Legal · immutable version

Managed content disclosure

What managed processing involves and how you control it.

Version
2026-10-02-1
Effective from (UTC)
2026-10-02T00:00:00Z
Operator
Operantix Systems Private Limited

Versioned document. This is the complete 2026-10-02-1 version. Its body will not change in place. Any later revision will have a new version and permanent URL. The permanent URL for this version is https://skyflo.ai/legal/managed-content/2026-10-02-1.

1. Your choice

Skyflo is operated by Operantix Systems Private Limited. Managed inference sends content from your Mac, or from the machine running a mission in Skyflo Cloud, through our model gateway to a model provider we engage and pay. It can be OpenAI or Google (through its Gemini API). Z.ai is currently disabled for managed processing, including token counting. Which one processes a request depends on the model: each model belongs to exactly one provider, the model picker names the provider beside each model, and a model you pin goes only to its provider. When you leave routing to Skyflo, successive requests in one mission can go to different providers. Which models are offered can change, and a provider none of whose models is offered receives no managed request, including for token counting. Voice Mode uses OpenAI only, and in Skyflo Cloud a mission that uses Codex reaches OpenAI only. Read this disclosure before choosing whether to enable it.

Buying a paid plan does not by itself enable managed content. You must accept the current disclosure and separately turn managed content on in the account console. This one choice covers both typed missions and Voice Mode: there is no separate voice switch to accept, and no way to enable spoken work without enabling managed content. You can leave it off and continue local, bring-your-own-key, or supported subscription-backed work. Those other remote-model modes remain subject to your provider's terms and settings.

Your managed-content choice is recorded against the disclosure version you accepted and the providers it names. Each new version we publish is one of two kinds, and says which. A version that changes how a provider you accepted processes content, or what Skyflo does with that content, stops managed requests until you accept it and enable managed content again. A version that only adds a provider keeps your choice covering the providers your version named, and only requests to the added provider wait until you accept it. Publishing an inactive draft does not change your choice.

This version is of the first kind. OpenAI and Google remain the current providers. It keeps the statements about Z.ai’s earlier processing and records that Z.ai is now disabled for managed requests and token counting. It adds Skyflo Cloud as a place managed requests are sent from, corrects how Voice Mode context reaches OpenAI (section 5), and states what Z.ai’s terms do and do not commit it to (section 6). Managed requests wait until you accept it.

Accepting an earlier version of this disclosure no longer covers managed processing once this version is in effect. Until you accept this version, managed requests, new Voice Mode calls and managed work in Skyflo Cloud wait, and Skyflo asks you once to review it, where the paused work is on your Mac, in Voice Mode or when you choose Skyflo Cloud. You can also accept it in the account console. Local, bring-your-own-key and supported subscription-backed work continue, and your missions keep their work.

2. Content that can leave your Mac

A managed request can include:

  • Your prompts and Skyflo's instructions to the agent.
  • Earlier mission messages, model responses, tool calls and results, and encrypted reasoning needed to continue the conversation.
  • Code, file contents, diffs, repository paths, terminal output, logs, and information returned by connected systems.
  • Images or screenshots included in the request, and the descriptions and schemas of available tools.

When you use Voice Mode, a managed session also includes your microphone audio and the transcript the provider derives from it. Section 5 describes that in full.

Generated responses return through our gateway to your Mac. For a mission in Skyflo Cloud, the same kinds of content are sent from the machine running the mission, and responses return to that machine; what Skyflo holds while a mission runs there is described in the Privacy Notice. If you let a mission you move to Skyflo Cloud continue its conversation, its earlier turns are sent to its provider from there as continuation context. Earlier context can be sent again on later turns. Do not assume that content remains on your Mac because a tool executed there.

Skyflo masks recognised secrets in supported text fields, including prompts, instructions, tool context, and replayed messages, before token counting and managed transmission. It refuses unsupported or unsafe request forms. These controls do not detect every secret or personal detail, and do not inspect text inside images or decrypt prior model reasoning. Do not submit information you are not authorised to send. Hashing the separate identifiers described below does not anonymise the request content itself.

3. Purposes and token counting

We process managed content to provide the model work you request. Processing also includes the security, abuse-prevention, and legal-compliance activities necessary to operate these services. We do not sell managed content, use it for advertising, or use it to train or fine-tune general-purpose models.

