Legal
Privacy policy
Last updated 15 September 2026
1. Who we are and how to contact us
Skybase (“we”, “us”) provides a project-management service at https://skybase.it and on workspace subdomains of skybase.it. Questions about this policy go to support@skybase.it.
2. What we collect
- Account data: your name, email address, password hash, avatar, role and, if you sign in with Google, the identifier Google gives us.
- Workspace content: projects, columns, jobs, tasks, comments, private notes, statuses, custom fields and the files you upload, including thumbnails we generate.
- Guest data: the name and email address of any client or collaborator you invite, so we can send the invitation and show who did what.
- Billing data: your plan, seat count and invoices. Card details are collected and stored by Stripe, not by us.
- Notification and email logs: which notifications were sent, delivered, opened or clicked, so your workspace administrators can troubleshoot delivery.
- Usage and technical data: IP address, browser, pages visited and, where enabled by configuration, analytics events from Google Analytics or Google Tag Manager.
3. How we use it
To run the service you signed up for: showing the right people the right projects, sending the notifications you have chosen, billing per seat, keeping your files available, investigating abuse, and improving the product. We do not sell personal data.
4. Legal bases
Where UK or EU data-protection law applies, we rely on performance of a contract (providing the service), legitimate interests (security, product improvement, fraud prevention), consent (analytics cookies where required) and legal obligation (tax and accounting records).
5. Sub-processors
We use the following providers to deliver the service. Each receives only what it needs for its role.
- Stripe for payments and invoices.
- Mailgun for sending email and reporting delivery events.
- Algolia for search, indexing job titles and descriptions per workspace with per-user access tokens.
- Amazon Web Services (S3) for private file storage with signed, expiring links.
- Pusher or a self-hosted Laravel Reverb server for real-time updates.
- Slack, GitHub and Google only when you connect them, and only for the data those integrations exchange.
- Anthropic when you use Claude features: the job title and description you choose to send are used to generate suggestions.
- Google Analytics where analytics are enabled for the marketing site.
6. Data isolation
Each workspace runs on its own subdomain with its own dedicated database. Uploaded files are stored privately and every download link is signed and expires after 8 hours.
7. Retention and deletion
We keep workspace content for as long as the workspace exists. Archived content stays available to the workspace until deleted. Bulk file exports built in the background are removed after 24 hours. A workspace administrator can request deletion of the whole workspace; deletion is confirmed by email and then carried out, after which the database and files are removed from active systems and later from backups.
8. Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, or to object to or restrict certain processing. Email support@skybase.it and we will respond within the time the law allows. Workspace content belongs to the workspace; requests about it may be routed to the workspace administrator.
9. Cookies
We use a session cookie to keep you signed in, a cookie to remember your light or dark theme, and, where enabled, analytics cookies on the marketing site. You can block cookies in your browser; the sign-in cookie is required for the app to work.
10. Security
Passwords are hashed, traffic is encrypted in transit, file links are signed and short-lived, email-sending endpoints are rate limited, and administrative access to the platform is protected by allow-lists and audit logging.
11. Children
Skybase is a business tool and is not directed at children under 16. Do not create an account if you are under 16.
12. International transfers
Our sub-processors may process data outside your country. Where required we rely on standard contractual clauses or equivalent safeguards.
13. Changes to this policy
We will post changes here and update the date at the top. Material changes will be announced in the app or by email.