roles, the page address or title (it does receive the internal name of the screen) or a single response. Answering your questions about the platform when you use the assistant. Performance of the terms (art. 6(1)(b)): it is a function you ask for. The conversation, while the account exists. Questions are also kept in a cache not linked to your account, to avoid asking the provider again, for 90 days. Do not write other people's data in the assistant.
Support What you write to us and your email address; if you use the contact form, also your name and the network address you send it from. Answering you. Legitimate interest in handling your enquiry (art. 6(1)(f)). In the holder's mailbox, as long as needed to handle the enquiry and any claims arising from it.
Platform templates Whatever is sent to them, always anonymously (see 2.3). Letting anyone do their assessment with them and keeping the responses as usage statistics. Legitimate interest in offering these templates (art. 6(1)(f)); the response stores nothing that identifies whoever fills it in. The response is kept, without identity.

To open an account you need your email, first and last name and a password, or to sign in with Google; without them we cannot give you access. The rest is voluntary. Emails sent by the platform wait in a database queue until they go out; failed ones stay in a failure queue until they are retried or discarded.

4. Who else receives data

  • Hosting: Hetzner Online GmbH. Stores all the platform's data.
  • Email: SMTP provider (mail.drozap.com). Sends the platform's emails.
  • SMS: Twilio, for phone verification and password recovery codes. It receives your number and the code.
  • Google, if you choose to sign in with Google: it is controller of its own sign-in service.
  • Google Fonts, which serves the typeface of the application screens (see below): it sees your network address and your browser.
  • Artificial intelligence: Cerebras, OpenAI, depending on the provider that handles each request, only when someone uses an artificial intelligence function and, for what comes from an ORM, only in ORMs whose controller has switched it on. From the assistant they receive your question, without your account (emails, phone numbers and links are removed, and so are dates, times and coordinates written in figures, but whatever you write in words, such as a name or a date spelled out, reaches them as it is: do not write anyone's names or health data in it), and the internal name of the screen, never its address or title; from ORMs, only factor values and aggregate statistics with nothing to attribute them to a person, even when they concern health, with the labels written by the ORM's controller; while filling, the request reaches them at the moment you press the suggestion (details in the terms of use).
  • Authorities and courts, when a law requires us.

We do not sell data or use them for advertising. The home page and the legal pages load no third-party resources. The other screens, including those of each ORM (its fill form, its result and its privacy page) and the sign-in screens, currently load the Lato typeface from Google Fonts: your browser asks Google for it, and in that request Google sees your network address and your browser, also if you answer anonymously, though it receives nothing you fill in. On the management screens that show a map, the map is served by OpenStreetMap directly to your browser, and on the location management screens your browser asks Open-Meteo for the point's elevation; in those requests both see your network address. An ORM's weather forecast is requested by our server from Open-Meteo using only the location's coordinates.

5. Transfers outside the European Union

Twilio and the artificial intelligence providers with a declared contract (Cerebras, OpenAI) are in the United States, and Google may process data there when you sign in with Google, when your browser downloads the Google Fonts typeface. These transfers are made only under standard contractual clauses, or the EU-US Data Privacy Framework where the provider is certified under it: that is the condition for using the provider. For the artificial intelligence ones the platform checks it itself, as it can only send anything to a provider whose contract is declared in the server configuration (today, Cerebras, OpenAI). You can ask for information about those safeguards at the privacy email.

Whatever is sent to an artificial intelligence provider from an ORM only leaves ORMs whose controller has switched it on, with nothing the provider could use to attribute it to a person: the values of the scored factors of a response (of an option, its position), aggregate statistics of your own responses (at least 5 responses, with no row of fewer than 3) and, in an ORM's dashboard, its rounded total and average; without identity, alias, signatures, free text, the date or time of any response (in aggregates, at most the split into six-hour windows), coordinates, identifiers or the ORM's name. The labels of factors, bands and modifiers leave as the ORM's controller writes them, who is bound not to put people's names in them. Even so, those providers are listed as recipients, because for whoever is responsible for the ORM they are still personal data.

