Legal · immutable version

Privacy Notice

How Skyflo collects, uses, stores, and shares personal data across the skyflo.ai website, the Skyflo account console, and Skyflo Desktop. It covers what happens to mission content in each of the three ways a model can be run, and the data we receive when you sign in with Google.

Version
2026-09-13-1
Effective from (UTC)
2026-09-13T09:09:43Z
Operator
Operantix Systems Private Limited

Versioned document. This is the complete 2026-09-13-1 version. Its body will not change in place. Any later revision will have a new version and permanent URL. The permanent URL for this version is https://skyflo.ai/legal/privacy/2026-09-13-1.

1. Who we are and what this covers

Skyflo is operated by Operantix Systems Private Limited (CIN U62010PN2026PTC252795), a company incorporated in India with its registered office at Office No. 01, 1st Floor, Future One, S. No. 245/5/1, D.P. Road, Aundh, Pune, Maharashtra 411007, India (“Skyflo”, “we”, or “us”). Operantix is the controller of personal data used to operate Skyflo accounts, billing, security, support, and its own service records. Where an organisation instructs us to process personal data in managed mission content on its behalf, we act as its processor under the applicable data-processing agreement. The organisation remains responsible for its lawful basis and instructions. OpenAI processes managed content for us and is a downstream processor where we act for that organisation.

This policy covers three surfaces, and they behave differently, so the difference is stated throughout rather than averaged into one paragraph:

  • skyflo.ai, the public website. No sign-in. Analytics run here.
  • app.skyflo.ai, the account console. Sign-in required. No analytics run here.
  • Skyflo Desktop, the macOS application where agents actually run.

Your use of the Services is also governed by the Terms and Desktop Licence.

2. In short

  • Agents run on your linked Mac. Missions, repository content, code, and files are held on that machine, and stay there unless you choose a mode that sends a request to a model.
  • There are three such modes, and section 4 is the whole point of this policy: local sends nothing, bring your own key sends your request to a provider you have your own account with, and managed inference sends it through Skyflo to a provider we pay.
  • Managed inference is off until you read the managed content disclosure and switch it on. While it is on, the content of a managed request reaches Skyflo and our model provider. We keep operational records about those requests and no copy of their content.
  • The account console holds account records: who you are, which organisation you belong to, which devices you have linked, which plan you are on, what you have used, and which documents you accepted.
  • Signing in with Google gives us your basic Google profile and email address, and nothing else. We do not request access to Gmail, Drive, Calendar, Contacts, or any other Google service.
  • We do not sell personal data, we do not use it for advertising, and we do not use your content or Google user data to train AI models.

3. What we collect

3.1 The website, skyflo.ai

  • Analytics. We use Google Analytics 4 on this host. It sets cookies and collects a device identifier, your IP address, the pages you view, the referring page, your approximate location derived from IP, and browser and operating-system details. Google Analytics does not run on the account console.
  • Download attribution. When a link identifies a source, medium, campaign, or creator, we store a random visitor identifier and the first and most recent valid attribution touch, including the time, landing URL, and referring page where available. Query details unrelated to attribution are removed. We record visits to the landing and download pages and when an installer link is selected. A signed first-party cookie lets this attribution survive redirects and a browser restart.
  • Historical beta and waiting-list submissions. Before public Desktop distribution, you may have given us an email address through a beta access or waiting-list form. We stored that address, the page the submission came from, and, on the former high-intent form only, the use case and cloud provider selected. Those forms and their Skyflo API routes are no longer available. The historical rows will be deleted no later than 5 October 2026. You can ask us to delete yours sooner. Section 10 explains this deadline.
  • Demo bookings. The demo page embeds Calendly. Whatever you enter into that scheduler, typically your name, email address, and any notes, is collected by Calendly and shared with us so we can hold the meeting.
  • Server and delivery logs. Our hosting provider records request metadata such as IP address, user agent, requested path, and timestamp for operational and security purposes.

3.2 The account console, app.skyflo.ai

Signing in is handled by Clerk, our authentication provider. You may sign in with Google, with GitHub, or with a one-time code sent to your email address. Skyflo does not offer password sign-in and therefore never holds a password for you.

Depending on the method you choose, Clerk receives and holds your account identifier at that provider, your name, your email address and whether the provider reports it as verified, and your profile picture URL. Section 6 covers Google specifically.

