Privacy Policy
Effective 18 September 2026
Skail Consulting LLC ("we", "us") makes Nowlark, an app that delivers notifications you send to yourself from your own scripts, servers and apps. This policy explains exactly what Nowlark processes, why, where it is kept and for how long. It is written to be complete rather than short.
1. The short version#
- There is no sign-up: no email address, no password, no name, no third-party login. The one exception is a message you choose to send us (section 2.9), where an email address is optional.
- We store what is needed to deliver your notifications and show you their history, and nothing for advertising or tracking. Nowlark contains no advertising, analytics or crash-reporting SDKs. Our websites count visits without cookies or scripts and keep no address (section 2.10).
- We do not sell or share your data with advertisers, data brokers or anyone else.
- You can delete everything from inside the app, at any time.
2. What we process, and why#
2.1 Your account#
On first launch our server creates an account for you and generates a random account key. The key is stored on our server only as a one-way hash, so nobody, including us, can read it back. For each device that holds the key we keep the device label it was issued to (for example "iPhone"), so you can see and revoke access in the app.
If your device provides it, we store your iCloud user record identifier as a label. It lets the app tell you when a device is signed in to a different Apple Account. It is never used to identify you to anyone, and never accepted as proof of identity.
2.2 Your devices#
To deliver notifications we store, for each device: the push token Apple issues for it, whether that token is for Apple's production or development service, the device's name and model identifier, and the iOS and app versions, plus when it was added and last seen.
2.3 Your API keys#
API keys are what your scripts and apps use to send. We store them only as one-way hashes, together with the name you give each key, the first few characters (so you can tell keys apart), how many notifications each has sent and when it was last used.
2.4 The notifications you send#
When one of your senders sends a notification, we store what it contains: the source name, title, body, link, image address, buttons, copy text, priority, grouping and de-duplication keys, when it arrived, whether you have read it, how many of your devices accepted it, and, for an Urgent one, whether it is still repeating and whether you acknowledged it. This is how the app shows you a history.
Notifications are deleted automatically once they are older than the history length you choose in Settings: 30 days by default, or up to 365 days with the Upgrade Pass. Deletion runs every hour and removes the rows; it does not hide them. You can delete any notification sooner from the app.
2.5 Your sources#
Each name your senders use appears as a source, with the settings you choose for it (muted, silent, colour, tone) and when it was first and last seen.
2.6 The Upgrade Pass#
If you buy the Upgrade Pass, Apple processes the payment. We never see your payment details. We store the Apple transaction identifier, the dates the pass covers, and whether Apple reported a refund, so the features it unlocked stay unlocked on every device.
2.7 Moving to another device#
If you move your account to a device on a different Apple Account, the transfer code you create is stored only as a one-way hash and expires after ten minutes.
2.8 IP addresses#
To stop automated abuse, we limit how often accounts can be created and transfer codes tried from one internet address. For this we keep only a keyed hash of the address, which cannot be turned back into the address, and delete it within two hours. We do not keep request logs containing IP addresses.
2.9 Messages you send us#
Skail Consulting LLC also runs the contact forms on skailstudio.com, orgomedia.ai and nowlark.com, and the "send feedback" screens in our apps. They all post to this same server, and this section is what it keeps when you use one. Nothing here is collected unless you press Send.
- What you write, and, if you fill them in, your name and email address. The email address is optional and is used only to reply to you; leave it empty to send anonymously, and we then cannot answer you.
- What the form says about where it came from: which site or app, and its kind (inquiry, bug, feature request or question).
- Diagnostics, only in an app and only when the box is ticked. The app version and build, the operating system version, the device model, your language, a rough free-storage band, whether you have the Upgrade Pass (yes or no, never an identifier), and recent error codes. The screen shows you exactly what will be sent before you send it. It also includes an install id: a random number the app made for itself, which is not linked to your name, your Apple Account or your iCloud and which you can reset in that screen.
- Screenshots and a log, only if you add them: up to three images totalling 5 MB, and, in OrgoMedia for Mac, a log file of up to 2 MB that the app cleans of file names, paths and keys on your Mac before it shows it to you.
- A reference (it begins
frm_) that we give you after you send. Quote it if you want the message removed.
