Privacy Policy
Last updated on August 9, 2026.
At Skillsail, we take the protection of your personal data very seriously. We process personal data in accordance with the principles of the EU General Data Protection Regulation (GDPR). In this privacy policy, we explain how Skillsail (hereinafter also "we", "us" or "our") collects, uses and protects personal data when you use the Skillsail platform (our AI-powered eLearning content creation, hosting, sharing, and export service), our website or related services. We also describe your rights regarding your personal data under the GDPR and how you can exercise these rights.
This Privacy Policy is a notice describing our processing activities. It is not itself a request for consent and does not make a User, parent, or legal guardian a party to the Customer's agreement. Where we rely on consent for a particular activity, that consent is requested separately and may be withdrawn as described below.
Who we are and how you can contact us
Skillsail GmbH is responsible for processing your personal data in connection with our services. Within the meaning of applicable data protection laws, Skillsail GmbH acts as the controller for the data processing activities described in this statement (except in cases where we process data on behalf of a customer, as explained below).
Note: If you use Skillsail as part of an organization's account (e.g., your employer or educational institution), that organization generally determines why and how Customer Personal Data is processed and acts as controller, while we act as processor under our agreement with the organization. Skillsail may separately act as controller for processing connected with our direct Customer relationship, service and account security, billing, fraud prevention, legal compliance, and support. The applicable role depends on the particular processing activity, and your organization's privacy notices may also apply.
When we act as a processor for our customers (organizations using Skillsail to create or deliver eLearning content), data processing is governed by our Data Processing Agreement (DPA) in accordance with Art. 28 GDPR.
Contact information: If you have questions or concerns regarding your personal data or this privacy policy, you can reach us at any time at hello@skillsail.com.
Company Details:
Skillsail GmbH
Elektrastraße 11
81925 Munich
Germany
Registered with the Commercial Register of the Local Court Munich (Amtsgericht München) under HRB 303017.
Data Protection Officer: We have not appointed a Data Protection Officer (DPO). Please direct privacy inquiries to the contact email address above. If our contact arrangements change, we will update this Policy.
General Audience and Younger Users
Skillsail is a general-audience business and professional service that may be used by eligible Users aged 13–17 subject to the conditions below; it is not directed to children under 13. A person under 13, or below any higher minimum age required by applicable law for the person's location or the relevant feature, may not use Skillsail. A person aged 13–17 may use Skillsail only as a Younger Authorized User invited or added to an Organization Account by a Customer and only while the Customer's authorization and prior and continuing permission from a parent, legal guardian, or other holder of parental responsibility who has legal authority under applicable law ("Guardian Permission") remain in effect. Younger Authorized Users cannot use the anonymous demo, create or administer an Organization Account, accept the Terms or Data Processing Agreement, purchase or manage a Subscription, or act as Account Owner, administrator, or billing contact. Those acts require a Customer representative who is at least 18 years old, has reached the age of majority and has full legal capacity under applicable law, and has authority to bind the Customer.
Guardian Permission is an eligibility condition for access. It does not accept the Customer's agreement, make the person giving permission a Customer, transfer the User's data-protection rights, or constitute consent to unrelated processing or marketing. Where Skillsail relies on consent under Article 6(1)(a) GDPR for an information-society service offered directly to a child, Article 8 GDPR applies separately. In Germany, a child may give that consent independently from age 16; below 16, consent must be given or authorized by the holder of parental responsibility, and the controller must make reasonable efforts to verify that authorization. Other countries may apply a different threshold or additional rules. Where an organization is controller, it is responsible for its lawful basis and child-specific obligations and Skillsail acts on its lawful documented instructions. Skillsail remains responsible for processing for which it is controller.
Our ordinary registration flow does not ask for a date of birth, a copy of an identity document, guardian contact details, or proof of Guardian Permission, and Skillsail does not ordinarily store an age band or permission status. We do not claim to verify a User's age or Guardian Permission merely because the User accesses Skillsail through ChatGPT or an identity provider. We rely on the Customer's contractual representation for account eligibility and use a notice-and-response process. This does not remove any consent-verification, age-assurance, or other duty that applies to a particular processing activity. Customer Data may nevertheless contain age-related information if a Customer or User chooses to submit it.
If you believe that a person is using Skillsail below the applicable minimum age, or that a Younger Authorized User is using it without Customer authorization, Guardian Permission, or another authorization required by applicable law, contact us at hello@skillsail.com so that we can investigate. If we become aware of such use or processing, after obtaining reasonably sufficient information, we will restrict further unauthorized access and take the steps required by applicable law. Those steps may include deletion, unless retention or other handling is required or permitted by law. Where an organization is the controller, we may notify it and act on its lawful documented instructions. We may need to verify the requester's identity and authority, and we will not disclose a User's data solely because a requester claims to be a parent or guardian.
In simple terms for younger Users: If you are under 13, or below a higher minimum age that applies where you live or to the feature you want to use, do not use Skillsail. If you are 13–17, use Skillsail only through an organization that invited you and only with permission from your parent or legal guardian. Skillsail needs basic account, content, and usage data to provide the service. Your organization's administrators may manage your access and see data associated with its workspace. If you use an AI feature or connect another AI client, the information needed for that request goes to the providers described below. Content or links you or your organization make public may be seen by other people. Do not include secrets or sensitive personal information in prompts or course content. Ask a parent, guardian, teacher, or organization administrator if you need help, and contact us if you want to understand or exercise your privacy rights.
Data we collect
We collect various types of information – including personal data – when you interact with Skillsail. This includes, among others:
- Account data: When a person creates or administers an Organization Account, is invited or added to one, or signs in, we collect information such as name, email address, organization name or membership, authentication-provider identifiers, and session information needed for login. We may also collect profile details the User voluntarily adds. If Google authentication is selected, we receive the profile information described in the Google User Data section. Organization admins can delete an Organization Account from the platform settings, and Users can contact us about privacy-rights requests.
