Privacy Policy
Effective July 2026 · operated by Reasontronic LLC
Different HemiSky features use different privacy protections. This policy describes what the
Service processes and where end-to-end encryption applies.
What we do NOT collect
- The contents of files sent app-to-app. These travel directly between devices, end-to-end encrypted;
we cannot read them and never store them.
- Advertising identifiers. There are no ads and no third-party ad trackers.
- Analytics on your browsing, photo library, or file activity.
What the Service does handle
- Phone number (optional). If you enroll for discovery and offline delivery, we store a
one-way SHA-256 hash of your number to let contacts find you. The number itself is not stored.
- Device identity. A public key your device generates; it is the address other devices dial.
- Accounts and conversations. Account handles, public keys, device records, contacts and group
membership support communication. Encrypted message events, call invitations and delivery receipts
may wait on the Service. Encryption protects message contents, but does not hide all communication metadata.
- Offline delivery. A small pointer (not the file) is parked until the recipient's device
collects it, then deleted.
- Browser download links. For recipients with no app, the Service holds a temporary,
encrypted copy of the shared file for a bounded window (your chosen expiry) and deletes it after
delivery or expiry.
- Browser sends. A sender without the app can request permission using your public handle.
No upload begins until one of your devices accepts. The Service then relays a temporary encrypted-at-rest
copy and schedules deletion after your device saves it or the bounded window expires. Browser uploads
are encrypted in transit and at rest, but the Service processes their plaintext contents; this path is
not end-to-end encrypted. The sender-supplied email
address is retained only with that short-lived request. When anti-bot protection is enabled, Cloudflare
Turnstile processes browser and network signals to validate the request.
- Billing. If you buy a plan, our payment processor handles your card; we store only a
subscription reference, never card details.
- Calls and conferences. Direct calls encrypt media between participants. Private group calls
use participant-held media keys. Open conferences use transport encryption: the conferencing service
can access their media. Room chat and reactions do not inherit a claim of end-to-end encryption from
encrypted media. Room, participant and connection metadata may be processed by the Service and its media provider.
On-device features
The file manager, storage insights, and the Fine gallery and editor operate entirely on your
device. Your photo library, your edits, and your folders are never uploaded.
Retention and your choices
Parked offers and link caches are TTL-bound and swept automatically. You can delete your enrollment
at any time, which removes that enrollment's phone-number hash and device record. Account and device
removal are separate controls. Uninstalling may leave local files, application data or system backups;
use your device's storage controls to remove those copies. Deletion and expiry are processed by cleanup jobs.
Contact
Privacy questions or requests: hello@thunderfile.com.