Privacy Policy
This Policy explains what data Skeema collects, why, and what control you have over it. We keep data collection minimal, never sell your data, and never use your diagrams to train our own models.
1. Data we collect
- —Account data — your email and authentication identifiers (e.g. Google OAuth) when you sign up.
- —Content — the boards, diagrams, prompts, and schemas you create or upload.
- —Usage data — basic product analytics (pages viewed, features used) to improve the Service.
- —Technical data — IP address and device/browser info, used for security and rate limiting.
- —Billing data — handled by our payment processor; we never store full card numbers.
2. How we use data
- —To provide, secure, and operate the Service;
- —To generate diagrams and code from your prompts (processed by our AI provider on your behalf);
- —To send transactional email (e.g. waitlist confirmation, account and billing notices);
- —To understand product usage in aggregate and improve features;
- —To prevent abuse, fraud, and to enforce our Terms.
3. AI processing & training
Prompts and relevant board context are sent to our AI providers solely to generate output for you. Depending on the feature, that processing is performed by OpenAI or by DeepSeek. We do not use Your Content to train our own models, and we do not sell it. Generated output belongs to you.
Because these providers operate internationally, your prompts and board content may be processed outside your country, including in the United States and China. If you are subject to data-transfer or data-residency restrictions, please take this into account before submitting confidential material.
4. Cookies
We use essential cookies for authentication and session management, and privacy-friendly product analytics. We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings; disabling essential cookies may break sign-in.
5. Storage & security
Your data is stored in managed, encrypted Postgres (Neon) and object storage. We use access controls, encryption in transit (TLS), and reputable infrastructure providers. No system is perfectly secure, but we work to protect your data and to notify you of material breaches as required by law.
6. Sharing
We share data only with sub-processors that help us run the Service, each under contractual data-protection obligations. We do not sell personal data.
- —Hosting — Vercel
- —Database — Neon (PostgreSQL)
- —File and image storage — Cloudflare R2
- —Caching and rate limiting — Upstash (Redis)
- —AI generation — OpenAI and DeepSeek
- —Payments — Razorpay
- —Transactional email — Resend
- —Error monitoring — Sentry
- —Product analytics — PostHog
7. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can export your data and permanently delete your account at any time from Settings inside the app — deleting your account removes your boards, projects, versions, and usage records. You can also email us to make a request.
8. Data retention
We keep your data while your account is active. On account deletion, we remove your content within a reasonable period, except where retention is required for legal, security, or accounting purposes.
9. Children
Skeema is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
10. Changes & contact
We may update this Policy; material changes will be communicated via the Service or email. For privacy requests or questions, email support@skeema.cloud.