Sky Matrix is built to keep your data on your device and to use outside services only where a feature genuinely needs them. This page explains what stays local, what leaves the device, the third parties involved, and how to verify the Android apps before installing them.
This page covers two separate products. Most of it describes Sky Matrix, the flight-briefing service. Matrix Clock is a different, free app with its own, much shorter answer — it is covered in its own section immediately below, and nothing described elsewhere on this page applies to it.
Matrix Clock (free Android app)
Matrix Clock collects no personal data. None at all. There is no account, no sign-in, no analytics, no crash reporting, no advertising and no tracking of any kind. It is a separate app from the Sky Matrix briefing service, and none of the licensing, AI, lookup, payment, waypoint-sharing or flight-sync behaviour described elsewhere on this page applies to Matrix Clock.
- Your alarms, rest plans and times stay on your device. They are held in the app's own storage and are never uploaded to us. Clearing the app's data removes them.
- The only thing the app ever sends is a request asking what the time is. It checks the clock against public internet time servers —
time.google.com, pool.ntp.org and time.cloudflare.com — because your phone's clock drifts and every alarm depends on it. Those requests contain no information about you. As with any internet request, your device's IP address is visible to the server it contacts; we never receive it and never store it.
- If you have Android's backup switched on, your alarms are included in it. That backup goes to your own Google account and is governed by Google's terms, not ours — we have no access to it. You can turn it off in your device's backup settings, and the app will keep working exactly as before.
- The position you can type on the Times tab, used to work out sunset and sunrise for the day/night split, never leaves the device. The app does not use your device's location and holds no location permission.
Because nothing is collected, there is nothing for you to request a copy of and nothing for us to delete. Uninstalling the app removes everything it held.
What stays on your device — Sky Matrix briefing service
Your flight data lives only in your browser/app storage on your device:
- The OFP text you load and every field you type (times, weights, crew, notes).
- Your PIN, stored only as a one-way hash, and your biometric enrolment, which stays in your device's secure hardware and is never sent to us.
- Documents you add to the in-app DOCS store and your saved announcements.
None of this is uploaded to any Sky Matrix server. Clearing the app's data removes it.
What leaves the device, and why
A few features need the internet and send the minimum data required:
- Licensing & trials, your Device ID and email are sent to our licensing service to issue or validate an access code.
- AI OFP reading & announcement fill, when you tap these, the relevant OFP text or announcement template is sent to our service to be processed and returned. It is not used to build a public profile of you.
- Aircraft, weather & NOTAM lookups, a flight number/registration or airport code is sent to the relevant data provider to fetch results.
- Payments, handled entirely on the checkout provider's site; we never see or store your card details.
- Shared waypoint positions, when your flight plan prints a latitude and longitude beside a waypoint, that waypoint's name and position are contributed to a shared reference database, so pilots whose operator prints no coordinates still get a complete nav log. Only the waypoint name and its position are sent — never your callsign, flight number, date, aircraft registration, route or any crew name. Flight plans hold other crew members' names and roster details, so none of that leaves your device. Your Device ID is not stored beside a position: it is combined with the waypoint name and hashed, so the records cannot be read back as a history of where you have flown. A position is only ever used once two different pilots' plans agree on it. You can turn this off at any time in Load → My Devices → My account; turning it off stops all sending, and you still receive positions others have contributed.
- Sending a flight to your own second device, only when you press Send this flight to my other device on the My Devices tab. Nothing is sent automatically and nothing is polled in the background. What you send is the flight you have open — the parsed flight plan itself, plus the times, nav-log actuals, weights and notes you have entered. It is stored against your account, readable only by devices signed in with your email (the same two the licence allows), and deleted automatically 36 hours later. A flight plan holds other crew members' names and roster details, so if you would rather none of that reach our servers at all, leave the switch in Load → My Devices → My account off and use the 6-digit share or a handover file instead, which move the same data device to device with no server copy.
