This Privacy Policy describes how Signull Labs Inc. ("Company," "we," "us," or "our") collects, uses, retains, and shares personal data in connection with the Skye mobile application (the "App" or "Services").
BY USING THE APP, YOU CONSENT TO THE PRACTICES DESCRIBED HEREIN. You represent that you are at least 13 (16 in the EEA/UK/Switzerland).
We update this Policy with at least 30 days' notice for material changes.
Quick Reference
- California: Section 10
- Other US States: Section 11
- EEA/UK/Swiss: Section 9
- Data Retention: Section 5
- Your Choices: Section 6
- Data Breaches: Section 8
- Sub-Processors: Section 1 (Table 1)
- Contact: Section 15
Section 1: Who We Are
Signull Labs Inc., USA. Web: signulllabs.com
We act as data controller for personal data described here, except where processing strictly on your behalf.
Table 1: Sub-Processors
The following third-party service providers process data on our behalf:
| Provider | Purpose | Data Processed | Retention / Notes |
|---|---|---|---|
| Google Cloud Platform | Cloud infrastructure & hosting | All data categories | Controlled by us per Section 5 |
| OpenAI | AI model processing (text generation, structured output, embeddings) — our primary AI provider | Connected service data, user context, your messages to Skye | Zero data retention. No model training. |
| Anthropic | AI model processing (text generation) | Connected service data, user context, your messages to Skye | Zero data retention. No model training. |
| Google (Gemini API) | AI model processing — fallback when our primary provider is unavailable or rate limited | Connected service data, user context, your messages to Skye | Zero data retention. No model training. |
| Groq | AI model processing for latency-sensitive features | Connected service data, user context, your messages to Skye | Zero data retention. No model training. |
| ElevenLabs | AI voice generation (audio briefings) | Briefing text content | Zero data retention. No model training. |
| Google Maps Platform | Geocoding, reverse geocoding, nearby places, weather lookups | Coordinates, addresses and place names — including destinations parsed from your calendar and email | Per Google Maps Platform terms. Not used to build an advertising profile of you. |
| Plaid Inc. | Financial account connectivity | Financial account & transaction data | Independent retention per Plaid privacy policy. See Section 4.2. |
| Mixpanel | Product analytics | Pseudonymous usage events keyed to your account identifier; device model, OS and app version; IP address (from which Mixpanel derives coarse location). Some event labels record what you tapped, which can include a nearby place name or a suggested prompt drawn from your data. | Not anonymous. See Sections 3.2 and 6.5. |
| Sentry | Error tracking & crash reporting | Crash logs, error reports, device and OS info, app version, your account identifier, and IP address. Error context may incidentally include fragments of the data the App was handling when it failed. On an error or crash, also a screenshot and a map of the screen's layout, with all text and all images drawn from your data blacked out before they leave the device. If you send feedback from the App, also whatever you write, any name or email you put in the form, and an unmasked screenshot if you attach one yourself. | Diagnostic use only. Never used for advertising or profiling. Feedback is only sent when you submit it. See Sections 6.9 and 6.10. |
| Apple | App distribution, payments, Sign in with Apple, and push notification delivery (APNs) | Account, download & payment info; the text of push notifications we send you, which can summarize an email, an event, or an alert | Per Apple's privacy policy |
We will notify users via email or in-App notification at least 30 days before adding a new sub-processor that processes personal data in a materially different way. This table reflects all sub-processors as of the Effective Date.
Section 2: Data We Collect
2.1 Account Information
- Name and email address
- Sign-in identifiers from Sign in with Apple or Google Sign-In, including the account identifier and, where the provider supplies them, your name and profile picture URL
- A profile photo, if you upload one (see Section 7.2)
- Account preferences and configuration
- Your height, if you provide it, so health features can compute derived metrics
2.2 Connected Service Data
When you connect a service we sync and store data per our retention schedule. Each connection is separate and you choose which to grant:
- Email (Gmail, iCloud Mail). Message metadata and content, plus text extracted from attachments in common document formats (PDF, Word, Excel, plain text). Message bodies and attachment text are read and sent to our AI providers so the App can summarize, triage, and answer questions about your mail. Today we store an AI-written summary of each message rather than its full body; features that draft or reply to mail may need to retain more, within the periods in Section 5. Connecting iCloud Mail requires an app-specific password, which we store encrypted and use only to fetch your mail.
