DRAFT — pending review by qualified legal counsel. This document is a structural placeholder, not a reviewed or binding privacy notice. Skofa will publish a reviewed version before accepting real paying customers.

Privacy Policy

Version 1.1 — Draft

1. What this policy covers

This policy describes how Skofa collects, uses, and protects information when you use the Skofa platform.

2. Information we collect

  • Account information: name, email address, password (stored as a salted hash, never in plain text).
  • Business information: whatever your business chooses to connect or enter — onboarding answers, documents, connected software data, and workflow/agent activity.
  • Usage information: audit logs, error events, and AI model usage recorded for security, billing, and reliability.

3. How we use information

We use information to operate the service you requested: authenticate you, run your configured AI agents, process billing, respond to support requests, and maintain the security and reliability of the platform.

4. Tenant isolation

Your business's data is logically isolated from every other business on the platform. Skofa does not use one business's data to serve another business.

5. Third-party processing

Connecting a third-party integration (e.g. a CRM or accounting system) means Skofa processes data from that system on your instruction, using credentials you control and can revoke at any time from the integrations page.

6. Cookies

Skofa uses only two cookies, both strictly necessary for the service to function — neither requires opt-in consent under applicable law, and Skofa does not set analytics, advertising, or tracking cookies of any kind.

Cookie Purpose Duration
skofa_session Keeps you signed in between requests. Required to use the product at all. 30 days, or until you sign out
skofa_oauth_state Protects against cross-site request forgery while you connect a third-party integration. Only set during that specific action. 10 minutes

Both cookies are httpOnly (unreadable by page JavaScript) and sent only over HTTPS in production. If Skofa ever introduces a cookie that is not strictly necessary — for analytics or marketing, for example — this policy and the product itself will be updated to ask for your consent before it is set, not after.

7. Data retention and deletion

You can request export or deletion of your business's data from account settings. Deletion begins a real grace period before permanent removal, described at the time of the request.

8. Security

Skofa encrypts stored third-party credentials, enforces role-based access control, and maintains audit logs of sensitive actions. No method of transmission or storage is 100% secure.

9. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. Contact us through the in-app support channel to exercise these rights.

10. Changes to this policy

Skofa may update this policy. Material changes will be reflected in a new version, tracked separately from prior versions you accepted.

11. Contact

Questions about this policy can be sent through the in-app support channel.