SAIG Studio Cloud — Privacy Policy
This policy explains what SAIG Studio Cloud ("the Service") collects, why, and what we do with it. It describes what the Service actually does.
1. What we collect
- Account identity — the name and email associated with your SAIG sign-in, and the account identifier returned by GitHub, Vercel or Supabase when you connect them.
- Access tokens — OAuth tokens and installation credentials issued by those providers, so the Service can create and configure the resources you ask for.
- Operational metadata — which resources were created, when, and whether the operation succeeded.
We do not collect the contents of your databases, and we do not read your repositories beyond what is required to perform an action you requested.
2. How access tokens are held
Tokens are stored organisation-scoped and encrypted at rest, accessible only to the server-side process acting on your instruction. They are never written to logs, never included in support messages or issue threads, and never shared with other tenants. Where credentials must reach your own infrastructure, they are transmitted as encrypted repository secrets on your own account.
3. Why we process it (UK GDPR)
Performance of a contract — to provide the Service you asked for. Legitimate interests — to secure and operate the platform and diagnose failures. We do not sell personal data, and we do not use it for advertising or profiling.
4. Sharing
We share data only with the providers you connect (GitHub, Vercel, Supabase), to carry out your instructions, and with infrastructure processors used to run the Service. Each acts under contract.
5. Retention
Tokens are held while your connection is active and deleted when you disconnect, revoke access, or close your account. Operational metadata is retained for a rolling period for security and audit, then deleted.
6. Your rights
You may request access to, correction, deletion, restriction or portability of your personal data, and may object to processing. You may revoke provider access at any time in that provider's own dashboard, which immediately ends our ability to act. You may complain to the Information Commissioner's Office (ico.org.uk).
7. Transfers
We are UK-based. Where processors operate outside the UK, transfers rely on adequacy regulations or standard contractual clauses.
Contact
dev@skylite.group · Skylite Group Ltd, England & Wales