Privacy Policy
Effective Date: August 3, 2026 | Last Updated: August 3, 2026
1. Introduction
Sklyz ("we," "our," or "us") operates the website sklyz.com and the Sklyz API (api.sklyz.com). We are committed to protecting your privacy and ensuring the security of your data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information.
2. Information We Collect
2.1 Information You Provide
- Directives and Queries: The text you submit through our directive analyzer, API endpoints, and contact forms.
- Contact Information: Name, email address, and business details when you book a strategy call or setup sprint.
- Account Information: If you create an account: email, name, organization, and authentication credentials.
2.2 Information Collected Automatically
- Usage Data: API request logs, timestamps, endpoint accessed, response status codes.
- Device Data: Browser type, operating system, IP address, user agent.
- Performance Data: Response times, error rates, service availability metrics.
3. How We Use Your Information
- To provide, maintain, and improve the Sklyz platform
- To process and respond to your directives and API requests
- To communicate with you about your account, bookings, and platform updates
- To detect, prevent, and address technical issues and security vulnerabilities
- To comply with legal obligations and enforce our Terms of Service
4. Data Sharing and Disclosure
We do NOT sell your personal data. We may share data with:
- Service Providers: OpenRouter (AI model inference), Hostinger (hosting infrastructure), Stripe (payment processing via Composio).
- Legal Requirements: When required by law, court order, or governmental regulation.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
5. Data Security
We implement industry-standard security measures including:
- TLS 1.3 encryption for all data in transit (HTTPS)
- HSTS (HTTP Strict Transport Security) with preload
- Content Security Policy (CSP) to prevent XSS attacks
- Rate limiting and DDoS protection
- Regular security audits and vulnerability assessments
- Data minimization — we collect only what we need
6. Data Retention
- API request logs: Retained for 30 days for operational monitoring
- Contact form submissions: Retained until the purpose is fulfilled or you request deletion
- Account data: Retained while your account is active, deleted within 30 days of account closure
7. Your Rights (GDPR & CCPA)
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data ("Right to be Forgotten")
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing of your personal data
- Non-Discrimination: Exercise your rights without discrimination (CCPA)
To exercise these rights, contact us at the email listed in Section 12.
8. Cookies and Tracking
Sklyz uses minimal cookies for essential functionality. We do not use third-party tracking cookies, advertising pixels, or fingerprinting. No analytics platforms (Google Analytics, Facebook Pixel) are loaded on our site.
9. Third-Party Services
Our platform integrates with third-party services that have their own privacy policies:
10. Children's Privacy
Sklyz is not intended for individuals under the age of 18. We do not knowingly collect personal information from children.
11. Changes to This Policy
We will notify you of material changes via email (if you have an account) or through a prominent notice on our website. Continued use after changes constitutes acceptance.
12. Contact Us
For privacy-related inquiries or to exercise your data rights:
13. Supervisory Authority
If you believe your data rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority.