Privacy Policy
This policy explains what Sklyvo collects when you use the service, why we hold it, and what you can ask us to do with it. It is written to be read, not to be survived.
Who we are
We are a team of designers, developers and AI engineers, and we work under the Venegard brand. Day to day we build for other companies: fast, conversion-focused websites and Shopify stores, web and mobile apps, custom AI systems such as chatbots and voicebots, and the process automations that take the repetitive work off people’s hands. Most of the people we work with are startups and agencies — from first-time founders to teams that have outgrown doing everything by hand.
Sklyvo began as something we needed ourselves: a way to find the companies worth talking to without losing days to maps, registries and spreadsheets. It worked well enough that we turned it into a product, and we now build and run it as one.
Sklyvo does three things. It searches public sources for companies that match the kind of customer you are after. It checks that the contact details it finds are real, so you are not writing into the void. Then it drafts a message to each of those companies separately, based on what it can actually see about them, and keeps the replies in one place so you can pick the conversation up. The point is not to send more email than before. It is to spend your time on the handful of people who answer, instead of on the searching that comes before them.
That purpose is also why this policy is short. To do the work above, the service needs business contact details, a connection to your mailbox and a record of what was sent — and very little beyond that. Everything in the sections below follows from it.
When this policy says we, it means Jan Sedlář, who builds and runs Sklyvo as a natural person and is the controller of the personal data described here. Venegard is the name the work goes out under, not a registered company, so it holds nothing and answers for nothing; the responsibility sits with a person, which is the point of naming one. We decide what is collected and why, and we answer for it. Should that ever move to a registered company, this paragraph is where it will change, and we will tell you before it does.
You can reach us any time at support@sklyvo.com. Anything that concerns personal data — a request to see what we hold, to correct it, to have it deleted, or simply a question about how a part of this policy works in practice — reaches the same address and is answered by the person named above, not passed around a queue. If a question in this policy matters to you, write to us rather than guessing. We would rather answer it once, clearly.
What we collect
We keep the smallest set of data the service can run on. It falls into four groups.
- Your account. Your name, your email address, the password you set, and the company details you enter yourself.
- Your workspace. The companies and contacts you search for, the messages Sklyvo drafts, the ones you send, and the replies that come back.
- Your connections. When you connect a mailbox, we store the access token that lets us send on your behalf. We never store your mailbox password.
- How the product is used. Sign-in times, the features you open, the browser and device you use, and errors the app runs into.
We do not collect special categories of personal data, and we ask you not to put any into your workspace. Sklyvo is built for business contact details, not for health, beliefs, or anything of that kind.
Why we hold it
Every piece of data above earns its place:
- To run the service you asked for: finding companies, verifying contacts, drafting messages and sending your outreach.
- To bill you correctly and to keep the accounting records the law requires us to keep.
- To keep the service safe, to detect abuse, and to work out what broke when something breaks.
- To tell you things you need to know, such as a change to this policy or a problem with your account.
The first three rest on our contract with you and on our legitimate interest in running a working, secure product. Where we rely on consent, such as an optional analytics cookie, you can withdraw it at any time without losing access to anything you pay for.
The contacts you find
Sklyvo searches public sources and returns business contact details. Those people did not sign up with us, so we treat their data with particular care.
You are the controller of the contacts in your workspace. We process them on your instructions. That means the duty to have a lawful reason for contacting them, and to honour their objections, sits with you.
If someone asks to be removed from your outreach, remove them. Sklyvo keeps a suppression list per workspace so a removed contact is never written to again, and we honour any request sent directly to us by passing it to the workspace that holds the record.
The legal basis for each purpose
European law asks us to name a reason for every use of your data, not just a purpose. Here they are, one by one, so you can check our reasoning rather than take it on trust.
- Running the service — performance of a contract. Your account, your workspace, the searches you run, the drafts, the sending and the replies. You asked for this and we cannot deliver it otherwise. Withdrawing it means closing the account.
- Billing and accounting — a legal obligation. Invoices and payment records are kept because tax and accounting law requires it, and that duty outlives your account.
- Security, abuse detection and debugging — legitimate interest. Ours, in keeping a product that works and is not used to harm anyone. We looked at what this costs you and concluded it is limited: logs are technical, short-lived and never used to profile you.
- Service messages — legitimate interest. Telling you that a payment failed, a policy changed, or a mailbox disconnected. These are not marketing and you cannot unsubscribe from them, because without them the service would fail silently.
- Optional connections — consent. Connecting a mailbox, Google Sheets, or anything similar happens only when you switch it on, and you can switch it off again without losing access to anything else.
- The contacts in your workspace — your basis, not ours. For those people we act on your instructions. Choosing and defending the lawful basis for contacting them is your job, and it is described in the section above.
Where a purpose rests on legitimate interest, you can object to it. Write to us and we will either stop or explain why the interest still outweighs the objection, in plain terms and in writing.
