Privacy Policy

Last updated: July 10, 2026

1. Scope and roles

This policy describes how SkyKoi handles personal information in its website, hosted services, device runtime, graph, integrations, and support operations. An organization that deploys SkyKoi to workers or other people usually decides why and how that data is processed; SkyKoi processes it for that organization under the applicable agreement.

2. Information categories

  • Account, organization, role, billing, support, and authentication records.
  • Device identity, health, operating-system, runtime, connection, and security events.
  • Graph metadata such as artifact name, type, version hash, relative path, relationship, provenance, and preview reference.
  • Content from files, accounts, messages, browser activity, processes, audio, or input only when the relevant source is presented and explicitly approved.
  • Integration grants and secrets needed to reconnect approved accounts. Secrets are stored separately from graph metadata.

Passwords, authentication tokens, secret keys, payment-card data, government identifiers, and secure-field input must not be placed in graph events. SkyKoi does not need a Social Security number for ordinary setup.

3. Device capture and monitoring

Capture is off by default. Before capture starts, the interface identifies the purpose, device, source categories, storage choice, retention period, and intended viewers. Sources are independently selectable and may be skipped or revoked. Private mode stops new capture.

Organizations must give affected people clear notice, use a lawful basis, avoid covert or disproportionate monitoring, honor protected activity, and follow employment, biometric, communications, and data-protection law. See the Capture & Monitoring Policy.

4. Purposes

  • Provide requested automation, search, previews, synchronization, collaboration, and support.
  • Authenticate devices and users; enforce approvals, roles, retention, and sharing rules.
  • Maintain reliability, reconcile offline events, investigate errors, and prevent abuse.
  • Meet legal obligations and exercise or defend legal claims.

We do not sell personal information or use device-capture content for targeted advertising.

5. Sharing and access

Information is available only to the user, organization members, service providers, or support personnel whose approved role and purpose require it. Administrators can grant access to a person or role and can revoke it. SkyKoi may disclose information when legally required or to address a security emergency, with notice where legally permitted.

Encryption reduces unauthorized access; it does not override an approved access grant. Standard hosted operation is not zero-knowledge because authorized services must materialize the graph and perform requested integrations.

6. Retention, deletion, and export

On-device capture defaults to a short bounded retention window and persistence is optional. The hosted signed-event history is retained until an organization owner uses the explicit graph-and-history erasure control or a contract-specific deletion schedule is executed; the device retention setting does not silently delete hosted history. Erasure removes active projections, previews, and signed device events while keeping a minimal audit record and sequence boundary that prevent an offline device from replaying erased history, subject to disclosed backup or legal-hold exceptions. Authorized users can export the visible graph as portable JSON.

7. Security and international processing

We use access controls, signed device events, authenticated encryption for stored integration secrets, transport encryption in production, audit records, and data minimization. No system is perfectly secure. Data may be processed where SkyKoi and its providers operate, subject to the safeguards in the applicable agreement.

8. Choices and rights

Depending on location and context, a person may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or an appeal. Organization-managed users should first contact their organization. Requests may be sent to privacy@skykoi.com. We verify requests and respond as required by applicable law.

9. Changes and contact

Material changes will be dated here and, where required, presented for notice or renewed consent. Privacy and data-protection questions may be sent to privacy@skykoi.com. Contractual notices use the legal entity and address stated in the customer's order form or agreement.