Privacy Policy
Effective date: September 21, 2026
This Privacy Policy explains how Fluenta SAS (RUT 220952010019, Punta del Este, Uruguay; "Fluenta", "we") collects and uses personal data when you use Skiffly (skiffly.dev, skiffly.cloud, the CLI, API and related services). Fluenta is the data controller for the data described here. For personal data that you process inside applications you run on Skiffly, you are the controller and we are your processor (see section 8).
1. Data we collect
Account data. When you sign in with GitHub we receive your GitHub user ID, username, display name, avatar URL, primary email address and public profile data (account creation date, number of public repositories and followers, used for abuse prevention). If you install the Skiffly GitHub App we receive installation IDs and the list of repositories you granted access to, and we obtain short-lived tokens to read source code for builds.
Workspace and billing data. Workspace names, members and roles, plan, prepaid balance, ledger entries, invoices, payment references and status. Payments are processed by PayPal and NOWPayments; we do not receive full card numbers or wallet private keys. We receive the payer identifier, amount, currency and transaction status from the provider.
Service data. Project and service configuration, environment variables (encrypted at rest), domains, deployment history, build and runtime logs, resource usage metrics (CPU, memory, storage, network) and the content of storage volumes and databases you create. Logs and metrics are retained for a limited period (currently up to 30 days for logs; usage aggregates for as long as needed for billing records).
Technical and audit data. IP addresses, user agent, request timestamps, API token usage, audit log entries (who did what and when in a workspace), error reports (via our self-hosted Sentry) and cookies needed for sessions and CSRF protection. We do not use third-party advertising cookies on the dashboard.
Communications. Emails you send us and transactional emails we send (delivered through Brevo), plus notification preferences.
2. Why we use it (legal bases)
- To provide the Service under our contract with you (accounts, builds, deployments, billing, support).
- For our legitimate interests: securing the platform, preventing abuse and fraud, monitoring availability, improving the product, enforcing our terms.
- To comply with legal obligations (tax and accounting records, responding to lawful requests).
- With your consent where required (for example optional marketing emails, which you can withdraw at any time).
3. Sharing
We share personal data only with processors that help us run the Service, under contracts that restrict their use of it: Hetzner Online GmbH (servers, Finland), Railway Corp. (control plane hosting), Cloudflare (DNS, TLS certificates), GitHub (authentication, source access), PayPal and NOWPayments (payments), Brevo (email delivery), and our own self-hosted monitoring. We may disclose data when required by law or to protect rights, safety and the integrity of the Service. We do not sell personal data.
4. International transfers
We are based in Uruguay, a country recognized by the European Commission as providing adequate data protection. Your workloads run in data centers in the European Union (Finland); the control plane and some processors are in the EU and the United States. Where data leaves the EEA or the UK we rely on adequacy decisions or standard contractual clauses.
5. Retention
Account data is kept while your account exists and for up to 30 days after deletion (backups may persist for up to 90 days). Billing records are kept for the period required by Uruguayan tax law (generally 10 years). Logs and technical data are kept for up to 30 days unless needed for an ongoing security investigation. Volumes and databases are deleted when you delete them or your account, subject to the backup window above.
6. Security
Data is encrypted in transit (TLS) and secrets are encrypted at rest (AES-256-GCM). Customer workloads run in sandboxed containers (gVisor or lightweight virtual machines) isolated by network policy. Access to production is restricted to authorized staff with audit logging. No system is perfectly secure; report vulnerabilities to security@skiffly.dev.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to restrict or object to processing, and to withdraw consent. You can view and change most data in the dashboard and delete your account there; for anything else write to privacy@skiffly.dev. You may also complain to your local data protection authority; in Uruguay this is the Unidad Reguladora y de Control de Datos Personales (URCDP).
8. Data you process on Skiffly
If your applications process personal data of your own users, you are responsible for that processing and for having a lawful basis. We process such data only on your instructions (running your workloads), keep it confidential, help you meet your obligations where reasonably possible and delete it when you delete the resources. Our Data Processing Addendum (including sub-processor list) is available on request at legal@skiffly.dev.
9. Cookies
We use strictly necessary cookies for sign-in sessions and CSRF protection on app.skiffly.dev and functional cookies to remember interface preferences. The marketing site may use privacy-friendly, cookieless analytics.
10. Children
The Service is not directed to children under 18 and we do not knowingly collect their data.
11. Changes
We will post changes here and, for material changes, notify you by email or in the dashboard at least 14 days in advance.
12. Contact
Fluenta SAS (RUT 220952010019), Punta del Este, Uruguay · privacy@skiffly.dev · legal@skiffly.dev