Before a mission request is admitted, we send its content to the provider of the model being considered to count input tokens: OpenAI and Google count with their own endpoints. Z.ai token counting is disabled along with its inference lane. If the request is admitted, we send the applicable content again to that same provider for inference. Content therefore reaches a provider during counting even if the request is subsequently refused, and when routing considers models from more than one provider, more than one provider can receive the content for counting before one of them runs the inference. Further counts can be needed when a quote must be refreshed. Two transmissions are a common sequence, not an absolute maximum.

Token counting does not generate a model answer. Skyflo bears the cost of token-count control traffic; it is not an additional charge or deduction from your managed allowance.

4. Optional managed titles

Managed title generation is not available in the initial paid release. Mission titles are generated locally. Enabling managed content does not enable a separate title-processing feature. Any later managed-title feature will require its own available control and applicable disclosure before it sends content.

5. Voice Mode

Voice Mode is a live spoken conversation with OpenAI's gpt-live-1 model, included on the Core, Pro and Max plans. It is managed processing, and everything in this disclosure applies to it. This section describes what is different about it.

What is sent, and where it goes

While a call is open, your microphone audio is streamed to OpenAI. OpenAI produces a running transcript of your speech from that audio and returns synthesised speech in reply. OpenAI receives and processes both the audio and the transcript, and may retain them under the provider retention described in section 6. Nothing in this section limits that.

What this section describes is Skyflo's own handling, which is narrower than you might expect.

The audio path is direct. Your Mac opens a media connection to OpenAI and the audio travels over it. Skyflo's model gateway creates the session with our provider key and returns only the connection answer; it is not in the media path, and neither is our account service or the local Skyflo service on your Mac. Operantix never receives your microphone audio, and stores neither the audio nor the transcript. What does pass through our gateway is the text described under Conversation context below, which it relays to OpenAI when a session opens and does not keep. We cannot produce a copy of the audio or the transcript, because we do not hold one.

Skyflo does not keep the transcript on your Mac either. It exists in the app while the call is open, so the conversation can work, and it is gone when the call ends. It is not written to your mission record.

What is recorded locally is the ordinary result of the work: a spoken instruction that Skyflo acts on is saved to that mission on your Mac as mission content, the same way a typed one is, along with whatever the mission produced. That local record is yours and stays on your Mac.

The gateway holds a separate control connection to OpenAI for the sole purpose of measuring how long the session ran. That connection carries duration, not content.

What starts and stops the microphone

The microphone is open only while a call is open, and macOS shows its own indicator throughout. Skyflo has no background listening, no wake word and no dictation feature. Closing the call, or ending it by speaking a farewell, releases the microphone. Muting stops audio from being sent for the duration of the mute; the session remains open and continues to be billed.

Each reconnection, and each change of the assistant's voice, opens a new session with the provider.

Conversation context

When a session opens, including on a reconnect or a voice change, your Mac may send a bounded record of the current mission's conversation so the assistant can continue where it left off rather than starting over. When the call is reconnecting or changing voice, it also sends up to 12 recent lines of the call's own transcript, each at most 1,000 characters. This text travels from your Mac through Skyflo's gateway to OpenAI; the gateway relays it and does not store it. It passes through the same secret-masking applied to typed managed requests, with the same stated limits. It is bounded in size and is not a transfer of your full mission history.

Skyflo may also send one short line describing what is currently open on screen, so that a spoken request about "this file" can be understood.

Work you ask for out loud

The voice model speaks and listens. It does not execute engineering work. A spoken request to change code, run a command or inspect a repository is handed to your ordinary mission harness and runs as a normal mission turn under that mission's approval settings. That turn is governed by the rest of this disclosure exactly as a typed one is, and it reaches whichever model and runtime the mission is configured to use, which may be a local or bring-your-own-key model rather than a managed one. A spoken instruction becomes ordinary mission content: it is saved with the mission, moves with it to Skyflo Cloud, and when it is sent to a mission already in Skyflo Cloud, the account service holds it like a typed instruction, for the period in the Privacy Notice.