- Learning content and user-generated data: Content you upload or create is stored through the platform, such as course materials, modules, resources, messages, or feedback. This content is private and not publicly accessible by default. It may be processed or disclosed when an authorized user shares, publishes, exports, or requests provider processing, and in the other circumstances described in this Policy, including lawful requests and business transfers. Skillsail does not itself use customer content to train or fine-tune shared, general-purpose AI models.
- Review comment data: When an authorized user shares a module for review with comments enabled, we store the information needed to display the review conversation. For a visitor who is not signed in, that is a reviewer display name of up to 80 characters that the visitor types and the text of each comment, up to 2,000 characters per comment. A display name is free text chosen by the person writing it, so it may itself contain personal data. We do not store an email address, IP address, browser user agent, or device fingerprint on a review record, and commenting does not create a Skillsail account. A signed-in member of the module's own organization is attributed under the first and last name from that member's Skillsail profile; we never fall back to the member's email address for attribution.
- Usage data: We collect information about how you use the platform – such as which features or pages you access, your content-generation, editing, sharing, export, and credit-usage operations, and similar service metrics. This may also include technically automatically collected data, such as your IP address, browser type, device information, provider-derived country or region where available, and timestamps of your activities recorded in log files. Vercel Web Analytics and Speed Insights load across our website and platform to collect page-view, approved custom-event, and real-user performance data. A Web Analytics data point may include its timestamp, requested URL or path and dynamic route, filtered query parameters, referrer, approximate country or region, browser, operating system, device type, and analytics-script version. A Speed Insights data point may include its route and URL, network class, browser, operating system, device type, country, Web Vital measurement and element attribution, SDK version, and server receipt time. Vercel states that Web Analytics does not use third-party cookies and uses a request-derived visitor hash whose session lifespan is discarded after 24 hours. Because Web Analytics and Speed Insights receive URLs or routes, we treat those records as potentially pseudonymous Personal Data where a URL contains a module, organization, or other identifier; we do not describe them as unconditionally anonymous. Custom-event payloads are limited to predefined operational fields, including fixed allowlisted categories derived locally, and must not contain Customer Content or directly identifying Personal Data. Sentry receives application errors and structured logs from the client, server, and edge, as well as production client traces and masked sampled session replay used to diagnose faults. Depending on the event, Sentry diagnostics may include an error message and stack trace, URL or route, request and network metadata, timestamp, browser and device data, IP address or derived location, internal User or Organization identifier, and contact details deliberately attached to a selected failure report. Production client traces are sampled at 100%. Replay is sampled for 10% of ordinary production sessions and 100% of production sessions in which a captured error occurs. Sentry Session Replay reconstructs DOM and interaction state rather than recording screen pixels and may include page and element structure, navigation, clicks, scrolling, and console or network metadata. Replay masks page text and all input values and blocks media before the replay data leaves the browser. An AI agent observability provider identified on our Subprocessors page receives production trace telemetry from our AI authoring agent service used to observe, evaluate, and improve agent reliability and quality. Depending on the feature, run, and configuration, this telemetry may include span structure, error diagnostics, model, token, cost, and timing information, tool names, and technical run and feature context, including session, chat, module, internal User or Organization, and connected-channel identifiers. It may also include Customer Content, such as prompts or instructions, generated output, authoring-tool inputs and outputs, and selected course content or files relevant to the run, when needed for the reliability and quality-evaluation purposes described below. The applicable data categories, purposes, recipients, and retention are described further below.
- Cookies and similar technologies: When you use our platform or website, we use cookies and similar technologies for security, usability, audience measurement, performance monitoring, and fault diagnosis (details can be found in the Cookies and Tracking section below). These measurement and diagnostic services are not used for advertising or cross-site marketing tracking.
- Communication data: When you contact us directly (e.g., for support requests) or subscribe to our newsletter, we collect information such as your name, email address, the content of your messages, your IP address, and submission metadata such as the time and source of the request. We also store communication preferences such as subscription, unsubscribe, complaint, and suppression status. A provider subscription status is not itself evidence of consent. Where consent is required, we must separately retain sufficient evidence of the consent event, including its wording, time, and source. Contact form IP addresses and submission metadata may be sent to our disclosed email and customer-relationship providers for contact handling, security, and abuse prevention.
- Lifecycle audience and communication data: When a person creates or administers an Organization Account, completes onboarding, or updates relevant account settings, we create or update a contact with the email communications provider identified on our Subprocessors page using the email address, first and last name, internal User and Organization identifiers, and app language. For Organization Account creators, we also synchronize the number of modules created, most recent module or chat activity, whether the account has been inactive for 21 days, whether credits are low, and the current plan and Subscription status. We do not send Customer Content, prompts, module titles, chat text, or uploaded files to the provider for these workflows. The provider may create a contact if none exists and maintain audience membership and a provider-level subscription status. Our routine contact and lifecycle updates preserve an existing unsubscribe. Audience membership and provider-level subscription status are technical delivery settings; neither is consent or other legal authorization to send optional marketing. We also process send, delivery, bounce, complaint, unsubscribe, preference, and suppression records. Campaign or workflow open and link-click measurement, if enabled, may be used only under an applicable lawful basis and the disclosed provider configuration. We do not use open or link-click measurement for necessary transactional emails.