- Calendar events and schedules, including titles, locations, descriptions, organizers, attendee lists, and conference dial-in details
- Contacts. Connecting a Google account grants read access to your Google Contacts, and the App can sync contacts from your device with your permission. This includes names, phone numbers, email addresses, organizations and job titles of the people in your address book.
- Messaging (Slack). Public channels, private channels and group conversations you belong to, and your direct messages.
- Social (X). Your posts, mentions of you, and recent followers.
- Music listening history and top artists (Spotify)
- Health and fitness data (Apple Health, and Whoop where connected) — Sensitive Data. Sleep, workouts, vitals, nutrition, activity, and body measurements.
- Financial accounts and transactions (Plaid) — Sensitive Data. Read-only. This covers your connected accounts and their names, types, masked account numbers and balances; your transactions and the merchants behind them; and your investment holdings and trades. Our connections are read-only: we do not request payment, transfer, or any other write-capable permission, and we cannot move money.
- Reminders, task lists, and alarms
- Package tracking and delivery info (parsed from email)
- Additional services you explicitly connect
2.3 Data About Other People
The data you connect necessarily describes other people: the senders and recipients of your email, the attendees of your meetings, your colleagues in a Slack channel, the people in your address book. We process that data solely to build your feed and answer your questions. We do not build standalone profiles of non-users, do not contact them, and do not sell or share their data. Where the App infers a relationship between you and another person, that inference is covered by Section 2.6 and Section 5.1.
2.4 Location Data
We derive location from calendar and email addresses, Apple location services (with your permission), and IP geolocation. With your permission the App records a timeline of location fixes from your device, and you may save a home and work address. Location is used for commute estimates, weather, and nearby recommendations, and coordinates and place queries are sent to Google Maps Platform to resolve them. Controllable via App settings and device permissions.
2.5 What You Tell Skye Directly
Messages you send Skye in chat, follow-up questions you ask on a card, and feedback you leave on a detail view are processed by our AI providers and stored with the corresponding agent interaction under Section 5.1.
2.6 AI-Inferred Data
The App uses AI to infer things about you from the data you connect — preferences, routines, and the people who matter to you. We store these as Memories and Relationships. A Relationship holds an inferred name, a description, and short supporting excerpts quoted from the source data. Inferences may be wrong. Retention for these categories is described in Section 5.1.
2.7 Technical and Usage Data
- IP address, device info, OS, app version, usage analytics keyed to your account identifier, and error/crash logs
- Push notification tokens for the devices you have signed in on
2.8 What We Do Not Collect
Regardless of what you connect, we do not use:
- Advertising identifiers, cookies, web beacons, browser tracking, or cross-app tracking
- Biometric identifiers used to identify you, such as face or fingerprint templates
- Data purchased from data brokers or scraped from sources you have not connected
We do not ask you to tell us your race or ethnicity, political opinions, religious beliefs, union membership, or sexual orientation, and we do not infer or categorize you by them. If a subject like that appears in an email, a message, or another source you connect, that text is processed like any other connected content.
2.9 How This Section Changes
The categories in this Section describe what the App collects today. Skye is an evolving product, and future features may draw on new kinds of data — images, video, social feeds, documents, or new connected services. Each source is separate and opt-in: we collect a new category only when you grant it, and only for the purposes in Section 3. Where a new category is a material change to this Policy, we give the notice described in Section 16.
Section 3: How We Use Your Data
3.1 Core Service
Processing data for your personalized feed, briefings, chat answers, location features, and notifications.
3.2 Improvement
Product analytics, debugging, and performance monitoring. Our analytics are pseudonymous, not anonymous: events are keyed to your account identifier so we can follow a single session end to end. They are not linked to advertising identifiers and are never used for advertising.
3.3 Security & Compliance
Fraud prevention, legal compliance, Terms enforcement.
