SKYTAL

Version 2026-08-21 · effective from 21 августа 2026 г. · updated 21 августа 2026 г.

This Policy explains how the SKYTAL operator processes personal and technical data when you use skytal.ru and the SKYTAL messenger, reflecting a P2P-first architecture, E2EE message content, and server-mediated delivery.

1. Operator and contacts

Data controller: Obedinennaia Kazanskaia Biznes Gruppa LLC (ООО «Объединенная Казанская Бизнес Группа») (INN 1656055260, OGRN 1101690032982).

Address: 8 Lushnikova St., office 29, Kazan 420034, Russia. Privacy inquiries: info@skytal.ru.

2. Scope

This Policy applies to skytal.ru, the SKYTAL mobile application, and related delivery, support, and (if activated in future) agreed SKYTAL access or service orders.

The data controller is a Russian legal entity listed in section 1. This Policy describes processing within the operator's activities in the Russian Federation.

Translations of this Policy into other website languages are provided for convenience. Your interface language does not mean the law of that language's country applies to you.

3. Privacy architecture

SKYTAL is a P2P-first messenger: WebRTC calls use a direct path when possible; TURN relay may be used when necessary.

Message content is protected with end-to-end encryption (E2EE). Servers relay ciphertext and necessary delivery metadata; message text is not decrypted on the server.

Encrypted attachments are handled through the service media layer. SKYTAL is not a fully decentralized system and does not claim that the server knows nothing about delivery.

4. Data categories

  • Profile and device identifiers required to operate the service
  • Message delivery metadata (routing, timestamps, delivery status, chat participation)
  • Encrypted message and attachment content (the server does not decrypt message text)
  • Website access request form data (see section 5)
  • Push notification registration data
  • Invitation and access data
  • Contact details and information about an agreed order or connection if public payment is enabled (public website payment is disabled as of the publication date)
  • Support requests
  • Website and infrastructure technical logs (IP address, user-agent, request time)

5. Website access request form data

On the Access page (/invite/) you can submit a connection request through the website form. The data you provide is sent to SKYTAL servers and stored to process your inquiry and coordinate access.

Operators process this data to respond to B2B connection requests and manage onboarding correspondence. Technically, requests are retained for a limited period depending on status: marked as spam — up to 30 days without activity; in active pipeline statuses or lost — up to 12 months without activity (status changes or operator notes extend the period). Successfully closed requests (WON) are not automatically deleted.

  • Name
  • Company / practice / team
  • Job title or specialization
  • Work email
  • Contact (phone, Telegram — optional)
  • Approximate number of participants
  • Use case
  • Brief description of your needs
  • Interface language (technically, when sending)

6. Data the service does not intentionally request

  • Passport data, biometrics, or full bank card details on SKYTAL servers
  • Address-book contacts without an explicit action by you in the application
  • Message content in plaintext on the server

7. Purposes of processing

  • Providing invitation-based access
  • Delivering messages, files, and call signaling
  • Registering devices and push notifications
  • Maintaining service security and stability
  • Handling user inquiries and requests
  • Processing payments if public payment for agreed orders is enabled, through supported payment providers
  • Complying with lawful requirements

8. Retention

Data is retained for periods necessary for processing purposes, security, and legal compliance. Specific retention periods for individual categories are described in the Data processing document and may be updated following internal review.

9. Sharing and cross-border transfers

Data may be shared with supported payment providers (including YooKassa and PLATIMA — when connected and the relevant function is enabled), push notification providers, and hosting partners under processing agreements or other applicable legal grounds.

Some processors may be located outside your country of residence, including in the Russian Federation.

The operator applies reasonable organizational and technical measures for cross-border transfers under applicable Russian law. Specific mechanisms and contractual bases are refined as infrastructure evolves.

10. Processors and third parties

Sharing is limited to what is necessary for the relevant purpose. Processing agreements or other measures under applicable law are used with processors.

  • Hosting and cloud infrastructure — server hosting and backup
  • Push notification providers — delivery of notifications to devices
  • Supported payment providers — YooKassa and PLATIMA (integration available; public website payment is disabled as of the publication date)

11. Security

We apply information security measures including channel encryption, access controls, and separation of service components. Absolute security is not guaranteed.

12. Your rights

Depending on applicable law, you may request information about processing, correction or deletion of data, restriction of processing, or lodge a complaint with a supervisory authority.

Send requests to info@skytal.ru or use the Data requests page (/data-removal/).

13. Children

The service is not intended for children under 16 without consent of a legal guardian where required by applicable law.

14. Website cookies and local storage

As of audit results, public pages on skytal.ru do not set advertising or analytics cookies and do not use localStorage in client code for main public sections.

Details are in the Use of cookies document (/legal/cookies/). Strictly necessary cookies may apply in separate restricted areas (for example admin.skytal.ru), which are not the public marketing website.

15. Policy updates

We may update this Policy. The current version and date are published on the website. Material changes will be communicated through available channels.