- Billing, subscription, and transaction data: When a Customer purchases or manages a Subscription, we and the applicable payment provider may process the organization name, billing email, plan, checkout, subscription, invoice, transaction, refund, dispute, tax, and payment-status information. Depending on the payment method and Link settings, the Stripe and Link services may also process Link account and authentication data, name, email, phone number, billing or shipping address, payment-method details, IP address or derived location, device identifiers, tax identifiers, and order and transaction details. Skillsail stores provider customer, subscription, and price identifiers; plan and subscription status and periods; cancellation or scheduled-plan metadata; credits; and entitlement status. The applicable Stripe entities and Sold through Link handle payment instruments, hosted checkout, billing and tax details, invoices and receipts, refunds, disputes, transaction support, and order or Subscription management in their services. They may provide Skillsail with order, Customer, transaction, tax, and status records needed to deliver the Platform and administer the relationship. Skillsail does not store full payment-card details and may access or receive only the provider records, identifiers, and status information needed for Subscription administration, support, accounting, fraud prevention, and legal obligations.
- Guardian and rights-request data: If a parent, legal guardian, representative, or organization contacts us about a younger User or a privacy-rights request, we may collect contact information, the claimed relationship to the User, correspondence, and information reasonably necessary to evaluate identity, authority, and the request. Permission to use Skillsail does not by itself provide us with guardian contact information or make the guardian a Customer.
- Authentication data: Login to the Skillsail platform uses secure authentication methods including Google OAuth. WorkOS AuthKit uses session and access-token cookies for authenticated web access. MCP bearer tokens are presented and verified for each request and are not stored in a general-purpose product database field. Authentication and authorization data are used for identity verification, session management, organization access control, integration operation and revocation, and protection of the Platform.
How we use your data (purposes and legal bases)
We process personal data for the following purposes. We rely on a legal basis under the GDPR for each:
Where Skillsail relies on legitimate interests under Article 6(1)(f) GDPR, we identify the specific interest, assess whether the processing is necessary, and document a balancing assessment before relying on that basis. We do not rely on that basis where the data subject's interests, rights, or freedoms override the identified interest, and we give particular weight to those rights where the data subject is a child. You may contact us for information about the balancing considerations applicable to you. Where Skillsail acts only as a processor, the Customer determines the legal basis and Skillsail acts on lawful documented instructions.
Note on AI use: We use AI technologies to assist in generating eLearning content. For details on AI processing and data usage, please see the AI Processing section below.
- Providing our services: We use your personal data to set up and manage your account, authorize organization access, create, host, edit, share, translate, and export eLearning content, administer usage allowances, and generally operate the Skillsail content-creation service for you and your organization.
Legal basis when Skillsail acts as controller: where the data subject is an individual Customer and the processing is necessary to perform that person's contract, Art. 6 para. 1 lit. b GDPR. For Authorized Users and representatives who are not parties to the Customer's contract, Skillsail relies on Art. 6 para. 1 lit. f GDPR only after the documented assessment described above for the specific interests in securely authenticating Users, administering organization-authorized access, protecting the Service against misuse, and responding to service and support requests. Where the organization is controller and Skillsail acts as processor, the organization determines and communicates the applicable legal basis. - Module review and feedback: Where an authorized user has enabled comments on a shared module, we process the reviewer display name and the comment text to show the review conversation to the people who can open that module, to attribute each comment to the person who wrote it, and to let a reviewer delete their own comment.
Legal basis when Skillsail acts as controller: Art. 6 para. 1 lit. f GDPR, after the documented assessment described above, for the specific interest in operating a review and feedback function that the module's author has deliberately enabled. Where the organization is controller and Skillsail acts as processor, the organization determines and communicates the applicable legal basis. - Personalization and platform improvement: We use data such as your usage habits and feedback to improve our services, fix problems, and develop new features (e.g., to optimize our AI-powered learning tools for your organization).
Legal basis when Skillsail acts as controller: Art. 6 para. 1 lit. f GDPR, after the documented assessment described above, for the specific interests in diagnosing faults, understanding feature performance, and improving the security and usability of the Service. Customer Personal Data that Skillsail processes solely as a processor is used for improvement only on lawful documented instructions, as otherwise permitted by the DPA and applicable law, or after it has been rendered anonymous so that it is no longer personal data. - Subscription administration and billing: We use the billing contact, provider identifiers and status, subscription, plan, credit, and entitlement data available to Skillsail to activate and manage plans, reconcile provider records and credits, support refunds and disputes handled through the provider, maintain required accounting and tax records, prevent fraud, and establish, exercise, or defend legal claims.
Legal basis when Skillsail acts as controller: Art. 6 para. 1 lit. b GDPR where objectively necessary to perform a contract with an individual Customer; Art. 6 para. 1 lit. c GDPR for applicable accounting, tax, and other legal obligations; and Art. 6 para. 1 lit. f GDPR, after the documented assessment described above, for the specific interests in administering the B2B subscription and billing relationship with organizational Customers through their representatives, preventing fraud, handling disputes, and establishing, exercising, or defending legal claims. The exact role and legal basis of each payment or Merchant-of-Record provider are governed by the specific processing activity, its agreement, and its notice. Stripe's published DPA describes Stripe as a processor for instructed payment-platform processing and as a controller for specified Stripe purposes, including selection of financial providers, fraud and loss prevention, security, legal and regulatory compliance, internal relationship management and billing, analytics, and product improvement. Sold through Link acts as merchant of record for Managed Payments transactions and determines processing needed for its transaction, tax, fraud, dispute, support, legal, and order-management responsibilities. - Service, lifecycle, and marketing communications: We use your contact details to send service-related communications, including account verification, password reset, important platform announcements, billing or plan information, and responses to support requests. We also use audience and lifecycle fields maintained with our disclosed email communications provider to operate onboarding and activation, plan or credit, inactivity and win-back, and similar customer-relationship workflows. We classify each active message as either a necessary service communication or optional direct marketing based on its content, recipient, and context. A technical subscribed or audience status maintained by a communications provider, account creation, Customer authorization, or permission from a parent or guardian is not marketing consent. We send optional advertising by electronic mail only where we can demonstrate either prior express consent or every condition of an applicable existing-customer exception: we obtained the address in connection with the sale of a good or service; the message promotes only our own similar goods or services; the recipient has not objected; and we gave a clear, simple, and free opportunity to object both when collecting the address and in every marketing message. Every optional marketing message includes a free unsubscribe mechanism, and a recipient may also object by contacting hello@skillsail.com. An unsubscribe, withdrawal, or objection stops future optional marketing. Necessary transactional and service communications may continue.
