Privacy Policy
Effective Date: August 10, 2026
Last Updated: September 8, 2026
This Privacy Policy explains how Andrei Ivanciu, operating as Skeevo("Skeevo," "we," "us," or "our") collects, uses, stores, and discloses personal information when you visit our website or use our software-as-a-service platform (the "Service").
Skeevo is operated as a sole proprietorship in Canada.
This Privacy Policy is intended to describe our privacy practices and the rights that may apply to you under Canadian privacy laws and, where applicable, privacy laws such as the European Union's General Data Protection Regulation ("GDPR") and California privacy laws including the California Consumer Privacy Act, as amended ("CCPA").
The laws that apply to a particular person, transaction, or processing activity depend on the circumstances, including where the person is located and the nature of the processing.
1. Privacy Contact
For privacy questions, requests, or concerns, contact:
- Andrei Ivanciu
Operating as Skeevo
Canada - Email: hello@skeevo.ai
2. Information We Collect
The information we collect depends on how you use Skeevo.
2.1 Account and authentication information
When you create or access an account, we may collect:
- email address;
- name;
- profile information provided through Google authentication;
- profile picture, where provided by an authentication provider;
- authentication and session information;
- account creation and login timestamps; and
- information reasonably necessary to maintain account security.
Skeevo currently supports two sign-in methods: Google OAuth, which provides your Google name, email address, and profile picture; and passwordless magic-link email authentication. Magic-link sign-in emails expire 15 minutes after they are issued and can be re-sent no more than once every 60 seconds.
Skeevo does not require you to provide your Reddit password.
2.2 Business and website information
When you use Skeevo's business-analysis features, you may provide:
- website URLs;
- business descriptions;
- product and service descriptions;
- target audience information;
- keywords;
- marketing objectives;
- website content or other information retrieved from a website you submit; and
- instructions or prompts you provide to Skeevo.
Skeevo may process publicly accessible website content associated with URLs you submit.
You are responsible for ensuring that you have the right to submit and have Skeevo process information you provide.
2.3 Analysis, opportunity, and generated-content information
Skeevo may collect and store information associated with your use of the Service, including:
- website crawl information;
- business and product analysis;
- keywords, topics, search phrases, and related analysis;
- generated search queries used for discussion discovery;
- potentially relevant Reddit discussions;
- summaries and relevance information;
- opportunity or lead information;
- generated comments and replies;
- drafts;
- campaign settings;
- saved opportunities;
- action status;
- usage information; and
- information about actions you complete, cancel, or regenerate.
2.4 Publicly accessible Reddit and online information
Skeevo may discover and process information appearing in publicly accessible online discussions, including Reddit.
Depending on the discussion, this information may include:
- post or comment content;
- usernames;
- subreddit information;
- public URLs;
- timestamps;
- discussion titles; and
- other information made publicly accessible by the relevant platform or user.
Skeevo may process this information to identify potentially relevant discussions, assess relevance or intent, summarize discussions, and generate draft responses for Skeevo users.
To discover this information, Skeevo may submit search queries to third-party search services. Those queries may incorporate keywords, phrases, or other terms derived from information you provide.
Skeevo does not require you to provide your Reddit password.
Skeevo does not treat publicly accessible information as information supplied directly by the person who originally published it. Where applicable law imposes additional obligations regarding information obtained from public or third-party sources, Skeevo will comply with applicable requirements or rely on an applicable legal exception.
2.5 Payment information
Payments are processed by Stripe or another payment provider identified during checkout.
Skeevo may receive and store information such as:
- payment-provider customer identifiers;
- subscription status;
- subscription type;
- billing period;
- transaction identifiers;
- payment status; and
- limited billing information.
Skeevo does not intentionally store your full payment-card number.
Payment information is handled according to the applicable payment provider's privacy practices.
2.6 Technical and security information
We may automatically collect information such as:
- IP address;
- browser type;
- operating system;
- device information;
- access timestamps;
- authentication events;
- security events;
- request information;
- rate-limit information; and
- other information reasonably necessary to secure and operate the Service.