In our own account records we store:

  • your Skyflo user identifier and email address;
  • your organisation identifier, its name, and your role in it;
  • one record per linked Mac: an identifier, the device name it reports, the platform, when it was linked, when it was revoked if it has been, and whether the device reported that its signing key is held in hardware;
  • your plan and entitlement snapshot, and the managed capacity used and remaining in the current window;
  • your acceptance of each published policy document, recorded as the document version, its SHA-256 digest, and the time you accepted it;
  • your managed-content choice and the settings derived from it;
  • the immutable first acquisition touch and the most recent valid touch associated with your account, including source, medium, campaign, creator identifier, timestamps, landing URL, and referring page where available; and
  • coarse product milestones such as account creation, Desktop first launch and activation, first mission creation, plan approval, first agent execution, an independent review report being attached, and paid conversion. These records contain identifiers and timestamps, not prompts, code, files, terminal output, or review contents.

3.3 Payments

Paid subscriptions are sold through Dodo Payments as merchant of record. Card numbers and other payment credentials are entered on Dodo’s hosted checkout and are never sent to or stored by Skyflo. We receive the subscription state we need to run your account: plan, billing interval, status, refund and dispute state, and provider reference identifiers.

3.4 Skyflo Desktop

Skyflo Desktop runs on your Mac and does the work there. Missions, plans, prompts, repository content, code, files, terminal output, and agent results are held on that machine. What leaves it depends entirely on which of the three modes in section 4 a request runs under.

When an account is connected, Desktop sends the account service coarse lifecycle milestones needed to understand whether the download journey worked. These include first launch, activation, first mission creation, plan approval, first agent execution, and an independent review report being attached. Each request carries only the event name, a random event identifier, and the time it occurred. It does not carry mission content or a mission identifier.

Optional product usage. Product usage is optional and off by default. If you enable it in Desktop, Skyflo receives active days, mission starts and final outcomes, the app version and Mac architecture, random app/event identifiers, and a count of skipped events. It receives no account details, prompts, code, files, terminal output or browsing history. This choice is independent of crash diagnostics and works without sign-in. Live usage records are kept for up to 90 days, and unsent events expire after 30 days. Switching sharing off clears unsent events and requests deletion of received records. If your Mac is offline, deletion is retried when it can connect. A one-way deletion marker is kept indefinitely to prevent restored copies from resending; backup copies expire within 35 days. Network infrastructure processes addresses for delivery and abuse protection. Because these records are not linked to your account, turn sharing off on each Mac to remove them; account deletion cannot identify them. Local and BYOK work is unaffected by this choice or an analytics outage.

4. Where your work goes, in each of the three modes

This is the part of Skyflo that is most often assumed rather than read, so it is stated as a table and then explained.

ModeContent leaves your Mac?Reaches Skyflo?Who is your counterparty for the model
Local executionNoNoNone; no model is called remotely
Bring your own keyYes, to the provider you configuredNoThat provider, under your own account with them
Skyflo managed inferenceYesYesSkyflo, which selects and pays the provider

4.1 Local execution

The mission record, the repositories agents touch, the files they read and write, and the output they produce are held on your machine. Where a mission does not call a remote model, no mission content leaves your Mac because of Skyflo. The account console manages your account, not your work.

4.2 Bring your own key

When you supply your own API key for a model provider, Skyflo Desktop calls that provider directly from your Mac. Your key is stored in your operating system’s keychain on that machine and is not transmitted to Skyflo’s servers. The content of that request goes from your Mac to that provider under that provider’s terms, privacy policy, and data-retention settings. Skyflo is not in the path and does not see it.

These providers are deliberately not listed as our processors in section 9. The transmission is made by your machine at your instruction, using an account you hold, and the provider is your counterparty rather than ours.

4.3 Skyflo managed inference

Managed inference is the mode where Skyflo is in the path. It is off by default, it requires you to read the managed content disclosure and record an affirmative choice in the console, and it can be switched off again at any time. Section 5 sets out exactly what is transmitted and what we keep.

Switching it off takes effect on the next request. Anything already sent has already been sent, and section 10 covers how long it and its records persist.

This table describes the model-request path. Local tools, browsers and connected systems can also send content to services you authorise, separately from model processing. Their own terms and data practices apply.