Legal basis when Skillsail acts as controller: Art. 6 para. 1 lit. b GDPR only where the communication is necessary to perform a contract with the data subject; otherwise legitimate interests in proportionate B2B service administration, support, and customer-relationship communication under Art. 6 para. 1 lit. f GDPR, subject to the balancing and right to object described above; or separate valid consent under Art. 6 para. 1 lit. a GDPR where required. The lawfulness of sending electronic direct marketing is assessed separately under the applicable ePrivacy and national marketing rules, including Section 7 of the German Act Against Unfair Competition (UWG). An existing-customer exception is used only where every legal condition is satisfied. Where the organization is controller and Skillsail acts as processor, the organization determines and communicates the applicable legal basis. - Security and performance: We process certain data (such as IP addresses, device information, and log data) to monitor suspicious activities, maintain the security and integrity of our platform, diagnose operational failures, and maintain reliable performance. This includes ordinary necessary infrastructure, authentication, firewall, provider, and application logs, as well as Sentry error monitoring, structured logs, production client traces, and masked sampled session replay, together with production trace telemetry from our AI authoring agent service. These diagnostic services are used for security, reliability, and fault diagnosis, not for advertising, cross-site marketing tracking, or individual learning or employee-performance scoring.
Legal basis when Skillsail acts as controller: Art. 6 para. 1 lit. f GDPR, after the documented assessment described above, for the specific interests in preventing misuse, protecting accounts and systems, investigating incidents, and maintaining reliable service performance. Processor activities remain subject to the Customer's lawful documented instructions and the DPA. - AI agent reliability and quality evaluation: We process the AI authoring trace data described above, including Customer Content where content-bearing trace analysis is enabled, to investigate failures, evaluate the quality, accuracy, safety, performance, and reliability of agent runs, detect regressions, and improve our prompts, model selection, and authoring tools. We do not use this processing for advertising, cross-site marketing tracking, behavioral profiles, or individual learning or employee-performance scoring, and we do not use it to train or fine-tune shared, general-purpose AI models. The provider that receives these traces is identified on our Subprocessors page.
Legal basis when Skillsail acts as controller: Art. 6 para. 1 lit. f GDPR, after the documented assessment described above, for the specific interests in measuring and improving the quality, accuracy, safety, performance, and reliability of AI-generated eLearning content and in detecting and diagnosing failures or quality regressions. Processor activities remain subject to the Customer's lawful documented instructions and the DPA. - Audience and performance measurement: We use Vercel Web Analytics to understand aggregated page views and approved interactions and Speed Insights to measure real-user web performance across our website and platform. We do not use these services for advertising, cross-site marketing tracking, behavioral profiles, or individual learning or employee-performance scoring. Custom events must not include Customer Content or Personal Data.
Legal basis when Skillsail acts as controller: Art. 6 para. 1 lit. f GDPR, after the documented assessment described above, for the specific interests in understanding aggregate service use, identifying performance problems, and maintaining an accessible, reliable service. Vercel Web Analytics and Speed Insights provide aggregate audience and performance measurements; they are not Sentry-style event diagnostics. Processor activities remain subject to the Customer's lawful documented instructions and the DPA. - Fulfillment of legal obligations: We may process or retain personal data when we are legally required to do so – such as to maintain proper business records, fulfill tax requirements, or respond to lawful government requests.
Legal basis: Legal obligation (Art. 6 para. 1 lit. c GDPR)
AI Processing
We use artificial intelligence (AI) technologies to assist in generating and improving eLearning content. When an authorized user invokes an AI feature, the prompts, instructions, selected course content or files, relevant metadata, and generated output needed for that request may be sent through the Vercel AI Gateway to a model or inference provider. The provider depends on the model chosen by the user or feature and the active routing and fallback configuration. Depending on the feature and configuration, a trace of that activity may also be sent to the AI agent observability and quality-evaluation provider identified on our Subprocessors page. The trace may contain the same prompts or instructions, selected course content or files, authoring-tool inputs and outputs, and generated output for the reliability and quality-evaluation purposes described above.
Skillsail does not itself use customer content to train or fine-tune shared, general-purpose AI models. A provider's handling, retention, and use of request data are governed by its actual role, the written business, API, and data-processing terms, and the configuration applicable to the selected route. A provider processing Customer Personal Data for a Skillsail-operated route is treated as a subprocessor or authorized further subprocessor where applicable. The current providers that may receive data are listed on our Subprocessors page. Users must submit only content they are authorized to disclose for the requested processing. Users must not submit health information, financial account details, government-issued identifiers, account credentials, authentication secrets, or other sensitive or highly regulated data through AI or MCP features.
Skillsail web chat may retain chat messages, session cursor and continuation state, event snapshots, approval records and tool inputs, and serialized stream events needed to provide and resume that feature. Direct MCP transport does not use a general product table to archive every raw JSON-RPC request and response. An MCP input may nevertheless become persistent Customer Data or an operational record when the User asks a tool to create or change a module, component, resource, media prompt, or other product record. Usage records may include provider, model, tool, token-count, timing, prompt-length or prompt-hash metadata, and error or reservation information without necessarily storing the raw prompt in that usage record.
