Legal
Privacy Policy
What personal data Skoora processes, why we process it, who we share it with, how long we keep it, and the rights you have under the GDPR.
- Operator
- Telmate AI ApS, CVR 46171578
- Effective and last updated
- 6 August 2026
Important
- Your ideas and evaluations belong to your account. They are not published and never shared as a dataset, though authorised personnel and our processors can access them to run and support the service.
- Idea content is sent to Google Gemini models so the features you ask for can be generated. We do not use identifiable customer idea content to train our own models.
- This marketing site uses a Cookiebot consent banner. Only consent storage is set by default, non-necessary scripts are blocked until you accept, and no advertising or third-party marketing analytics are connected.
- You can access, correct, export or delete your data.
This summary is for orientation only. The sections below are the full policy.
01
Who is responsible for your data
Telmate AI ApS, CVR 46171578, is the data controller for the personal data described in this policy.
Privacy questions and requests to exercise your rights can be sent by email to support@telmate.ai.
We have not appointed a Data Protection Officer, because we are not required to do so. Privacy requests are handled directly by the company.
02
Scope of this policy
This policy covers the Skoora marketing website and the Skoora application, including account creation, idea evaluation, discovery, plans and prompts, support correspondence, and any referral or affiliate participation.
It does not cover third-party websites or tools you choose to use, such as an AI app builder you paste a prompt into. Those services have their own policies.
03
What data we process
- Account and profile data: name, email address, authentication identifiers from Google sign-in where used, account status and settings.
- Idea and evaluation content: the ideas, descriptions, answers and context you submit, and the scores, signals, reports, plans and prompts generated from them.
- Personalisation and onboarding preferences: background, interests and similar inputs you give so results can be tailored.
- Usage and credit ledger: actions you take in the product, credits granted and consumed, and feature usage.
- Referral and affiliate data: application details, referral attribution, and payout records where a program applies.
- Device, session and security data: IP address, browser and device information, session and login events, security events, error reports, activity logs and presence information showing that a session is active.
- Communications: emails and support messages you send us and our replies.
- Payment metadata: transaction identifiers, amounts, currency, status, country and tax data received from Stripe. We do not store full card numbers.
04
Where the data comes from
- From you, when you create an account, submit an idea, contact us or apply to a program.
- From your use of the service, generated automatically as you interact with it.
- From our providers, such as authentication, payment, email and infrastructure providers.
- From a referrer, when someone refers you and we record that attribution.
05
Why we process it, and our legal basis
- Purpose
- Create and run your account, deliver evaluations, plans and prompts you request
- Data
- Account, idea content, generated output, credit ledger
- GDPR legal basis
- Performance of a contract, Article 6(1)(b)
- Purpose
- Process purchases and manage credits
- Data
- Payment metadata, credit ledger
- GDPR legal basis
- Performance of a contract, Article 6(1)(b)
- Purpose
- Send transactional email such as sign-in, receipts and service notices
- Data
- Account data, email delivery records
- GDPR legal basis
- Performance of a contract, Article 6(1)(b)
- Purpose
- Keep the service secure, prevent abuse and fraud, debug errors, and improve reliability and quality
- Data
- Device, session, security, error and activity data
- GDPR legal basis
- Legitimate interests, Article 6(1)(f)
- Purpose
- Understand aggregate product usage to improve features
- Data
- Usage and activity data
- GDPR legal basis
- Legitimate interests, Article 6(1)(f)
- Purpose
- Store the optional referral cookie, and send marketing email where we use it
- Data
- Referral attribution, contact data
- GDPR legal basis
- Consent, Article 6(1)(a), withdrawable at any time
- Purpose
- Meet accounting, tax, bookkeeping and other legal duties, and respond to lawful requests
- Data
- Payment and payout records, correspondence
- GDPR legal basis
- Legal obligation, Article 6(1)(c)
| Purpose | Data | GDPR legal basis |
|---|---|---|
| Create and run your account, deliver evaluations, plans and prompts you request | Account, idea content, generated output, credit ledger | Performance of a contract, Article 6(1)(b) |
| Process purchases and manage credits | Payment metadata, credit ledger | Performance of a contract, Article 6(1)(b) |
| Send transactional email such as sign-in, receipts and service notices | Account data, email delivery records | Performance of a contract, Article 6(1)(b) |
| Keep the service secure, prevent abuse and fraud, debug errors, and improve reliability and quality | Device, session, security, error and activity data | Legitimate interests, Article 6(1)(f) |
| Understand aggregate product usage to improve features | Usage and activity data | Legitimate interests, Article 6(1)(f) |
| Store the optional referral cookie, and send marketing email where we use it | Referral attribution, contact data | Consent, Article 6(1)(a), withdrawable at any time |
| Meet accounting, tax, bookkeeping and other legal duties, and respond to lawful requests | Payment and payout records, correspondence | Legal obligation, Article 6(1)(c) |
Where we rely on legitimate interests, we have considered your interests and rights, and you can object as described under your rights below.