Third-party services
| Service | Purpose | Data shared |
| Cloudflare (Workers) | Licensing, trials, and the AI/data endpoints | Device ID, email, OFP/announcement text |
| Anthropic (Claude) | AI OFP reading and announcement fill | OFP text / template text you submit |
| Flightradar24 | Aircraft type and route lookup | Flight number or registration |
| Lemon Squeezy | Checkout & billing (merchant of record) | Your payment & contact details (with them, not us) |
| Cloudflare (Workers) | Anonymous usage milestones | Device ID + a step name (app opened / OFP loaded). No OFP content or route. |
| Resend | Sending your access-code emails | Your email address |
| Cloudflare (Workers) | Hosting the app and website | Standard web request logs |
Each provider processes data under its own privacy policy. We share only what the feature you invoked requires. Anonymous usage milestones — so we can see where people get stuck, the app records that a step happened (app opened, OFP loaded). Only your Device ID and the step name are sent — never OFP content, route, times or any flight data.
Security model
- Licences are protected with an ECDSA P-256 digital signature, only our server holds the private key, so codes can't be forged, and each code is bound to a single device (a subscription covers two devices, so you hold one code per device).
- Your PIN is stored as a salted one-way hash; biometric unlock uses the platform authenticator (WebAuthn) and never exposes your fingerprint/face to the app.
- Our Android apps are signed with our own private release key, Android verifies that signature on install and will only accept future updates signed with the same key.
- The app is served only over HTTPS. Sensitive data is never placed in URLs.
- Honest caveat: any client-side gate deters casual access but is not a guarantee against a determined attacker. Use a strong PIN and keep your device secured.
Android APKs, verify before you install
If you sideload one of our Android apps, confirm the file is authentic by checking its SHA-256 checksum against the matching value below before installing.
File: skymatrix.apk (Sky Matrix v1.4, flight briefing)
SHA-256:
ab7e2d5bcaab82145ef3d347378647298ad37885c04c6429995414590e572dc4
Signing certificate SHA-256:
ea800de5c4b00976981962d834bce5d135632eea0085f3eab102ce7e4fce3025
File: MatrixClock.apk (Matrix Clock v2.7, free — formerly Sky Alarm)
SHA-256:
a5ba2bf23977820f40c7e7699d3ed2bbdb60745d8534aa5d91f7662b1df6de39
Signing certificate SHA-256:
ce8e2a552cab9a1273aaaa2b9f0a9cc6b91838f4f54a1e9e783e7a46b67c4b07
The older SkyMatrixClock.apk and SkyAlarm.apk links still work and serve this same file, so the checksum above applies to all three. The app was called Sky Alarm, then Sky Matrix Clock, and is now Matrix Clock; it installs over any earlier version without uninstalling, because the package and signing key are unchanged. You can check the version you have at the foot of the app’s own screen.
File: MatrixBudget.apk (Matrix Budget v3.5, delivered by our checkout provider)
SHA-256:
e0f971754733fe29da71b325031faafcdc4efe467ab053aa40756298e45bf8b7
The file checksum changes with every release. The signing certificate does not — it identifies the developer, and it is the stronger of the two checks: a file that hashes correctly but is signed by someone else is not our build. To verify it, run apksigner verify --print-certs -v <file.apk> and match the value printed as Signer #1 certificate SHA-256 digest. Our APKs are signed with APK Signature Scheme v2, so keytool will wrongly report them as unsigned — use apksigner.
To check a file, on Windows run certutil -hashfile <filename> SHA256, or on macOS/Linux shasum -a 256 <filename>. The output must match the value above exactly. These checksums are for the current published builds; each one changes whenever that app is rebuilt.
Only install an APK obtained from our official download or checkout link. Because these apps are sideloaded, Android will warn about "unknown sources", that is expected; the checksums above are how you confirm the file hasn't been tampered with.
Your choices
You can stop all outbound data by simply not using the online features, the core briefing works offline. Waypoint sharing and sending a flight to your own second device each have their own switch in Load → My Devices → My account. To delete your data, clear the app's storage on your device. For a licence transfer or account/data request, email admin@skymatrix.biz.
Contact
Questions about privacy or security: support@skymatrix.biz.