The Customer must not authorize a Younger Authorized User to use an AI or MCP feature unless the selected processing route and provider configuration have been approved for under-18 use, including any required safety measure or Zero Data Retention arrangement, and the Customer's authorization, Guardian Permission, and every additional legal requirement remain satisfied. Use of a connected AI client is also subject to that client's own eligibility terms. The Customer is responsible for its intended audience, content choices, permissions, and instructions. Skillsail remains responsible for its own processing, provider arrangements, disclosures, and safeguards and may disable a route that does not satisfy those conditions.
AI output may be inaccurate, incomplete, or unsuitable. Younger Users should ask a parent, guardian, teacher, or organization administrator for help before relying on or publishing AI output and should report harmful or unsafe results to the organization or Skillsail.
Skillsail does not use the AI content-generation and MCP processing described in this Policy to make decisions based solely on automated processing that produce legal or similarly significant effects about a User. If that changes, we will update this notice and provide any safeguards required by applicable law before beginning that processing.
Connected AI Clients and MCP Integrations
Skillsail provides a Model Context Protocol (MCP) endpoint that an authorized user can connect to a compatible AI client, including ChatGPT. At the user's direction, that client sends prompts, tool arguments, and relevant request context to Skillsail. Skillsail returns the result requested by the user, which may include course or module structure and content, operation status, resource metadata, generated media metadata, or short-lived upload, download, media, or export links.
The connected client and its operator process the prompts and tool results on their side under their own terms and privacy notice and may act as an independently selected service provider or controller for that connected-client relationship. If Skillsail engages the same company to process Customer Personal Data in a separate Skillsail-operated route, that separate processing is classified by its actual role, including as a subprocessor or authorized further subprocessor where applicable. OpenAI may therefore provide ChatGPT in a User- or Customer-selected relationship and separately process data for a Skillsail-operated AI feature.
A connected client may be used only when its age, account, and permission requirements are met. Authorization to use Skillsail does not override the connected client's terms. The Customer retains the eligibility, Customer-authorization, Guardian Permission, and additional legally required authorization responsibilities assigned to it under the Skillsail Terms.
OAuth access tokens authenticate MCP calls. Skillsail does not include access tokens, refresh tokens, client secrets, or other OAuth credentials in MCP tool results. A connected client may retain prompts and tool results according to its own settings and policies. Users can stop future access by disconnecting the integration or revoking its authorization.
Google User Data
When you choose to sign up or log in using Google authentication, we access and collect specific information from your Google account. This section details our practices regarding Google user data.
What Skillsail receives through WorkOS AuthKit after Google sign-in:
- Your WorkOS user identifier
- Your Google account email address
- Your first and last name, where available
- Your Google profile picture URL, where available
- Your locale, where available through WorkOS AuthKit
Skillsail delegates Google login to WorkOS AuthKit. Skillsail's application code does not request Google Drive, Gmail, Calendar, contacts, or their content through this sign-in flow. The exact identity scopes enabled for Google login are controlled in the WorkOS configuration and must be configured consistently with this notice.
How we use Google data:
- To create and manage your Skillsail account
- To authenticate you when you log in to our platform
- To display your name and profile picture in your account
- To communicate with you about your account and our services
Important: We use Google identity data for the account, authentication, authorization, profile-display, communication, and security purposes described above. We do not use it for purposes unrelated to those account and Service functions.
We do NOT sell Google user data: We never sell, rent, or trade your Google account information, and we do not disclose it to third parties for their marketing or advertising purposes.
Data Sharing and Disclosure
We take your privacy seriously and limit sharing of your personal data to the following circumstances:
With whom we share data:
- Service and downstream providers: We share data with third parties needed to operate the platform and fulfill requested features. A recipient's role depends on the actual processing route. A provider that Skillsail engages, directly or through another provider, to process Customer Personal Data on a Customer's behalf is treated as a subprocessor or further subprocessor for that route and is subject to the applicable authorization and contractual requirements. A service independently selected and connected by a User or Customer may instead process its copy under that separate relationship. Payment, Merchant-of-Record, and scheduling providers may act as processors, controllers, or independent providers according to the specific function and governing terms. These recipients support functions including hosting, object storage, authentication, AI content and media generation, translation, billing, email, customer relationship management, monitoring, and support. We share only the data needed for the applicable service. A current role-aware list of disclosed recipients can be found on our Subprocessors page.
- User-directed sharing and publishing: When an authorized user makes a module public or shares a module, template, resource, or export link, the selected content and associated media may be accessible to the intended recipients or, depending on the chosen setting, anyone with the link. Temporary media and download links act as bearer links: anyone who receives one can use it until it expires. Media preview links normally expire after one hour, and resource and export download links normally expire after two hours. A link already issued may remain usable until that expiry even if the module's sharing setting is changed in the meantime.
- Review comments on a shared module: Where comments are enabled on a shared module, every reviewer display name and every comment in that module's review conversation can be read by anyone who is able to open the link under the applicable sharing settings, including the passphrase where one is set. Review comments are not restricted to the module's author. Once a signed-in member of the organization comments, the first and last name from that member's Skillsail profile is published to everyone holding that link. The module's author continues to see the full review history after the link is made private again or comments are switched off. We do not send reviewer display names or comment text to analytics or marketing providers. They are shared with a connected AI service when the module's author uses that service's review tools to read or answer feedback, as described under user-selected connected services below. They may also be included in the AI authoring traces and evaluation records described above when the module author uses agent features to work with that feedback and content-bearing trace analysis is enabled. We do not otherwise send them to an AI provider on our own initiative. Errors raised by the review feature reach our error-monitoring provider as technical diagnostics tagged with a feature area only, without comment text or reviewer names, and the masked session replay described below also applies to visitors who open a shared link without signing in.