06
AI processing
To generate the features you request, Skoora sends your idea content and the relevant profile preferences to Google Gemini models. The generated output is returned to your account.
- Output is automated assistance for your own judgement. It does not produce decisions about you that have legal effects or similarly significant effects on you.
- Telmate AI ApS does not use identifiable customer idea content to train its own models.
- How model providers handle data passing through their services is governed by our contracts with them and the settings available to us. Those contracts and settings can change, and we cannot make an absolute or permanent promise on a provider's behalf. Where a change is material to your data, we will update this policy.
07
Who we share data with
We do not sell personal data. We share it only with providers and parties that need it to deliver the service:
- Google, for Google sign-in and Google Gemini models.
- Supabase, for database storage and authentication.
- Resend, for transactional email delivery.
- Stripe, for payment processing.
- Cloud hosting and error-monitoring providers, so the application can run and faults can be diagnosed.
- Professional advisers, auditors, or public authorities and courts, where this is necessary or legally required.
Most of these providers act as our processors under a data processing agreement. Some, such as a payment provider handling its own compliance duties, act as independent controllers for parts of the processing. Each provider publishes its own privacy notice, which we recommend reading if you want the detail of their practices.
08
International transfers
Some providers process data outside the EU and EEA, in particular in the United States.
Where that happens, we rely on an appropriate safeguard: an adequacy decision of the European Commission, certification under the EU-US Data Privacy Framework where the provider is certified, or the European Commission's Standard Contractual Clauses combined with additional measures where needed. You can ask us which mechanism applies to a specific provider.
09
How long we keep data
We keep personal data only as long as we need it for the purpose it was collected for, or as long as law requires. In practice:
- Data
- Presence information showing an active session
- Period
- About 2 hours
- Data
- Activity and tool click analytics
- Period
- Up to 12 months, then deleted or aggregated so it no longer identifies you
- Data
- Email delivery records
- Period
- Up to 24 months
- Data
- Support correspondence
- Period
- Up to 3 years
- Data
- Account, idea content and generated output
- Period
- While your account is active. After a verified deletion request, normally erased or anonymised within 30 days, unless we must preserve specific records
- Data
- Payment, bookkeeping and affiliate payout records
- Period
- The statutory bookkeeping period, generally 5 years after the end of the relevant financial year
- Data
- Backups
- Period
- Expire on our providers' standard rotation schedules, so deleted data can persist briefly in backup copies
| Data | Period |
|---|---|
| Presence information showing an active session | About 2 hours |
| Activity and tool click analytics | Up to 12 months, then deleted or aggregated so it no longer identifies you |
| Email delivery records | Up to 24 months |
| Support correspondence | Up to 3 years |
| Account, idea content and generated output | While your account is active. After a verified deletion request, normally erased or anonymised within 30 days, unless we must preserve specific records |
| Payment, bookkeeping and affiliate payout records | The statutory bookkeeping period, generally 5 years after the end of the relevant financial year |
| Backups | Expire on our providers' standard rotation schedules, so deleted data can persist briefly in backup copies |
10
How we protect data
We use encryption in transit, access controls and least-privilege administration, authentication through established providers, logging and error monitoring, and providers that maintain their own security programmes.
Your idea content is not published and is not shared as a dataset. It is accessible to your account, and to the limited set of authorised personnel and processors who need access to operate, secure and support the service. No system is perfectly secure, so we do not promise that a breach can never happen. If a breach affects your rights, we will notify you and the relevant authority as required by law.
11
Your choices and your GDPR rights
Subject to the conditions in the GDPR, you have the right to:
- access the personal data we hold about you,
- have inaccurate data corrected,
- have data erased,
- restrict processing in certain situations,
- object to processing based on our legitimate interests, including profiling,
- receive your data in a portable format,
- withdraw consent at any time, without affecting processing already carried out,
- lodge a complaint with the data protection supervisory authority in your country of residence.
Email support@telmate.ai to exercise a right. We may need to verify your identity before we act, and some rights are subject to statutory exceptions, for example where we must keep accounting records. We answer within one month, and tell you if we need longer.
12
Children
Skoora is for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, email us at support@telmate.ai and we will delete it.
14
No sale of data, no ad profiling
We do not sell or rent personal data. We do not share your ideas or evaluations as a dataset, and we do not use your data to build advertising or interest profiles or to serve targeted ads.
15
Changes and contact
We update this policy when our processing, providers or legal duties change. The date at the top of this page shows the current version. Material changes will be communicated by email or in the product before they take effect.
Telmate AI ApS, CVR 46171578. Privacy contact by email: support@telmate.ai.
Contact us about privacy
Email us and we will respond within one month.
Telmate AI ApSsupport@telmate.ai