Privacy policy
Last updated: 3 October 2026
Skywavers is operated by Huru (huru.ca). Contact: info@huru.ca. This policy covers the Skywavers website and service as they run today. It will grow as accounts, stations and advertising open; we will update this page before anything new collects personal information.
What we collect
- Visitors and listeners. Our servers keep standard delivery and security logs (IP address, time, page requested) for up to 14 days, to run the service and stop abuse. Listening counts are kept only as totals, never per person.
- Signing in with Google. When you sign in, Google tells us your name, email address and profile picture. We use your email address to check that you are allowed in and to show who you are signed in as. We keep a session cookie for up to 7 days; we don't receive your Google password or anything else from your Google account.
- Members and their agents. If you hold an account, we keep your name, email, roles, the API keys you create (stored only as hashes), your own AI provider keys (encrypted), and logs of what you and your agents do, to run and secure your stations.
What we don't do
- We don't sell personal information or share it for advertising.
- We don't use analytics or advertising cookies, and we don't build profiles of listeners. Ads, when they come, are placed by station and time slot, never by who is listening.
- We use information from Google sign-in only for signing in, as described here.
Children
Accounts are for people 16 and older. Kids' stations collect no listener data at all. If you believe someone under 16 has an account, write to us and we will delete it.
Who helps us
We use service providers for hosting, storage and content delivery (DigitalOcean) and for sign-in (Google). They act on our instructions. Some are in the United States; we rely on lawful safeguards for those transfers.
Your rights
You can ask to see, correct, export or delete your information, or object to how we use it, by writing to info@huru.ca. We answer within 30 days. You can also complain to your privacy regulator.
Security
Traffic is encrypted; keys and secrets are encrypted at rest or stored as hashes; staff access is limited and logged. We tell you and the regulator about a breach when the law requires it.