SKM

Privacy Policy

Last updated: 27 September 2026

This policy explains what SKM collects, why, who else handles it, and your rights. It covers the SKM web app at app.skema.tech and the SKM connector used from AI assistants such as Claude and ChatGPT (mcp.skema.tech).

Who is responsible

SKM is operated by skema.tech, the data controller for the personal data described here. For anything about your data — questions, corrections, deletion — write to hello@skema.tech.

What we collect, and why

What Why Where it comes from
Email address and name To identify your account, show collaborators who is who, and contact you about the service You, or Google if you sign in with Google
Password, stored only as a bcrypt hash To sign you in You, if you use an SKM password
Financial models, and the documents and files you upload or pick from Google Drive They are the service: SKM stores them so you can build on them You
Chat messages and voice input To answer you You
Activity log: what you did, when, from which IP address, and which app (for example Claude) acted for you Security, and so a model's history shows who changed what Recorded as you use SKM
Connection records for AI assistants: which assistant you approved and when its access tokens were used To let the assistant act for you, and to let you revoke it Created when you approve a connection
Daily usage counts (chat requests, model builds, AI tokens) To apply fair-use limits Recorded as you use SKM
Anonymous page-view statistics To see which parts of the app are used Umami, a privacy-focused analytics tool we host ourselves. It sets no cookies and does not identify you

We don't sell your data, show advertising, or build profiles of you.

Legal basis

We process your account data, models, files and messages to provide the service you asked for (GDPR Art. 6(1)(b)). We keep activity logs, usage counts and page-view statistics because we have a legitimate interest in keeping SKM secure, fair to all users and improving it (Art. 6(1)(f)). Connecting Google Drive or an AI assistant happens only when you choose to.

Who else handles your data

SKM relies on these providers. Each processes data only to provide its part of the service.

Provider What it does What it receives
Render Hosts the SKM app and connector Everything passing through the app
Neo4j Aura The database Your account, models and activity log
Amazon Web Services (S3, Stockholm) File storage Documents you upload and generated reports
Anthropic AI models behind the chat, document reading and research Your messages, the parts of your models and documents needed to answer, and research queries
ElevenLabs Voice input and spoken replies Audio you record and text read aloud to you
Google Sign-in and Google Drive, only if you use them Confirms who you are; lets SKM read Drive files you choose
Cloudflare Domain name service Technical connection data

When SKM researches a company it looks up public company registers and websites (for example Brønnøysundregistrene). These lookups contain company names, not information about you.

Other SKM users see a model only if you share it with them, together with that model's activity history.

AI assistants you connect

If you connect SKM to an AI assistant such as Claude or ChatGPT, results SKM returns to it — model data included — are processed by that assistant's provider under its own terms and privacy policy, not this one. SKM sends the assistant only what the tools you or it call return, and only for models you can access. You can disconnect in the assistant's settings at any time; we can also revoke its access on request.

International transfers

Some providers, including Render, Anthropic and ElevenLabs, are based in the United States, so data may be processed outside the EEA. Where that happens it is covered by the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

How long we keep it

Your rights

You can ask us to show you everything we hold about you, correct it, delete it, give you a copy in a portable format, restrict how we use it, or object to processing based on legitimate interest. Write to hello@skema.tech; we'll answer within one month.

Deleting your account removes your login, saved layouts and all access tokens (including AI assistant connections), and detaches your name and IP address from the activity history. The activity entries themselves remain, without identifying you, so shared models' histories stay complete for the other people who worked on them.

If you think we've mishandled your data you can complain to Datatilsynet, the Norwegian Data Protection Authority (datatilsynet.no), or the authority where you live.

Security

Passwords are stored only as bcrypt hashes, connections use HTTPS, access tokens are stored as one-way hashes, and every request is checked against the models you're allowed to see or edit.

Changes

If we change this policy in a way that affects you, we'll tell you before the change takes effect.