Data & privacy

Privacy Policy

This Privacy Policy explains how Gilad Morad ("Skynet", "we", "us", or "our") collects, uses, and shares personal information when you use Skynet, the prompt-optimization service at skynetml.com (the "Service"). It also describes the choices and rights you have. For the purposes of the GDPR, we are the controller of the personal information described here, except where we act as a processor for content you submit.

Last updated
August 14, 2026
Effective
August 11, 2026
Reading time
6 min
Current document
11 sections

01

Information we collect

Information you provide

  • Account information: your email address, display name, and password. If you sign in with a third-party provider such as Google or GitHub, we receive basic profile information from that provider.
  • Authentication data: passkey/WebAuthn credentials, two-factor settings, recovery codes, and personal access tokens you create. Passwords and recovery codes are stored only as cryptographic hashes; we cannot read them.
  • Content you submit: the datasets, prompts, evaluation code, module configurations, and related materials you upload or create to run optimization jobs, together with the results and metrics we generate for you.
  • Bring-your-own-key (BYOK) credentials: if you choose to provide your own LLM provider API key, we store it encrypted at rest and use it to run your jobs. We do not display the full key back to you.
  • Communications: messages you send us for support or other inquiries.

Information collected automatically

  • Billing and transaction data: your credit balance, purchase history, and the amount of a purchase. Card payments are processed by Stripe; we receive confirmation and limited metadata (such as the last four digits and card brand) but never your full card number.
  • Usage and job telemetry: records of the jobs you run, credits consumed, timestamps, feature usage, and error and performance logs used to operate, secure, and debug the Service.
  • Device and connection data: IP address, browser and device type, and similar technical information, including data used for rate limiting and abuse prevention.
  • Cookies: we use strictly necessary cookies to keep you signed in and to keep the Service secure. See “Cookies” below.

If you use the optional voice-input feature, the audio you record is sent to our speech provider (Groq) to transcribe it into text; we do not retain the audio after transcription.

02

How your content reaches LLM providers

The core function of the Service is to optimize prompts against large language models. To do this, we send the prompts and dataset content involved in your jobs to third-party LLM providers, reached through OpenRouter and, where configured, a self-hosted gateway. Those providers process the content to return completions, which we use to produce your results.

We do not use your content to train our own models, and we do not sell your content. The LLM providers' handling of the content they receive is governed by their own terms and privacy policies. If you use BYOK, your jobs run against the provider tied to your own key.

03

How we use information

We use personal information to:

  • Provide, maintain, and improve the Service, including running your optimization jobs and returning results (legal basis: performance of a contract).
  • Process payments, manage credit balances, and prevent payment fraud (legal basis: performance of a contract and legitimate interests).
  • Authenticate you, secure accounts, and enforce usage limits and our Terms, including rate limiting and abuse prevention (legal basis: legitimate interests and legal obligation).
  • Communicate with you about the Service, including security notices, transactional messages, and support (legal basis: performance of a contract and legitimate interests).
  • Monitor, debug, and analyze the Service to keep it reliable and secure (legal basis: legitimate interests).
  • Comply with legal obligations and respond to lawful requests (legal basis: legal obligation).

Where we rely on legitimate interests, we balance them against your rights. Where the law requires consent, such as for any non-essential cookies, we ask for it.

04

How we share information

We do not sell your personal information. We share it only in these circumstances, with service providers who process it on our behalf under appropriate contracts:

  • LLM providers (via OpenRouter, and a self-hosted gateway where configured) to run your optimization jobs.
  • Stripe, to process payments and manage billing.
  • Speech transcription (Groq) when you use voice input.
  • Hosting and infrastructure providers that run our application, database, and email delivery.
  • Analytics and error-monitoring providers (currently PostHog and Sentry, when enabled) to understand feature usage and diagnose failures. Analytics can be disabled in account settings; we configure these providers to minimize personal data.
  • Professional advisers, and authorities or other parties, where necessary to comply with law, enforce our Terms, or protect the rights, property, or safety of our users or others.
  • A successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

We may also share aggregated or de-identified information that cannot reasonably be used to identify you.

05

International transfers

We and our service providers may process your information in countries other than your own, including the United States. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism.

06

Data retention

We keep personal information for as long as your account is active and as needed to provide the Service. Specific practices include:

  • Account and content data are retained until you delete the item or your account, subject to short operational delays.
  • Some conversational and job data is automatically purged on a rolling basis, and logs are capped and rotated, so older operational data is removed over time.
  • Billing and transaction records are retained as required for accounting, tax, and legal purposes, in de-identified form where possible after your account is closed.
  • Backups are retained for a limited period and then overwritten on a rolling basis.

07

Your rights and choices

Depending on where you live, you may have some or all of the following rights: to access the personal information we hold about you; to correct inaccurate information; to delete it; to restrict or object to certain processing; to data portability; and to withdraw consent where processing is based on consent. If you are in the EEA or the UK, these are your GDPR rights. If you are a California resident, you have rights under the CCPA/CPRA, including the right to know, delete, and correct, and the right not to be discriminated against for exercising them; we do not sell or share your personal information as those terms are defined under California law.

You can exercise many of these rights directly in the Service: you can update your profile, export your data, and delete your account from your account settings. For any other request, contact us at privacy@skynetml.com. We will respond as required by law, and you have the right to lodge a complaint with your local data protection authority.

Please note that deleting your account removes your data from the Service, but it does not by itself delete records held by independent third parties such as your payment processor or, for BYOK, your own LLM provider. Those are governed by their own policies.

08

Cookies

We use strictly necessary cookies to keep you signed in, to secure the Service, and to remember basic preferences. Because these cookies are essential to provide the Service, they do not require consent. We do not use advertising cookies. You can block cookies in your browser, but the Service may not function correctly without the essential ones.

09

Security

We use technical and organizational measures to protect personal information, including encryption in transit, encryption at rest for sensitive credentials such as BYOK keys, hashing of passwords and recovery codes, optional two-factor authentication and passkeys, and rate limiting against abuse. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10

Children's privacy

The Service is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us at privacy@skynetml.com and we will take appropriate steps to delete it.

11

Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you, for example by email or through an in-Service notice. The “last updated” date below indicates when this Policy was last revised.