SKAITH
HomeSign in
Privacy notice

Privacy Policy

This notice explains what personal information Skaith collects, why it is used, when it is disclosed, and the choices available to account users and other individuals whose information appears in customer records.

Effective
August 29, 2026
Version
2026-08-29
In this document
  1. Scope and roles
  2. Information we collect
  3. Sources of information
  4. How we use information
  5. Document automation and financial conclusions
  6. How we disclose information
  7. Current service providers
  8. Cookies and similar technology
  9. Retention and deletion
  10. Security
  11. Privacy choices and requests
  12. United States state disclosures
  13. Location of processing
  14. Children
  15. Changes to this policy
  16. Contact and appeals
Browse 16 sections
  1. Scope and roles
  2. Information we collect
  3. Sources of information
  4. How we use information
  5. Document automation and financial conclusions
  6. How we disclose information
  7. Current service providers
  8. Cookies and similar technology
  9. Retention and deletion
  10. Security
  11. Privacy choices and requests
  12. United States state disclosures
  13. Location of processing
  14. Children
  15. Changes to this policy
  16. Contact and appeals
Plain-language note

This document is written for Skaith’s current U.S. business service. It does not turn an audit result into legal advice or guarantee a supplier credit.

1. Scope and roles

This Privacy Policy applies to Skaith websites, accounts, Free Audit workspaces, support, email intake, document auditing, evidence packets, and recovery workflows. It does not govern a third-party website or service that links to Skaith.

For account, website, security, and business-contact information, Skaith generally determines why and how information is used. For personal information contained in agreements, invoices, forwarded emails, and other Customer Content, Skaith generally processes the information on behalf of the business customer. That customer controls the records and should receive requests concerning its records. The Data Processing Addendum describes that relationship.

2. Information we collect

  • Account and identity information, including name, verified email address, identity-provider subject, organization, role, invitations, and sign-in events.
  • Customer Content, including agreements, amendments, pricing schedules, invoices, service locations, vendor and account identifiers, wearer or employee names that appear in records, emails, attachments, evidence, decisions, dispute communications, and credits.
  • Usage and audit information, including uploads, workflow events, feature use, plan and quota state, finding decisions, exports, administrative actions, and retention settings.
  • Device, network, and security information, including IP address, user agent, request identifiers, timestamps, authentication state, challenge results, malware/privacy screening state, and diagnostic error codes. We do not intentionally place document text in application logs or product analytics.
  • Communications and support information that you choose to send, including waitlist interest and troubleshooting details.
  • Billing information if paid service later opens. Payment-card details would be collected by the payment processor, not stored directly by Skaith; Skaith would receive subscription, transaction, and limited billing metadata.

3. Sources of information

We receive information from account users and workspace administrators; files and email rules they configure; identity, email, network-security, and optional payment providers; suppliers that reply to a Customer-authorized recovery request; and the operation of the service itself. We do not buy consumer profiles or obtain personal information from data brokers.

4. How we use information

  • Create and secure accounts and workspaces; authenticate users; enforce roles, invitations, limits, and entitlements.
  • Receive, screen, store, classify, extract, and compare documents; produce source-backed findings, calculations, evidence packets, and customer-requested recovery workflows.
  • Provide support, service notices, security alerts, and Customer-authorized transactional communications.
  • Detect malware, prohibited data, fraud, abuse, unauthorized access, replay, cross-tenant access, and violations of our policies.
  • Maintain reliability, measure coarse product usage, troubleshoot failures, audit administrative actions, and improve supported document handling.
  • Comply with law, enforce agreements, establish or defend legal claims, and protect people, customers, Skaith, and the public.

5. Document automation and financial conclusions

Skaith uses native text extraction and optical character recognition to propose document facts. Current financial comparisons are produced by deterministic rules using confirmed source facts and exact decimal arithmetic; a language model does not independently decide that a charge is owed or recoverable. Ambiguous or missing authority is intended to route to review rather than silently create a dollar conclusion.

Automation can be wrong. Account users can inspect the cited source, correct or exclude a finding, and decide whether to act. Skaith does not make decisions about employment, credit, insurance, housing, health care, or another legally significant consumer matter.

6. How we disclose information

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not use Customer Content to advertise to individuals.

  • To authorized members of the same workspace, according to their roles.
  • To infrastructure and service providers that support identity, email, network protection, hosting, storage, malware screening, support, optional analytics/error monitoring, and optional payments, subject to contractual and technical limits.
  • To a supplier or designated recipient only when Customer directs a packet, recovery request, or related communication to be sent.
  • To professional advisers and transaction counterparties under appropriate confidentiality protections for financing, diligence, merger, acquisition, reorganization, or sale.
  • To courts, regulators, law enforcement, or others when we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, or the integrity of the service.