We use this information for purposes including authentication, security, abuse prevention, rate limiting, troubleshooting, fraud prevention, and maintaining the reliability of the Service. Session tokens expire 24 hours after login; magic-link authentication links expire 15 minutes after issuance.
3. How We Collect Information
We may collect information:
- directly from you when you create an account or use the Service;
- from authentication providers when you choose an authentication method;
- from websites and URLs you submit for analysis;
- from publicly accessible online discussions and search results;
- from payment providers in connection with subscriptions;
- automatically through your use of the Service; and
- from service providers that help us operate the Service.
4. How We Use Personal Information
We use information we collect for purposes including:
Providing the Service
- creating and maintaining accounts;
- authenticating users;
- analyzing websites;
- building business and product profiles;
- identifying relevant discussions;
- ranking potential opportunities;
- generating AI-assisted drafts and summaries;
- storing campaigns and saved information;
- enforcing subscription and usage limits; and
- providing customer support.
AI processing
We may process submitted business information, website content, discussion information, prompts, and related data through AI systems to:
- analyze business information;
- identify relevant topics and search phrases;
- assess potential discussion relevance;
- compute relevance or similarity scores;
- summarize information;
- classify potential opportunities;
- generate marketing suggestions; and
- generate draft responses.
Security and abuse prevention
- prevent unauthorized access;
- detect fraud and abuse;
- enforce rate limits;
- protect infrastructure;
- detect malicious requests;
- prevent unauthorized server-side requests;
- protect against malicious inputs and prompt-injection attempts;
- investigate security incidents; and
- maintain the security and reliability of the Service.
Payments and administration
- process subscriptions;
- maintain billing records;
- manage cancellations and renewals;
- communicate about account or billing issues; and
- satisfy applicable accounting and legal obligations.
Communications
We may send transactional communications relating to:
- account access;
- authentication links;
- security events;
- subscription activity;
- service availability;
- important changes to the Service; and
- support requests.
We do not currently use your personal information to send third-party advertising.
Legal and compliance purposes
We may process information where reasonably necessary to:
- comply with applicable law;
- respond to valid legal requests;
- establish, exercise, or defend legal claims;
- enforce our agreements;
- prevent fraud or abuse; or
- protect the rights, safety, and security of Skeevo, users, or others.
5. Legal Bases Where GDPR Applies
Where the GDPR applies, we may rely on different legal bases depending on the processing activity.
These may include:
- Performance of a contract: where processing is necessary to provide your account or requested Service;
- Legitimate interests: where processing is reasonably necessary for security, fraud prevention, service operation, abuse prevention, or other legitimate business purposes and those interests are not overridden by applicable rights;
- Consent: where we request consent for a particular processing activity;
- Legal obligations: where processing is necessary to comply with applicable law; and
- Other lawful bases: where permitted by applicable law.
Where processing is based on consent, you may withdraw consent as permitted by law. Withdrawal does not affect processing that occurred before withdrawal or processing that has another lawful basis.
6. AI Processing
Skeevo currently runs open-weight AI models on infrastructure controlled by Skeevo, served through a self-hosted Ollama deployment. The models currently in use are a Gemma-family large language model for analysis, classification, and text generation, and a nomic-embed-text embedding model for similarity scoring. These models are used to analyze business information, process website content, identify relevant discussions, summarize information, assess potential opportunities, compute relevance scores, and generate draft content.
Skeevo's current architecture is designed so that submitted business information and prompts used for AI processing are not intentionally sent to external commercial generative-AI providers for model inference.
Skeevo may nevertheless use third-party infrastructure and service providers for functions such as hosting, networking, authentication, email, payments, security, search, or other necessary services. Depending on the service involved, information may therefore be processed outside the systems directly operated by Skeevo.
We do not use your submitted business information or prompts to train external commercial AI models.