3.4 What We Do NOT Do
- No AI Training. Never train, fine-tune, evaluate, or benchmark AI models with your data. Our internal model evaluations run entirely on synthetic personas we author ourselves.
- No Sale. Never sell personal data.
- No Advertising. No behavioral/targeted/cross-context advertising.
- No Brokering. No sharing with data brokers.
- No Money Movement. Our financial connections are read-only; we cannot initiate a payment or a transfer.
3.5 Automated Processing and Actions
AI generates all of the content in your feed, your briefings, and Skye's answers.
The App can also act on your behalf. Actions may include working with the sources you have connected — creating or updating a reminder, setting an alarm, adding a detail to a contact, reading and triaging your mail, drafting a reply or a message, scheduling or changing a meeting, and similar tasks we add over time.
Today, every action is drafted and shown to you first, and nothing is carried out until you confirm it. That is a deliberate design choice: text arriving in an email or a message can reach the model, but it cannot cause an action without your tap.
As the App grows more capable, we expect to offer features that carry out some routine actions without asking each time, where you have turned that on. When we do, we will describe what the feature can do before you enable it, keep it off until you enable it, give you a way to turn it off and to require confirmation, and record actions taken so you can review them.
We do not use automated processing to make decisions producing legal or similarly significant effects about you under GDPR Art. 22.
Section 4: How We Share Your Data
We share data only as described in Table 1 (Section 1) and as follows:
4.1 Service Providers
All sub-processors in Table 1 are contractually bound to process data only as directed.
4.2 Financial Data: Plaid
Special Disclosure: Plaid acts as both our processor and an independent service provider. Plaid retains data per its own privacy policy (https://plaid.com/legal/), governed by the Gramm-Leach-Bliley Act. Review before connecting financial accounts.
4.3 Connected Services
Gmail, Google Calendar, Google Contacts, iCloud Mail, Slack, Spotify, X, Whoop, and any other service you connect process data per their own policies.
4.4 AI Providers and Web Search
To answer a question or build a card, our AI providers may run a web search. We instruct the model never to put your name, email, home or work location, or verbatim private content into a search query, and to search only on public terms such as a company, product, or public figure. Queries reach the search provider used by that AI provider. We cannot guarantee a model will never deviate from that instruction.
4.5 Access by Our Personnel
A small number of authorized personnel can access our systems to operate, debug, and support the Service. Our internal tools redact the most sensitive fields at the database layer — the contents of your email, calendar entries, memories, reminders, and briefings are withheld from those tools by default. Access is limited to those who need it, is logged, and those logs are retained per Section 5.1. We do not read your data for any purpose other than operating the Service, investigating a problem, responding to your support request, or complying with law.
4.6 Legal Disclosures
We may disclose data for legal process, safety, and compliance. Where permitted, we'll notify you.
4.7 Business Transfers
In mergers/acquisitions, data may transfer. This Policy continues unless you're notified otherwise.
4.8 De-Identified Data
We may create and share anonymized, aggregated data not subject to this Policy.
4.9 Google User Data
Skye's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace data to develop, improve, or train generalized AI or ML models. Our handling of Google user data has been assessed against Google's security requirements by an independent assessor.
Section 5: Data Retention
Most connected-service data is retained for no longer than 90 days. The schedule below states the period for each category and what that period is measured from — for most categories that is when we collect the data; for calendar events it is the end of the event; for records we keep in sync with a connected source it is the last time that record was synced. At expiration, personal data is permanently deleted or irreversibly scrubbed.
Ninety days is a maximum for the categories it applies to, not a target. Many are deleted or scrubbed substantially sooner, and we may shorten retention for any category at any time without notice. We will not extend retention beyond the periods below without at least 30 days' notice under Section 16.
Three groups of data behave differently, and the schedule marks each one: data we hold as a live mirror of a connected source, which persists while that source stays connected; data we infer about you, which persists until you ask us to delete it; and your account record itself.