- User-selected connected services: When a user authorizes an MCP or other integration, we exchange the prompts, tool arguments, and results needed to fulfill that user's requests with the selected service. That service processes its copy under its own terms and privacy policy, as described in the Connected AI Clients and MCP Integrations section above.
- Within your organization: If you use Skillsail through an organizational account, your data may be accessible to your organization's administrators as per your organization's policies. Organization administrators are responsible for managing the Organization Account and may instruct deletion of the organization and the user data associated with that organization.
- Legal requirements: We may disclose your data if required by law, court order, or governmental authority, or to protect our rights, property, or safety.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity subject to applicable law, contractual obligations, and any notice or choice that applicable law requires.
Third-party transfers: We transfer data to third parties only when necessary to provide our services, comply with law, carry out a User's authorized sharing, publishing, or connected service request, or complete a disclosed business transfer. Depending on the service and processing route, a recipient may act as a Skillsail processor, a subprocessor or further subprocessor for Customer Personal Data, an independent payment or scheduling provider, or a service selected by the User or Customer. We do not sell personal data or disclose it for unrelated cross-platform advertising.
Service Providers, AI Providers, and Connected Services
We work with service providers, AI and inference providers, independent providers, and User-selected connected services. A label such as "downstream" does not determine the provider's legal role. When Skillsail engages a provider, directly or through another provider, to process Customer Personal Data on a Customer's behalf, that provider is treated as a subprocessor or further subprocessor for that route. A service independently selected and connected by a User or Customer may process data under its separate terms and privacy notice. The same company may have different roles in different routes.
The current disclosed recipients, including their role, purpose, provider details, and location, are available on our Subprocessors page. That page also explains AI gateway routing, the safeguards applicable to international transfers for which Skillsail is responsible, and how we handle provider changes.
Data Retention and Deletion
We retain your personal data only for as long as necessary to provide our services and fulfill the purposes described in this privacy policy.
The periods and criteria below apply to copies controlled by Skillsail. Copies controlled by a Customer or an independently selected connected service are subject to that party's retention rules. Where a provider processes personal data on Skillsail's behalf, provider-specific retention and deletion controls apply in addition to the periods below. We do not describe a route as zero data retention unless that setting has been verified for the exact provider account, project, model route, and gateway configuration.
Retention periods:
- Account and workspace content: We retain account, organization, and Customer Data while the relevant account or workspace remains active and until an authorized deletion or termination process applies, subject to the specific temporary, legal, backup, provider, and deletion-queue rules below. Skillsail does not currently apply an automated inactivity-only deletion period.
- Audience and lifecycle communication records: We retain the contact, audience, lifecycle-segmentation, delivery, preference, unsubscribe, suppression, and communication records needed for the active customer relationship and the permitted communication purposes described above. Optional direct marketing stops when consent is withdrawn, the recipient objects to direct marketing, or the recipient unsubscribes; necessary transactional messages may continue. Routine Skillsail updates preserve an existing unsubscribe while the provider contact remains. Account deletion deletes the active contact from our email communications provider. Skillsail does not currently retain a separate application-level marketing suppression record. If that person later signs up again and the provider creates a new contact with a technical subscribed status, that status does not restore withdrawn consent, cancel an objection, or authorize optional marketing. Optional marketing may resume only if its legal eligibility is independently established. Exact provider retention and deletion settings must match our documented provider configuration.
- Review comments and reviewer records: A reviewer can delete their own comment for as long as that module's review comment cookie remains valid. The deletion takes effect immediately for readers, and the stored comment text is blanked by a daily cleanup process 30 days later. A placeholder for the deleted comment stays in the thread so that replies remain readable, and the name attributed to that comment is retained. Making a module private again, switching comments off, or changing the passphrase does not delete review data. Deleting the module, or deleting the Organization Account, removes the review threads, comments, and reviewer records that belong to it. When an individual user account is deleted, we anonymize that person's reviewer identity by replacing the stored name with "Former member" and clearing the link to the account; the text of comments written by that person is retained as content, because those comments sit inside review threads created and continued by other people, so anonymization does not guarantee that no name remains anywhere in a review conversation. A reviewer record created by a visitor who is not signed in is deleted automatically once its 30-day access window has passed without the visitor ever posting a comment; a record with comments is retained with them, and the only self-service removal available to such a visitor is deleting their own comments as described above. A request sent to hello@skillsail.com is handled against the reviewer record.
- Legal obligations: Some data may be retained longer if required by law (e.g., financial records for tax purposes).
- Billing and payment records: We may retain billing, subscription, plan, credit, entitlement, and provider-identifier or status records available to Skillsail where required or permitted for Subscription administration, legal obligations, accounting, fraud prevention, dispute handling, or the establishment, exercise, or defense of legal claims. The applicable Stripe entities and Sold through Link retain the payment-instrument, hosted checkout, invoice, receipt, order, refund, dispute, support, and tax records they control under their own retention rules and legal obligations. A deletion request made through Link for Managed Payments data may also cancel affected Subscriptions and delete associated Stripe objects; we reconcile provider notices and status changes with the Skillsail-controlled records described above.
- Credit-ledger records after deletion: When an Organization or User deletion applies to a credit-ledger record, the current release marks that record for deletion exactly 180 days after the deletion date. The daily authenticated cleanup process removes records after that date. This limited post-deletion period supports allowance reconciliation, accounting integrity, fraud and dispute review, and the establishment, exercise, or defense of legal claims, subject to any longer period required by law.
- Temporary exports: Export download links normally expire after two hours. The corresponding export package is queued for deletion after the link expires; scheduled cleanup may occur later than the link expiry.
