Legal · immutable version

Managed content disclosure

What managed processing involves and how you control it.

Version
2026-09-13-1
Effective from (UTC)
2026-09-13T09:09:43Z
Operator
Operantix Systems Private Limited

Versioned document. This is the complete 2026-09-13-1 version. Its body will not change in place. Any later revision will have a new version and permanent URL. The permanent URL for this version is https://skyflo.ai/legal/managed-content/2026-09-13-1.

1. Your choice

Skyflo is operated by Operantix Systems Private Limited. Managed inference sends content from your Mac through our model gateway to OpenAI, the model provider we engage and pay. Read this disclosure before choosing whether to enable it.

Buying a paid plan does not by itself enable managed content. You must accept the current disclosure and separately turn managed content on in the account console. You can leave it off and continue local, bring-your-own-key, or supported subscription-backed work. Those other remote-model modes remain subject to your provider's terms and settings.

Your managed-content choice is recorded against a particular disclosure version. If we activate a replacement disclosure, managed requests stop until you accept it and enable managed content again. Publishing an inactive draft does not change your choice.

2. Content that can leave your Mac

A managed request can include:

  • Your prompts and Skyflo's instructions to the agent.
  • Earlier mission messages, model responses, tool calls and results, and encrypted reasoning needed to continue the conversation.
  • Code, file contents, diffs, repository paths, terminal output, logs, and information returned by connected systems.
  • Images or screenshots included in the request, and the descriptions and schemas of available tools.

Generated responses return through our gateway to your Mac. Earlier context can be sent again on later turns. Do not assume that content remains on your Mac because a tool executed there.

Skyflo masks recognised secrets in supported text fields, including prompts, instructions, tool context, and replayed messages, before token counting and managed transmission. It refuses unsupported or unsafe request forms. These controls do not detect every secret or personal detail, and do not inspect text inside images or decrypt prior model reasoning. Do not submit information you are not authorised to send. Hashing the separate identifiers described below does not anonymise the request content itself.

3. Purposes and token counting

We process managed content to provide the model work you request. Processing also includes the security, abuse-prevention, and legal-compliance activities necessary to operate these services. We do not sell managed content, use it for advertising, or use it to train or fine-tune general-purpose models.

Before a mission request is admitted, we send its content to OpenAI to count input tokens. If it is admitted, we send the applicable content again for inference. Content therefore reaches the provider during counting even if the request is subsequently refused. Further counts can be needed when routing considers another eligible model or a quote must be refreshed. Two transmissions are a common sequence, not an absolute maximum.

Token counting does not generate a model answer. Skyflo bears the cost of token-count control traffic; it is not an additional charge or deduction from your managed allowance.

4. Optional managed titles

Managed title generation is not available in the initial paid release. Mission titles are generated locally. Enabling managed content does not enable a separate title-processing feature. Any later managed-title feature will require its own available control and applicable disclosure before it sends content.

5. Provider processing and retention

OpenAI processes managed content for us. Where we process an organisation's personal data on its behalf, OpenAI is a downstream processor under the applicable terms. Its published Data Processing Addendum addresses processing instructions, confidentiality, rights-request assistance and international transfers; we remain responsible for the protections required for our own processing. OpenAI Data Processing Addendum. Our respective responsibilities and any applicable data-processing agreement continue to apply; this disclosure does not replace them.

We disable retrievable response storage for managed inference. This prevents us from using a stored OpenAI conversation to continue your mission. It does not disable OpenAI's separate retention for security or caching. Your Mac keeps the mission history that Skyflo uses for continuation.

OpenAI's published API data controls describe abuse-monitoring retention of up to 30 days by default, with longer retention where required by law or reasonably necessary to protect its services or others from harm. Such records can include content and can be reviewed by authorised personnel. Submitted images are scanned for child sexual abuse material; flagged images may be retained for manual review, including under stricter provider retention controls. Skyflo does not claim Zero Data Retention or exclusion from human review. OpenAI API data controls.

