Skyzer
Security + privacy

Built like an operator would want.

Skyzer holds your store credentials, your customer data, and your revenue signals. We treat all three like they're irreplaceable, because they are.

Credentials encrypted at rest

Every API key, OAuth 2.0 refresh token, and password we hold is encrypted with AES-256-GCM using a key that never leaves the server. Database dumps are encrypted in transit and at rest on backup storage. Sessions are signed by Auth.js with a rotating server-only secret.

Hosting in Canada

The app, MySQL 8, and the worker queue run on a hardened OVH VPS in Beauharnois, Quebec. All traffic is HTTPS-only with automatic TLS renewal. Canadian hosting keeps us under PIPEDA and gives Canadian customers data residency by default.

Least-privilege API access

WooCommerce gets a tenant-specific REST key with the smallest viable scope. Klaviyo runs on a private API key with read access only, no broadcast or list-manipulation rights. GA4 and Merchant Center use scoped OAuth 2.0 tokens you can revoke from your Google account at any time.

AI sees aggregates, not PII

The brief writer receives a deterministic Findings JSON (aggregated counts, IDs, masked summaries). Raw customer emails, phone numbers, card data, and product images never enter an AI prompt. Every LLM call is grounded and validated against Findings before it reaches your inbox.

No model training on your data

We use Gemini and OpenAI APIs with zero-retention data settings. Your data is not used to train any model and is not shared with other customers. Every workspace is isolated at the query level, cross-tenant reads are structurally impossible.

Right to delete

Owners can request workspace deletion at any time from the app or via our contact page. We purge all primary data within 24 hours, backups age out within 7 days, and we send a written confirmation once deletion is complete.

The data we collect

We only pull the data needed to generate your morning brief. Concretely, that's:

  • From WooCommerce: orders + line items, customers, products + stock, refunds, order status changes. Up to 24 months of history.
  • From Klaviyo: campaign metadata + performance, flow definitions + performance, aggregate profile counts, segment definitions + counts, signup forms, subscriber growth events.
  • From you: the email and password you use to sign in, your workspace name + timezone, your role + memberships.

The data we don't collect

  • No credit card numbers. Card processing (when it lands) goes through Stripe, we never see card data.
  • No raw customer PII in the AI. The brief writer sees masked aggregates, not individual emails or addresses.
  • No browsing analytics. We don't run third-party analytics on the app surface. The marketing site uses minimal Google Tag Manager.

Data retention

While your workspace is active, your data is retained for as long as the workspace exists. AI prompt + completion logs are kept for 180 days for debugging, then deleted automatically.

After workspace deletion, all primary data is removed within 24 hours. Backups age out within 7 days. We send a written confirmation once the deletion is complete.

Subprocessors

Skyzer relies on a small number of subprocessors, each with a specific purpose:

  • OVH (Canada), infrastructure hosting.
  • Google (Gemini API), AI inference. Data not used for training.
  • OpenAI (API), AI inference for the insight detail page. Data not used for training.
  • Stripe (when billing ships), payment processing.

Reporting a security issue

If you believe you've found a security vulnerability in Skyzer, please reach out via our contact page and start the subject with "Security issue". We acknowledge within 24 hours and aim to triage within 3 business days. We don't yet run a paid bug bounty, but we credit responsible disclosure publicly with your permission.

For everything else, read the security FAQ.