Decisions can be answered out loud. A spoken answer is read as a decision only while a decision is actually waiting, only from a complete sentence, and it takes the narrowest option the decision offers unless you widen it explicitly. Voice cannot approve anything you could not approve by clicking, and it cannot decide on your behalf.

Transcription accuracy

Speech recognition is imperfect, and a transcriber given silence can produce text that nobody said. Skyflo discards input fragments its own microphone never carried, but we do not warrant that a transcript is an accurate record of what you said. Do not rely on a voice transcript as a record.

Provider processing and retention for voice

We set the provider's conversation storage to off for voice sessions, as we do for typed managed requests. This prevents a stored OpenAI conversation from being used to continue your work. It does not disable OpenAI's separate retention for abuse monitoring, security or caching, which is described in section 6 and applies to voice sessions as it does to other API traffic. Audio and transcripts can be within that retention.

We send the same pseudonymous safety identifier described in section 6. We do not send your name or email address as that identifier.

What Skyflo records about a voice session

We keep operational metadata for each session: account, device and session references, the chosen assistant voice, the start and end times, the reason the session ended, the seconds billed by the provider, and the resulting reservation and receipt. We do not keep the audio, the transcript, or what was said.

If you have turned on optional diagnostics, a finished conversation also reports a small set of numbers and fixed labels: how long the connection took, how many decisions were settled and how many were refused, how often it reconnected, how long the microphone was muted, and how the call ended. That report is rebuilt field by field from a fixed list, so no transcript, mission title or free text can travel in it. It is subject to the same diagnostics consent as everything else.

Cost and metering

A voice session is billed by the provider per second of session time and spends the same managed allowance as your typed managed work. The assistant's own thinking and any work it delegates are separate charges against that allowance. If the allowance runs out during a call, the call is closed at its authorised limit and settled rather than cut off without a record.

Other people in the room

Your microphone can capture voices other than your own. Only start a call where the people who may be heard are content to be, and obtain any consent that your jurisdiction or your employer requires before recording or transmitting another person's voice. Your own acceptance of this disclosure is not consent on their behalf.

Turning it off

Voice Mode is available only while managed content is enabled. Turning managed content off in the account console ends the ability to start a call, and a call already in progress stops. Your plan may also be a factor: Voice Mode is not part of the Free plan.

6. Provider processing and retention

OpenAI and Google can process managed content for us under the published terms named below. Z.ai is listed for historical processing and is currently disabled. Where that content includes personal data an organisation controls, we remain responsible for the protections the law requires of our own processing. For personal data we process on an organisation’s behalf, our Data Processing Addendum sets out those protections. It authorises OpenAI and Google as subprocessors for managed inference, and does not authorise Z.ai, for the reasons below. The DPA applies through acceptance of a Terms version that incorporates it. If your accepted Terms predate the DPA, accept the current Terms in the account console’s Privacy page before relying on the DPA for affected personal data. Accepting this disclosure alone does not accept a new Terms version.

Provider Models Processing entity Published terms we rely on
OpenAI GPT-5.6 Luna, Terra and Sol, GPT-6 Astra, and the gpt-live-1 voice model OpenAI, under its API terms Data Processing Addendum, API data controls, enterprise data commitments
Google Gemini 3.8 Flash Google, through the paid tier of the Gemini API, contracting under the Google Cloud terms entity for our billing account Gemini API Additional Terms of Service, Google's Data Processing Addendum for products where Google is a processor
Z.ai GLM-5.3 and GLM-5.3-Flash JINGSHENG HENGXING TECHNOLOGY PTE. LTD., Singapore Z.ai Terms of Use, Z.ai Privacy Policy and Data Processing Addendum for API Services

OpenAI. We disable retrievable response storage for managed inference. This prevents us from using a stored OpenAI conversation to continue your mission. It does not disable OpenAI's separate retention for security or caching. Your Mac, or the machine running a mission in Skyflo Cloud, keeps the mission history that Skyflo uses for continuation.

OpenAI's published API data controls describe abuse-monitoring retention of up to 30 days by default, with longer retention where required by law or reasonably necessary to protect its services or others from harm. Such records can include content and can be reviewed by authorised personnel. Submitted images are scanned for child sexual abuse material; flagged images may be retained for manual review, including under stricter provider retention controls. Skyflo does not claim Zero Data Retention or exclusion from human review. OpenAI API data controls.

