DRAFT — pending review by qualified legal counsel. This document is a structural placeholder, not a reviewed or binding privacy notice. Skofa will publish a reviewed version before accepting real paying customers.
Privacy Policy
Version 1.1 — Draft
1. What this policy covers
This policy describes how Skofa collects, uses, and protects information when you use the Skofa platform.
2. Information we collect
- Account information: name, email address, password (stored as a salted hash, never in plain text).
- Business information: whatever your business chooses to connect or enter — onboarding answers, documents, connected software data, and workflow/agent activity.
- Usage information: audit logs, error events, and AI model usage recorded for security, billing, and reliability.
3. How we use information
We use information to operate the service you requested: authenticate you, run your configured AI agents, process billing, respond to support requests, and maintain the security and reliability of the platform.
4. Tenant isolation
Your business's data is logically isolated from every other business on the platform. Skofa does not use one business's data to serve another business.
5. Third-party processing
Connecting a third-party integration (e.g. a CRM or accounting system) means Skofa processes data from that system on your instruction, using credentials you control and can revoke at any time from the integrations page.
6. Cookies
Skofa uses only two cookies, both strictly necessary for the service to function — neither requires opt-in consent under applicable law, and Skofa does not set analytics, advertising, or tracking cookies of any kind.
| Cookie | Purpose | Duration |
|---|---|---|
skofa_session |
Keeps you signed in between requests. Required to use the product at all. | 30 days, or until you sign out |
skofa_oauth_state |
Protects against cross-site request forgery while you connect a third-party integration. Only set during that specific action. | 10 minutes |
Both cookies are httpOnly (unreadable by page JavaScript) and sent only over HTTPS in production. If Skofa ever introduces a cookie that is not strictly necessary — for analytics or marketing, for example — this policy and the product itself will be updated to ask for your consent before it is set, not after.
7. Data retention and deletion
You can request export or deletion of your business's data from account settings. Deletion begins a real grace period before permanent removal, described at the time of the request.
8. Security
Skofa encrypts stored third-party credentials, enforces role-based access control, and maintains audit logs of sensitive actions. No method of transmission or storage is 100% secure.
9. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. Contact us through the in-app support channel to exercise these rights.
10. Changes to this policy
Skofa may update this policy. Material changes will be reflected in a new version, tracked separately from prior versions you accepted.
11. Contact
Questions about this policy can be sent through the in-app support channel.