- Temporary direct uploads: A signed direct-upload link normally expires after ten minutes. Uploaded bytes first land in private staging storage and are promoted to a separate sealed key only after server-side validation. Rejected uploads are deleted, and abandoned staging uploads older than 24 hours are eligible for scheduled cleanup. Unverified uploads from the previous upload flow that remain attached to a chat are eligible for scheduled cleanup after 30 days. Actual deletion is asynchronous and may occur later.
- AI and MCP request data: Prompts, tool arguments, selected files or content, generated results, and operation metadata are retained where they become Customer Data or are needed to provide the requested feature, maintain security, diagnose an error, evaluate or improve AI agent reliability and quality as described above, or handle support. The applicable account/content, log, deletion, and legal-retention criteria in this section apply. Transient direct MCP transport data does not receive a separate retention period merely because it passed through the MCP endpoint; any retained copy falls into one of the disclosed content, usage, approval, provider, support, or log categories. Gateway and model-provider copies follow the verified contract and configuration for the selected route.
- Application, authentication, security, and error logs: Vercel Function runtime logs for the current Pro project are available for one day under the current provider plan. Other necessary authentication, firewall, storage, database, AI-provider, and security records follow the documented schedule for the system that creates them. They are retained only for the period justified to operate and secure the Service, investigate incidents, prevent abuse, diagnose faults, or meet applicable legal obligations, then deleted or rendered anonymous under that schedule. Sentry errors, structured logs, client traces, and masked sampled replay follow the retention configured for our Sentry project and account. AI agent observability traces and evaluation records follow the retention configured for the applicable provider project and account. The applicable periods are determined by the current provider-account controls, data type, product, and plan. We review and update the documented retention criteria after a material configuration or plan change; this Policy does not claim a fixed provider period.
- Audience and performance measurement: Vercel Web Analytics page views and approved custom events, and Speed Insights real-user performance measurements, follow the retention configured for our Vercel project, account, product, and plan. Because those settings and plan terms may change, we review and update the documented retention criteria after a material configuration or plan change rather than state a fixed period here.
- Support, guardian, authority-verification, and rights-request correspondence: We retain these records while the matter is open and afterward for the period reasonably necessary to document the response, meet legal obligations, resolve disputes, and establish, exercise, or defend legal claims.
- Backups and deletion queues: Deletion from active systems may not immediately remove data from encrypted backups, provider recovery copies, or asynchronous deletion queues. Such copies are isolated from ordinary use and are overwritten or deleted under the applicable recovery or cleanup schedule unless law requires or permits longer retention.
Organization deletion: Organization admins can delete an Organization Account from the Skillsail settings page. When an Organization Account is deleted, we initiate asynchronous removal of the organization workspace and associated active platform data, including training content, uploaded files, generated media, usage records, organization settings, and user records associated with that organization. Active, paused, or otherwise non-terminal subscriptions for that organization are canceled. Backup, provider, legal-retention, and processor-data exceptions remain subject to the criteria above, the DPA, and applicable law.
If a user belongs only to the deleted organization, their Skillsail user identity may also be deleted. If a user belongs to another Skillsail organization, we retain the identity and data needed for that other organization and remove only the deleted organization's data and membership.
Individual deletion requests: You can request deletion of your account and associated data at any time by:
- Contacting us at hello@skillsail.com
- Providing your account email and verification of identity
- We will respond without undue delay and within the period required by applicable law. Where legally permitted due to complexity or request volume, that period may be extended after notice. If Skillsail acts as processor, we may refer the request to the relevant Customer or act on its documented instructions.
Upon account deletion, we will remove your personal data from our active systems, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, resolving disputes).
A parent, legal guardian, or legally authorized representative may contact us to notify us that Guardian Permission or another authorization has been withdrawn or to make a data-rights request when that person is legally entitled to do so. The Customer may separately contact us to withdraw its own authorization or request an access restriction. We may verify the requester's identity and authority. A guardian's ability to act for a User depends on applicable law and reasonably verified authority; Guardian Permission does not automatically transfer the User's data-protection rights to the guardian. Where the organization is controller, we may refer the request to it or act on its documented instructions. Once Guardian Permission, another required authorization, or the Customer's authorization ends, the Customer must revoke the affected User's access, and Skillsail may restrict access following reasonably verified notice. Withdrawal does not automatically erase data already processed; that data remains subject to applicable retention, deletion, legal-obligation, and controller-processor rules.
Younger User content-removal requests: A younger User or a person legally authorized to act for that User may ask us to remove content the User posted or made public through Skillsail. After reasonably verifying the request and the content concerned, we will remove or restrict the content where required by applicable law and where we control the relevant copy. Removal does not guarantee erasure of copies already shared with, saved by, or independently published by other people or services, and limited records may remain where retention is required or permitted by law. Where the Customer is the controller, we may coordinate the request with that Customer.
Data Protection and Security
We implement reasonable and appropriate technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction.
Security measures include:
- Encryption: Customer-facing transmissions are protected using HTTPS/TLS, and provider-to-provider transmissions use the safeguards applicable to those services.
- Access controls: We limit access to personal data by our employees and contractors to people who need it to perform their duties and are bound by confidentiality obligations. Access by providers is limited to the applicable service and governed by the role and safeguards described in the provider sections above.
- Secure infrastructure: Our platform is hosted on secure, professionally maintained servers with regular security updates and monitoring.
- Authentication security: Our authentication provider uses secure authentication mechanisms, including OAuth 2.0 for Google sign-in, to securely manage user access.
- Security review: We conduct security reviews, monitoring, and maintenance appropriate to the Service. No independent third-party audit report is incorporated into the DPA unless expressly stated there.
- Data minimization: We only collect and process the data reasonably necessary for the disclosed purposes and design our systems to limit unnecessary collection and disclosure.
