Privacy Policy
Version 2026-09-27 · Effective 27 September 2026
This policy explains what personal data SKE collects, why, who receives it and how long we keep it. It covers ske.io (the website and docs), app.ske.io (the dashboard), the SKE API and the ske command-line tool.
Summary
- We collect what we need to run your account and SKE: your email address, your name, and records of what you do in SKE, such as deployments and the audit log.
- We don’t sell or share your personal information, and we don’t show ads.
- Nothing optional runs in your browser unless you allow it.
- When you use SKE for your own customers, for example its mail catcher, we process their data only on your instructions, under our Data Processing Agreement.
- You can ask for a copy of your data, or for your account to be deleted, through our contact form.
Who we are
SKE (“we”, “us”) is the controller of the personal data this policy describes, except where it says we act as a processor for our customers.
- Privacy contact: our contact form
- Data protection officer: we haven’t appointed one
What we collect
This section lists the personal data we collect, why, and how long we keep it. We don’t sell or share any of it.
| Data | Where it comes from | Why we use it | Legal basis | How long we keep it |
|---|---|---|---|---|
| Account details: your email address and name | You, when you register, accept an invitation, sign in or edit your profile | To create and run your account, sign you in with a magic link, and show your name to your teammates | Contract | Until your account is deleted |
| Terms acceptance: the version of the Terms of Service you accepted and when | You, when you tick the box to register or accept an invitation | To show which Terms you agreed to | Contract, and our legitimate interest in being able to prove it | Until your account is deleted |
| Sign-in data: magic links, sign-in tokens, and the tokens the CLI and MCP clients use | Created when you sign in | To keep you signed in and let your tools act for you | Contract | Magic links: 10 minutes. Sign-ins from the dashboard or the CLI: 30 days from last use. API tokens: 30 days after they expire or are revoked. MCP tokens: a week after they expire or are revoked |
| Organization and team records: organizations, workspaces, memberships, roles, teams and invitations, including the email address, inviter and message of an invitation | You and your teammates | To run organizations and control who can do what | Contract. For people who were invited but haven’t joined yet, our legitimate interest in letting teams invite people | While the organization exists. Invitations: until 30 days after they are accepted, declined, revoked or expire |
| Activity records: the audit log of changes and operations (including console commands and tinker input), deploy history with who started each deploy, and job history | Created when you use SKE | To show your organization what happened and who did it, to keep SKE secure, and to investigate problems | Contract, and our legitimate interest in security | Audit log: 12 months. Deploy and job history: while the environment or organization exists |
| Technical data: your IP address and browser (user agent) | Your browser or tool, with each request | To keep SKE secure: the audit log records them with each action, and rate limits use them for a short time to stop abuse | Legitimate interest in security | With the audit entry, 12 months. Rate limits: minutes to a day. Browser sessions on the API host: 2 hours |
| Visits and bot checks: your IP address, browser and the pages you visit, and, on sign-in, registration, the waitlist and the contact form, the signals Cloudflare Turnstile reads | Your browser. Cloudflare, which hosts our sites and runs Turnstile, collects them | To serve our sites and keep bots out | Legitimate interest in running and securing our sites | Cloudflare keeps its logs as its own privacy policy says. Turnstile results: not kept by SKE |
| Contact enquiries: your name, email, company, job title, team size, cloud, topic and message, with your IP address and browser | You, on ske.io/contact | To answer you | Steps you ask for before a contract, and our legitimate interest in answering enquiries | 12 months |
| Support tickets: the topic, subject and message of each ticket you open and every reply to it, including replies sent by email, with your name, email address and organization, the page, workspace, project and environment you opened it from, your browser, and when you last read it | You, when you open a ticket in the dashboard or reply to one, and our support staff, when they reply | To answer you | Contract | Until 12 months after the ticket is closed, or until your account is deleted if that comes first |
| Support emails: what you send to our support email address, for example from the “Trouble signing in?” link on the dashboard’s sign-in page, and the emails about your tickets that SKE sends there | You, by email, and SKE, when it tells our support staff about your tickets | To answer you | Contract. If you don’t have an account, our legitimate interest in answering you | 12 months |
| Waitlist requests: your email address and, if you give them, your name, company and what you’re building, with your IP address and browser, and whether and when we approved or rejected your request | You, on the dashboard’s sign-up page while sign-ups are closed | To decide who gets an account, and to email you when yours is ready | Steps you ask for before a contract | Until we decide. An approved request is deleted when you register, or 12 months after we approve it if you don’t, and the approval then lapses. A rejected request is kept for 12 months after we reject it |
| Cookie choices: a random consent ID, the choice, the time and the banner version, with no IP address and no account | Your browser, when you choose in the banner or in Cookie settings | To prove what you chose | Legal obligation | 2 years |
An account needs your email address, and we ask for your name when you first sign in. The contact form needs your name, email, company, team size, cloud, topic and message; your job title is optional. Everything else in the table is optional or created as you use SKE.