5.1 Retention Schedule
| Data Category | Retention Period | Action |
|---|---|---|
| Emails (incl. attachment text) | Up to 90 days | Deleted |
| Calendar events | Up to 90 days after event end | Deleted |
| Messages (Slack) | Up to 90 days | Deleted |
| Social posts & mentions (X) | Not stored | Fetched at generation time; only what appears in an agent interaction is retained |
| Music listening history | Up to 90 days | Deleted |
| Location timeline | Up to 90 days | Deleted |
| Health & fitness samples (vitals, sleep stages, nutrition, sessions, hourly summaries) | Up to 90 days | Deleted |
| Financial transactions, including investment trades | Up to 90 days after the transaction date | Deleted |
| Feed cards, briefings, summaries & agent interactions (including your messages to Skye and the feedback you leave) | Up to 90 days | Deleted, or irreversibly scrubbed of personal data |
| Drafted actions awaiting your confirmation | 7 days | Deleted |
| Security & internal access audit logs | Up to 90 days | Deleted |
| Live mirrors of a connected source: contacts, reminder lists and reminders, financial accounts (names, types, masked numbers and balances), investment holdings, health roll-ups (daily summaries, workouts, sleep totals) | While the source stays connected, then up to 90 days after the last sync | Deleted. Disconnect the source, or delete your account, to remove these sooner. |
| AI-inferred data: Memories and Relationships (including the supporting excerpts quoted from source data) | Until you ask us to delete them | User-controlled; see Section 6.6. Relationship excerpts tied to a source are removed when you disconnect that source. |
| Account & profile | Duration of account | Deleted on closure |
The retention periods above may be extended where reasonably necessary for backups, disaster recovery, security logging, fraud prevention, dispute resolution, tax/accounting compliance, or legal holds. Where feasible, retained data is isolated and access-restricted.
Short-lived caches. Some generated text is cached outside the main database for performance — a line summarizing a calendar event, a greeting carrying your first name, a resolved place name. These expire on their own within days and are cleared when you delete your account.
5.2 Post-Deletion
Deleting your account removes your profile and everything linked to it from our database, and disconnects your connected services. This happens when you make the request, and in any event within 48 hours. Legal holds may extend retention.
One thing outlives that deletion and is removed separately: usage and crash data already sent to Mixpanel and Sentry, which is held on their retention schedules. Email privacy@signulllabs.com and we will remove it.
Section 6: Your Choices and Controls
6.1 Connected Services: Connect, review, and disconnect sources at any time in the App's settings. Disconnecting a source revokes our access, deletes the cards built from it, and removes the data it imported on the schedule in Section 5.1.
6.2 Actions: Today, Skye carries out an action only after you confirm it. Decline a drafted action and nothing happens; an unconfirmed action expires on its own. Any future feature that acts without asking each time is off until you enable it, and can be switched back to confirm-first at any time. See Section 3.5.
6.3 Location: Revoke permission in iOS settings; disable location features in App settings.
6.4 Communications: Choose which notification types you receive in App settings. Service-critical alerts remain active.
6.5 Analytics: Opt out by emailing privacy@signulllabs.com. We will disable analytics collection for your account and request deletion of your existing analytics records from our providers.
6.6 Memories and Relationships: To see, correct or delete what Skye has inferred about you, email privacy@signulllabs.com. We will respond within the timeframes in Sections 9, 10 and 11.
6.7 Access and Portability: To receive a copy of your data in a portable format, email privacy@signulllabs.com. We will provide it within 45 days (30 days for EEA/UK/Swiss requests).
6.8 Account Deletion: Delete your account from App settings, or by emailing privacy@signulllabs.com. See Section 5.2 for what deletion covers.
6.9 Feedback: You can send us feedback from Settings. Some accounts can also open the same form by shaking the phone. Nothing leaves the App until you press send — a shake only opens the form, it does not report anything on its own. What you write goes to Sentry (Section 3.2) alongside your account identifier so we can follow up on the right account, and any screenshot you attach yourself goes unmasked, because you chose it. To have a report removed, email privacy@signulllabs.com.
6.10 Crash Diagnostics: When the App hits an error or crashes it records a picture of the screen and a map of the layout, so we can see which screen failed and in what state. Before that picture leaves your device every piece of text and every image drawn from your data is blacked out — what reaches us shows shapes and positions, not your balances, messages or health figures. This is separate from feedback you send us, and it happens without being asked. To opt out, email privacy@signulllabs.com.
