Effective date: July 24, 2026
Skedgi is built on one principle: your working life stays under your control. This policy explains what the app touches, where it lives, and the narrow situations in which data leaves your phone — each optional feature is described below with its controls and retention.
| Data | Where it lives | Who can see it |
|---|---|---|
| Personal schedule entries, invoices, expenses, and business profile | Your device only, unless you separately opt to publish an opaque conflict or mark an entry as Field Tech work as described below | Only you by default |
| Jobs you dispatch to a crew (title, time, address, notes, status, customer name and phone, closeout note, price) | Our dispatch server (US) — only while you're in a crew, see "Crews & dispatch" below | Your crew, filtered by role: techs never see prices — the server strips them before delivery |
| Technician-created entries explicitly marked “Full Field Tech details” (title, time, address, work notes, status, and job customer) | Our dispatch server (US), in rolling schedule snapshots while sharing is enabled | The crew owner and dispatchers; other technicians cannot read the board |
| Optional private-calendar conflicts | Our dispatch server receives only an opaque “Busy” interval: start, end, all-day flag, and time zone | The crew owner and dispatchers see “Busy” and the time; they do not receive the title, location, customer, attendees, notes, calendar name, or Apple event identifier |
| Capture photos and voice transcripts | Processed by our AI service; not placed in a Skedgi database. The AI provider may retain limited safety and abuse-monitoring logs under its published data controls. | Our AI provider processes the content to return your draft; authorized provider personnel may review flagged abuse data where its policy permits. |
| A random device identifier (e.g. "sk-3f9a…") | Our capture service's counters and RevenueCat subscription records | Used only to meter captures and recognize your subscription. It contains no name, email, or contact information, but it can link activity from the same app installation. |
When you photograph a job ticket or receipt, or speak a note, that content is sent over an encrypted connection to our processing service (a Cloudflare Worker), which passes it to Google's Gemini API to be read, returns the structured result to your phone, and discards the input. Neither we nor the processing pipeline retains your photos, transcripts, or their contents in a Skedgi database after the request completes. The AI provider may retain limited safety and abuse-monitoring logs under its published data controls. Captures are metered (10/month free, up to 1,500/month with Pro) using the random app identifier.
When you ask Skedgi AI a question, your question plus a snapshot of your own data (jobs, invoices, expenses, people — and, if you're in a crew, the roster and today's assignments, never techs' prices) is sent over an encrypted connection to our server, which passes it to Google Gemini to compose the answer. It is processed to answer you and is not used to train models. Schedule questions like "what's my day tomorrow?" are answered on your phone and never leave it. Skedgi AI is off until you explicitly enable it in the app.
With memory enabled, Skedgi stores small pieces of context (like "completed the Hilton retrofit") with Remembra, our memory service, tied only to a random device identifier — never your name. Memory can be turned off in Settings. "Clear AI memory" requests deletion of every active memory record tied to that identifier and reports in the app whether the deletion request succeeded.
If you start or join a crew (Settings → Teams), Skedgi gains a shared-work layer, and that is the one place your working data is held on a server: for jobs to reach a teammate's phone, they have to travel through one. Solo users never touch it.
What crosses: when an owner dispatches a job to a crew member, the job's title, start time, duration, address, notes, status, closeout note, and the customer's name and phone number are sent over an encrypted connection to our dispatch server and stored there so every crew phone can sync it. The job's price is visible only to the owner and dispatchers — the server strips prices before delivering a job to a tech; they are never merely hidden on the tech's phone. The crew roster (display names and roles) is stored too. Job photos, invoices, expenses, and other private records stay on your device — they are never uploaded.
Technician schedule sharing: a technician can separately enable “Share Field Tech work” and “Use private calendars to prevent conflicts.” Field Tech sharing publishes only entries the technician explicitly classifies as work and gives the owner or dispatcher their operational details. Private-conflict sharing publishes only an opaque Busy interval (start, end, all-day flag, and time zone). It never sends a private title, address, customer, attendee, note, calendar/source name, Apple event identifier, or the reason for the conflict. These are two independent, revocable choices; both are off by default. Switching the app's visible profile does not change what was classified or authorize new sharing.