California categories. In the terms California law uses, we collect “identifiers” (your name, email address and IP address), “internet or other electronic network activity information” (your browser and your activity records), “professional or employment-related information” (the company and job title you give on the contact form), and one kind of “sensitive personal information”: account log-in credentials (sign-in links and tokens), which we use only to sign you in. We disclose each of them for business purposes to the providers listed in Who receives your data. We don’t sell or share any of them.
We don’t collect payment details (SKE has no paid plans yet), and nothing in SKE, the CLI or the dashboard reports usage, errors or telemetry back to us today. We don’t use your data for automated decisions that have legal or similarly significant effects on you. We do count things like deployments, in totals that can’t identify anyone, to run and improve SKE, and we don’t try to identify anyone from them.
Data we handle for our customers
SKE deploys and runs our customers’ applications in the customers’ own cloud accounts. Some features handle data about our customers’ own users. For that data the customer is the controller, and we act as its processor under our Data Processing Agreement. The customer’s own privacy notice applies to its users.
| Data | What SKE does with it | How long SKE keeps it |
|---|---|---|
| Emails and SMS caught by the mail and SMS catchers, including senders, recipients, subjects, bodies and attachments | Stores them so the customer can inspect them | The environment’s setting: 7 days by default, 30 days at most |
| Email delivery events from the customer’s Amazon SES: the sender, recipients, subject and headers of each email and, if the customer turns on open or click tracking, recipients’ IP addresses and browsers | Records the events the customer chooses to track for its SMTP provider (delivery, bounces, complaints, opens and clicks) | 90 days |
| Environment variables sent with each deploy | Stores them to deploy the application | Until the environment is deleted |
| Console commands and tinker input, which can contain the customer’s users’ data | Records them in the customer’s audit log | 12 months |
| Alert destinations: email addresses, chat webhooks and bot tokens | Stores them to send the customer’s alerts | Until the customer deletes the channel |
| Contact details in an Amazon SES production-access request | Stores them and sends them to the customer’s AWS account | Until the customer deletes the SMTP provider |
| Application logs and metrics from the customer’s cloud account | Logs pass through to the customer and aren’t stored. Metrics are stored as numbers only | Metrics: up to 90 days |
Secrets set in the dashboard or with ske secret set |
Pass through to the customer’s AWS or Google Cloud secret store and aren’t stored by SKE | Not stored |
If you are one of our customers’ users, contact that customer about your data. We’ll help them answer you.
Cookies
We use a small number of cookies and browser storage entries that SKE needs to work. They don’t need your consent. Optional ones need your consent, and none of them is in use yet.
Needed for SKE to work
| Name | Where | What it does | How long |
|---|---|---|---|
ske_refresh_token |
The SKE API (HttpOnly, used only by sign-in) | Keeps you signed in to the dashboard | 30 days from your last visit |
ske_consent |
ske.io and app.ske.io | Remembers your cookie choice | 6 months |
ske-session |
The SKE API, only when you approve an MCP client | Keeps that approval step working | 2 hours |
dashboard-sidebar-app-sidebar |
app.ske.io | Remembers whether you collapsed the sidebar | Until you close your browser |
nuxt-color-mode (browser storage) |
app.ske.io | Remembers light or dark mode | Until you clear it |
ske:console:… (browser storage) |
app.ske.io | Remembers your last 20 console commands and tinker inputs for each environment, so you can run one again | Until you clear it. It isn’t cleared when you sign out |
starlight-theme, sl-sidebar-state (browser storage) |
ske.io docs | Remember the docs’ theme and sidebar | Until you clear it, or until you close the tab |
| Cloudflare Turnstile | Sign-in, registration, the waitlist and the contact form | Checks that you aren’t a bot | Not stored by SKE |
Optional, only with your consent. None of these is in use yet. If you allow one now, it starts when we add it, and this policy will name its provider first.
- Error monitoring: when something breaks in your browser, it sends us the error, the page, the steps just before it, your browser and device type, and your account if you’re signed in.
- Product analytics: records the pages you visit and the features you use, linked to your account while you’re signed in.
- Session replay: records your clicks, scrolling and what’s on screen. What you type is hidden.
You can change your choice at any time with the Cookie settings link at the bottom of every page on ske.io, on the dashboard’s sign-in and registration pages, and in the dashboard’s account menu. One choice covers ske.io and app.ske.io and lasts 6 months, whether you accepted or rejected.
If your browser sends a Global Privacy Control signal, we don’t show the banner and nothing optional runs, unless you turn something on in Cookie settings yourself. We don’t respond to “Do Not Track” separately, because nothing optional runs without your consent anyway. No third party tracks you across other websites through SKE.
The ske CLI stores your sign-in tokens and settings in ~/.ske on your computer, so it can act for you. ske logout removes the tokens.
Who receives your data
We use these service providers to run SKE. Except where it says otherwise, they process personal data for us under contracts that limit them to that. The current list, with what each receives and where, is at ske.io/subprocessors.
