Skilly
Back to tryskilly.app Legal

Privacy Policy

Last updated: August 11, 2026

1. What we collect

We collect the minimum needed to run Skilly:

  • Account data — your email address and authentication identifiers via WorkOS AuthKit
  • Billing data — subscription status, held by Polar. We never see your full card number.
  • Usage metrics — per-session numbers: session length, turn count, token counts, costs, feature usage, and account or tenant identifiers when available
  • Browser extension session data — the active page URL, visible page text and interface structure, your spoken request, and requested page actions while you explicitly run a Skilly session. This context lets Skilly answer questions, point to controls, and perform limited actions during that session.
  • Skill Builder data — the software, learning goal, level, and pace you submit are processed to generate your course. If you request the Markdown by email, Resend processes your email address and generated course for delivery. Marketing consent is separate and optional.
  • Website analytics — page views, campaign parameters, click events, conversion events, and session replays of website visits via PostHog. Replays show scroll and cursor paths to help us find UX problems; all input fields are automatically masked.
  • Waitlist data — if you join the waitlist, we store your email and chosen platform in our Resend audience
  • Lead attribution data — if you submit a waitlist, newsletter, skill-request, or checkout form, we may send your email address to PostHog so we can connect marketing activity to product signup and subscription funnels. We do not send that email address to Google Analytics.

2. What we do NOT collect

To earn and keep your trust, Skilly deliberately does not store:

  • Audio recordings of your voice
  • Screenshots of your screen
  • The content of your prompts or Skilly\u2019s responses
  • Keystrokes, browsing history, or background page activity. The browser extension reads only the page where you explicitly start a live session and stops when you end the session, close the tab, or navigate away.
  • Cursor position or other device telemetry from the macOS app beyond what's needed for a single live teaching session (note: the marketing website at tryskilly.app records website cursor paths via PostHog session replay to find UX issues — see "Website analytics" above)

Audio, screen data, and browser page context are streamed to OpenAI for real-time processing during an active teaching session and are not retained by us afterward. We keep operational and analytics metadata about sessions, but not the session content itself.

3. Browser extension permissions and limited use

The Skilly browser extension requests access to webpages so it can understand the page where you start a session, point to the correct interface element, and carry out limited actions you request. Skilly asks for confirmation before destructive actions or actions on page controls that have not been explicitly marked as safe. It uses browser storage for your sign-in session and selected skill, browser identity APIs to complete sign-in, and an offscreen document to keep the microphone and real-time voice connection active while the session runs.

Skilly does not sell browser data, use it for advertising or credit decisions, or allow humans to read it except when you give explicit consent for support, when required for security or law, or after it has been aggregated and anonymized for internal operations.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

4. Third-party data processors

Skilly uses the following third-party services to run the product. Each link goes to that service's own privacy policy.

Purpose: Real-time voice and visual-context inference in the macOS app and browser extension, plus course generation in the website Skill Builder

Data shared: Audio, visible screen or webpage context, model prompts, and the software/learning goal entered into Skill Builder. These are sent only for the requested operation. OpenAI processes them to generate responses and is contractually prohibited from using API data for training.

Location: United States

Purpose: Product analytics, marketing attribution, funnel measurement, and session replay on the marketing website

Data shared: Event names, page URLs, campaign parameters, first-party analytics identifiers, session replays with input fields masked, and email addresses when users submit waitlist, newsletter, skill-request, or checkout forms.

Location: United States

Google Analytics

Privacy policy ↗

Purpose: Website traffic, acquisition, and conversion measurement

Data shared: Page views, campaign parameters, device/browser metadata, and non-PII conversion events. We do not send email addresses, names, or freeform form text to Google Analytics.

Location: United States

Purpose: Authentication and account management via AuthKit in the macOS app and browser extension

Data shared: Email address, hashed password or OAuth identifier, account metadata

Location: United States

Purpose: Subscription billing and payment processing

Data shared: Billing email, subscription status, payment method token (no card numbers stored by us)

Location: United States

Purpose: Static asset CDN and DDoS protection for the marketing site and Builders assets; during the staged migration, legacy desktop clients may still use Cloudflare as an API relay while Studio becomes the application backend

Data shared: Static asset and legacy API request logs, IP addresses retained by Cloudflare’s infrastructure for short periods, and TLS connection metadata

Location: Global CDN/edge network (varies)

Purpose: Transactional email delivery (waitlist confirmations, account notifications)

Data shared: Email address, message content, delivery status

Location: United States

Purpose: Website hosting and serverless routes for marketing forms and tools on tryskilly.app

Data shared: Server access logs, IP addresses, TLS connection metadata, and serverless function request metadata

Location: Global CDN (varies)

5. Cookies and tracking

Skilly's website uses first-party analytics storage for PostHog and Google Analytics so we can understand repeat visits, campaign performance, downloads, waitlist submissions, checkout completion, and the path from marketing to product activation. We do not use advertising cookies, and we do not send email addresses, names, or freeform form text to Google Analytics.

6. Data retention

  • Account data is retained while your account is active and for 30 days after deletion
  • Billing records are retained as required by applicable financial regulations (typically 7 years)
  • Anonymous usage metrics are retained indefinitely in aggregated form, but cannot be traced back to an individual
  • Waitlist entries are retained until launch or until you unsubscribe via the link in any email we send

7. Your rights

Depending on where you live, you may have rights under GDPR, CCPA, or similar laws, including:

  • The right to access the data we hold about you
  • The right to correct inaccurate data
  • The right to delete your data ("right to be forgotten")
  • The right to export your data in a portable format
  • The right to opt out of any non-essential processing

To exercise any of these rights, email hello@tryskilly.app. We'll respond within 30 days.

8. Children

Skilly is not directed at children under 13, and we do not knowingly collect data from them. If you believe we have, contact us and we'll delete it.

9. Changes to this policy

We'll update this page when we add, remove, or change data processors, or when we change what we collect. Material changes will be communicated via email to your account address.

10. Contact

Privacy questions or requests: hello@tryskilly.app.

See also: Terms of Service