Skippr AI

Trust & compliance

Privacy Policy

Effective Date: July 17, 2026

Company: Skippr Ltd. ("Skippr", "we", "us", "our")

Registered office: 99 Milton Keynes Business Centre, Foxhunter Drive, Linford Wood, Milton Keynes, Buckinghamshire MK14 6GD, England

Email: privacy@skippr.ai | DPO: dpo@skippr.ai

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use:

  • Our websites (e.g., skippr.ai, skippr.com) and any page that links to this Policy;
  • Our AI agent platform (deployed via live video call, session link, SDK, website embed, or in-product module);
  • Our waitlist, community spaces, and support channels; and
  • Other services that reference this Policy (together, the "Services").

If you do not agree with this Policy, please do not use the Services.

Quick Summary (At-a-glance)

  • What the product does. Skippr's multimodal AI agent (the "Agent") runs live demo, onboarding, upsell, and support sessions.
  • Two user models. You may use the Services as a Direct User (for your own purposes) or as a Client deploying the Agent to your own customers and prospects ("End Users").
  • Website vs. product roles. For the website/app, Skippr is the Controller. For sessions deployed to End Users, you (or your organization) are the Controller; Skippr acts as your Processor (DPA available on request).
  • Sessions may be recorded. Sessions may include video, audio, screen capture, and transcript recordings. Session analytics and Derived Output are stored in your workspace.
  • Client obligations. If you deploy the Agent to End Users, you must inform them that the session is conducted by an AI, may be recorded, and that they can request data deletion via privacy@skippr.ai or through your own privacy process.
  • LLM use without direct identifiers. We may use trusted AI Processing Services. We do not include account emails or similar direct identifiers in those requests.
  • Cookies (website only). Non-essential cookies/analytics run only with consent where required.
  • No sale; limited sharing. We do not sell personal information. Website advertising tools, if used, may be considered "sharing" in some US states; we provide an opt-out and honor Global Privacy Control (GPC) where required.
  • Your rights & deletion. You (and End Users) can request permanent deletion by email; in-product "delete" is archive only.

Table of Contents

  1. Definitions
  2. Information We Collect
  3. How We Use Information
  4. Legal Bases (EU/UK)
  5. When We Share Information
  6. Cookies and Similar Technologies (Web)
  7. Retention
  8. Security
  9. International Transfers
  10. Children
  11. Your Privacy Rights
  12. End User Privacy Rights
  13. Do-Not-Track & Global Privacy Control
  14. California Notice (CPRA/CCPA)
  15. Agent Privacy Disclosures
  16. Client Obligations When Deploying the Agent to End Users
  17. Updates
  18. Governing Law
  19. Contact
  20. Access/Deletion Requests
  21. Roles & Your Responsibilities (Controller/Processor)

1) Definitions

  • Agent: Skippr's multimodal AI agent that conducts live sessions (demos, onboarding, upsells, implementation, support) via video call, session link, SDK, embed, or in-product module.
  • Direct User: An individual or organization using the Services for their own internal purposes.
  • Client: An organization that deploys the Agent to interact with its own End Users.
  • End User: A third party (e.g., a Client's customer, prospect, or user) who participates in a session deployed by a Client.
  • Customer Content: Content you provide to the Services (prompts, uploads, chats, Knowledge Base materials, configuration).
  • Session Data: All content captured, generated, or processed during an interactive session, including: screen recordings and periodic screenshots, voice recordings and audio, transcripts, participant inputs and responses, interaction analytics, and metadata. Session Data may additionally include video recordings of participants, qualification scores, and follow-up actions triggered.
  • Knowledge Base and Workspace Data: Product documentation, FAQs, scripts, pricing information, objection-handling guides, branding assets, agent configurations, and any other content uploaded by a Client or Direct User to their workspace for use in building, configuring, and operating agents.
  • Derived Output: Reports, analytics, session summaries, qualification scores, and recommendations produced by the Services from your inputs or Session Data.
  • AI Processing Services: Third-party services used to power the Services' conversational/visual capabilities and Derived Output generation.
  • Voice Data: Audio input captured during sessions. Voice Data is processed in real-time for speech-to-text and text-to-speech functionality. Voice recordings are also retained as part of Session Data (session recordings) per your workspace settings.

