Privacy Policy
Last updated: July 25, 2026
Atprosphere is a native iOS client for Bluesky, built on the AT Protocol and developed by SparrowTek LLC ("we," "us"). This policy explains what information the app handles, where it goes, and what never leaves your device.
The short version: Atprosphere has no analytics, no ads, no trackers, and no server that collects your data. Your account lives on the AT Protocol network you sign in to — not with us.
Information you provide
When you sign in, you authenticate directly with your AT Protocol account provider (for example, Bluesky) using OAuth. We never see or store your password. The app receives access tokens that let it act on your behalf, and those tokens are stored securely in the iOS Keychain on your device.
Content you create in the app — posts, replies, likes, reposts, follows, lists, direct messages, profile edits, and images you attach — is sent to the AT Protocol network under your account. Most AT Protocol content is public by design and is governed by the policies of your account provider, not by us.
Information stored on your device
- Session credentials — OAuth tokens and cryptographic keys, kept in the iOS Keychain.
- Cached content — timeline posts, profiles, and images are cached locally so the app loads fast and works better on poor connections.
- Preferences — appearance and app settings.
Signing out removes your session from the device. Deleting the app removes all locally cached data.
iCloud sync
Atprosphere saves your timeline reading position to your private iCloud database (CloudKit) so you can pick up where you left off across your devices. This data is stored in your personal iCloud account, is not accessible to us, and is subject to Apple's iCloud terms. If iCloud is unavailable, the app simply keeps the reading position on-device.
Our authentication service
During sign-in and token renewal, requests pass through our authentication service (auth.atprosphere.com), which exists solely to give you longer-lived sessions so you don't have to log in every day. It is stateless: it signs authentication requests and forwards them to your account provider. It does not store your tokens, your identity, or any personal data, and it keeps no user database.
Who your data goes to
- Your AT Protocol provider (for example, Bluesky PBC) — all account activity, per their privacy policy.
- The AT Protocol network — public content is federated and may be read by anyone, including third-party services that index the network.
- Apple — iCloud sync of reading position, within your own iCloud account.
We do not sell, rent, or share your personal information with anyone. We collect no analytics, run no advertising, and embed no third-party tracking SDKs.
Children
Atprosphere is not directed at children. You must meet the minimum age required by your AT Protocol account provider and by the laws of your region to use the service.
Data deletion
To delete content you have published, delete it in the app (or via any AT Protocol client) — deletion propagates through the network per your provider's policies. To delete your account, use your account provider's tools. To remove everything Atprosphere stores on your device, sign out or delete the app; to remove synced reading positions, delete Atprosphere data from iCloud in iOS Settings.
Changes to this policy
If we change this policy, we will update this page and the date above. Material changes will be called out in the app's release notes.
Contact
Questions about privacy? Contact SparrowTek LLC at support@sparrowtek.com.