← SkyViewer

Privacy

Effective July 27, 2026

Plain-language summary

SkyViewer uses your location to calculate the sky above you. Camera access is optional and starts only after you clearly allow the camera overlay or automatic on-device alignment support. SkyViewer briefly examines low-rate camera frames on your phone to learn projection geometry while the live sky can benefit and the page is visible; those frames are immediately discarded and are never stored, uploaded or included in analytics. Camera geometry alone never proves precise celestial alignment. Sensor initialization, selected-object alignment and Moon Assist each offer a separate engineering-upload choice. A supported Sun or Moon alignment is evaluated and applied locally even when you decline its optional diagnostic upload; declining a Moon upload still lets Moon Assist run locally. Your observation journal, photographs, discoveries and tour progress are stored locally unless you explicitly create an encrypted sync vault. Approximate coordinates are added to a journal entry only when you choose that option.

Optional audience analytics

Analytics remain disabled until you choose “Allow analytics.” If accepted, SkyViewer records an anonymous installation identifier, session times, broad device category, language, app build, referring hostname, campaign tags and broad product milestones such as completing First Light. Projection learning may share a coarse camera cohort made from device class, orientation, rounded video-size buckets and facing mode, plus the delivered video dimensions, estimated field of view and a heuristic quality score. That score measures internal agreement; it is not a calibrated probability. The cohort excludes the phone model, camera label and hardware identifiers. Routine orientation analytics contain only aggregate error, spread, evidence-source and sample-count metrics. Camera frames are never uploaded. Audience analytics and coarse camera-calibration contributions are retained for up to 730 days; alignment diagnostic aggregates and the latest sanitized client diagnostic are retained for at most 30 days.

Disabling analytics stops future collection and removes the identifier from this browser. Previously aggregated server records cannot be connected back to the browser.

Encrypted private sync

Private Sync is optional. Progress and Academy chapters are encrypted in your browser before upload. The service stores the encrypted payload, vault identifier and update time but cannot read its contents. The recovery key never leaves your browser; a separate one-way authentication credential is sent instead. Journal photographs and precise journal locations are excluded. SkyViewer cannot recover a lost key. Encrypted vaults inactive for 730 days are deleted.

Optional community profile

Public profiles are off by default. If you opt in, your chosen callsign, short biography, observer level and discovery count become visible to people with your observer code. Community photographs and comments remain private until moderation. Public gallery copies contain no EXIF metadata. When submitting a photograph, you may separately choose to contribute private calibration fields: GPS coordinates, capture time, camera and lens model, focal length, orientation and exposure. These fields are encrypted at rest, are never displayed in the public gallery, and are used only to evaluate and improve sky alignment. If you leave that option off, EXIF data is discarded. Precise location, journal, email, device details and real name are otherwise not included. You can disconnect a device or permanently delete the public profile from the Community screen.

Network and diagnostic data

Coordinates rounded to a 0.05° grid are sent to SkyViewer’s weather endpoint, which retrieves Open-Meteo conditions; exact GPS values never enter that request URL. Coordinates rounded to 0.01° and a date-only timestamp are sent to SkyViewer’s geomagnetic endpoint to calculate true north; exact GPS values are not placed in that request URL. Satellite orbital data comes from AMSAT’s daily ISS/amateur-satellite feed and retained CelesTrak records. Coverage is limited and expired orbital elements are not used for current predictions. Your browser reads SkyViewer’s cache; visiting or reloading the app does not trigger a provider download. Manual city searches are sent to the app’s geocoding endpoint. Routine consent-gated client diagnostics contain only capability states, broad device/browser families and sanitized error codes; precise coordinates, raw user-agent strings, journals and identifiers are excluded. Separately, only after you explicitly approved an initialization trace on that device, or approve the clear prompt on the selected-object diagnostic or Moon Assist, a full engineering trace is uploaded. A previously approved initialization trace starts with Initialize on that same device without asking again; clearing site storage removes that approval. It can contain precise coordinates, raw relative and absolute orientation, compass state, accelerometer, gravity and rotation-rate readings when available, permission and startup milestones, screen and viewport geometry, raw user-agent and device/browser details, camera configuration (but no image), the selected object identity, computed target and camera coordinates, renderer state, and the accepted, rejected or cancelled result. The initialization trace includes a rolling window of up to five seconds immediately before Initialize, marks the sensor-restart boundary, then records 30 seconds after restart so the two sides can be compared. These full traces are used to diagnose alignment, are bounded to the latest 20 initialization, 20 selected-object and 50 Moon attempts, and expire after at most 30 days.

Camera and sensors

The camera overlay and automatic alignment support are optional. Camera geometry learning begins only after you use its clear permission control and allow any camera prompt shown by your browser. Once allowed, SkyViewer may automatically sample low-rate frames on your device only while the live sky can benefit and this page is visible. Sampling stops when it is not useful, when the page is hidden, or when you turn it off.

These frames are held only long enough to calculate temporary image statistics and camera projection geometry, then immediately discarded. They are never saved, uploaded, sent to analytics or made available to the server. This geometry is an acquisition aid, not evidence of precise sky orientation. Motion readings are ordinarily processed on your device. In the ten-second selected-object workflow, a user-centred real Sun or Moon can provide an approximate local north correction from the stable final five seconds; other targets remain diagnostic-only. For the Sun, use only the live camera screen and never look directly at it. Choosing Cancel at the Sun/Moon upload prompt performs the supported alignment locally without uploading its engineering trace. If you approve the Moon Assist engineering diagnostic, its five-second trace is uploaded whether the assist succeeds, is rejected, or is cancelled. None of these diagnostics captures camera frames, photographs, video or audio. SkyViewer may also keep the latest raw trace locally, plus a small local, image-free camera profile containing delivered video dimensions, browser-provided camera configuration identifiers and settings, estimated field of view, and which scientific fields remain unknown. You can reset that profile from the Alignment controls or clear diagnostic traces by clearing this site’s storage. Assisted and simulated modes can replace unavailable sensors. A journal photograph is stored only after you select and save it.

Your controls

You can deny camera or location access, turn automatic camera alignment off, reset its local camera profile, and use drag controls or a manually entered approximate place. My Sky → Plus & Privacy can export, restore or clear local progress, disconnect private sync, and download a sanitized support report. Browser site settings control permissions and site storage.

Sponsorship preview

The optional orbital-salvage experience may display clearly labelled SkyViewer house advertisements that promote its own future sponsorship programme. These bundled sample images make no third-party advertising request and record no advertising impression. A separate rewarded sponsor experience opens only after you explicitly choose to view it; skipping or closing it never removes the normal debris reward. Live third-party advertising remains disabled until a provider, required consent controls, operator details and campaign terms are configured.

Public discussion

Public comments and reactions are currently disabled while reporting, moderation and deletion tools are prepared. Optional observer profiles remain code-based and are not listed in a public directory. The operator’s legal identity, contact address, deletion process and applicable terms must be published before accepting payments or marketing the service broadly.