5. Managed inference in detail

5.1 What is transmitted

When a managed request runs, the request your agent has assembled travels from your Mac to Skyflo’s model gateway and is sent by us to our model provider. Depending on what the mission is doing, that request may contain:

  • Your prompts and the agent’s instructions, including the system and harness instructions Skyflo supplies;
  • Continuation context, which is the earlier turns of the same mission replayed in full: previous messages, the tool calls the model made, the results those tools returned, and the model’s own encrypted reasoning from earlier turns;
  • Code and repository content that a tool read on your machine and returned into the conversation, including file contents, diffs, paths, and command output;
  • File and tool context more generally, including terminal output, logs, and the output of connected systems, wherever a tool has placed it in the conversation;
  • The schemas of the local tools the agent may call, so the model knows what is available; and
  • The model’s generated response, which returns along the same path.
  • Images or screenshots included in a managed request, which can contain personal or confidential information as well as visible text.

Skyflo masks recognised secrets in supported text fields, including prompts, instructions, tool context, and replayed messages, before token counting and managed transmission. It refuses unsupported or unsafe request forms. These controls do not detect every secret or personal detail, and do not inspect text inside images or decrypt prior model reasoning. Do not submit content you are not authorised to send. The pseudonymous identifiers described below do not anonymise the content of your request.

5.2 Counting and repeated transmission

Before a managed mission request is admitted, its content is sent through our gateway to OpenAI for input-token counting. An admitted request sends the applicable content again for inference. Counting itself sends content even if inference is later refused. Routing to another eligible model or refreshing a quote can require further counts, so two transmissions are not a maximum. Token-count traffic is paid by Skyflo and does not reduce customer managed allowance.

5.3 What we keep about a managed request

We keep the operational records listed below to authorise, meter, reconcile, secure, and evidence managed requests. Our managed path handles content transiently and does not persist prompts, code, file content, tool output, reasoning, or responses in our account database, operational logs, or diagnostics. This does not cover content you separately send to support. The retained metadata is associated with your account and is not anonymous.

  • your organisation, user, and device identifiers;
  • identifiers for the mission, thread, turn, routing decision, attempt, and reservation the request belonged to;
  • which model reference and provider model ran it, and which price and policy revisions applied;
  • Content digests used to compare the integrity of the request body, input, and tool schemas. These are not readable copies of content and should not be treated as proof of anonymisation.
  • the size of the request in bytes, the token counts the provider reported for input, cached input, cache writes, output, and reasoning, and the number of bytes of output delivered;
  • the capacity reserved and the cost settled, and the signed receipt digest that evidences it;
  • the provider’s response and request identifiers, and the service tier it reported;
  • timing and delivery state: when the request was reserved, claimed, dispatched, and resolved, whether it completed, failed, was cancelled, or ended indeterminate, and a short machine-readable reason where it did not complete;
  • rate-limit figures the provider reported to us, which we use to decide what we can admit next; and
  • security and error information, such as refused authorisations and failed integrity checks.

5.4 Our model provider, and what we can and cannot tell you about it

OpenAI is the provider we engage and pay for managed inference. The Managed content disclosure describes its processing, our disabled retrievable response storage, provider safety and cache retention, pseudonymous routing identifiers, and restrictions on provider-hosted tools and stored objects. Those details also apply to the managed processing described in this Notice. Please read that disclosure before enabling the feature; the console presents the precise version and records your affirmative choice.

Our choice to disable retrievable response storage does not mean that OpenAI retains nothing. We do not claim Zero Data Retention, anonymous request content, physical isolation of each customer's cache, or a guarantee that content never leaves your country. A replacement disclosure requires a new affirmative choice before managed processing continues. Using OpenAI with your own key remains your separate provider relationship.

5.5 Mission titles

Managed title generation is not available in the initial paid release. Mission titles are generated locally. Enabling managed content does not enable a separate title-processing feature. Any later managed-title feature will require its own available control and applicable disclosure before it sends content.

6. Google user data

This section describes exactly what Skyflo does with data received from Google when you choose Sign in with Google. Google Sign-In is optional; GitHub and a one-time email code are the alternatives, and the account works identically either way.

6.1 What we access

Skyflo requests only the basic OpenID Connect scopes: openid, email, and profile. Through them we receive your Google account identifier, your email address and whether Google reports it as verified, your name, and your profile picture URL.