2) Information We Collect

a) Information you provide

  • Account details (name, work email, company, hashed password if you create one), workspace/project names, content you upload, support requests, and community contributions.
  • Knowledge Base and workspace data you upload (product docs, FAQs, scripts, pricing, branding assets, agent configurations, objection-handling guides, and any other content used to build and operate your agents).
  • Agent configuration (integration settings, follow-up rules, CRM mappings, recording preferences, disclosure text).

b) Information collected automatically (website/app)

  • Log data (IP address, device/browser info, pages viewed, timestamps) and cookie-based analytics/functional data as described in Section 6.

c) Session data

When a session takes place (whether you are a Direct User or a Client's End User), the Services may collect and process:

  • Video and audio recordings of the session (including participant voice and, where screen sharing is active, visual content on screen);
  • Real-time screen captures of the product interface being demonstrated or navigated;
  • Transcripts of the conversation (generated via speech-to-text);
  • Participant inputs (text chat messages, selections, form responses during the session);
  • Session metadata (timestamps, duration, language, connection quality, participant identifiers such as name and email if provided);
  • Behavioral analytics generated during the session (qualification scores, engagement metrics, drop-off points, intent signals, interaction patterns);
  • Follow-up actions triggered (emails sent, meetings booked, CRM records created/updated).

Voice Data. Audio input is processed in real-time for speech-to-text and text-to-speech. Voice recordings are retained as part of Session Data (session recordings) per your workspace settings.

Knowledge Base and workspace data. The Agent references Knowledge Base materials and agent configurations during sessions. All content you upload to your workspace (including Knowledge Base materials, branding assets, agent configurations, and other reference data) is stored in your workspace, used to operate your agents, and is not shared with other customers. You may edit and delete agents and workspace content through in-product controls at any time. For permanent deletion including backup erasure, email privacy@skippr.ai.

d) End User data (when the Agent is deployed by a Client)

When a Client deploys the Agent, we process End User personal data on the Client's behalf as their Processor. This may include:

  • End User name and email (if provided or collected during the session);
  • Voice and video of the End User during the session;
  • End User inputs, questions, and responses;
  • Behavioral data and qualification scores generated about the End User;
  • Follow-up data (emails sent to End User, meetings booked).

We process End User data solely on the Client's instructions and for the purposes of providing the Services to the Client.

e) Diagnostics/monitoring

We collect limited telemetry (feature usage events, error rates, performance metrics) to monitor reliability and address bugs. This is not background browsing or session history.

3) How We Use Information

  • Provide and improve the Services. Create and secure accounts, deliver reports, operate projects/collaboration, conduct agent sessions, provide support, and improve features.
  • Sessions, analytics, client improvement, and follow-up. Session Data (including screen and voice recordings, transcripts, and analytics) is used to: power real-time conversational AI and visual understanding; generate session analytics and Derived Output; enable Clients to review session recordings, improve session quality, and follow up with participants; and improve our agents' accuracy and performance. Knowledge Base materials are retrieved during sessions to inform responses. Follow-up actions (emails, meeting bookings, CRM updates) are triggered as configured by you.
  • Communications. Service and security notices; with your consent where required, product updates and marketing. We do not use End User contact details for Skippr's own marketing.
  • Security and compliance. Detect and prevent fraud/abuse, meet legal obligations, and enforce terms.

LLM/AI clarity. For sessions, we transmit only the content and prompts necessary for the task, plus minimal technical context (e.g., language, anonymized workspace ID). We do not include account emails or similar direct identifiers in AI requests. Our contracts restrict AI processors from using your content for model training or advertising. We do not use Customer Content, Session Data, Knowledge Base materials, or Voice Data for advertising or for training general-purpose models. We may use aggregated or de-identified information (that does not identify you or any End User) to maintain and improve the Services.

4) Legal Bases (EU/UK)

We rely on:

  • Contract (to provide core services you request);
  • Legitimate interests (to secure and improve services, deliver sessions you request as controller);
  • Consent (marketing emails; non-essential website cookies/analytics where required);
  • Legal obligations (tax/accounting, responding to lawful requests).

Where we store Session Data in your workspace, our legal basis is performance of a contract and/or our legitimate interests, balanced with your controls and rights.

For End User data processed on behalf of Clients, the Client determines the legal basis as Controller. Skippr processes such data as Processor on the Client's instructions.

