Built like an operator would want.
Skyzer holds your store credentials and your data. We treat both like they're irreplaceable - because they are.
Credentials encrypted at rest
Every API key, OAuth token, and password we hold is encrypted with AES-256-GCM using a key that never leaves the server. Our database dumps are encrypted in transit and at rest on backup storage.
Hosting in Canada
MySQL 8 and the app run on a hardened OVH VPS in Beauharnois, Quebec. We chose Canadian hosting deliberately - it keeps us under PIPEDA and gives Canadian customers data residency.
Least-privilege API access
WooCommerce gets a tenant-specific REST key with the smallest viable scope. Klaviyo runs on a private API key with read access only - no broadcast or list-manipulation rights.
AI sees aggregates, not PII
The brief writer receives a deterministic Findings JSON - aggregated counts, IDs, masked summaries. Raw customer emails, phone numbers, card data, and product images never enter an AI prompt.
No model training on your data
We use Gemini and OpenAI APIs with data-retention turned off. Your data is not used to train any model and is not shared with other customers.
Right to delete
Owners can request workspace deletion at any time. We purge all data + backups within 7 days and send a written confirmation when the deletion completes.
The data we collect
We only pull the data needed to generate your morning brief. Concretely, that's:
- From WooCommerce: orders + line items, customers, products + stock, refunds, order status changes. Up to 24 months of history.
- From Klaviyo: campaign metadata + performance, flow definitions + performance, aggregate profile counts, segment definitions + counts, signup forms, subscriber growth events.
- From you: the email and password you use to sign in, your workspace name + timezone, your role + memberships.
The data we don't collect
- No credit card numbers. Card processing (when it lands) goes through Stripe - we never see card data.
- No raw customer PII in the AI. The brief writer sees masked aggregates, not individual emails or addresses.
- No browsing analytics. We don't run third-party analytics on the app surface. The marketing site uses minimal Google Tag Manager.
Data retention
While your workspace is active, your data is retained for as long as the workspace exists. AI prompt + completion logs are kept for 180 days for debugging, then deleted automatically.
After workspace deletion, all primary data is removed within 24 hours. Backups age out within 7 days. We send a written confirmation once the deletion is complete.
Subprocessors
Skyzer relies on a small number of subprocessors, each with a specific purpose:
- OVH (Canada) - infrastructure hosting.
- Google (Gemini API) - AI inference. Data not used for training.
- OpenAI (API) - AI inference for the insight detail page. Data not used for training.
- Stripe (when billing ships) - payment processing.
Reporting a security issue
If you believe you've found a security vulnerability in Skyzer, please email g@koryntis.com with the subject "Security issue". We acknowledge within 24 hours and aim to triage within 3 business days. We don't yet run a paid bug bounty, but we credit responsible disclosure publicly with your permission.
For everything else, read the security FAQ.