We do not request, and therefore cannot access, any Google API scope beyond those. Skyflo does not read, write, or store your Gmail messages, Google Drive files, Google Calendar events, Google Contacts, Google Photos, or any other Google service data.

6.2 How we use it

Google user data is used only to create and authenticate your Skyflo account, to identify you inside the account console, to address service and transactional email to you, to attribute your organisation membership and device approvals, and to detect and prevent abuse of the sign-in flow. It is not used for advertising, for profiling, or for building a marketing audience.

Skyflo does not use Google user data to develop, improve, or train generalised AI or machine-learning models. Google user data is not sent to our model provider: the identifiers we transmit in managed mode are keyed hashes, as described in section 5.4.

6.3 How we store it

Your Google identity record is held by Clerk, our authentication processor, in its systems. Our own account database stores your Skyflo user identifier and your email address, and links them to your organisation, devices, plan, and acceptances. We hold this for as long as your account exists, and then as described in section 10.

6.4 How we share it

We do not sell Google user data, and we do not transfer it to third parties for advertising or for any purpose unrelated to running Skyflo. It is disclosed only to the processors listed in section 9 that are necessary to operate the account, and only where the law requires disclosure or where you have directed us to share it.

Skyflo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6.5 How to withdraw it

You can disconnect Skyflo from your Google Account at any time at myaccount.google.com/permissions. Doing so stops future Google sign-ins; it does not by itself delete your Skyflo account. To have the account and its data deleted, write to contact (at) skyflo.ai as described in section 13.

6.6 A separate matter: Google Analytics

Google Analytics on the skyflo.ai website is unrelated to Google Sign-In. It measures website traffic, it runs only on the marketing host, and it involves no access to your Google Account. See sections 3.1 and 8.

7. Why we process it, and on what basis

PurposeData usedLawful basis (UK and EU GDPR)
Create and authenticate your accountIdentity data from Clerk, including Google or GitHub profile and emailPerformance of a contract
Run the account console: organisations, linked devices, plansAccount records in section 3.2Performance of a contract
Take payment and manage subscriptionsSubscription state from Dodo PaymentsPerformance of a contract
Deliver managed model work to an individual contracting with usNecessary managed request contentPerformance of that contract, subject to applicable data restrictions
Process an organisation’s managed content on its instructionsPersonal data in its requestProcessor instructions under the applicable processing agreement; the organisation determines the lawful basis
Meter managed usage, reserve and settle capacity, and prevent abuse of itThe operational records in section 5.3Performance of a contract and legitimate interests
Evidence that you accepted a published documentAcceptance records: version, digest, timestampLegal obligation and legitimate interests
Keep the service secure and prevent abuseLogs, device records, sign-in challengesLegitimate interests
Answer support requests and hold demosEmail address and what you write to usLegitimate interests and consent
Measure website trafficAnalytics data in section 3.1Consent, where consent is required
Attribute downloads, account creation, Desktop adoption, and paid conversion to an acquisition sourceDownload attribution and lifecycle milestones in sections 3.1 to 3.4Legitimate interests in understanding and improving acquisition, subject to applicable cookie-consent requirements
Retain historical beta and waiting-list submissions for the period stated in section 10Email address and form fields you previously submittedConsent
Enable managed inference on your accountYour recorded managed-content choiceConsent

Where we rely on consent you can withdraw it at any time, and withdrawing it does not affect processing that already happened. Withdrawing the managed-content choice stops future managed requests; it does not recall requests already sent.

The managed-content control is an additional authorisation to transmit content. It is not consent on behalf of every person mentioned in a mission, nor a substitute for the lawful basis or international-transfer safeguards required for that data.

8. Cookies and similar technologies

  • Strictly necessary. On app.skyflo.ai, Clerk sets session cookies. Without them you cannot stay signed in. Cloudflare Turnstile may also run during sign-in as a bot challenge.
  • First-party download attribution. On skyflo.ai, a signed, HTTP-only cookie stores a random visitor identifier plus first-touch and last-touch acquisition details for up to 180 days. It is available across skyflo.ai and app.skyflo.ai so attribution can survive sign-in redirects. It does not contain an email address, account identifier, prompt, code, or file content. If you sign in, the server links the attribution record to your account.
  • Analytics. On skyflo.ai, Google Analytics sets cookies that identify a returning browser and record which pages were viewed. These do not run on the account console.
  • Third-party embeds. The demo page loads Calendly, which sets its own cookies when you interact with the scheduler.