Prompt caching can retain representations of request content on provider infrastructure. OpenAI describes a 30-minute minimum cache lifetime for GPT-5.6 and later models, refreshed by reuse, with cache state retained for at most 24 hours. Earlier supported models can also use extended caching for up to 24 hours. These are provider-published limits, not a promise of immediate deletion. Cache-routing identifiers are not a guarantee of physical isolation between Skyflo customers. OpenAI prompt caching, API data controls.

OpenAI states that API content is not used for model training by default. Skyflo does not opt managed customer content into provider training or voluntary data sharing. OpenAI enterprise data commitments.

Google. Gemini 3.8 Flash runs on the paid tier of the Gemini API. Each request is a single stateless call: Google keeps no conversation for us to continue from, and your Mac, or the machine running a mission in Skyflo Cloud, keeps the mission history. Google's published terms for paid services state that Google does not use prompts, including system instructions, cached content and files, or responses to improve its products; that it logs prompts and responses for a limited period of time solely for detecting and preventing violations of its Prohibited Use Policy, maintaining the safety and security of its services, and any required legal or regulatory disclosures, a period its abuse-monitoring documentation for the Gemini API states as 55 days; and that this data may be stored transiently or cached in any country in which Google or its agents maintain facilities. Google processes prompts and responses under its Data Processing Addendum for products where Google is a data processor. Gemini API Additional Terms of Service. Gemini applies caching to repeated request content on its own initiative, which can retain representations of that content briefly on Google's infrastructure. Skyflo does not send your name or email address to Google, and does not send Google the pseudonymous identifiers described below. We do not claim Zero Data Retention or exclusion from Google's abuse review.

Z.ai. GLM-5.3 and GLM-5.3-Flash previously ran on Z.ai's international API, operated by JINGSHENG HENGXING TECHNOLOGY PTE. LTD. of Singapore. Z.ai's Data Processing Addendum for API Services states that it does not store the content customers or their users provide or generate through the API, that this content is processed in real time to provide the service and is not saved on its servers, and that processing generally takes place in Singapore. Its Terms of Use state that content from customers using its API services is not used to develop or improve its services unless the customer explicitly agrees; Skyflo has not agreed. Z.ai Privacy Policy and Data Processing Addendum, Z.ai Terms of Use. Z.ai reports cached input for repeated request content, which means representations of recent requests can be retained briefly to serve them; Skyflo never replays the model's prior reasoning to Z.ai. Z.ai does not publish a separate abuse-monitoring retention period, so we make no claim about one. Earlier requests sent Z.ai the pseudonymous safety identifier described below. No new managed request is sent to it while disabled.

What Z.ai does not commit to. Z.ai’s published terms and Data Processing Addendum commit it to process API content only to provide its service and on our instructions, to keep reasonable security measures, and to tell us of requests it receives from the people whose data it processes. They do not commit Z.ai to tell us of a personal data breach, and they do not list its sub-processors or give us notice of new ones, so we cannot name them. We cannot see inside Z.ai’s systems and so cannot detect a breach there ourselves. We monitor our own gateway and our Z.ai account, and if Z.ai tells us of a breach affecting your data, or we learn of one in another way, we will tell you as the law requires. Skyflo excludes Z.ai from Auto and refuses pinned GLM requests and token counts before sending content. Auto uses remaining admitted OpenAI and Google models. Enabling managed content does not waive these requirements. Separately, unless we record a clearance before then, Z.ai’s models leave Skyflo managed inference at 00:00 UTC on 9 November 2026, whether or not this restriction has been lifted. Using Z.ai with your own key is your own provider relationship and is not affected.

What is the same everywhere. No provider receives your name or email address as an identifier from Skyflo. No provider is given a Skyflo-hosted tool, file store or conversation record. Every provider can process content internationally as described in section 7. Skyflo's own ceilings on cost and volume apply to every provider; a request refused by one provider's capacity may be routed to another eligible model, which can be at a different provider.

We send pseudonymous identifiers derived with Skyflo-held secret keys from internal organisation, conversation, repository-scope and request-revision information for safety and cache routing. We do not populate those identifier fields with your name or email address. They can still distinguish or link activity; names and other identifying details may separately appear in content you submit.