We keep the message and the details above for 24 months (730 days) and any screenshots or log for 180 days, then delete them automatically. We read them, and add a private note and a status ("read", "replied", "archived") of our own, to reply to you and to fix what you reported. We use them for nothing else, we do not share them, and they never leave the two service providers in section 4. To have a message removed sooner, email us its reference and we delete the message and its files.
To stop the forms being used to flood us, we count how many messages one internet address (per site, per hour) and one install id (per day) have sent. As in section 2.8 the address is kept only as a keyed hash, deleted within two hours; the install id is kept the same way for up to 25 hours.
2.10 Visits to our websites#
The same server counts visits to the pages of nowlark.com, skailstudio.com and orgomedia.ai, so we can see which pages are read and whether a message follows. For each visit we keep the page (without anything after a ?), the name of the website you came from (not the address of the page), whether your device is a computer, phone or tablet, and a fingerprint. The fingerprint is a keyed hash of your internet address and browser type, made with a key that is replaced every day and deleted after two days. It can tell us that two visits today were by different people. It cannot be turned back into your address and cannot be matched with a visit on another day, so someone who returns tomorrow counts again. We set no cookie, run no script in your browser for this and use no third-party analytics service. Visits by search-engine crawlers and scripts are not counted. We keep these counts for 90 days.
3. What stays with you and Apple#
- Your account key is kept in your iCloud Keychain and in your own private iCloud database, so your other Apple devices can use your account without signing in. Apple holds this data under your Apple Account; we cannot read it.
- Your settings (theme, accent, links and similar) are kept on your device and, with iCloud Sync on, in your iCloud key-value storage, so your devices match. We cannot read these either.
- Links and images. When you open a link in a notification, your device connects to that website directly. When a notification includes an image, your device downloads it directly from the address the sender gave, so that server sees your device's IP address, as with any web request.
4. Who processes your data#
We use two service providers, strictly to run Nowlark:
- Apple, whose Push Notification service carries each notification to your devices (so notification content passes through Apple, as with every iOS notification), and which provides the App Store and iCloud.
- Fly.io, which hosts our server and database in Chicago, United States. The database is on an encrypted volume.
We do not share your data with anyone else, except where the law requires it.
5. How long data is kept#
| Data | Kept for |
|---|---|
| Notifications | The history length you choose (30 days by default) |
| Account, devices, keys, sources | Until you delete them or your account |
| Upgrade Pass records | As long as your account exists |
| Transfer codes | Ten minutes |
| Hashed IP addresses | Up to two hours |
| Messages sent through a contact form or in-app feedback (section 2.9) | 24 months |
| Screenshots and logs sent with those messages | 180 days |
| Hashed install ids (message limit) | Up to 25 hours |
| Website visit counts (section 2.10) | 90 days |
| The daily key behind a visit's fingerprint | Two days |
Backups. Our host takes a daily snapshot of the database volume and keeps each for 5 days. Data you delete disappears from our live database immediately and from snapshots within 5 days, as they roll over.
6. Deleting your data#
A message you sent through a form is not part of your Nowlark account; to remove one, email us its reference (section 2.9).
In the app, Settings › Delete Account erases your account, every notification, every key and every registered device from our database straight away. It cannot be undone. Deleting the app alone does not do this; your data then remains until its history length expires, so use Delete Account if you want it gone immediately.
7. Your rights#
You can see and delete your data in the app at any time. You can also email us to ask for a copy of the data we hold about you, or for it to be corrected or deleted, and we will respond within 30 days.
If you are in the European Economic Area or the United Kingdom, you have the rights of access, rectification, erasure, restriction, objection and data portability under the GDPR. We process your data because it is necessary to provide the service you asked for (Article 6(1)(b)). You may also complain to your local data protection authority.
If you are in California, you have the right to know, to delete and to correct your personal information. We do not sell or share personal information as those terms are defined under California law.
8. Security#
All traffic uses HTTPS. Keys and codes are stored only as hashes, the database volume is encrypted, and access to our servers is restricted to us.
9. Children#
Nowlark is not directed at children under 13 (or under 16 in the EEA and UK), and we do not knowingly collect their information. If you believe a child has used Nowlark, contact us and we will delete the account.
10. International transfers#
Our servers are in the United States. If you use Nowlark from elsewhere, your data is processed in the United States, with the protections this policy describes.
11. Changes#
If we change this policy, we will update the effective date above and publish the new version at this address.
12. Contact#
Skail Consulting LLC Email: support@skailstudio.com