You can block or delete cookies in your browser settings. Deleting the first-party attribution cookie stops that browser from carrying the existing attribution into a later sign-in, but does not delete attribution already linked to an account. To opt out of Google Analytics across sites, install the Google Analytics Opt-out Browser Add-on. Blocking analytics cookies does not affect the account console or Skyflo Desktop.

9. Who we share it with

We use the following processors and service providers. Each receives only what it needs for its stated function.

ProviderWhat it does for SkyfloWhat it receives
ClerkAuthentication and session management for the account consoleYour identity record: provider account identifier, name, email address, profile picture URL
VercelHosting and content delivery for the website and the account consoleRequest metadata and logs
RenderHosting for the account service, the model gateway, and their databaseAccount and managed-usage records and service logs; transient managed request and response content handled by the gateway
OpenAIModel provider for Skyflo-managed inference onlyThe managed request content in section 5.1, and the keyed identifiers in section 5.4
SentryError and performance monitoring for our own servicesError reports and diagnostics, which exclude prompts, code, tool output, and provider payloads
SupabaseDatabase holding historical beta access and waiting-list submissionsThe email address and form fields you previously submitted
Google AnalyticsWebsite traffic measurement on skyflo.ai onlyAnalytics identifiers, IP address, page views
CalendlyDemo scheduling on the demo pageWhat you enter into the scheduler
CloudflareTurnstile bot challenge presented during sign-inChallenge signals such as IP address and browser characteristics

Dodo Payments is listed separately because its role is different. It is the merchant of record for paid subscriptions, which means it sells the transaction in its own name and acts as an independent controller of the payment data you give it, rather than as our processor. It receives the payment details you enter with it and your billing contact data; it gives us the subscription state we need to run your account.

Model providers you configure yourself are also not in that table, for the reason given in section 4.2: that transmission is made by your machine at your instruction, and the provider is your counterparty rather than our processor. OpenAI appears above only in its capacity as the provider we engage and pay for managed inference.

We may also disclose personal data where the law requires it, to establish or defend legal claims, or as part of a merger, acquisition, or sale of assets, in which case we will tell you before your data becomes subject to a different policy.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

10. How long we keep it

  • The managed transmission path does not persist request or response content in Skyflo’s account database, operational logs, or diagnostics. It handles the content transiently for the request. Your Mac retains its local mission history. Content you independently send to support is handled for that support purpose.
  • Managed operational records, the metering and integrity data listed in section 5.3, are kept while your account is open and for as long as the usage they evidence can still be disputed or has to be reconciled with our provider. They are what lets us show you what you used and answer a billing question about it.
  • OpenAI’s separate safety, image-review and cache retention is described in the Managed content disclosure. Turning managed content off or deleting a Skyflo account does not immediately erase copies retained by OpenAI under those conditions. We handle valid rights requests and seek required provider assistance. The lack of a stored Skyflo conversation does not eliminate those responsibilities.
  • Active account records, including account-linked attribution and lifecycle milestones, are kept while your account is open. When an account is deleted we remove or anonymise them within 30 days, subject to the two bounded exceptions below and any longer period required by law.
  • Encrypted immutable database backups can contain a copy of account records deleted from the live service. We keep each backup for no more than 35 days. Because an immutable backup cannot be edited safely, deletion takes effect there when that backup rotates out. Backups are used only to recover the service, not for ordinary account operations.
  • Security, fraud-prevention, and rights-request evidence may be kept for no more than 365 days after account deletion when needed to investigate abuse or a security event, prevent repeat misuse, or prove that a rights or deletion request was handled. These records are limited to the identifiers, timestamps, outcome, and evidence needed for those purposes and are not used to restore the account.
  • Acceptance records for published documents are kept for as long as the agreement can still be relied on or disputed, because their purpose is to evidence what you agreed to and when.
  • Billing records are kept for the period required by tax and accounting law.
  • Historical beta and waiting-list submissions no longer have public Skyflo form or API routes. We will delete the remaining rows no later than 5 October 2026, and sooner where you ask us to remove yours.
  • Anonymous website attribution events are kept for no longer than 14 months. The browser cookie itself expires no later than 180 days after it is set.
  • Website analytics are kept no longer than Google Analytics’ maximum event-level retention window of 14 months.
  • Operational logs are kept for a short rolling period for security and debugging.