Prompt caching can retain representations of request content on provider infrastructure. OpenAI describes a 30-minute minimum cache lifetime for GPT-5.6 and later models, refreshed by reuse, with cache state retained for at most 24 hours. Earlier supported models can also use extended caching for up to 24 hours. These are provider-published limits, not a promise of immediate deletion. Cache-routing identifiers are not a guarantee of physical isolation between Skyflo customers. OpenAI prompt caching, API data controls.

OpenAI states that API content is not used for model training by default. Skyflo does not opt managed customer content into provider training or voluntary data sharing. OpenAI enterprise data commitments.

We send pseudonymous identifiers derived with Skyflo-held secret keys from internal organisation, conversation, repository-scope and request-revision information for safety and cache routing. We do not populate those identifier fields with your name or email address. They can still distinguish or link activity; names and other identifying details may separately appear in content you submit.

The managed gateway permits local function tools and rejects provider-hosted tools. It does not create provider file-storage objects, vector stores, or hosted conversation records for your mission. File contents and images can nevertheless be included directly in a request, as described in section 2. A locally executed tool can contact an external service you have connected; that service's processing is separate from OpenAI's model processing.

6. Skyflo's records and international processing

Our gateway, hosted on Render, handles request and response content transiently to relay it. The managed path does not persist that content in our account database, operational logs, or diagnostic reports. This statement concerns managed transmission; it does not cover material you separately choose to send to support.

We retain operational metadata to authorise requests, meter usage, reconcile costs, prevent abuse, and resolve billing questions: account, device, mission and attempt references; model and policy versions; content digests; token counts; reserved and settled usage; provider request references; timestamps; delivery outcomes; and security events. These records are associated with your account and are not anonymous. Digests support integrity comparisons and do not contain a readable copy of the content.

The Privacy Notice explains retention criteria and exceptions for operational, billing, consent, security and rights-request records. Withdrawing managed consent does not delete records needed for those purposes. Account deletion removes or anonymises ordinary account records within 30 days, subject to its stated legal exceptions, backup rotation of at most 35 days, and specified security and rights-evidence retention of at most 365 days. Billing evidence may require longer retention under applicable law. Privacy Notice.

Managed processing is not restricted to India or to your country. Our gateway is hosted in the United States, and OpenAI and its authorised service providers may process data internationally. Ask contact@skyflo.ai for information about the safeguards applicable to your data and copies of relevant transfer terms, subject to appropriate protection of confidential information. We must have a lawful basis and applicable transfer safeguards before processing restricted transfers; your managed-content switch does not replace them.

7. Your authority and sensitive information

Only submit content you have the right to disclose to Operantix and OpenAI. For employer, client, or third-party data, obtain the necessary authority and ensure required notices, lawful bases, and contractual protections are in place. Your own choice does not provide consent on behalf of every person whose data appears in a repository.

Do not send passwords, payment-card data, protected health information, or other regulated or highly sensitive information through managed inference. If an applicable data-processing agreement or transfer arrangement is needed for your use, put it in place before sending the affected personal data. Using your own provider key is not a substitute for permission to disclose content to that provider.

8. Turning it off and exercising rights

You can turn managed content off in the account console. New managed requests, including token counts, are then refused. Work already sent may have been processed; turning the feature off does not recall it or guarantee immediate provider deletion.

Turning managed content off does not cancel a paid subscription or stop renewal. To stop future subscription charges, cancel in Billing. Refund rights are explained in the Refund Policy and are unaffected by whether you exercise a privacy right.

For access, correction, deletion, or other privacy requests, contact us below. We can address our metadata and request appropriate assistance from OpenAI. The absence of a stored Skyflo conversation does not remove our obligation to respond to a valid rights request or coordinate with our processor where required.

9. Contact

Operantix Systems Private Limited, trading as Skyflo. CIN: U62010PN2026PTC252795.

Office No. 01, 1st Floor, Future One, S. No. 245/5/1, D.P. Road, Aundh, Pune, Maharashtra 411007, India.

Privacy and managed-content questions: contact@skyflo.ai. Grievance Officer: Karan Jagtiani, reachable at that email and postal address.

Customer care and grievance telephone: +91 7020882073.

We acknowledge consumer complaints within 48 hours and redress them within one calendar month. Privacy rights requests are handled within the period required by applicable law, with any permitted extension explained. These channels do not limit your right to contact a competent regulator or court.