Skip to content
Thermocloud
  • Features
  • Platform
  • Operations
Sign in Create account
Thermocloud home

Legal

Privacy Policy

This policy explains how Thermocloud handles information across its website, web application, and mobile applications.

Effective and last updated July 25, 2026

On this page

  1. Scope
  2. Our role and yours
  3. Information we handle
  4. How we collect it
  5. How we use it
  6. Notifications
  7. How we disclose it
  8. No sale and no tracking
  9. Cookies and device storage
  10. Retention
  11. Security
  12. Choices and requests
  13. Children
  14. Where we operate
  15. Changes
  16. Contact

1. Scope and who we are

Skyko Design LLC (“Skyko,” “we,” “us,” or “our”) operates Thermocloud. This policy applies to the public website, authenticated web service, our mobile applications, related APIs, and support communications that we provide together as the “Service.”

Thermocloud is a facility- and equipment-monitoring service used by customer organizations. An organization administrator may invite users, assign roles and access, configure sensors and alarms, and control who can see information in its workspace. If you use the Service through an organization, that organization may also have its own policies and may control the records it submits to the Service.

2. Our role and your organization’s role

For account information that we collect to create and secure your login, we act as the controller and decide how that information is handled. For Customer Data that an organization submits to its workspace — facility records, device configuration, telemetry, alarm content, notes, and similar operational material — we act as a processor or service provider and handle that information on the organization’s instructions.

This distinction matters when you make a request about your information. We can act directly on requests about your own account. Requests about records an organization controls usually need to be directed to, or coordinated with, that organization’s administrator, and we will help route them where we reasonably can.

3. Information we handle

Account and organization information

We handle identifiers and account details such as name, email address, username, telephone number, password credential, multifactor-authentication enrollment information, organization membership, role, access scope, invitations, and notification preferences. Passwords are stored as one-way hashes rather than readable text. Organization and customer records may include a business name, contact name, mailing or site address, and default notification email address or phone number.

Facility, device, and monitoring information

The Service handles information supplied by customers and their connected equipment, including facility and area names, location hierarchy, floorplan images and sensor positions, device identifiers and serial numbers, device configuration, sensor types, readings, units, timestamps, online or offline status, onboarding events, dashboards, and related operational metadata.

Alarm and operator activity

We handle alarm rules, thresholds, timing, notification routes, alarm events, acknowledgement and resolution activity, notes, assignments, maintenance or mute settings, and delivery status. Records may identify the account that performed an action.

Mobile app information

If you enable alarm notifications in the Thermocloud mobile app, the Service receives a push-notification device token and may store the device name, app version, platform, environment, registration time, and whether the registration is active. Mobile sessions also use revocable access and refresh credentials; server-side copies of those credentials are stored as hashes.

The Thermocloud mobile app does not request access to your device’s location, camera, microphone, contacts, photo library, or biometric data, and it does not collect precise or approximate geographic location. References to “locations” in the Service mean customer-defined facilities and areas, not device positions. The app contains no third-party advertising, analytics, or cross-app tracking software.

Technical, security, and support information

We may handle IP address, user agent, request and correlation identifiers, session dates, login and security events, audit records, error and diagnostic details, and similar information. If you contact support, we handle the contact details, message, and any files or operational information you choose to provide.

Automated sensor-onboarding analysis

Where automated payload analysis is enabled and the Service receives a sensor-onboarding payload, it may send that raw payload to OpenAI, a third-party artificial-intelligence provider, to suggest identifier, timestamp, metric, and control-field mappings. A raw payload contains the fields supplied by the connected device, so customers should configure devices not to include unrelated personal or confidential information.

4. How we collect information

We receive information directly from you, from an administrator or another authorized member of your organization, from sensors and gateways connected to the Service, from your browser or app as you use the Service, and from sign-in or notification providers when you choose or enable those features.

5. How we use information

We use information to:

  • create and secure accounts, authenticate users, and enforce organization, role, and access permissions;
  • onboard, install, and operate sensors and hardware, receive and display telemetry, build dashboards, floorplans, and site records, and maintain monitoring history;
  • analyze sensor payload structure and suggest onboarding field mappings when automated analysis is enabled;
  • evaluate alarm rules, coordinate response, and deliver configured notifications;
  • provide support, investigate errors, maintain availability, and improve the Service;
  • detect misuse, protect customers and the Service, and preserve security and audit records; and
  • comply with legal obligations and enforce applicable agreements.

6. Alarm notifications

Depending on customer configuration, the Service may send alarm information through email, SMS, push notification, or a customer-directed webhook. A notification may include facility, sensor, reading, severity, status, and alarm-link information needed to understand and respond to an event.

Push registration is optional and can be turned off in the app or in your device settings. Web account settings may allow users to update personal email and SMS preferences, while organization administrators and alarm managers may control organization defaults and alarm-specific routes. Turning off one channel does not necessarily disable alarms or other channels configured by the organization.

