SKMPrivacy Policy
Last updated: 27 September 2026
This policy explains what SKM collects, why, who else handles it, and your rights. It covers the SKM web app at app.skema.tech and the SKM connector used from AI assistants such as Claude and ChatGPT (mcp.skema.tech).
Who is responsible
SKM is operated by skema.tech, the data controller for the personal data described here. For anything about your data — questions, corrections, deletion — write to hello@skema.tech.
What we collect, and why
| What | Why | Where it comes from |
|---|---|---|
| Email address and name | To identify your account, show collaborators who is who, and contact you about the service | You, or Google if you sign in with Google |
| Password, stored only as a bcrypt hash | To sign you in | You, if you use an SKM password |
| Financial models, and the documents and files you upload or pick from Google Drive | They are the service: SKM stores them so you can build on them | You |
| Chat messages and voice input | To answer you | You |
| Activity log: what you did, when, from which IP address, and which app (for example Claude) acted for you | Security, and so a model's history shows who changed what | Recorded as you use SKM |
| Connection records for AI assistants: which assistant you approved and when its access tokens were used | To let the assistant act for you, and to let you revoke it | Created when you approve a connection |
| Daily usage counts (chat requests, model builds, AI tokens) | To apply fair-use limits | Recorded as you use SKM |
| Anonymous page-view statistics | To see which parts of the app are used | Umami, a privacy-focused analytics tool we host ourselves. It sets no cookies and does not identify you |
We don't sell your data, show advertising, or build profiles of you.
Legal basis
We process your account data, models, files and messages to provide the service you asked for (GDPR Art. 6(1)(b)). We keep activity logs, usage counts and page-view statistics because we have a legitimate interest in keeping SKM secure, fair to all users and improving it (Art. 6(1)(f)). Connecting Google Drive or an AI assistant happens only when you choose to.
Who else handles your data
SKM relies on these providers. Each processes data only to provide its part of the service.
| Provider | What it does | What it receives |
|---|---|---|
| Render | Hosts the SKM app and connector | Everything passing through the app |
| Neo4j Aura | The database | Your account, models and activity log |
| Amazon Web Services (S3, Stockholm) | File storage | Documents you upload and generated reports |
| Anthropic | AI models behind the chat, document reading and research | Your messages, the parts of your models and documents needed to answer, and research queries |
| ElevenLabs | Voice input and spoken replies | Audio you record and text read aloud to you |
| Sign-in and Google Drive, only if you use them | Confirms who you are; lets SKM read Drive files you choose | |
| Cloudflare | Domain name service | Technical connection data |
When SKM researches a company it looks up public company registers and websites (for example Brønnøysundregistrene). These lookups contain company names, not information about you.
Other SKM users see a model only if you share it with them, together with that model's activity history.
AI assistants you connect
If you connect SKM to an AI assistant such as Claude or ChatGPT, results SKM returns to it — model data included — are processed by that assistant's provider under its own terms and privacy policy, not this one. SKM sends the assistant only what the tools you or it call return, and only for models you can access. You can disconnect in the assistant's settings at any time; we can also revoke its access on request.
International transfers
Some providers, including Render, Anthropic and ElevenLabs, are based in the United States, so data may be processed outside the EEA. Where that happens it is covered by the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
How long we keep it
- Account, models and files — until you delete them or ask us to delete your account.
- Activity log — one year, then deleted automatically.
- AI assistant connections — access tokens stop working after an hour and renewal tokens after 30 days, or as soon as the connection is revoked.
- Usage counts — reset daily.
Your rights
You can ask us to show you everything we hold about you, correct it, delete it, give you a copy in a portable format, restrict how we use it, or object to processing based on legitimate interest. Write to hello@skema.tech; we'll answer within one month.
Deleting your account removes your login, saved layouts and all access tokens (including AI assistant connections), and detaches your name and IP address from the activity history. The activity entries themselves remain, without identifying you, so shared models' histories stay complete for the other people who worked on them.
If you think we've mishandled your data you can complain to Datatilsynet, the Norwegian Data Protection Authority (datatilsynet.no), or the authority where you live.
Security
Passwords are stored only as bcrypt hashes, connections use HTTPS, access tokens are stored as one-way hashes, and every request is checked against the models you're allowed to see or edit.
Changes
If we change this policy in a way that affects you, we'll tell you before the change takes effect.