6. How long data are kept

DataPeriod
Account, emergency contact, trusted devices, messaging, assistant conversationsWhile the account exists
Sign-in log365 days
Activity log365 days; the record of rights handled, 1095 days
Request metrics90 days
Error log90 days
Assistant question cache90 days
Mobile submission index (so that resending after a dropped connection does not leave two identical ORMs). It holds neither your account, nor your address, nor which ORM it was: a fingerprint of the key the phone sends and, encrypted with it, the response number24 hours, with the expiry rounded down to the hour; the daily purge deletes the expired ones
Access codes and recovery linksUntil used or expired (between 6 and 30 minutes)
Database backups, taken before each deployment14 days
Web server logs (access and errors), outside the application37 days at most, in the worst case, with the log rotation (logrotate) the deployment has measured on this server. That period assumes each log receives some line in every rotation period: if one stays empty for a whole period, logrotate may not rotate it, and its previous copy waits for the next rotation. Requests that fill an ORM, show its result or open its privacy page are not written to the access log. If one of them causes an error in the web server itself, that line of the error log does keep your network address, for that same period.
ORM responsesThe response, always; the identity, readable for 5 years and blocked until 10, unless the ORM's controller declares longer (see its privacy page)

The platform log periods are applied by a daily purge process on the server, and those for the identity in responses by another daily process; the deployment checks both are scheduled. Data deleted from the database may remain in backups until they rotate.

7. Your rights and how to exercise them

You can ask for access to your data, their rectification or erasure, object to processing based on legitimate interest, ask for it to be restricted and, for what you gave us in your account, receive it in a commonly used format (portability).

  • About the platform (your account, your sign-ins, the logs): write to the privacy email, privacy@skyorm.com. If needed, we will ask for something showing it is you.
  • About your responses to an ORM: contact its controller using the contact on its privacy page. If you write to us, we will pass the request on.

SkyORM takes no decisions about you based solely on automated processing. An ORM's score is a recommendation calculated with the rules of whoever publishes it, and people take the decision to fly or jump (terms of use, section 2).

We answer within one month, extendable by two further months for complex cases, telling you beforehand. If you believe your data have been handled wrongly, you can complain to the Spanish Data Protection Agency (www.aepd.es).

8. Minors

Platform accounts may only be opened by people aged 14 or over (art. 7 of Spanish Organic Law 3/2018). If we learn that an account belongs to someone under 14, we will close it and delete its account data. If a minor may fill an ORM, what is needed for that is decided and ensured by that ORM's controller.

9. Cookies and browser storage

SkyORM only sets its own cookies, strictly necessary for what you ask for to work. There are no analytics, advertising or third-party cookies, so there is nothing to accept. No third party sets or reads cookies in your browser: downloading the typeface from Google Fonts uses no cookies, although it does let Google see your network address and your browser (sections 4 and 5).

CookieWhat forDuration
Session cookie (PHPSESSID, unless the server renames it) Keeping you signed in, your chosen language, form protection, password access to an ORM and, if you answer anonymously, being able to see your result for 20 minutes. Until you close the browser.
trusted_device_id Recognising the device on the trusted device screen when signing in, so you are not asked for the second factor on one you marked as trusted. Only set if you go through that screen. 1 year.

In addition, without cookies, the browser keeps in its own storage, always first-party and read by no third party: the draft of the ORM you are filling, so you do not lose it (in the tab, which deletes it when closed, if you answer without signing in or anonymously; and in the browser if you are signed in and not answering anonymously); the half-filled sign-up form, without the password, in the tab; the ongoing conversation with the assistant and its state; the display preferences of the ORM builder and of the administration screens (searches and open sections); and a technical flag that the fonts have already loaded.

10. Security

Passwords stored as hashes, lockout after failed attempts, second factor, per-ORM permissions, server-side validation of everything submitted, logs with time limits and backups. The full list, including what the application does not do, is in the terms of use, section 5, letter c.

11. The mobile app

Besides the web, SkyORM has a mobile app for Android and iOS, downloaded from Google Play and the App Store. It does the same as the public web: add an ORM, fill it in and see its result. Everything said so far applies equally when you fill from the app; this section is what changes because it is an app and not a browser.

11.1 This version has no accounts and no sign-in

The first version of the app has no accounts, no sign-up and no sign-in. It does not ask you for an email, a user password or a profile, and it does not connect to any platform account. Everything it does goes through the public part of the service (the addresses starting with /api/mobile/public/), the same one anyone can use from a browser without signing in. So nothing the app processes in this version is tied to an account of yours, and what section 3 says about accounts does not apply to it.

11.2 Filling in and sending an ORM from the app

An ORM sent from the app is recorded by the same path and under the same rules as one sent from the web form: the same server-side validation, the same identity mode inferred from what you send, the same minimisation of the anonymous response, the same data protection notice frozen inside the response, the same scoring and the same alert to whoever has to authorise. The same is stored, no more and no less, and what is stored belongs to whoever publishes that ORM, with the periods and rights in section 2.2. Before sending, the app shows you that ORM's notice, and the server rejects the submission if there is no record that you were shown it.