5) When We Share Information

We do not sell personal information. We share information only with:

  • Service providers / sub-processors (categories): cloud hosting, storage/backup, security and monitoring, analytics (web), payment processing, customer support, product/design tooling, AI Processing Services, and — where configured by the Client — CRM platforms, calendar services, and email delivery services.
  • Third-party integrations configured by you: When you (as Direct User or Client) configure the Agent to send data to CRM systems, calendar tools, email platforms, or other services, we transmit data to those systems on your behalf and per your instructions. Those systems' own privacy policies apply.
  • Corporate events: In M&A/financing scenarios we will continue to protect data as described here.
  • Legal: Compliance with law, safety and rights protection; fraud/abuse prevention; responding to lawful requests.
  • At your direction: When you integrate or export to services you choose.

If our websites use advertising or remarketing tools, that may be "sharing" for cross-context behavioral advertising in certain US states. You can opt out via our "Do Not Sell or Share My Personal Information" link and via GPC signals where applicable.

We maintain a current list of our sub-processors at https://skippr.ai/subprocessors.

6) Cookies and Similar Technologies (Web)

  • Essential cookies operate the site (auth, security, load balancing).
  • Non-essential (analytics, A/B testing, advertising) run only with your consent where required.
  • You can manage or withdraw consent at any time via "Cookie Settings".

Cookies do not apply to agent sessions; those are covered in their respective sections.

7) Retention

We keep personal information only as long as needed for the purposes described or as required by law.

  • Account/workspace data: Until you delete your account or we no longer need it to provide the Services.
  • Session Data: Session recordings (video, audio, screen captures, transcripts), analytics, and Derived Output: 12 months by default or until we process your permanent deletion request.
  • Knowledge Base and workspace data (agent configurations, branding assets, other uploaded content): Retained until you delete them through in-product controls or your account is terminated. You may edit and delete agents and Knowledge Base materials at any time within the product. For permanent deletion (including erasure from backups), email privacy@skippr.ai.
  • End User Session Data: Retained per the Client's settings (default 12 months) or until permanent deletion is requested by the Client or the End User (via either privacy@skippr.ai or the Client directly).
  • Follow-up records (emails, CRM entries): Retained per workspace settings. Note that copies transmitted to third-party systems (CRM, email platforms) are subject to those systems' retention policies.
  • Support tickets: Approximately 3 years after resolution.
  • Billing/transaction records: 7 years (legal requirement).
  • Website cookies/analytics: Per tool settings and your consent choices.

Archive vs. permanent deletion. In-product "Delete" currently archives items and removes them from normal views; it does not immediately erase underlying data. To request permanent deletion, follow Section 20. Once approved, we erase data from active systems within 30 days, and from encrypted backups on the next scheduled rotation (typically within 35 additional days). Where data was sent to approved processors, we instruct them to delete corresponding copies within 30 days, subject to their technical and legal limits.

8) Security

We use reasonable and appropriate safeguards, including encryption in transit/at rest (where applicable), role-based access controls with MFA for staff, secure development practices, logging/monitoring, vulnerability management, and an incident response process.

Session recordings and transcripts are encrypted at rest. Access to Session Data is restricted to authorized workspace members based on their role. Certain recognised sensitive fields (such as password and payment inputs) are masked client-side on a best-effort basis before capture.

9) International Transfers

We operate from the United Kingdom with cloud infrastructure in the United Kingdom, the EEA, and the United States. Where required, we use recognized transfer mechanisms (e.g., adequacy decisions, standard contractual clauses with UK addendum, or other appropriate safeguards).

10) Children

The Services are not directed to children under 13 and are intended for professional/business use. We do not knowingly collect personal information from children. If we learn we have, we will delete it.

Clients must not knowingly direct sessions at children under 13 (or the applicable age of consent in relevant jurisdictions).

11) Your Privacy Rights (Direct Users and Clients)

Depending on your location, you may have rights to access, correct, delete (including permanent deletion of Session Data and project artifacts by request), restrict or object, withdraw consent, or data portability. You may also opt out of marketing at any time.

  • EU/UK: You may lodge a complaint with your local supervisory authority.
  • US states with privacy laws: You may have rights to know, delete, correct, and to opt out of targeted advertising ("sharing"). We honor GPC signals where required.
  • Canada: You may access/correct your data and ask about cross-border processing and safeguards.

Contact privacy@skippr.ai to exercise your rights. We verify requests and respond within required timeframes.

12) End User Privacy Rights

If you are an End User who has participated in a session deployed or conducted by a Client or another organization, you have the following rights. You may exercise these rights through either of two paths:

  • Contact Skippr directly at privacy@skippr.ai; or
  • Contact the Client (the organization that deployed or conducted the session) through their own privacy or data subject request process.