11. Security

Both hosts are served over HTTPS with HSTS and a per-host Content-Security-Policy, so the marketing surface and the authenticated console are not treated as one trust boundary. The account API is called from our servers using your verified session; the browser does not hold an account-API credential. The console is excluded from search indexing.

Because password sign-in is not offered, there is no Skyflo password to leak. Where your Mac supports it, the key that identifies your device is generated in the Secure Enclave; the console shows you which of your devices reported a hardware-backed key, and you can revoke any device at any time.

For managed inference specifically: the credential that pays our model provider exists only in the gateway service and nowhere else, every managed request is individually authorised and bound to the device that asked for it, and our logs and error reports are written to exclude prompts, code, tool output, shell output, environment values, credentials, and provider payloads.

No system is perfectly secure, and no control here is a guarantee. If a breach affects your personal data we will notify you and the relevant authority where the law requires it.

12. International transfers

Operantix is established in India. Its managed gateway is hosted in the United States, and OpenAI and other service providers may process data in other countries. Managed processing has no India-only or customer-selected regional guarantee.

For a transfer subject to UK, EEA, or other transfer restrictions, the appropriate safeguards must be in place before the affected data is transferred. Where applicable, these include the EU Standard Contractual Clauses and the UK Addendum, or another permitted mechanism, covering the relevant transfer and onward processing. You may request information and a copy of the applicable safeguards from contact@skyflo.ai, with confidential details protected where appropriate. Enabling managed content is not a waiver of transfer protections.

13. Your rights and choices

Subject to the law that applies to you, including the UK and EU GDPR, India’s Digital Personal Data Protection Act 2023, and the California Consumer Privacy Act, you may ask us to:

  • confirm what personal data we hold about you and give you a copy;
  • correct data that is wrong or incomplete;
  • delete your account and the data attached to it, subject to the bounded retention periods in section 10;
  • export your data in a portable form;
  • restrict or object to a particular use, including any use we base on legitimate interests;
  • withdraw a consent you previously gave, such as the managed-content choice or a historical beta or waiting-list signup.

We do not hold a stored conversation from the managed transmission path to export or erase. We can address the operational records we retain and will coordinate required assistance from OpenAI for a valid rights request. We will explain what action was taken, any lawful retention exception, and any applicable review or complaint route.

Write to contact (at) skyflo.ai from the email address on your account. We confirm your identity before acting on an access or deletion request, because an unverified deletion is somebody else’s account being destroyed. We answer within the period the applicable law sets, and within 30 days where no period is set.

If you are in the United Kingdom or the European Economic Area you may also complain to your local supervisory authority. In India, you may contact our Grievance Officer and use the statutory complaint and appeal routes available under the law then in force. References to the Digital Personal Data Protection Act do not represent that every provision or Board remedy has commenced.

14. Children

Skyflo is not directed at children. You must be at least 18 years old, or the age of legal majority where you live, to use the Services. We do not knowingly collect personal data from children, and we will delete it if we learn we have.

15. Changes to this policy

We will not edit this published version in place. If we change this policy we will publish a new version at a new dated URL, and skyflo.ai/legal/privacy will serve that newer version from the moment it goes live. Where a change materially affects how we handle data you have already given us, we will give notice and, where the law requires it, ask for consent.

Your managed-content choice is recorded against one specific disclosure version. If we activate a replacement disclosure for managed processing, existing choices for the older version no longer authorise new managed requests. You must read and affirmatively accept the replacement and enable managed content again. Publishing an inactive draft does not change your choice.

16. Contact

Privacy questions, rights requests, and complaints go to contact (at) skyflo.ai, or by post to the registered office below. Please include enough information for us to identify your account and respond.

Operantix Systems Private Limited
Office No. 01, 1st Floor, Future One,
S. No. 245/5/1, D.P. Road, Aundh,
Pune, Maharashtra 411007, India
CIN: U62010PN2026PTC252795

Grievance Officer. Karan Jagtiani is our Grievance Officer and privacy contact, reachable at contact (at) skyflo.ai or by post at the address above. If you are not satisfied with how we have handled your personal data, write to him directly. We acknowledge consumer complaints within 48 hours and redress them within one calendar month. Privacy rights requests are handled within the period required by applicable law, with any permitted extension explained.

Customer care and grievance telephone: +91 7020882073