If you answer anonymously, the app stores no more about who you are than the web does: no name or alias, no account, no network address, no browser or app, and no exact time. The response is stored without identity, without free text and without a signature, and its dates and times are rounded down to the hour, exactly as on the web. The app's requests are on the same list of identity-free routes as web filling: the request metrics store neither user nor pseudonym of your address and round their time down, the error log and the email alert it generates are stored without address, without browser and without account, and not even which ORM the request was for is written down. Your network address is used only in the moment, for the limiters that stop abuse, and it enters them turned into a fingerprint with a secret key; not even there is it stored in the clear. The app also sends a fixed application name, the same on every phone, which the server neither reads nor stores.

Searching for an ORM by its exact name and opening a password-protected ORM go the same way: neither the name you type nor the password is stored anywhere, on the server or on the phone. The password is exchanged for a 24-hour permission for that ORM and nothing else; that permission is a signature the server recomputes every time it sees it, so there is no permissions table at all, and changing the ORM's password voids every live one at once.

11.3 What the app keeps on your own phone

The app keeps inside the phone, in the private storage the system reserves for it, and sends it nowhere: the list of ORMs you have added with their details (name, address, description, logo and how many pages and factors it has), the temporary 24-hour permission for those you opened with a password, and your language and theme preferences. None of that travels to SkyORM, to the stores or to anyone else: it is yours and lives only on your device. On Android it is also excluded from automatic backup and from transfer to a new phone. It disappears when you remove the ORM from the list or uninstall the app, and the permission expires on its own after 24 hours. An ORM's password is never stored, not here either.

What you are filling in is not kept on the phone: this version has no drafts and no outbox. The answers, and with them any signature you draw, exist only while you have the ORM open; if you leave without sending, they are lost, and the app warns you before you leave.

11.4 Technical fault reports

If the app hits a fault, it can send us a technical report so we can fix it: the error message, its type, the screen it happened on, the trimmed call stack, the installed version number and the platform. It never carries your answers, what you type, your signature, or any password or credential, and it carries no account, because in this version there is none. When the fault is in a fill request, it does not carry which ORM it was or the full address either, only the generic route; in a fault of the screen itself it may carry the ORM you had open, which is public and is in its QR code. Nothing is sent from a development build. If there is no connection, or the server cannot take it, the report waits on the phone (at most the 30 most recent) until it can be sent. Whatever the server accepts is stored in the error log in section 3 and, because it arrives by an identity-free route, without your network address, without your browser and without an account.

11.5 The submission index, so a resend does not duplicate an ORM

When the app sends an ORM it sends a random key for that submission with it, so that if the connection drops and it retries, two identical ORMs are not stored. The server notes that key for 24 hours and encrypted: the row holds neither your account, nor your network address, nor which ORM it was; it holds a fingerprint of the key and, encrypted with that same key —which the server does not keep— the response number. Its only timestamp is the expiry time, rounded down to the hour so that subtracting the 24 hours does not give back the second of the submission. The daily purge deletes the expired ones (section 6).

11.6 The app stores

Apple (App Store) and Google (Google Play) receive nothing of what you fill in. Responses travel straight from your phone to our server and no store takes part in that path. What the stores do is distribute the app: downloading, installing and updating it is governed by Apple's and Google's own privacy policies, not by this one, and whatever each of them processes on its own account in doing so (your store account, the device, install statistics or reviews) is their business and does not reach us. The app carries no advertising, no analytics and no third-party component that tracks what you do, asks for no location permission —on Android it declares only the internet access permission, and on iOS it asks for none— and talks to no server other than SkyORM's.

11.7 Your rights from the app

They are the same as in section 7, and are exercised the same way: about the platform, at the privacy email, privacy@skyorm.com; about a response to an ORM, before its controller, whose name and contact the app itself shows you in the notice you read before sending, and which are also on that ORM's privacy page (section 2.2). Bear in mind what section 2.3 says: we cannot tell which anonymous response is yours, so there is no way to give you access to it or erase it (art. 11 GDPR).

12. Changes to this policy

If it changes, we will publish the new version here with its date. If the change affects how your data are processed, we will also announce it within the platform.

Legal notice Privacy Terms of use Support Terms version: 2026-09-15 Privacy policy version: 2026-09-16