Sky is a browser extension that turns text you highlight — or a page you explicitly ask it to read — into structured leads. This policy explains exactly what data we handle, why, and who processes it. The short version: we only ever see text you deliberately choose to capture. Sky does look at one thing on its own — whether the page you are on reads like someone asking for what you sell, so it can offer to catch it — and that look happens entirely on your own device. Nothing about the page is sent to us or to anyone else for it, and you can switch it off. See §2.
"We" and "us" mean Sky. For any privacy question or request, contact us at hi@skal.ai.
We collect only what's needed to sign you in and to capture the leads you ask us to capture. We do not sell your data, show you ads, or use your captured content to train AI models.
| Data | Why | When |
|---|---|---|
| Email address | To create your account and sign you in with a one-time code. | When you sign in. |
| Text you capture | Sent to our server for AI extraction into lead fields. Two things can be sent, both only on your action: text you select and confirm by clicking the ☁️ or pressing the shortcut, or — when you explicitly ask Sky to read the page you're on — the text visible on that page. A page read always starts from a button that names it (and its cost) before anything is sent. | Only on an explicit capture. |
| Screenshots you paste or drop into the panel | Sent to a vision model at the same provider that reads your text (see §4), which reads the conversation or profile in the picture into lead fields. The image itself is never stored: not in our database, not in logs, and not in your browser. Only the leads read from it are kept, and only once you confirm them. | Only when you paste, drop or choose a screenshot. |
| Messages and screenshots you send to Sky's Telegram bot | If you connect a Telegram chat to your account, a message you forward to the bot is read the way a highlight is, and a screenshot you send it the way a screenshot pasted into the panel is (see the two rows above). The bot receives only what you send it directly in that private chat; it is never added to your groups and ignores anything from one. What it read is held for up to a day while it waits for you to tap Save or Skip, then deleted either way. The image itself is never stored. | Only when you connect a chat and send something to it. |
| A company name, for Look up | When you press Look up on a lead, the company name on that lead, and nothing else, is sent to the public registers you have switched on: GLEIF (the LEI register), SEC EDGAR (US form D filings) and Companies House (UK). All three are off by default. If you accept a match, it is stored on the lead, with which register it came from. | Only when you press Look up, and only to registers you switched on. |
| Search terms, for Find people | Search terms built from your ideal customer profile, and any sentence you add, are sent to Companies House and SEC EDGAR to find company officers. This has its own switch, off by default. What comes back is shown to you and not stored, unless you keep someone as a lead. | Only when you run Find people, with its switch on. |
| Files you bring in | A LinkedIn connections export, a Google Contacts export, a spreadsheet or a WhatsApp chat export, if you choose to import one from the dashboard. The file is read in your browser and no AI reads it. What is stored is the people in it as leads: name, company, role, contact details, and, unless you have switched “Keep the original text” off, the row’s own cells or the person’s own messages from that chat. Somebody already in Sky is filled in rather than added again. | Only when you import a file. |
| Page URL & title of the capture | Saved alongside a lead so you remember where it came from. | Only on an explicit capture. |
| Extracted lead fields | The structured result (name, company, etc.), stored so you can review, edit, and manage your leads. | When you save a lead. |
| Things you keep while reading | When you press Keep this, the text you highlighted (or the post under your cursor), the note you typed, and the page’s URL and title are stored as a clip. No AI reads a clip, on the way in or later. Delete any clip from the dashboard. | Only when you press Keep. |
| Your settings | Lists, templates, and your Ideal Customer Profile — stored to configure captures. | When you change settings. |
| A random install identifier | An anonymous, randomly generated ID kept in your browser — not derived from your device or hardware, and reset if you reinstall. Used only to detect abuse, such as one person creating many accounts to get around free limits. | Generated on your first capture, sent when you save a lead. |
| Subscription details | Your plan, its status and renewal date, and the Paddle customer and subscription identifiers for your account — so we know what you're entitled to and can open your billing portal. No card details: those are entered into Paddle's checkout and never reach Sky. | Only if you buy a paid plan. |
| What you ask Sky | What you type into the find box, into Find people, into Ask Sky, and the brief you give Pick a sample, with the count of results each returned and, for Ask Sky, which tools it ran. We keep this as measurement, to decide what those features should do next. It holds no lead, no person and no rating. | When you use those features. Deleted after 90 days. |
| AI usage counts | For each AI call, the number of tokens used and the model that answered, totalled per account per day, so we can report what Sky costs to run. No text is kept with them. | On every AI call. |
| Webhook deliveries (Scale and above) | If you connect a webhook, each capture is sent to the endpoint you gave us: the lead's fields, its score and breakdown, and the captured text. We keep a log of each delivery and whether it succeeded, so you can see it in the dashboard. | Only if you set up a webhook. The log is kept for 30 days. |
| Live feed URL | If you create a live feed for Google Sheets or Looker Studio, we mint a secret token that lives on your profile. Anyone holding that URL can read your leads (name, company, role, location, contact, need, summary, list, status, deal value, score and source) until you rotate or revoke it. The feed never includes the captured text or the reasons behind a score. The same URL also serves your What's working counts (won, lost and captured by score band, by source and by list). | Only if you create one. Revoke it any time from the dashboard. |
| What happened with a lead | A dated line each time something moves: you captured them, you captured them again, you changed their status, Sky drafted a message, you sent one, or you accepted a public register match. It records the event, not the message. Sky keeps one row per person, so without this there is no way to tell a second conversation from a first. | As it happens, on your own leads. |
| What a lead scored, and when | Every score Sky has given someone, with the per-trait working, the weights in force at the time and a fingerprint of the ICP that produced it. Re-scoring overwrites the number on the lead, so this is the only record that a score ever moved. It is never shared and never leaves your account. | Whenever a lead is scored or re-scored. |