AI processing may produce inaccurate or incorrect results. Generated content is automated output and should be reviewed by a human before being relied upon or published.
8. Third-Party Services
Skeevo relies on third-party providers to operate parts of the Service.
These may include:
Google may provide authentication services when you choose Google login.
Stripe
Stripe processes subscription payments and billing information.
Search and online-content services
Skeevo operates its own self-hosted SearXNG meta-search instance, which issues the search queries described in this Privacy Policy to discover publicly accessible online discussions, including potentially relevant Reddit discussions, and reads public Reddit feeds. Search results are processed on Skeevo's own servers.
Email providers
Skeevo sends transactional messages such as magic-link authentication emails and service notifications through an SMTP email provider.
Hosting and infrastructure providers
Skeevo uses hosting, networking, storage, database, security, and other infrastructure services necessary to operate the application.
Third-party providers have their own terms and privacy policies. Their processing of information may be subject to those policies, contractual arrangements, and applicable law.
9. Reddit and Publicly Accessible Information
Skeevo may process publicly accessible Reddit content and related information discovered through SearXNG search queries and Reddit's public feeds.
This processing may include identifying discussions relevant to information supplied by a Skeevo user, assessing relevance, summarizing discussions, and generating draft responses. Before a discussion is queued for your review, automated filters exclude posts older than the configured recency limit (currently 10 days), posts already reviewed in earlier scans, promotional or announcement-style posts, and posts with low embedding-based relevance to your business. A separate AI verification step assesses whether the author is personally involved in the topic. Candidate queues for a website are cleared when a new scan is run for that website.
Skeevo does not require a user's Reddit password.
Skeevo does not automatically publish generated comments to Reddit on behalf of users unless a future feature expressly states otherwise.
Reddit content remains subject to Reddit's own terms, policies, rights, and controls. Reddit users may delete or modify content, and third-party platforms may change or remove access to content.
Because Skeevo relies in part on third-party platforms and services, Reddit-related functionality may change or become unavailable.
If no relevant discussions are identified, Skeevo may refresh its analysis of the submitted website and repeat the discovery process automatically.
11. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Retention periods may vary depending on the type of information and the purpose for which it is processed.
Account information
Account information is generally retained while your account remains active. Session tokens expire 24 hours after login and are not retained beyond their validity.
After account closure, we may retain limited information for legal, security, fraud-prevention, accounting, backup, dispute-resolution, or other legitimate purposes.
Business inputs and generated content
Business information, website analysis, cached analyses, discussion review queues, saved opportunities, generated drafts, campaign information, and related account content are generally retained while your account remains active. Completed analyses are cached by a content fingerprint of the crawled website and reused when the same website content is submitted again, so a website is not re-analyzed unless its content changes. Discussion candidate queues for a website are cleared when you run a new scan for that website.
You may be able to delete certain information through the Service. Information that you delete may remain temporarily in backups or may be retained where reasonably necessary for legal, security, fraud-prevention, accounting, or other permitted purposes.
Security and access information
Security and access information may be retained for a period reasonably necessary for security, fraud prevention, troubleshooting, legal compliance, and investigation of incidents.
Financial records
Billing and financial records may be retained for the period required by applicable tax, accounting, and legal requirements — in Canada, records supporting income-tax filings are generally required to be retained for six years.
Backups
Deleted information may remain temporarily in encrypted or otherwise protected backups until those backups are overwritten or securely deleted according to applicable retention practices.
12. Your Privacy Rights
Depending on where you live and which privacy laws apply, you may have rights concerning your personal information.
These may include:
- the right to know what information we process;
- the right to access personal information;
- the right to correct inaccurate information;
- the right to request deletion;
- the right to request restriction of processing;
- the right to object to certain processing;
- the right to data portability;
- the right to withdraw consent where processing is based on consent; and
- the right to lodge a complaint with an applicable privacy regulator.
Not every right applies in every circumstance.
For example, we may need to retain certain information to comply with legal obligations, resolve disputes, maintain security, prevent fraud, or establish or defend legal claims.