7. Current service providers

The public Skaith service currently uses Amazon Web Services for Cognito authentication, Cloudflare for DNS, secure connectivity and sign-in abuse prevention, and Resend for transactional and inbound email. Core application data and source documents are stored on operator-controlled private infrastructure. Local Tesseract and Poppler tools perform optical character recognition in the current default deployment. Optional providers are not enabled merely because adapter code exists.

The current subprocessor list identifies provider purposes and locations. We may replace or add providers as the service evolves and will update that list before materially expanding processing.

8. Cookies and similar technology

Skaith uses cookies that are necessary for authentication, session security, OAuth state, development safeguards, and preferences. Cloudflare Turnstile may process device and network signals to distinguish legitimate authentication attempts from abuse. We do not currently use third-party advertising cookies. If optional product analytics is enabled, it is limited to allowlisted events, opaque identifiers, and coarse properties rather than document content.

Browsers may offer Global Privacy Control or Do Not Track signals. Because Skaith does not sell personal information or use cross-context behavioral advertising, there is no sale or targeted-advertising preference to apply in the current service. We will honor legally required signals if our practices change.

9. Retention and deletion

Source-document retention is selected by the workspace owner or administrator and defaults to 365 days. Operational records, extracted facts, findings, decisions, audit logs, and recovery records may be retained longer while the workspace remains active to preserve the evidence trail, prevent quota abuse, meet contractual or legal obligations, resolve disputes, and secure the service.

Deleting a document or workspace removes or schedules removal of active copies according to product behavior. Limited residual copies can remain temporarily in protected storage versions, logs, or backups until their lifecycle expires, unless preservation is required by law. We isolate and restrict those copies and do not restore deleted information except for disaster recovery or legal necessity. Contact [email protected] for a deletion request or questions about the applicable retention period.

10. Security

We use measures designed for the sensitivity of the service, including encrypted transport, private object storage, tenant-scoped authorization, role checks, malware and prohibited-data screening, signed webhooks, bounded uploads, audit logs, source retention controls, and protected identity-provider authentication. Access to production systems is limited to operational need.

No safeguard, service, or transmission is completely secure. Customers should use strong unique credentials, enable available multi-factor authentication, restrict workspace membership, keep original records, and notify [email protected] promptly of suspected unauthorized access.

11. Privacy choices and requests

Depending on location and applicable law, an individual may have rights to know, access, correct, delete, or receive a copy of personal information; to opt out of certain sales, sharing, targeted advertising, or profiling; to limit certain sensitive-data uses; and to appeal a denied request without discrimination.

Submit a request to [email protected] with the subject “Privacy Request.” We will verify the requester and may ask for information reasonably necessary to match the request and protect the account. Authorized agents must provide proof of authority. If the information is in Customer Content, we may direct the request to the business customer or assist that customer in responding. We may retain information where an exception applies, including security, legal claims, accounting, or compliance.

12. United States state disclosures

In the preceding 12 months, the categories collected and disclosed for business purposes are those described in Sections 2 and 6: identifiers and account data; commercial and transaction records; internet or network activity; professional or employment-related information contained in business records; approximate location inferred from IP address; and inferences limited to document classification and audit workflow. We do not knowingly sell or share these categories for cross-context behavioral advertising.

Skaith is a business service and may not meet the applicability thresholds of every state privacy law. We nevertheless use the request process above to evaluate verified requests and provide rights where required. We do not offer financial incentives for personal information.

13. Location of processing

The public service is intended for U.S. businesses and is operated from the United States. Information may be processed in the United States and in other locations where a listed provider operates. Do not use the service if Customer requires data localization or international-transfer terms that are not stated in a signed agreement.

14. Children

Skaith is not directed to children and does not knowingly collect personal information from anyone under 18. Do not create an account or submit information about a minor unless it appears incidentally in an authorized business record and its processing is lawful. Contact us if you believe a child submitted information directly.

15. Changes to this policy

We may update this policy as the service, providers, or law changes. The page will show the effective date. We will provide additional notice when required or when a change materially expands how we use previously collected personal information.

16. Contact and appeals

Email privacy questions, requests, or appeals to [email protected]. Use “Privacy Appeal” for an appeal of a request decision.

SkaithSkaith provides document-comparison and contract-compliance tooling and does not provide legal advice.
TermsPrivacyAcceptable useData processingSubprocessors