Cookies, Browser Storage, and Tracking
We use cookies and similar browser technologies, including local storage, session storage, and IndexedDB, on our website and platform for security, usability, and requested feature handoffs. Cookies are small text files stored on your device. The other browser-storage mechanisms can retain preferences or, where you choose the pre-signup creation flow, the prompt and attachment needed to continue that flow after authentication.
Types of cookies and browser storage we use:
- Language and user preferences: When you change your preferred language on our website, we set a cookie to remember your choice. The platform also uses a cookie for the sidebar preference and local storage for interface preferences such as the theme and preview-panel layout.
- Pre-signup prompt and attachment storage: If you start creating from the public landing page before signing in, we store the pending prompt in both session storage and local storage so it can survive the authentication redirect. If you select a file, we store its name, type, bytes, and save time in IndexedDB on your device for the same handoff. The file is not uploaded to Skillsail until after authentication. These records are usable for no more than one hour. While Skillsail remains open, we schedule physical removal at that boundary. We also remove them when the handoff is read and check for stale records whenever Skillsail next opens. Browser suspension, closure, timer throttling, or a browser-storage error can delay physical removal until a later successful cleanup opportunity or until you clear the site's browser data.
- Review comment cookies: If you comment on a module that has been shared for review, we set one signed cookie for that module, named with the prefix __Host-rv_ followed by the module identifier, so that the review conversation can recognize you as the author of your own comments and allow you to delete them. The cookie is HMAC-signed and set as httpOnly, Secure, SameSite=Lax, with the path "/" and a lifetime of 30 days. Its contents are opaque identifiers and timestamps only: a reviewer identifier, the module identifier, a marker of the cookie's purpose, and the times at which it was issued and expires. It contains neither your display name nor any comment text. This cookie is necessary for the commenting function you use and is not a measurement or advertising technology. All review comment cookies are deleted when you sign out.
- Appointment booking cookies: On our appointment booking forms, we use Cal.com as our booking service provider. Cal.com may set cookies to manage your booking session and ensure the booking process works properly.
- Authentication cookies: We use WorkOS as our authentication provider for secure login to the Skillsail platform. WorkOS may set cookies to maintain your login session and ensure secure authentication across the platform.
- Audience and performance measurement: Vercel Web Analytics and Speed Insights load across our website and platform. Web Analytics measures page views and approved custom events without third-party cookies, while Speed Insights measures real-user web performance metrics. Custom-event payloads must not contain Customer Content or Personal Data. We do not use either service for advertising or cross-site marketing tracking.
- Error monitoring and masked session replay: The Sentry client records errors, structured logs, production client traces, and masked sampled replay for security, reliability, and fault diagnosis. Production client traces are sampled at 100%. Replay is sampled for 10% of ordinary production sessions and 100% of production sessions in which a captured error occurs. Session Replay reconstructs DOM and interaction state and may contain page and element structure, navigation, clicks, scrolling, and console or network metadata; page text and all input values are masked and media is blocked before replay data leaves the browser. Error and trace events may contain the diagnostic data categories listed in the Usage data section above. Sentry is not used for advertising or cross-site marketing tracking.
Important notes about cookie and browser-storage usage:
- No marketing purposes: We do not use the preference or pre-signup browser-storage entries, Vercel Web Analytics, Speed Insights, or Sentry described above for marketing or advertising. They support security, usability, aggregate audience and performance measurement, fault diagnosis, and the feature handoff you request, without cross-site marketing tracking.
- Function-specific storage: Authentication, security, language or preference, review comment, and requested handoff storage are used where necessary for those functions. Vercel Web Analytics, Speed Insights, and Sentry are separate measurement and diagnostic technologies and are not all classified as strictly necessary cookies. Their GDPR legal basis and any separate consent requirement under applicable ePrivacy law are assessed for each technology and configuration.
- Third-party services: WorkOS and Cal.com may set cookies for the authentication and booking functions described above. Vercel and Sentry provide the measurement and diagnostic technologies described above; this statement does not claim that those services set advertising cookies. Their processing is governed by the applicable service relationship, terms, and privacy information for the stated purposes. Cloudflare provides object storage and file delivery; this notice does not claim that our ordinary Cloudflare storage or delivery route sets a browser cookie.
Your Rights Under GDPR
Where the GDPR applies, and subject to the conditions and exceptions in the GDPR, you have rights regarding your personal data. You can exercise these rights by contacting us at hello@skillsail.com.
Your data subject rights include:
- Right to access (Art. 15 GDPR): You have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and to access such data.
- Right to rectification (Art. 16 GDPR): You have the right to obtain the rectification of inaccurate personal data and to have incomplete personal data completed.
- Right to erasure (Art. 17 GDPR): You have the right to obtain the erasure of your personal data under certain circumstances.
- Right to restriction of processing (Art. 18 GDPR): You have the right to obtain restriction of processing under certain circumstances.
- Right to data portability (Art. 20 GDPR): You have the right, where the statutory conditions are met, to receive personal data you provided in a structured, commonly used, and machine-readable format and to transmit it to another controller.
- Right to object (Art. 21 GDPR): You have the right to object to processing of your personal data based on legitimate interests. If you object to processing for direct marketing, we stop processing your personal data for that purpose; this is not subject to a legitimate-interest balancing test.
- Right to withdraw consent (Art. 7 GDPR): Where processing is based on consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you believe that the processing of your personal data violates the GDPR.
The competent supervisory authority for Skillsail GmbH is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27
91522 Ansbach
Germany
Website: www.lda.bayern.de
Contact
If you have questions, concerns, or issues regarding this privacy policy or our privacy practices, please do not hesitate to contact us:
Email: hello@skillsail.com
Postal address:
Skillsail GmbH
Elektrastraße 11
81925 Munich, Germany
We are happy to help and will strive to answer your concerns or questions about privacy as quickly as possible.