How it's secured: there is still no email account or password. Your phone authenticates with a cryptographic key generated on the device; the private key never leaves your phone. All traffic is encrypted in transit. The server is operated by us on dedicated infrastructure in the United States (hosted with Hetzner), is used for nothing but crew sync, and its data is never sold, shared, or used for any other purpose.
Retention, revocation & leaving: crew jobs are retained on the dispatch server while the crew exists so members can sync. Turning schedule sharing off increases a revocation version and immediately purges that technician's schedule snapshots and published schedule rows from the server; an old phone cannot restore them with a stale upload. "Leave crew & delete my data" in Settings → Teams first revokes the member's server sessions and certificates, purges their published schedule data, and returns unfinished assignments to the crew's Unassigned list. Only after that succeeds does the phone remove its local crew roster, incoming jobs, assignments, and status data; personal records and jobs the technician authored stay on the phone. Completed crew-job history may remain with the crew as its business record. For a broader deletion request, email admin@dolphytech.com and we respond within 30 days. When an owner removes a member, that member's access and schedule sharing are revoked through the same server-first process.
Your customers' data: customer names and phone numbers you dispatch belong to your business. We process them only to deliver the job to your crew and never use them for anything else.
If you allow calendar access, Skedgi reads your calendar events to show them alongside your jobs, can auto-import calendar appointments as Skedgi entries so your day is complete in one place, and writes the jobs you schedule into your calendar so the two stay in sync (a two-way mirror). All of this reading and writing happens on your device through Apple's Calendar. We never receive or store your calendar itself. If a technician separately turns on private-conflict sharing, the dispatch server receives only the detail-free Busy interval described above, never the calendar event's content or Apple identifier. Note that once a calendar appointment becomes a Skedgi entry, it is ordinary Skedgi data: like any other entry it stays on your phone unless you later dispatch it to a crew or ask Skedgi AI about your schedule. You can turn auto-import and the sync off anytime in Settings, and revoke calendar access in iOS Settings.
Photos you attach to a job stay on your device — they are never uploaded, not even to crew members. Every image is re-encoded on the way in, which strips EXIF metadata including GPS location before it is stored. Capture photos sent for AI reading are not placed in a Skedgi database; the AI provider may retain limited safety and abuse-monitoring logs as described above.
When you pair a Direct Line with another Skedgi user, the two phones exchange their public identity keys through a short-lived rendezvous on our server (deleted within 15 minutes). Your private keys never leave your phone. On a paired Direct Line, your voice travels through our self-hosted voice server only as end-to-end-encrypted audio keyed by the two phones — the server carries ciphertext and cannot listen.
The crew walkie (the shared channel you join by going On Duty in a crew) works differently: with more than two phones there is no pairwise key, so crew-channel audio is encrypted in transit but not yet end-to-end encrypted — it is decrypted and re-routed by our voice server like a conventional radio relay. We will extend end-to-end encryption to crew channels; until then the app never claims it there. Going On Duty also makes your name visible to your crew as reachable on the walkie.
In all cases: no calls, audio, or messages are recorded or stored — voice exists only in transit.
If you allow location access, Skedgi reads your current location only while you're viewing your route, to estimate drive times and when to leave for your next job. It is used on-device for planning and is never tracked in the background and never sold or shared. You can decline it and the app falls back to your home address.
To show the forecast for a near-term job, Skedgi geocodes the address on your phone using Apple's location services and asks Apple Weather for weather at those coordinates. The address and coordinates are handled under Apple's privacy terms; they do not pass through a Skedgi server. Skedgi displays Apple's required weather attribution and legal link with each forecast. We do not receive or retain the coordinates or forecast on our servers.
Purchases are processed by Apple. We use RevenueCat to validate receipts, recognize an active subscription against the random app identifier, and provide purchase analytics. RevenueCat receives purchase history and that anonymous identifier. We never receive your card or bank details, name, or Apple ID.
Skedgi's cloud AI features are for adults age 18 or older and require an in-app age confirmation before they can be enabled. The app is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided information to us, contact us so we can investigate and delete it.
If this policy changes materially we'll update it here with a new effective date.