The managed gateway permits local function tools and rejects provider-hosted tools. It does not create provider file-storage objects, vector stores, or hosted conversation records for your mission. File contents and images can nevertheless be included directly in a request, as described in section 2. A locally executed tool can contact an external service you have connected; that service's processing is separate from the provider's model processing.

7. Skyflo's records and international processing

Our gateway, hosted on Render, handles request and response content transiently to relay it. The managed path does not persist that content in our account database, operational logs, or diagnostic reports. This statement concerns managed transmission; it does not cover material you separately choose to send to support.

We retain operational metadata to authorise requests, meter usage, reconcile costs, prevent abuse, and resolve billing questions: account, device, mission and attempt references; model and policy versions; content digests; token counts; reserved and settled usage; provider request references; timestamps; delivery outcomes; and security events. For voice sessions this also includes session references, the chosen assistant voice, start and end times, the end reason and the seconds billed, as described in section 5. These records are associated with your account and are not anonymous. Digests support integrity comparisons and do not contain a readable copy of the content.

How long Skyflo keeps each of these records, including after account deletion and in backups, and what each provider says it keeps, is set out in section 10 of the Privacy Notice. Withdrawing managed consent does not delete records needed for those purposes.

Our operational records also name which provider and model processed each request, so that a rights request or a billing question can be traced to the right processor.

Managed processing is not restricted to India or to your country. Our gateway is hosted in the United States. OpenAI and its authorised service providers may process data internationally; Google may store or cache data transiently in any country in which it or its agents maintain facilities; Z.ai generally processes in Singapore. Each provider's authorised service providers may process data internationally. Ask contact@skyflo.ai for information about the safeguards applicable to your data and copies of relevant transfer terms, subject to appropriate protection of confidential information. We must have a lawful basis and applicable transfer safeguards before processing restricted transfers; your managed-content switch does not replace them.

8. Your authority and sensitive information

Only submit content you have the right to disclose to Operantix and to the provider that will process it, which for a request you leave to Skyflo's routing can be any provider in section 6 whose models are offered at the time. For employer, client, or third-party data, obtain the necessary authority and ensure required notices, lawful bases, and contractual protections are in place. Your own choice does not provide consent on behalf of every person whose data appears in a repository.

Do not send passwords, payment-card data, protected health information, or other regulated or highly sensitive information through managed inference, including by speaking it during a voice session. Where your organisation needs processor terms, our Data Processing Addendum provides them, and Z.ai is disabled until the required commitments are in place. If your use needs a processor commitment or transfer arrangement that is not in place, do not send the affected personal data through managed inference. Using your own provider key is not a substitute for permission to disclose content to that provider.

9. Turning it off and exercising rights

You can turn managed content off in the account console. New managed requests, including token counts and new voice sessions, are then refused, and a voice session in progress stops. Work already sent may have been processed; turning the feature off does not recall it or guarantee immediate provider deletion. We cannot delete voice audio or a voice transcript from our own systems, because we do not store them.

Turning managed content off does not cancel a paid subscription or stop renewal. To stop future subscription charges, cancel in Billing. Refund rights are explained in the Refund Policy and are unaffected by whether you exercise a privacy right.

For access, correction, deletion, or other privacy requests, contact us below. We can address our metadata, tell you which provider processed a given request, and request appropriate assistance from that provider. The absence of a stored Skyflo conversation does not remove our obligation to respond to a valid rights request or coordinate with our processor where required.

10. Contact

Operantix Systems Private Limited, trading as Skyflo. CIN: U62010PN2026PTC252795.

Office No. 01, 1st Floor, Future One, S. No. 245/5/1, D.P. Road, Aundh, Pune, Maharashtra 411007, India.

Privacy and managed-content questions: contact@skyflo.ai. Grievance Officer: Karan Jagtiani, reachable at that email and postal address.

Customer care and grievance telephone: +91 7020882073.

We acknowledge consumer complaints within 48 hours and redress them within one calendar month. Privacy rights requests are handled within the period required by applicable law, with any permitted extension explained. These channels do not limit your right to contact a competent regulator or court.