Privacy Policy
Effective August 16, 2026
Skail is an independent analytics product operated by Alpha Digital, LLC (Milwaukee, Wisconsin). It connects to the platforms a Shopify store already uses, verifies the numbers, and produces a clear brief on what happened and what to do next. This policy explains exactly what we access, what we keep, and what we never do. If anything here is unclear, email stream@goskail.com.
Read-only, always
Every platform connection Skail makes is read-only. We request read-only scopes and never write, edit, publish, delete, or change anything in your Shopify store or any connected account. Skail observes; it does not act.
What we access, and what we keep
We pull the data needed to measure store performance and store it as aggregates, not as records about individual people:
- Shopify: order timestamps, order totals, and whether an order came from a repeat customer. We aggregate these into monthly and rolling-window totals (revenue, order count, average order value, repeat rate). We do not store customer names, email addresses, phone numbers, shipping addresses, or customer IDs.
- Klaviyo, Google Analytics 4, Google Ads, Meta Ads (when you connect them on a paid plan): aggregate performance metrics only, such as email revenue, ad spend, return on ad spend, sessions, and conversion rate. Not individual subscriber, visitor, or customer records.
- QuickBooks (when you connect it on a paid plan): your monthly Profit and Loss summary only, on an accrual basis. That means month-level income, cost of goods sold, and expense totals, which is what lets Skail work out your gross margin and the true breakeven return your ad spend has to clear. We do not read or store individual transactions, invoices, bills, payroll records, customer or vendor records, or bank and card account numbers, and Skail cannot create or change anything in your books.
- Your account: your name and email address for login, and your billing status. Your name and email are also added to our marketing email list (see below).
OAuth access tokens for your connected platforms are encrypted at rest (AES-256-GCM) and are used only to pull the data described above.
Google user data
Skail's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
If you connect Google Analytics or Google Ads, Skail requests two scopes and uses them only to read the single property or ad account you select:
- Google Analytics (analytics.readonly): sessions, traffic-channel breakdowns, and conversion rate. Read-only by definition; no Analytics setting is ever changed.
- Google Ads (adwords): campaign name, status, cost, clicks, impressions, conversions, and conversion value, which produce the return-on-ad-spend and wasted-spend analysis in your brief. Skail only ever issues read-only search queries. Google does not offer a read-only version of this scope, which is why the permission screen describes broader access than Skail uses.
Data obtained through these scopes is used only to generate your own reports. It is never transferred to anyone else, never used for advertising or to serve ads, and never used to train machine-learning models. No human reads it, except where you ask us to, where it is needed to investigate a security issue or a bug you have reported, or where the law requires it. You can disconnect either platform at any time from your store's connectors page, which revokes Skail's access.
Skail is an AI product, so to be explicit about what that does and does not mean here: aggregated metrics are sent to Anthropic's API to write the analysis in your brief, and Anthropic does not train on data sent through its API. Data obtained from Google APIs is neverused to develop, improve, or train generalized or non-personalized AI or machine-learning models, ours or anyone else's.
How we protect your data
All data Skail handles, including data obtained from Google APIs and every other connected platform, is protected by the following mechanisms:
- Encryption in transit: every connection to Skail and every call Skail makes to a connected platform uses HTTPS/TLS. Skail never transmits your data over an unencrypted channel.
- Encryption at rest: OAuth access and refresh tokens are encrypted with AES-256-GCM at the application layer before they are stored, and the database itself is encrypted at rest by our hosting provider.
- Access controls: your data is readable only by your own account. Internal administrative access is restricted to named operators, protected by two-factor authentication, and denied by default. No human reads your platform data except in the cases listed above.
- Retention and deletion:disconnecting a platform immediately deletes the stored tokens for it. Deleting a store deletes that store's data. You can also request deletion of your data at any time by emailing stream@goskail.com.
- Incident response: if we become aware of a security incident affecting your data, we will notify you promptly and describe what was affected and what we have done about it.
Industry benchmarks
We use anonymized, aggregated, store-level metrics (such as median average-order-value or revenue for a given industry) to compute benchmarks that help you see how your store compares to similar businesses. These benchmarks never include personal data, and they are only ever computed across enough stores that no individual store's numbers can be identified from them. A benchmark is never derived from a single store or a handful of stores.
What we never do
- We never sell, rent, or share your data with anyone for their own use.
- We never build profiles of your individual customers.
- We never write to or modify any connected platform.
- We never use your data to train machine-learning models.
Our website and analytics
Our public marketing website (goskail.com) uses Google Analytics 4, the Meta Pixel (with Meta's Conversions API), the X (Twitter) Ads pixel, and Microsoft Clarity to understand how visitors find and use the site and to measure our advertising. These tools set cookies and collect standard web-analytics data such as pages viewed, referrer, approximate location, and device or browser type. This is used only to run and improve Skail's own marketing; it is never combined with the store performance data you connect.
Microsoft Clarity additionally records anonymized session replays and heatmaps of the marketing pages: mouse movement, scrolling, and clicks. Text you type into a form is masked before it leaves your browser, so these recordings do not capture what you enter.
We deliberately do notrun these trackers inside the signed-in application, so the pages where your store's data appears are kept free of third-party analytics. No session replay is ever recorded inside the application: your store's numbers are never on screen in anything we or a third party records. You can also block these cookies with your browser or an opt-out extension.
Marketing emails and advertising audiences
When you create a Skail account, we add your name and email address to our marketing email list (managed by Mailchimp) and tag the contact with your current plan (for example, free or paid) so we can send you relevant product updates and offers. We may also use this list to build advertising audiences, including lookalike audiences on platforms such as Meta and X, in which case your email is shared only in hashed (non-readable) form for matching. We never sell this information, and you can unsubscribe from marketing email at any time using the link in any message we send, or by emailing stream@goskail.com. This account-level contact information is kept separate from the aggregated store-performance data you connect.
Service providers
We rely on a small set of vetted providers to run Skail. They process data only to provide their service to us:
- Vercel — application hosting.
- Supabase — encrypted database.
- Anthropic — the AI model that analyzes your aggregated metrics to write your brief. Only aggregated, non-personal metrics are sent; Anthropic does not train on data sent through its API.
- Resend and Google Workspace — sending and receiving email.
- Mailchimp — our marketing email list.
Retention and deletion
We keep your store's aggregated data for as long as your store is connected, so your history compounds into better briefs over time. You can delete a store at any time from inside the app, which permanently removes that store's connections, tokens, audits, baselines, and history. If you uninstall the Skail app from Shopify, Shopify notifies us and we permanently delete all data for that shop, in line with the compliance process below.
Shopify compliance requests
Skail honors Shopify's mandatory data-protection webhooks. Because we store no personal data about your individual customers, a customer data-request or customer-redaction request has no individual data to return or erase; we log each request and respond accordingly. When a shop is uninstalled, the shop-redaction request permanently deletes all of that shop's data from Skail.
Your rights
Depending on where you live (including under GDPR and the CCPA), you may have the right to access, correct, export, or delete your data, and to object to or restrict certain processing. To exercise any of these, email stream@goskail.com and we will respond within the time your law requires.
Not financial advice
Skail's briefs are analysis, not financial, investment, tax, or legal advice. Every recommendation is a suggestion to evaluate against your own judgment and your team's.
Changes
If we change this policy we will update the effective date above and, for material changes, notify account holders by email.
Contact
Alpha Digital, LLC · Milwaukee, WI · stream@goskail.com