Sending data outside the EU
Your workspace and its backups stay in the European Union. Some of the companies listed above are established elsewhere, and where a transfer outside the EU or the EEA happens, it runs on the European Commission’s standard contractual clauses together with whatever additional measures the provider offers, such as encryption in transit and at rest and regional processing where it can be chosen.
In practice this concerns the model provider that drafts your text, the search and enrichment providers, and payment processing. It does not concern your workspace database, your files or your backups, which do not leave the region described above. If you want the specific transfer mechanism a given provider relies on, ask us and we will point you at it.
Where it lives
Everything the service stores sits on servers inside the European Union, in the AWS eu-west-1 region in Ireland. Encryption is on in transit and at rest. Where a provider processes data outside the EU, that transfer runs on the European Commission’s standard contractual clauses. Here is where each category actually sits and who handles it.
- Your account and your workspace. Your name, email address, hashed password, the company details you enter, the companies and contacts you collect, the drafts, the messages you send and the replies that come back — all of it lives in a PostgreSQL database run by Supabase. Supabase is the processor: it hosts the database and keeps it running, and does not use what is in it.
- Files you upload. Documents in Storage, anything you attach to outreach, and the preview thumbnails the app generates from them sit in Supabase Storage, in the same region and under the same terms.
- Signing in with Google, Facebook or LinkedIn. Handled by Supabase Auth together with the provider you pick. We receive the email address and name that provider confirms, and nothing else. Your password at that provider never passes through us.
- Mailbox credentials. The access token for a connected mailbox, or the SMTP and IMAP details when you connect a server directly, are stored encrypted in the same database, with the keys held apart from it.
- Application logs. Request logs and runtime errors are produced by Vercel, which runs the application. They contain IP addresses, the pages requested and the technical detail of an error. There is no analytics or product-tracking service anywhere in Sklyvo, so no behavioural profile of you exists to store.
- Backups. Held by Supabase alongside the database, in the same region.
Who else sees it
Nobody buys your data from us, because we do not sell it. It reaches other companies only where the service cannot work without them. Each one gets the smallest slice that lets it do its job, and each is bound by a contract to process it only on our instructions.
Running the product
- Vercel — hosting and the servers the application runs on. Every request passes through it, so it sees your IP address, your browser and the address you opened. Purpose: serving the application to you.
- Supabase — database, file storage and social sign-in, as described above. Purpose: storing your workspace so it is there when you come back.
Payments
- Stripe — subscriptions and payments. Receives your email address, the plan you chose and the number of seats. Your card details go from your browser to Stripe directly and never touch our servers. Purpose: taking the payment and telling us when a subscription starts, renews or ends.
- Fakturoid — invoicing, only when it is switched on. Receives the billing details needed to issue an invoice. Purpose: issuing and keeping invoices.
- Resend — the emails the product sends you: password resets, verification codes, notifications about your workspace. Receives your email address and the content of that one message. Purpose: delivering it. It is never used for your outreach.
- The mailbox you connect — Google, Microsoft, or any server you connect over SMTP and IMAP. Your outreach leaves from your own mailbox, not ours, so the recipient, the subject and the body pass through your provider, and the replies come back the same way. Purpose: sending your messages and reading the answers.
Finding companies and writing to them
- Google Gemini — drafts your messages and answers in Skly Bot. Receives the prompt: what your company offers, what the target company’s website says, and the instructions you set. It does not receive your account details, and the content is not used to train the model. Purpose: writing the draft.
- Google Places — company search. Receives the search terms and the area you are looking in, and nothing about you. Purpose: returning the companies that match.
- The websites of the companies you search for. Sklyvo opens each public site and reads it, the way a browser would. Nothing about you is sent there.
- Serper, Hunter and Proxycurl — contact enrichment, used only while those providers are switched on. They receive a company name, a domain or a public profile address and return contact details. Purpose: finding a real contact instead of guessing at one.
Connections you switch on yourself
- Google Sheets — when you connect it, the CRM rows you pick are written into a sheet in your own Google account. Purpose: keeping a copy where your team already works.
How we protect it
Security is not a paragraph you write once, so this section describes what is actually in place rather than what sounds reassuring.
- In transit and at rest. Every connection runs over HTTPS. The database and the file storage are encrypted at rest by the provider.
- Passwords. Hashed with bcrypt and never stored as text. We cannot read your password, which is also why we can only ever reset it, never tell you what it was.
- Mailbox credentials. Encrypted before they touch the database, with keys held apart from it, so a copy of the database alone is not enough to send mail as you.
- Second factor and passkeys. Available on every account. Turning one on is the single largest improvement you can make to your own security here.
- Sessions. Each session carries a version number. Changing your password or revoking sessions raises it, which invalidates every token issued before — including one that was stolen.
- Access on our side. Limited to the people who need it to do their job, and logged. Support access to a workspace is deliberate, time-limited and leaves a trail.
- Backups. Taken by the database provider and kept in the same region, so a restore never moves your data somewhere else.
No system is perfect, and anyone who tells you otherwise is selling something. If a breach ever affects your data, we will tell you and the supervisory authority within 72 hours of finding out. We will tell you what happened, what it means for you and what we did about it — not the version that sounds best.