13. California Privacy Rights
If California privacy law applies to you, you may have additional rights, which can include rights to:
- know or access personal information collected about you;
- request deletion;
- request correction;
- obtain information about categories and purposes of processing;
- opt out of certain forms of sale or sharing of personal information;
- limit certain uses of sensitive personal information where applicable; and
- receive equal treatment for exercising applicable privacy rights.
Skeevo does not currently sell personal information for monetary consideration.
Skeevo also does not currently use personal information for cross-context behavioral advertising.
If our practices change in a way that triggers additional California rights or obligations, we will update this Privacy Policy and provide legally required notices and choices.
14. Canadian Privacy Rights
Skeevo is operated from Canada and may be subject to Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial privacy legislation.
Where applicable, you may request access to personal information we hold about you, request corrections, ask questions about our privacy practices, or challenge our handling of your personal information.
We aim to collect, use, disclose, and retain personal information only for purposes that are appropriate in the circumstances and in accordance with applicable privacy law.
15. European Privacy Rights
If the GDPR applies to your personal information, you may have additional rights including:
- access;
- rectification;
- erasure;
- restriction of processing;
- objection;
- portability;
- withdrawal of consent where consent is the legal basis; and
- the right to lodge a complaint with an applicable supervisory authority.
Where we obtain personal information from publicly accessible sources, including Reddit, we may not have a direct relationship with the individual whose information appears in that content.
Where applicable law requires additional notice regarding information obtained from another source, we will comply with applicable requirements or rely on an applicable legal exception.
Skeevo does not currently make decisions producing legal or similarly significant effects about users solely through automated decision-making.
16. Exercising Your Rights
To make a privacy request, contact:
Please provide enough information for us to identify the relevant account or request.
We may need to verify your identity before completing a request in order to prevent unauthorized disclosure, access, correction, or deletion.
We will respond within the time required by applicable law.
If a request is complex or legally restricted, we may explain the reason for any delay, limitation, or refusal.
17. Security
We use reasonable technical and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, loss, and destruction.
Our security measures may include:
- HTTPS/TLS encryption for data transmitted between your browser and the Service;
- authentication and authorization controls;
- protected authentication tokens;
- infrastructure and database access controls;
- rate limiting;
- URL validation and server-side request protections;
- input sanitization;
- protections against certain prompt-injection and malicious-input techniques;
- security headers;
- infrastructure isolation; and
- monitoring and security procedures.
No internet transmission or electronic storage system is completely secure.
Accordingly, we cannot guarantee absolute security.
18. International Data Transfers
Skeevo's application is hosted on third-party cloud infrastructure, and our service providers (hosting and storage, SMTP email delivery, Google authentication, Stripe payments, and our self-hosted SearXNG search instance) may process or store information in Canada, the United States, the European Union, or other jurisdictions where those providers operate.
Where applicable privacy law imposes requirements on international transfers, we will use legally recognized transfer mechanisms or other safeguards appropriate to the circumstances.
19. Children's Privacy
Skeevo is intended for adults and businesses.
The Service is not directed toward children under the applicable age of majority.
We do not knowingly collect personal information from children in violation of applicable law.
If you believe a child has provided personal information to Skeevo in circumstances where collection is not permitted, contact us so that we can investigate and take appropriate action.
20. Data Breaches and Security Incidents
If we experience a security incident involving personal information, we will assess the incident and take reasonable steps required by applicable law.
Where notification is legally required, we will notify affected individuals, regulators, or other parties as required.
21. Changes to This Privacy Policy
We may update this Privacy Policy when our practices, technology, Service, or legal obligations change.
When we make material changes, we may provide notice through the Service, by email, or through another reasonable method.
The "Last Updated" date at the top of this Privacy Policy indicates when the policy was most recently revised.
22. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or Skeevo's handling of personal information, contact:
- Andrei Ivanciu
Operating as Skeevo
Canada - Email: hello@skeevo.ai