Legal
Privacy Policy
Last updated
Skimabase is a desktop app. Your projects stay on your computer. We receive the account details Google shares when you sign in and, if you buy a plan, the billing records needed to manage it. We don’t run analytics or telemetry, and we don’t sell personal information.
1. Who we are
Skimabase is provided by Not configured: LEGAL.operatorName (“we”, “us”). This policy explains what information the Skimabase desktop app and this website collect, how it is used, and the choices you have.
Questions about this policy or your data: Not configured: LEGAL.contactEmail.
2. The short version
- Projects, schemas, generated code and AI conversations are stored on your device, not on our servers.
- Signing in with Google gives us your name, email address, profile picture and a Google account identifier. We use them to sign you in and to identify your account.
- Payments are handled by Stripe. We never see your card details.
- There are no analytics, advertising or crash-reporting tools in the app or on this website.
- AI features are optional and send requests from your device directly to OpenRouter, using your own key.
3. Information we collect
Account information
When you sign in, our authentication provider, Supabase, creates an account record containing your email address, the name and profile picture URL your Google account provides, your Google account identifier, and sign-in timestamps. We assign the account an internal user ID.
Billing information
If you start a checkout or open the billing portal, we create a Stripe customer for your account. We send Stripe your email address and your internal user ID. We store your Stripe customer ID, your subscription’s status, price, billing period and cancellation state, and the plan your account is entitled to. Stripe collects your payment details directly; they never reach us. To avoid processing the same payment event twice, we keep each Stripe event’s ID, type and processing status, but not its contents.
Your project content
Schemas, entity files, layouts, generated (Derived) output, migration plans and AI conversations are saved in your project folder on your computer. Skimabase does not upload them to our servers. Billing requests never include project content.
Information stored only on your device
- Your sign-in session, in a file in the app’s configuration folder that only your operating-system user can read.
- Your OpenRouter API key, if you add one, in a file in the same folder.
- Preferences such as recent projects, open sessions, the selected AI model and the database provider.
- Database and SharePoint passwords are kept in memory while the app is running and are not saved to disk.
This website
This website does not use cookies, analytics or advertising. It remembers your light or dark theme choice in your browser’s local storage. The provider that hosts the website may process standard request information, such as IP address and browser type, to deliver pages and protect the service.
4. Google user data
Skimabase uses Google only to sign you in and to identify your account with your basic profile. The app opens Google’s sign-in page in your system browser and completes sign-in through Supabase Auth.
What we access
The basic sign-in information Google shares for the scopes openid, email, profile: your name, email address, profile picture and Google account identifier. Not configured: GOOGLE_SIGN_IN.scopesConfirmed
We do not request access to Gmail, Google Drive, Google Calendar, Contacts or any other Google service, and the app does not call Google APIs on your behalf.
How we use it
- To sign you in and keep you signed in.
- To show your name and picture in the app’s account settings.
- To identify your account for billing, including sending your email address to Stripe.
How we store and share it
Your account record is stored by Supabase, our authentication provider. Your session is stored on your device as described above. We share Google user data only with the service providers listed in this policy, and only to provide Skimabase. We do not sell it, use it for advertising, or use it to train AI models.
Skimabase’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Removing access
Signing out removes the session from your device. You can revoke Skimabase’s access at any time from your Google Account permissions, and you can ask us to delete your account as described in “Your choices and rights”.
5. How we use information
- To provide sign-in and keep your account secure.
- To manage subscriptions, payments and the plan your account is entitled to.
- To respond when you contact us.
- To meet legal obligations and to prevent abuse.
6. AI features
AI features are optional and off until you add your own OpenRouter API key. When you use them, the app sends your prompt and the relevant parts of your project directly from your device to OpenRouter, which routes the request to the model you choose. These requests do not pass through our servers.
OpenRouter and the model provider handle that data under their own terms and privacy policies. Review them before sending sensitive information. AI conversations are saved in your project folder.
7. Service providers
We rely on these providers to operate Skimabase:
| Provider | Purpose |
|---|---|
| Sign-in identity provider. | |
| Supabase | Authentication, account records and billing records. |
| Stripe | Checkout, payments, invoices and the billing portal. |
| GitHub | Hosts app downloads and the update information the app checks for new versions. |
| OpenRouter | AI requests, only if you add your own key. |
When the app checks for updates or you download a release, GitHub receives standard request information such as your IP address. Databases and SharePoint sites you connect to are operated by you or your organization.
8. Data retention
We keep your account and billing records while your account exists. Your session stays on your device until you sign out. When you ask us to delete your account, we delete your account record and the billing records we hold, except where we must keep information to meet legal, tax or accounting obligations. Stripe retains payment records under its own policies.
9. Security
Sign-in uses the system browser with PKCE, and your session file is readable only by your operating-system user. Billing data is kept in database tables that only our server-side functions can access. Payment details are handled by Stripe. No system is perfectly secure, but we limit what we collect so there is less to protect.
10. Your choices and rights
You can ask to access, correct, export or delete the personal information we hold about you. Contact Not configured: LEGAL.contactEmail from the email address on your account. Depending on where you live, you may have additional rights under local law, including the right to complain to a data protection authority.
You can also sign out, remove your OpenRouter key, and delete project folders yourself at any time.
11. Children
Skimabase is a professional tool and is not directed to children under 13. We do not knowingly collect their information.
12. International transfers
Our service providers may process information in countries other than yours. Where we transfer personal information, we rely on the safeguards those providers offer.
13. Changes and contact
We will update this policy when our practices change and revise the date above. Significant changes will be announced on this website or in the app.
Contact: Not configured: LEGAL.contactEmail. See also the Terms of Service.