Last updated: 2026-07-23 · Effective: 2026-05-09
TL;DR
Browsing and scoring collect no personal data, accounts, or tracking IDs.
The one exception: if you request a free API key, we store the email address you give us to issue and manage that key.
We don't sell anything to anyone.
Your location stays on your device unless you tap "Score where I am" — then it's used once to find your postcode and discarded.
Anonymous analytics (no cookies, no profiles) tell us roughly how many people use the app.
Sky Score is operated by Bilal Khizar, an independent developer based in the United Kingdom. Web: skyscore.co.uk. Contact: support@skyscore.co.uk.
For data protection purposes, we act as the data controller for the limited data described below.
Browsing and scoring: none. Using the Sky Score website or apps does not require an account, email address, name, phone number, or any other identifying information. There are no payment forms or surveys.
API key signup (optional): if you request a free API key on the
developer demo page, we collect the email address you enter (and a display name if you
choose to give one). We use it solely to issue your key, enforce the one-key-per-email limit, contact you about your key if
we ever need to (for example abuse or deprecation notices), and revoke the key on request. Lawful basis: performance of a
contract (UK GDPR Article 6(1)(b)), you are asking us to issue and operate the key, with our legitimate interest in
preventing abuse (Article 6(1)(f)) for the rate-limit and one-key-per-email checks. The address is stored in our AWS account
in eu-west-2 (London), in the signup register (DynamoDB) and in the API key's own metadata; it is never sold
or shared for marketing, and is kept for as long as the key remains active.
Email support@skyscore.co.uk to delete it; we revoke the key and remove the
record within 30 days.
When you tap "Score where I am" in the native iOS or Android app:
If you deny the location permission, the rest of the app works normally — you just have to type a postcode manually.
We use GoatCounter, an EU-hosted privacy-respecting analytics service. GoatCounter sets no cookies, doesn't log IP addresses, doesn't track users across sites, and stores aggregate counts only (page views, referrers, screen sizes). Comparable to a server-side log of HTTP requests with personal data scrubbed.
Sky Score's backend runs on AWS Lambda + API Gateway in the eu-west-2 region (London). API Gateway logs include
request timestamps, paths, response codes, source IPs, and user agents. Logs are retained for 7 days then
automatically deleted. Used solely for debugging and to investigate suspected abuse. We do not link logs to identities.
| Subprocessor | Purpose | Data | Region |
|---|---|---|---|
| Amazon Web Services (AWS) | Backend compute, API Gateway, DynamoDB | Anonymous request logs (7-day retention) | eu-west-2 (London) |
| S3 + CloudFront | Static asset delivery | Standard CDN logs | Multi-region |
| api.postcodes.io | Postcode lookup from coordinates | Lat/lon (transient) | UK |
| GoatCounter | Anonymous analytics | Aggregate counts | EU (Berlin) |
| Codemagic | Building iOS / Android binaries | Source code only — no user data | EU |
| Apple App Store / Google Play | App distribution + crash reports if you opt in | Standard store telemetry | Various |
Full list with their respective privacy policies: SUBPROCESSORS.md in our public repo.
Sky Score's content (the underlying scores) is computed from public datasets: DEFRA Strategic Noise Maps, HM Land Registry Price Paid Data, EPC certificate register, ONS National Statistics Postcode Lookup, NHS facility data (via OpenStreetMap), TfL Open Data. All under the Open Government Licence v3.0. We don't request data about you from any of these sources.
Even though we hold very little data about you, your UK GDPR rights apply. You can:
To exercise these rights, email support@skyscore.co.uk.
Sky Score has no minimum age requirement and does not knowingly collect data from anyone, including children. The iOS app is rated 4+ on the App Store.
The Sky Score website (skyscore.co.uk) does not use cookies. The native iOS and Android apps do not use cookies either.
All API calls use HTTPS (TLS 1.2+). AWS infrastructure is hosted in eu-west-2 with standard AWS security controls.
API rate limiting is in place. Full security posture:
SECURITY.md. Security issues:
support@skyscore.co.uk (we acknowledge within 48 hours).
Material changes (new subprocessors, new data types) trigger an update to the "Last updated" date and an in-app notice. Non-material changes (typos, formatting) won't trigger a notice.
Privacy questions: support@skyscore.co.uk. We aim to reply within 5 working days.