7. How we disclose information

We disclose information only as reasonably needed for the Service and the purposes described above, including to:

  • your organization: administrators and authorized members according to their roles and access scope;
  • service providers: providers that support hosting, databases, storage, email delivery, SMS and messaging, authentication, security, monitoring, and other operations, subject to the configuration used for the Service;
  • notification and platform providers: mobile platform providers such as Apple for push delivery, and destinations selected by a customer for email, SMS, or webhooks;
  • web asset and sign-in providers: our website loads fonts and JavaScript hosted by Google, so your browser sends Google ordinary web-request information such as IP address and user agent when a page loads; if your organization uses a configured single-sign-on option, Google or Microsoft also receives sign-in information for that authentication;
  • OpenAI: where automated payload analysis is enabled and the Service receives a sensor-onboarding payload, as described in Section 3;
  • professional advisers and authorities: where reasonably necessary to comply with law, protect rights or safety, investigate misuse, or establish or defend legal claims; and
  • a successor: in connection with a merger, financing, acquisition, reorganization, or sale of all or part of the business, subject to appropriate confidentiality protections.

Customer-configured webhooks can send alarm data to an external destination chosen by that customer; the destination’s handling of that information is governed by its own terms and policies. We ask our service providers to protect information consistently with this policy and to use it only to provide services to us.

8. No sale of information, no advertising, no tracking

We do not sell personal information, and we do not share it for cross-context behavioral advertising. The Service does not display third-party advertising, and our mobile applications do not include advertising or cross-app tracking software and do not track you across apps or websites owned by other companies.

9. Cookies and device storage

The web Service uses cookies needed for signed-in sessions and request security. It also uses browser local storage for functional preferences such as light or dark appearance and, during sensor onboarding, a resumable setup draft. These technologies support Service operation and are not used for cross-site behavioral advertising.

On iOS, authentication credentials are kept in the device Keychain. The app uses device preferences to remember notification choices and the push token, and it may keep authenticated floorplan images in a private, organization-scoped local cache for performance. The app clears that cache when you sign out, so a later account cannot see another organization’s maps. Device and operating-system controls may also affect how long local data remains.

10. Retention

Retention varies by record type, customer arrangement, operational need, and legal requirement. We keep account, organization, facility, telemetry, alarm, notification-delivery, security, audit, and support records for as long as reasonably needed to provide and secure the Service, maintain appropriate business records, resolve disputes, and meet legal obligations. Operational records may be archived rather than immediately deleted, and residual copies may remain for a period in backups or security logs.

Where a customer organization controls a workspace, retention or deletion of its monitoring records may depend on that organization’s instructions and its obligations. Contact us for information about a specific record or request.

11. Security

We use administrative, technical, and organizational measures intended to protect information. Measures reflected in the current Service design include authentication, role- and access-based controls, hashed credentials, secure credential storage on mobile devices, configuration for encrypted network connections, audit logging, and protection for selected sensitive stored values. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

You are responsible for keeping credentials confidential, using available security features, maintaining appropriate access for your organization, and telling us promptly if you suspect unauthorized use.

12. Your choices and requests

  • You can review and update available profile and notification settings in the web Service.
  • You can turn off push notifications in the app or in your device settings at any time, and you can sign out to revoke the active mobile session.
  • Your organization administrator can manage membership, role, access, and organization-controlled operational data.
  • You may contact us to ask about access to, correction of, export of, or deletion of information associated with you, and we will respond as applicable law requires.

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, to withdraw consent, or to appeal a decision we make about a request. You will not be treated differently for exercising these rights. To protect users and organizations, we may need to verify your identity, authority, and organization relationship before acting. Some requests must be handled by your organization administrator as described in Section 2, and some records may be retained where required by law, security needs, or an applicable agreement.

13. Children

The Service is a business tool intended for organizational and professional use by adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided information to us, contact us and we will take appropriate steps to delete it.

14. Where we operate

Skyko operates in the United States, and information handled through the Service is processed and stored in the United States and in other locations where we or our service providers operate. If you access the Service from outside the United States, you understand that your information will be transferred to and handled in the United States, where data-protection laws may differ from those in your country. Where a transfer requires a specific legal mechanism, we will use one that applicable law permits.

15. Changes to this policy

We may update this policy as the Service or our practices change. We will post the revised policy here and update the date above. We may also provide additional notice through the Service when an update materially affects how we handle information.

16. Contact us

For privacy questions or requests, contact:

Skyko Design LLC
PO Box 1192
Gold Bar, WA 98251
United States
support@thermocloud.net
Thermocloud

Environmental intelligence for modern facilities.

  • © 2026 Thermocloud
  • Support
  • Privacy Policy
  • Terms & Conditions