Privacy Policy
Effective date: July 27, 2026
This Privacy Policy explains how Sabhahith Works Private Limited (Bengaluru, India), the operator of SkeletIQ (“we”, “us”, or “our”), collects, uses, and shares information when you use the Service at skeletiq.com. Under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), Sabhahith Works Private Limited is the Data Fiduciary for your personal data and you are a Data Principal; where other data-protection laws apply to you, we act as the equivalent data controller.
1. Information we collect
Account and profile
When you register or sign in, we collect your email address, display name, and (if provided by your identity provider) profile picture. If you sign in with Google or GitHub, we receive a provider account identifier and your verified email from that provider. We also record sign-in activity such as your last login time.
Content you create
We store the content you create with the Service, including projects, the natural-language prompts you submit, generated architectures and diagrams, chat conversations and messages, prompt templates you save, reviews and architecture decision records, canvas comments, and any ratings or feedback you provide.
Billing information
For paid plans and credit purchases, we store your plan, credit balances, and billing identifiers (such as customer and subscription references) associated with our payment processor. Your full card details are collected and processed by Razorpay and are not stored by us.
Your model provider keys (BYOK)
If you connect your own model-provider API key, we store it encrypted at rest using AES-256-GCM and retain only a masked preview (e.g. the last few characters) for display. The key is used only to route your requests to the provider you selected.
Usage and technical data
We record operational data such as model-usage logs (model, provider, token counts, and cost), credit-consumption records, an activity feed of actions you take, an immutable audit trail of security-relevant events, and standard server logs (including IP address and request metadata) used for security, debugging, and abuse prevention.
Local storage and cookies
We use your browser’s local storage to hold your authentication tokens and interface preferences such as theme and workspace selection, along with your analytics choice below. Clearing this storage signs you out.
Depending on how your session was established we may also set strictly necessary cookies for sign-in (a refresh token and a CSRF token). These are required for the Service to work and are not used for tracking. The only non-essential cookies are the analytics cookies described in section 5, which are set solely if you accept them.
2. How we use information
- to provide, operate, secure, and improve the Service;
- to generate architectures and related output in response to your prompts;
- to authenticate you, manage teams, and enforce plan limits and credit metering;
- to process payments and prevent fraud and abuse;
- to send transactional messages (such as team invitations and account notices); and
- to comply with legal obligations and enforce our Terms.
3. AI processing and model providers
To generate output, the prompts and project content you submit are transmitted to a large language model provider — either a provider we operate the Service with (such as OpenAI, Anthropic, or a self-hosted Ollama model) or, if you use Bring Your Own Key, the provider whose key you connected. These requests are routed through our model gateway. The provider processes your input to return a response; its handling of that data is governed by the provider’s own policies.
4. Service providers we share data with
We share limited information with third-party service providers (subprocessors) that help us run the Service:
- Google and GitHub — sign-in and identity (only if you use those options);
- Razorpay — payment processing and billing;
- Resend — delivery of transactional email;
- Google Analytics — product analytics; and
- Model providers (OpenAI, Anthropic, Ollama, OpenRouter) — AI generation, as described above.
We do not sell your personal information. We may also disclose information where required by law or to protect the rights, safety, and security of our users and the Service.
5. Analytics
We use Google Analytics to understand how the Service is used at an aggregate, event level (for example, sign-ups, projects created, and generations run). This helps us improve the product.
Analytics is off until you accept it. We ask once, on your first visit, and the Google Analytics script is not loaded and no analytics cookie is set unless you say yes. Declining costs you nothing — every feature works either way — and you can change your mind at any time by clearing this site’s data in your browser, which makes us ask again. You can also limit collection through your browser or device settings.
6. Data retention and deletion
We retain your information for as long as your account is active or as needed to provide the Service. When you delete content or your account, we apply a “soft delete” and then remove associated data, though related records may cascade or be disassociated rather than immediately erased. Backups are taken periodically and rotate on a short retention window, so residual copies may persist briefly after deletion. For integrity and security reasons, audit-trail records are immutable and retained. To request deletion of your account or data, contact [email protected].
7. Your rights
As a Data Principal under the DPDP Act you have the right to:
- Access — obtain a summary of the personal data we process about you and the processing activities we carry out;
- Correction and erasure — have inaccurate or incomplete data corrected or completed, and have data erased where it is no longer needed for the purpose it was collected for;
- Withdraw consent — withdraw any consent you have given, at any time and as easily as you gave it. Withdrawal does not affect processing already carried out, and some features may stop working without the data they depend on;
- Grievance redressal — raise a complaint with our Grievance Officer (see below) and, if unresolved, with the Data Protection Board of India; and
- Nomination — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
Depending on your location you may also have rights to export your data or to object to or restrict certain processing. You can manage much of your data directly in the app, or exercise these rights by contacting [email protected]. We respond within the timelines set by applicable law.
8. Our lawful basis
We process your personal data on the basis of the consent you give when you create an account and use the Service, and for the legitimate uses permitted by the DPDP Act — including providing the Service you have asked for, billing, security, preventing abuse, and meeting our legal obligations. We do not sell your personal data, and we do not use your content to train our own models.
9. Security
We use technical and organizational measures to protect your data, including encryption in transit, hashing of passwords, encryption of connected provider keys at rest, token-based authentication with revocation, and rate limiting. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. International data transfers
We operate from India, where Sabhahith Works Private Limited is incorporated. The Service is hosted in Hyderabad, India, and your account and project content are stored there.
Some processing necessarily happens outside that location, because the Service depends on providers operating in other countries:
- AI model providers — the prompts and architecture content you submit for generation are sent to the model provider serving your request, which for our hosted models is generally in the United States. If you connect your own provider key, your content goes to that provider on the terms you have with them.
- Email delivery — transactional email (verification, invitations, billing notices) is sent through a provider that processes the recipient address and message content, generally in the United States.
- Content delivery and security — requests pass through a global CDN and security layer that terminates connections in the region nearest you.
- Payments — processed in India by our payment gateway. We never receive or store your card details.
- Backups — encrypted database backups are stored with a cloud object-storage provider. They are encrypted before they leave our servers, and the provider cannot read them.
Where we transfer data internationally we take steps consistent with applicable law — including the DPDP Act and any restrictions the Central Government notifies on transfers to particular territories — to protect it. India has not, to date, notified any territory as restricted for these purposes. Section 4 lists the categories of service providers we share data with.
11. Teams and shared visibility
If you use the Service as part of a team, content shared within that team — including projects and related activity — may be visible to other team members according to their role. Team owners and admins may be able to manage that shared content.
12. Children
The Service is not directed to children, and we do not knowingly collect personal information from anyone below the minimum age required to consent under applicable law. If you believe a child has provided us information, contact [email protected] and we will take appropriate steps.
13. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice.
14. Contact and grievance redressal
For any privacy question or to exercise your rights, contact us at [email protected]. If you are not satisfied with our response, you may escalate to our Grievance Officer — details are on our Contact & Grievance Redressal page. You also have the right to complain to the Data Protection Board of India if your grievance remains unresolved.
Sabhahith Works Private Limited
1080/2 K B Road, Sharadha Galli, Yellapur, Uttara Kannada – 581359, Karnataka, India
CIN: U62011KA2026PTC222900 · GSTIN: 29ABUCS1454Q1Z9
+91 70193 92625 · [email protected]