Privacy Policy

Last updated: October 5, 2026

Overview

Skeamo reads the code of an app you built and helps you get its backend ready for real customers. This policy explains what we collect, why, and the choices you have. We keep it short and in plain language on purpose.

You can look around without an account. We only start associating data with you once you sign in.

Information we collect

Account details: your email address, used to sign you in with a one-time link. We don't ask for or store passwords.

Your code: the repository or files you bring, so we can write your launch report, run your app in a workspace and propose fixes. Backend connection details you give us are used only to make the changes you approve.

Usage and billing: a metered ledger of reports, fixes, workspace time and launches, plus subscription status. Payment details are handled by Stripe. We never see or store your card number.

How we use it

To run the product: read your code, write the launch report, run your app in an isolated workspace, propose fixes you review, and launch when you choose.

To meter fairly: track credit usage so billing reflects what you actually run.

To improve the product: anonymised, aggregated outcomes help us tune what the report checks. We never sell your data.

Third-party services

We rely on a small set of providers, each handling only what its job requires: Stripe for payments, Anthropic for the AI that reads your code and proposes fixes, Vercel for hosting, workspaces and launches, GitHub when you connect a repository, your database provider (Supabase, Firebase or Neon) when you connect one, and ElevenLabs for optional voice.

Each provider processes data under its own privacy terms. If a provider isn't configured, that feature is switched off and the rest of the app keeps working.

Data retention

We keep your account and project data for as long as your account is active. Delete your projects or account and we remove the associated data, except where we're legally required to keep billing records.

Your rights

You can access, export or delete your data at any time. Email us and we'll act on requests promptly, typically within 30 days, and sooner where the law requires it.

Security

Sessions use signed, self-expiring tokens. Traffic is encrypted in transit. We scope every integration to the minimum data it needs and fail closed when a service is unavailable.

Changes to this policy

If we make material changes, we'll update the date above and, for significant changes, notify signed-in users by email.