Skippr will honor requests received through either path.

a) Right to Know

You may request information about what personal data was collected during your session, how it was used, and with whom it was shared. Contact privacy@skippr.ai or the Client (the organization that deployed the session) directly.

b) Right to Access

You may request a copy of the personal data collected about you during a session, including session recordings, transcripts, and analytics.

c) Right to Deletion

You may request permanent deletion of your Session Data (recordings, transcripts, analytics, and any Derived Output relating to you) by emailing privacy@skippr.ai. Include:

  • Your name and email (as used during the session);
  • The approximate date and context of the session;
  • The name of the company/product whose session you participated in (if known).

We will identify the relevant Client workspace, verify your identity, notify the Client, and process the deletion. Erasure from active systems is typically completed within 30 days of approval; backups are overwritten on the next scheduled rotation (typically within 35 additional days).

d) Right to Correction

You may request correction of inaccurate personal data. Contact privacy@skippr.ai or the Client directly.

e) Right to Object

Where processing is based on legitimate interests, you may object. Contact privacy@skippr.ai or the Client directly.

f) Complaint

EU/UK End Users may lodge a complaint with their local supervisory authority. US End Users have rights under applicable state privacy laws.

Important: Where a session was deployed by a Client, the Client is the data Controller for your data. Skippr processes your data as the Client's Processor. You may contact either the Client or Skippr directly — both paths are valid. Skippr will independently honor deletion requests received at privacy@skippr.ai regardless of which path you use.

13) Do-Not-Track & Global Privacy Control

We currently do not respond to legacy DNT signals (no industry standard). Where required by law, we honor GPC or other recognized universal opt-out signals for "sale"/"sharing" or targeted advertising.

14) California Notice (CPRA/CCPA)

  • We do not sell personal information. Where our websites use advertising/remarketing tools, that may be "sharing"; opt out via the "Do Not Sell or Share" link or through GPC signals.
  • You have rights to know, delete, correct, and to non-discrimination.
  • We do not sell/share minors' personal information (under 16).
  • Categories collected depend on your use: Identifiers (e.g., email), Internet/Network Activity (site analytics), Commercial Info (purchases), Inferences (product interest), and Audio/Visual Information (session recordings, including screen captures and voice recordings). See Section 7 for retention.

15) Agent Privacy Disclosures

a) What the Agent Collects During a Session

  • Video and audio of all participants (when recording is enabled);
  • Real-time screen captures of the product interface;
  • Full transcript of the conversation;
  • Participant-provided information (name, email, text inputs, responses to questions);
  • Behavioral analytics (engagement patterns, qualification scores, intent signals);
  • Follow-up actions (emails, calendar bookings, CRM updates).

b) How Sessions Are Recorded

The Agent records sessions by default. The recording includes video, audio, screen captures, and transcript. Recordings are stored in the Client's or Direct User's workspace and subject to workspace retention settings.

Clients may configure recording behavior (e.g., disable recording, adjust what is captured) in their workspace settings.

c) AI Disclosure

The Agent is an AI agent. It identifies itself as AI at the start of sessions. It is not a human.

d) Multi-Language Processing

The Agent operates in multiple languages. Session content may be processed, transcribed, and stored in any language used during the session.

e) How Recordings Are Used

Session recordings (screen, voice, video, transcript) are used for the following purposes:

  • Generating Derived Output: Session summaries, analytics, qualification scores, and follow-up recommendations;
  • Client review and improvement: Clients can review recordings to improve session quality, refine Knowledge Base materials, train their teams, and follow up with session participants;
  • Agent improvement: Skippr uses session recordings and analytics to improve our agents' accuracy, conversational quality, and performance;
  • Follow-up actions: Triggering configured actions such as emails, calendar bookings, and CRM updates.

f) Client Access to Session Recordings

Clients who deploy the Agent have access to session recordings, transcripts, and analytics within their workspace. Clients may use this data to review session quality, identify areas for improvement, adjust the Agent's configuration and Knowledge Base, and conduct follow-ups with End Users — all subject to their obligations as data Controller (see Section 16).