- Cloudflare hosts ske.io and app.ske.io and the CLI downloads, and sits in front of the SKE API, which means it receives the IP address, browser and page of every visit, and everything sent to and from the API. It also counts visits at its network edge to give us traffic totals, with no script and no cookies. Its Turnstile bot check runs on sign-in, registration, the waitlist and the contact form, and Cloudflare also uses Turnstile data as a controller to improve its bot detection. It also receives the emails sent to SKE’s support address, which it forwards to our support staff, and email replies to support tickets, which it passes to the SKE API.
- Amazon Web Services (AWS) runs the SKE API and its background jobs, keeps our logs and stores caught-email attachments, all in the EU (Frankfurt, Germany).
- Our database provider runs our database.
- Bunny Fonts (bunny.net) serves the fonts on the page where you approve an MCP client, so it receives that page’s IP address and browser. It does this under its own terms, not a contract with us.
We also send data where you tell us to:
- Your own cloud accounts. SKE sends environment variables, secrets, images and settings to your AWS account or Google Cloud project to deploy and run your applications.
- The alert destinations your organization sets up, such as Slack, Discord, Microsoft Teams, Telegram, a webhook or an email address. Alerts include project and environment names, commits, errors, and the name or email of the person who started a deploy.
- Your teammates. Depending on their role, people in your organization can see your name, email address and what you do there, such as the deploys you start. People with access to the audit log, Owners and Admins by default, also see the IP address recorded with each of your actions.
We may also disclose data when the law requires it, to protect people’s safety or SKE’s security, or as part of a sale or reorganization of the business, which we would tell you about first.
International transfers
The SKE API, its files and its logs are in the EU (Frankfurt, Germany). Some of our providers, such as Cloudflare, process data in the United States and other countries. When data leaves the European Economic Area or the United Kingdom, we rely on one of two safeguards. The first is an adequacy decision, or in the UK adequacy regulations, such as the EU-US Data Privacy Framework and its UK extension, where the provider is certified. The second is the European Commission’s Standard Contractual Clauses, with the UK Addendum. To get a copy of the safeguards, ask us through our contact form.
How long we keep data
The periods are in the tables above. In short:
- Your account stays until it is deleted. When it is, your sign-in data, tokens, memberships and support tickets go at once. Organizations where you were the only Owner and the only member are deleted with it. If an organization you alone own has other members, one of them has to become an Owner first. Your email is replaced in deploy history. Your audit entries stay until they expire, at most 12 months later, with the IP address and browser they recorded, and show “Deleted user” instead of your name. Support emails, including those about your tickets, stay until they are 12 months old.
- A waitlist request stays until we decide on it. Once you register, the approved request is deleted. If you don’t register within 12 months of approval, it is deleted and you would have to join the waitlist again. A rejected request is deleted 12 months after we reject it.
- We keep a deleted organization for 30 days, and will restore it if an Owner asks through our contact form. After that, everything it holds is deleted, attachments and audit entries included.
- Application logs are kept for 14 days.
- Failed background jobs, which can contain alert text, are kept for 7 days.
Your rights
Depending on where you live, you have the right to:
- get a copy of your personal data, and have it in a format you can take elsewhere;
- have wrong data corrected;
- have your data deleted;
- have us limit how we use it;
- withdraw consent at any time, in Cookie settings, without affecting what happened before.
You also have the right to object to any use of your data that relies on our legitimate interests, such as the security records in the audit log. We will stop unless we have compelling reasons to continue, or need the data for legal claims.
If you live in California, you have the right to know what we collect and how we use it, to delete it, to correct it, and not to be treated differently for using these rights. We don’t sell or share personal information, and we have no actual knowledge of selling or sharing the data of anyone under 16. We don’t use sensitive personal information beyond what’s needed to provide SKE.
How to use these rights. Write to us through our contact form, with the email address on your account if you have one, or the email address you used with us if you don’t. We may ask you to confirm the request from that address before we act. Someone you authorize can ask for you, with your signed permission. We answer within one month, or tell you why we need longer. For now, deleting an account is done on request: we delete it for you rather than through a button in the dashboard.
Complaints. You can complain to us through our contact form. In the EU you can also complain to your local data protection authority. In the UK you can complain to the Information Commissioner’s Office (ico.org.uk).
Security
We keep your data safe with access controls, encryption in transit, and hashing of sign-in tokens. Cloud credentials you connect are encrypted at rest. If a breach affects your data, we’ll tell you and the authorities as the law requires.
Children
SKE is for people aged 18 or over. We don’t knowingly collect data from children. If you think a child has given us personal data, tell us through our contact form and we’ll delete it.
Changes to this policy
If we make a material change, we’ll email everyone with an SKE account before it takes effect and say what changed. Other changes are shown by the date at the top. Earlier versions stay available under Versions.
Contact
Write to us through our contact form.
Versions
- 2026-09-27Current