Section 7: Data Security
7.1 Measures
Industry-standard measures: encryption at rest and in transit, access controls, monitoring, database-layer redaction of sensitive fields in internal tools, audit logging of internal access, and contractual requirements on our providers. No system is perfectly secure.
7.2 Some Uploaded Images Are Served Publicly
A profile photo you upload is stored in a public cloud storage bucket and served from a URL that requires no authentication. The URL is not published or listed anywhere, and is not guessable in practice, but anyone holding it can view the image. Do not upload an image you would not be willing to have viewed by someone who obtains that link. You can replace or remove your photo at any time in App settings, which deletes the stored file. Where a future feature stores media differently, we will say so.
Section 8: Data Breach Notification
- GDPR users: Supervisory authority notified within 72 hours where required; affected individuals notified without undue delay if high risk.
- US users: Notification per applicable state breach laws.
- All users: Nature of breach, data affected, measures taken, recommended steps.
Section 9: EEA, UK & Swiss Privacy Rights
9.1 Legal Bases
- Contract (6(1)(b)): Core service delivery
- Consent (6(1)(a), 9(2)(a)): Optional services, sensitive data (health, financial), device location, contacts
- Legitimate Interests (6(1)(f)): Security, product analytics, debugging, and processing data about third parties that appears in the sources you connect, where our interest in delivering the Service you asked for is not overridden by their rights
- Legal Obligations (6(1)(c)): When required
9.2 Your Rights
Access (15), Rectification (16), Erasure (17), Restriction (18), Portability (20), Object (21), Withdraw Consent. Exercise any of these at privacy@signulllabs.com; we respond within 30 days.
9.3 Automated Decision-Making
No Art. 22 decisions. All automated features are configurable, and no action is taken without your confirmation.
9.4 Transfers
US processing via SCCs. Pursuing DPF certification.
9.5 Complaints
EU: local DPA | UK: ICO | Swiss: FDPIC
9.6 EU/UK Representative
[TO BE APPOINTED — GDPR Art. 27]
Section 10: California Privacy Rights (CCPA/CPRA)
Know, Delete, Correct, Opt-Out, Limit Sensitive Use, Non-Discrimination.
We do not sell or share data. Contact: privacy@signulllabs.com. Response within 45 days.
10.1 Categories
Collected per Section 2. Disclosed to providers per Section 4 / Table 1. No sales.
10.2 Sensitive Personal Information
Health data, financial account information, and precise geolocation are sensitive personal information under the CPRA. We use them only to perform the Service you requested and for the purposes permitted under Cal. Civ. Code § 1798.121(a). We do not use or disclose them to infer characteristics about you for any other purpose, so the "Limit the Use of My Sensitive Personal Information" right does not restrict any additional use — but you may still disconnect any source at any time.
10.3 Financial Incentives
We do not offer financial incentives for personal data.
Section 11: Other US State Privacy Rights
Similar rights for VA, CO, CT, UT, TX, OR, MT, and others. Appeal: privacy@signulllabs.com ("Privacy Appeal").
Section 12: Children's Privacy
Not directed to children under 13 (16 EEA/UK/CH). No knowing collection. Promptly deleted if discovered. Contact: privacy@signulllabs.com.
Section 13: International Transfers
US processing. SCCs for EEA/UK/CH transfers. Pursuing DPF certification.
Section 14: Tracking and Do Not Track
We do not use cookies, web beacons, browser tracking, cross-app tracking, or ad networks, and we do not participate in cross-context behavioral advertising. DNT signals do not apply to a native mobile app, but we respect the principle.
Section 15: Contact Us
Signull Labs Inc.
Privacy: privacy@signulllabs.com
Legal: legal@signulllabs.com
EU/UK Representative: [TO BE APPOINTED]
Data Protection Officer: [TO BE APPOINTED IF REQUIRED]
Section 16: Changes
Material changes: 30 days' notice. Continued use = acceptance.