16) Client Obligations When Deploying the Agent to End Users

If you are a Client deploying the Agent to interact with your End Users, you are the data Controller for all End User personal data processed during those sessions. You must:

a) Provide Adequate Disclosure and Obtain End User Approval

Before or at the start of each session, ensure End Users are clearly informed that:

  1. They are interacting with an AI agent, not a human;
  2. The session may be recorded (video, audio, screen, transcript);
  3. Session data will be processed by Skippr (as your processor), stored, and used for analytics, follow-up communications, and improving the AI agent's performance;
  4. They may request access to or deletion of their data by contacting privacy@skippr.ai or through your own data subject request process;
  5. A link to the applicable privacy policy is available.

End User policy approval is required. Before an End User can participate in a session, you must ensure they have reviewed and accepted the applicable Skippr policies (Terms of Service and Privacy Policy). This applies to all deployment methods (SDK, meeting link, embed, in-product module). You may satisfy this through either:

  • Skippr's built-in consent mechanism: A configurable consent prompt (e.g., checkbox, banner, or interstitial) displayed to the End User before the session begins. You must ensure this is enabled and the End User affirmatively accepts before proceeding; or
  • Your own channel: Collect the End User's acceptance through your own onboarding flow, terms page, or other mechanism before directing them to a session. You are responsible for maintaining records of acceptance.

The obligation to verify End User approval rests with you as Controller.

b) Establish a Lawful Basis

You are responsible for determining and maintaining a lawful basis for processing End User data through the Services, including for recording, analytics, and automated follow-ups.

c) Handle Data Subject Requests

If End Users contact you directly with data subject requests (access, correction, deletion, objection), you are responsible for fulfilling them. Skippr will provide reasonable technical assistance.

If End Users contact Skippr directly at privacy@skippr.ai, we will notify you and assist in fulfilling the request.

d) Do Not Target Minors

You must not knowingly deploy sessions directed at individuals under 13 (or the applicable age of consent).

17) Updates

We may update this Policy. The "Effective Date" will change and, for material updates, we will provide reasonable notice.

18) Governing Law

This Policy is governed by the laws of England and Wales, with exclusive jurisdiction of its courts.

19) Contact

Data Protection Officer: dpo@skippr.ai
General privacy inquiries: privacy@skippr.ai

Postal: Skippr Ltd., address above.

20) Access/Deletion Requests

For Direct Users and Clients

Submit privacy requests by emailing privacy@skippr.ai from the email on your account. Include:

  • Request type: access, correction, permanent deletion (erasure), portability, restriction, or objection;
  • Scope: account, workspace, project(s), session ID(s) (if known), relevant dates/URLs;
  • Authority: if acting for an organization, your role (e.g., workspace admin) and authorization if required.

For End Users

Submit privacy requests by emailing privacy@skippr.ai. Include:

  • Your name and email (as used during the session);
  • Request type: access, correction, permanent deletion, objection;
  • Session context: approximate date, the company/product whose session you participated in (if known);
  • Any additional identifying information that may help us locate your data.

Verification

We may verify identity and (for workspace requests) administrative authority. For End User requests, we may need to confirm identity with the relevant Client.

What We Delete

For approved permanent deletion requests, we erase specified Session Data (recordings, transcripts, analytics), Derived Output, project artifacts, and related metadata from active systems and instruct sub-processors to delete corresponding data. We retain data we must keep by law (e.g., billing records, security logs) for the required period only.

Note for End Users: Deletion of Session Data from Skippr's systems does not affect copies that may have been transmitted to third-party systems (e.g., CRM, email platforms) by the Client. You should contact the Client directly to request deletion from those systems.

Timelines

We respond within legal timeframes (generally 30 days). Erasure from active systems is typically completed within 30 days of approval; backups are overwritten on the next scheduled rotation (typically within 35 additional days).

Limitations

We may decline or limit a request where identity/authority cannot be verified, where it would adversely affect others' rights, or where retention is legally required. If denied, we explain why and how to appeal if applicable.

21) Roles & Your Responsibilities (Controller/Processor)

ScenarioControllerSkippr's Role
Website/app usageSkipprController
Sessions — Direct User (own use)Skippr (account/service data); You (Customer Content)Controller / Processor
Sessions — deployed to End Users (Client)You / your organizationProcessor
End User data in Client-deployed sessionsClient is ControllerSkippr is Processor

Your responsibilities as Controller (Client): You determine the lawful basis for processing End User data, ensure adequate disclosures are made, handle (or cooperate with Skippr to handle) End User data subject requests, and configure session recording and data routing in compliance with applicable law.

DPA: A Data Processing Addendum is available on request: privacy@skippr.ai.

Avoid capturing secrets or sensitive data unless lawful to do so, and request deletion promptly if captured in error.