| Write keys (Scale and above) | If you let your CRM update Sky, we store a hash of the key you minted, the name you gave it and when it was last used. We do not store the key itself, which is why it is shown only once. A key can set a lead's outcome and the amount on a win. It cannot read your leads or change anything else. | Only if you mint one. Revoke it any time from the dashboard. |
| HubSpot connection (Scale and above) | If you connect HubSpot, we store the access and refresh tokens HubSpot issues to Sky for your portal, unreadable from your browser, so that a push can create a contact and a note. We also record which HubSpot contact a pushed lead became. | Only if you connect it. Tokens are deleted the moment you disconnect. |
storage — to save your settings and sign-in session locally in your browser.activeTab — to send a capture request to the tab you're on when you use the keyboard shortcut.sidePanel — to open Sky as a side panel beside the page you're working on.contextMenus — to add Sky's right-click entries: capture a selection, or capture the page you're on.<all_urls>) — so the capture button can appear anywhere you select text (WhatsApp Web, LinkedIn, email, forums, docs). This access is used only to show the button, to read the text you choose to capture (a selection, or the page you explicitly ask Sky to read), and to run the on-device check described in §2. Nothing is ever read in the background and sent anywhere.We share data only with the service providers that make Sky work, and only for that purpose:
| Provider | Role | Data they process |
|---|---|---|
| Supabase | Authentication, database, and hosting. | Your email, account, settings, and saved leads. |
| Fireworks AI | AI models that structure your captured text, or a screenshot you paste in, into lead fields. | The text or image you capture, at the moment of capture. It exists only in memory for the length of the request. It is not written to storage, and it is not used to train models. |
| Groq | Backup AI model. Used only if Fireworks is unavailable, so that a capture still works rather than failing. | The same captured text, only on the occasions the backup is used. It is processed to return the result and is not used to train models. |
| Paddle | Payments. Paddle.com Market Ltd is the Merchant of Record for every Sky purchase — they sell the subscription to you, and they handle the payment, invoicing, taxes and refunds. | Your name, email, billing address and country, and your payment details. Card numbers go directly to Paddle and never reach Sky's servers — we only ever store their customer and subscription identifiers, plus your plan and renewal date, so we know what you're entitled to. |
| Vercel | Hosting for the Sky website and dashboard. | Standard request data such as your IP address and browser user agent, processed to serve the site. Your leads are not stored there. |
| PostHog | Product analytics for the Sky website and dashboard. Not used in the extension. | Which pages you viewed and when, plus your country, browser and
device type. On the dashboard we switch off PostHog's automatic
click-tracking, because the things you click there are your leads'
names and companies — those are never sent.
On the dashboard only, and only while you are signed in, we record a fully masked replay of the session so we can see where the product is confusing: your cursor, clicks, scrolling and the layout you saw. Every piece of text is blanked out before it leaves your browser — lead names, companies, emails, notes, anything you type. We see that you clicked a button three times; we cannot see what any of it said. Request and response bodies are not recorded either. Nothing is replayed from the marketing pages, and nothing is replayed when you are signed out. |
| Resend | Sends Sky's email to you: the weekly digest and the one welcome note. | Your email address and the contents of those emails, which for the digest means the leads of yours it names. |
| GLEIF, SEC EDGAR, Companies House | Public company registers, queried only when you press Look up on a lead or run Find people, and only if you switched that register on. Off by default. | The company name on the lead (Look up), or search terms built from your ideal customer profile (Find people). Never the lead itself, the captured text, or your profile as written. |
| HubSpot | Your own CRM, only if you connect it, and only when you press Push on a lead. Sky never pulls from it. If you mint a write key, your CRM can send an outcome back, but that is your tool calling Sky rather than Sky reading your CRM. | The lead's name, email, company, role and location as a contact, and a note holding the captured text, the score with its breakdown and the source page. That note lives in your HubSpot under HubSpot's terms. |
We may also disclose information if required by law. We never sell your data, and we don't share it with advertisers.
Sky's paid plans are sold through Paddle as Merchant of Record. When you subscribe, your payment details are entered into Paddle's own checkout and are processed by Paddle — Sky never sees or stores your full card details. Paddle handles your billing under its own buyer terms and privacy policy. You can manage your card, view invoices, or cancel at any time from Manage billing in your Sky dashboard, which opens Paddle's secure customer portal. See our Refund Policy for how refunds work.
Your leads are scoped to your account using database row-level security — only you, signed in, can read or write your own leads. Nothing is saved until you review and confirm a capture.
We keep your account and leads until you delete them or ask us to close your account. A lead you delete goes to the trash and stays there until you empty it; there is no automatic purge today. What you type into the find box, Find people, Ask Sky and Pick a sample is deleted after 90 days, and the webhook delivery log after 30 days. A live feed token lasts until you rotate or revoke it, a write key until you revoke it, and HubSpot tokens until you disconnect. What happened with a lead and what it scored are kept for as long as the lead is, and are deleted with it. There is no age limit on those two on purpose: neither can be reconstructed later, and dropping the old half would leave the newer half describing a stretch of time it cannot account for. Screenshots are never kept at all. You can export your leads to CSV at any time, and you can request deletion of your account and all associated data by emailing hi@skal.ai.
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to withdraw consent. To exercise any of these, contact hi@skal.ai and we'll respond within a reasonable time.
Sky is not intended for anyone under 16, and we do not knowingly collect data from children.
If we make material changes, we'll update the date above and, where appropriate, notify you. Continued use of Sky after a change means you accept the updated policy.
Questions, requests, or concerns? Email hi@skal.ai.