Skindle
DRAFT · NOT YET IN EFFECTThis policy is a working draft. The operating entity and contact address are still to be confirmed, and the text has not been reviewed by a lawyer. It describes how the Service is built to handle data today; it is not yet a published policy.

Privacy Policy

Last updated: [date]

This policy explains what Skindle (the "Service"), provided by [legal entity name] ("we", "us"), collects, why, and what you can do about it. It applies to visitors of this site and to people who use the Service through an Organization.

1. What we collect

DataWhere it comes fromWhy
Account details: name, work email, password (stored as a salted hash), role, organization membershipYou, or the person who invited youTo run your account and your Organization
Organization content: the content pack, brand settings, invited email addressesOrganization owners and adminsTo serve your team its content
Working data: call notes, target lists you import, outcomes, boards, templates, settingsMembers, as they use the appTo sync your work across devices
AI requests: the prompt built from your content and notes, the model's reply, token counts and costGenerated when a member uses an AI featureTo produce the brief, roleplay or rewrite, and to apply fair-use limits
Billing: customer and subscription identifiers, seat counts, plan, invoice statusStripeTo manage subscriptions. Card numbers stay with Stripe.
Technical: IP address, browser type, request logs, error logsYour browserSecurity, rate limiting, keeping the Service running

Target lists and call notes may contain personal data about the people your team contacts. Your Organization decides what to put there and is responsible for having a lawful basis to process it; we process it only on your behalf.

2. How we use it

To provide and secure the Service, to sync data between your devices, to send transactional email (invitations, password resets, billing notices), to enforce plan and fair-use limits, and to improve reliability. We do not sell personal data and we do not use your content to train AI models.

3. Who else handles it (subprocessors)

ProviderPurpose
RenderHosting for the application and its database
StripePayments, subscriptions and the billing portal
ResendTransactional email
OpenAI and/or AnthropicAI features, only for the text sent when a member uses one. If your Organization supplies its own key, requests go to that provider under your own agreement.

4. Cookies and local storage

The Service keeps your session token and a cached copy of your working data in your browser's local storage, and sets one flag cookie so the home page opens the app for signed-in browsers. We do not use advertising cookies or third-party analytics on the app or on this site.

5. Retention

Account and Organization data are kept while the Organization exists. When an Organization is deleted or a member is removed, their working data is deleted; backups roll off within [retention period]. AI request logs are kept for usage accounting and then deleted. Billing records are kept as long as tax and accounting rules require.

6. Security

Traffic is encrypted in transit (HTTPS). Passwords are stored as bcrypt hashes. Organization-supplied AI keys are encrypted at rest. Access to production systems is limited to the people who operate the Service. No system is perfectly secure; if we learn of a breach affecting your data we will notify the Organization owner without undue delay.

7. Your rights

You can export your working data from the app at any time, correct your name and password yourself, and ask us to delete your account. Depending on where you live you may also have rights to access, portability, restriction or objection under laws such as the GDPR or the CCPA; write to us and we will respond within the time the law allows. Members of an Organization should also contact their Organization owner, who controls the Organization's data.

8. Children

The Service is for business use by adults. We do not knowingly collect data from anyone under 18.

9. Changes

We may update this policy. Material changes will be announced in the app or by email before they take effect.

10. Contact

[legal entity name]
[mailing address]
hello@skindle.ai