If you find a security problem in Sklyvo, write to support@sklyvo.com. We would much rather hear it from you than from someone else.
Cookies
The app sets one cookie to keep you signed in. That one is essential and cannot be turned off, because without it the service cannot tell one session from another. Anything beyond it is optional, asked for on your first visit, and refusable without consequence.
How long we keep it
Nothing is kept indefinitely, and nothing is kept because it might be useful one day. Each category has a period and a reason for it.
- Your account and your workspace — for as long as the account is open. Everything in it is yours to delete sooner, at any time, from inside the product.
- Contacts and companies — the same. Deleting a contact removes it from the workspace; the suppression list keeps only what is needed to make sure that person is never written to again, which is the address itself and nothing more.
- Drafts you never sent — kept while the account is open, deleted with the rest of the workspace.
- Sent messages and replies — kept while the account is open, because they are the record of the conversation you are having. Copies also sit in your own mailbox, where your own retention applies.
- Mailbox tokens and connection details — deleted immediately when you disconnect the mailbox, without waiting for the account to close.
- Files in Storage — until you delete them, or until the account closes.
- Application and access logs — 12 months, then deleted. They are technical records, not a history of you.
- Invoices and payment records — kept for the period accounting and tax law prescribes, which outlives the account. This is the one category we cannot delete on request.
- Backups — roll off within 30 days. A deletion you ask for today is gone from the live database at once and out of the backups within that window.
When you close your account
Closing the account is a decision you make in the product, and it does what the word says. We delete the workspace and everything in it within 24 hours — contacts, companies, drafts, sent messages, replies, uploaded files, mailbox tokens and settings. Backups containing it roll off within 30 days, after which no copy remains anywhere in our systems.
Two things survive, and both are narrow. Invoices and the payment records attached to them stay for as long as accounting law requires, because we are not allowed to delete them. And if your address was on a suppression list, we keep it there, because forgetting that someone asked not to be contacted would be the worse outcome for them.
Before you close the account, export what you want to keep — the CRM export gives you your contacts and their history in a portable file. After the 24 hours, there is nothing left for us to send you. If you would rather pause than close, tell us; keeping the workspace dormant is usually possible and always reversible, while deletion is not.
If we close an account ourselves, for the reasons set out in the Terms of Use, the same deletion applies, and we will tell you before it happens unless the law stops us.
Automated decisions
Sklyvo ranks companies and drafts text automatically, and you decide what happens next. No automated decision produces a legal effect for you or for the people you contact, and nothing is sent that you have not set running yourself.
What you can ask for
European law gives you a set of rights over your own data. They are not favours and you do not have to justify using them. Here is each one and what it means in practice here.
- Access. A copy of everything we hold about you, together with what it is for, who else receives it and how long we keep it. Much of it you can already see inside the product; ask and we will send the rest.
- Correction. Anything wrong gets fixed. Your own account details you can edit yourself at any time.
- Deletion. Your data removed, within the limits described above — invoices are the exception, and we will say so rather than quietly keep more.
- Restriction. Processing paused while a dispute about accuracy or lawfulness is sorted out. The data stays, but we stop using it.
- Objection. Against anything we do on the basis of legitimate interest. We either stop, or explain in writing why the interest still outweighs your objection.
- Portability. Your data in a structured, machine-readable file, so you can take it to another provider. The CRM export already does this for the bulk of it.
- Withdrawing consent. Where something runs on consent, such as a connected mailbox, you can withdraw it at any time. That does not make what happened before it unlawful, and it does not affect anything running on a different basis.
- A human decision. Sklyvo ranks and drafts automatically, but no automated decision here has a legal effect on you. If one ever did, you could ask for a person to look at it.
How to use those rights
Write to support@sklyvo.com. Say which right you are using, or simply describe what you want — you do not need to name an article of the regulation, and getting the terminology wrong costs you nothing.
We answer within 30 days. If a request is genuinely complex we may take up to two months, in which case we will tell you inside the first month that we are taking longer, and why. There is no charge. We only refuse a request that is manifestly unfounded or repetitive, and if we ever do, we will say so plainly and tell you how to challenge it.
We may need to confirm that you are who you say you are before handing over a copy of anything, because sending someone’s data to the wrong person is the failure this is all meant to prevent. Usually replying from the address on the account is enough.
One thing to keep in mind: if you are asking about a contact you found through Sklyvo rather than about yourself, the request belongs to the workspace that holds that contact, not to us. Tell us anyway and we will point it to the right place.
If our answer does not satisfy you, you can complain to your national data protection authority at any time, and you do not have to come to us first. In the Czech Republic that is the Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7. Elsewhere in the EU it is the authority for the country you live or work in.
Children
Sklyvo is a tool for businesses and is not directed at anyone under 16. We do not knowingly collect their data, and we delete it if we learn we have.
Changes to this policy
If we change something that matters, we will say so by email before it takes effect, and the date at the top of this page will change with it. Smaller corrections, such as fixing a wrong link, we simply make.