Last updated: July 10, 2026
This policy describes how SkyKoi handles personal information in its website, hosted services, device runtime, graph, integrations, and support operations. An organization that deploys SkyKoi to workers or other people usually decides why and how that data is processed; SkyKoi processes it for that organization under the applicable agreement.
Passwords, authentication tokens, secret keys, payment-card data, government identifiers, and secure-field input must not be placed in graph events. SkyKoi does not need a Social Security number for ordinary setup.
Capture is off by default. Before capture starts, the interface identifies the purpose, device, source categories, storage choice, retention period, and intended viewers. Sources are independently selectable and may be skipped or revoked. Private mode stops new capture.
Organizations must give affected people clear notice, use a lawful basis, avoid covert or disproportionate monitoring, honor protected activity, and follow employment, biometric, communications, and data-protection law. See the Capture & Monitoring Policy.
We do not sell personal information or use device-capture content for targeted advertising.
Information is available only to the user, organization members, service providers, or support personnel whose approved role and purpose require it. Administrators can grant access to a person or role and can revoke it. SkyKoi may disclose information when legally required or to address a security emergency, with notice where legally permitted.
Encryption reduces unauthorized access; it does not override an approved access grant. Standard hosted operation is not zero-knowledge because authorized services must materialize the graph and perform requested integrations.
On-device capture defaults to a short bounded retention window and persistence is optional. The hosted signed-event history is retained until an organization owner uses the explicit graph-and-history erasure control or a contract-specific deletion schedule is executed; the device retention setting does not silently delete hosted history. Erasure removes active projections, previews, and signed device events while keeping a minimal audit record and sequence boundary that prevent an offline device from replaying erased history, subject to disclosed backup or legal-hold exceptions. Authorized users can export the visible graph as portable JSON.
We use access controls, signed device events, authenticated encryption for stored integration secrets, transport encryption in production, audit records, and data minimization. No system is perfectly secure. Data may be processed where SkyKoi and its providers operate, subject to the safeguards in the applicable agreement.
Depending on location and context, a person may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or an appeal. Organization-managed users should first contact their organization. Requests may be sent to privacy@skykoi.com. We verify requests and respond as required by applicable law.
Material changes will be dated here and, where required, presented for notice or renewed consent. Privacy and data-protection questions may be sent to privacy@skykoi.com. Contractual notices use the legal entity and address stated in the customer's order form or agreement.