Legal
Privacy Policy
By default, nothing leaves your machine. Skuade runs locally and we never see your prompts, your code or your files. We only collect data if you enable the optional Store and sign in — and even then, only your email and basic profile data. This policy is structured around two modes: local (no collection) and Store (minimal collection).
01Two modes of use
Local mode (default)
No account, no telemetry, no data leaving your machine. Your prompts and files go directly from your machine to third-party AI providers under your own subscription. In this mode we are not a controller of any of your data — we process nothing.
Store mode (opt-in)
Only here do we collect data, and we act as data controller. Our entire privacy exposure lives in this mode, described below.
02What we collect — and don't
What we NEVER collect
- Your prompts or the content you send to AI models.
- Your code, files or project contents.
- Usage telemetry, behavioral analytics or advertising tracking.
What we collect only in Store mode
- Email address (account identity).
- Basic Google profile data if you sign in with Google: name, avatar and identifier (
sub). - A hashed session token (SHA-256) with a 90-day lifetime.
- The content of any workflows you choose to publish to the Store.
03How we use it
- Create and authenticate your Store account.
- Publish, moderate and distribute the workflows you share.
- Maintain security and prevent abuse.
04Legal bases (GDPR)
- Contractual necessity (Art. 6(1)(b)): creating your account, authenticating you and providing the Store.
- Legitimate interest (Art. 6(1)(f)): operating and moderating the community Store and keeping it secure.
06Retention
Session tokens expire after 90 days. Account data is kept until you delete your account or request erasure. Published workflows remain while published or until you remove them.
07Your rights
If the GDPR applies to you, you have the right to: access, rectify, erase, restrict and port your data, object to processing, withdraw consent and lodge a complaint with your supervisory authority. California residents may exercise access and deletion rights; we reiterate that we do not sell or share personal information. Write to the contact in Section 12; we respond within one month.
08International transfers
The Store's infrastructure (Cloudflare Workers and D1) is hosted in the United States. If you are in the European Economic Area, your data is transferred outside the EEA under the Standard Contractual Clauses (SCCs) and the supplementary measures Cloudflare incorporates in its Data Processing Addendum.
09Security
Session tokens are stored hashed (SHA-256) and the OAuth secret lives only as a Cloudflare secret, never on the client. The security of data residing on your own machine is your responsibility and depends on your operating-system account; note that agents run without isolation (see Terms, Section 7).
10Children's privacy
The Service is not directed to minors and we do not knowingly collect data from anyone under 16. If you believe a minor provided us data, write to the contact in Section 12 and we will delete it.
11Changes
We may update this policy; the current version will be published here with its date. Material changes will be highlighted prominently.
12Contact
To exercise your rights or ask about privacy: