Privacy Policy

Last updated: 27 June 2026

Skopos ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and disclose your personal data when you use our log monitoring service available at skopos.ink (the "Service").

This Policy complies with the EU General Data Protection Regulation (GDPR) and Italian Legislative Decree 196/2003.

1. Data Controller

The Data Controller is Skopos, with registered office in Italy. For any privacy-related question contact: support@skopos.ink.

2. Personal data we collect

We collect and process the following categories of personal data:

  • Account data: email address, hashed password, account creation date.
  • Billing data: when you subscribe to a paid plan, we process billing details via our payment provider (we do not store credit card numbers directly).
  • Log data: the application logs you send to our Service through our SDK, which may contain technical information about your applications.
  • Usage data: aggregated metrics about how you use the Service (login times, features used, AI chat usage).
  • Technical data: IP address, browser type, device information, collected automatically for security and analytics.

3. Legal basis for processing

We process your personal data on the following legal bases (GDPR Art. 6):

  • Contract performance (Art. 6(1)(b)): to provide the Service you subscribed to.
  • Legal obligation (Art. 6(1)(c)): tax, accounting, and regulatory requirements.
  • Legitimate interest (Art. 6(1)(f)): security, fraud prevention, service improvement.
  • Consent (Art. 6(1)(a)): for non-essential cookies and marketing communications, when applicable.

4. How we use your data

  • To provide and maintain the Service.
  • To process payments and send invoices.
  • To send transactional emails (verification, alerts, account notifications).
  • To analyse your logs and generate AI-powered insights (only with your data, never aggregated across customers).
  • To detect and prevent fraud, abuse, and security incidents.
  • To comply with legal obligations.

5. Data retention

We retain your data only as long as necessary. Log data retention depends on your subscription plan:

  • Starter: 7 days
  • Indie: 21 days
  • Pro: 60 days
  • Business: 90 days

After these periods, log data and derived AI insights are automatically and permanently deleted by our retention worker. Other data categories:

  • Account data: for the duration of your account, plus 12 months for legal/billing requirements after account closure.
  • Backups: daily database backups are retained for 30 days, then permanently deleted.

6. Third-party processors

We share data only with vetted sub-processors strictly necessary to operate the Service:

  • Hetzner Online GmbH (Germany, EU): hosting infrastructure for the API and database.
  • Vercel Inc. (USA, SCC + DPF): frontend hosting and CDN.
  • Cloudflare, Inc. (USA, SCC + DPF): DNS, edge security, and inbound email routing for skopos.ink.
  • Anthropic PBC (USA, SCC): AI processing for log insights and chatbot (no training on customer data).
  • Resend (USA, SCC): transactional email delivery.
  • Lemon Squeezy, Inc. (USA, SCC) acts as our Merchant of Record (MoR) for all payment transactions. In this role, Lemon Squeezy is the data controller for billing, payment, and tax data, and Skopos receives only the minimum information needed to fulfill the subscription.

All non-EU transfers are based on Standard Contractual Clauses (SCC) or equivalent safeguards per GDPR Articles 44–46. New sub-processors are announced at least 30 days in advance via email, giving you the opportunity to object.

7. Your rights (GDPR Articles 15–22)

You have the right to:

  • Access your personal data (Art. 15).
  • Rectify inaccurate or incomplete data (Art. 16).
  • Erasure — "right to be forgotten" (Art. 17).
  • Restrict processing (Art. 18).
  • Object to processing based on legitimate interest (Art. 21).
  • Data portability in a structured, commonly used, machine-readable format (Art. 20).
  • Withdraw consent at any time, without affecting the lawfulness of prior consent-based processing (Art. 7).
  • Lodge a complaint with a supervisory authority — typically the Italian Garante per la protezione dei dati personali, or the authority of your habitual residence, place of work, or place of the alleged infringement (Art. 77).

To exercise these rights, email support@skopos.ink. We respond within 30 days.

8. Security

We apply industry-standard security measures: TLS encryption in transit, bcrypt password hashing, rate limiting, isolated database access, regular backups. No method is 100% secure, but we work continuously to protect your data.

9. Changes to this Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email at least 30 days before they take effect.

10. Contact

Email: support@skopos.ink