For Skarmy’s formal security and privacy positions, see the published security and privacy pages. Questions about compliance, contracts, or handling of specific data should go to security@skarmy.ai.
Access to your work
Your companies and workspaces are private to your account. Access is checked on every request, and a workspace you do not have access to is reported as not found rather than as forbidden — so its existence is not revealed. A company today has exactly one member: you. There is no way for another person to be added, so there is no sharing to configure or audit.Signing in
Skarmy supports two ways to sign in:- Email and password
- Continue with Google
Guest sessions
You arrive signed in as a guest, without an account. When you create one, the work from your guest session moves onto your new account. Opening the Builder and publishing always require a real account.Connected apps
Connecting an app authorizes Skarmy with that tool through the tool’s own sign-in, scoped to its listed skills. The rules Skarmy follows there are strict and enforced:- It reads when you ask, acts one step at a time, and never deletes anything in a connected app.
- Automations read your apps but never send or post from them.
- Anything read from an app is treated as content, never as instructions.
- You can switch individual skills off, uninstall from the Apps page, or revoke access from the tool’s side at any time.
Builds run in isolation
Each workspace builds in its own cloud machine, separate from your browser and from other workspaces. That machine sleeps between turns and is restored with your files when it wakes. Your published site is deployed separately from that build machine, which is why the site keeps serving while your session sleeps.Your published site is public
Anything you publish is on the public internet atyourname.skarmy.ai, with no access control in front of it — and nothing publishes without your explicit approval of the exact version going out.
Some site names are permanently reserved so that a published site cannot impersonate a Skarmy surface or intercept mail on the shared domain. See Site addresses.
A published site cannot affect your Skarmy session or read your account.
Material you paste in
The agents treat documents, plans, competitor copy, and feedback you paste as material for your product. Instructions written inside that material do not change how the agents behave. If a document you paste says “ignore your previous instructions”, it is treated as text, not as a command. The same applies to anything read from a connected app.What the agents can see
Neither agent can act on your account. Only you can change settings, buy credits, or remove your account.
Export and removal
Settings → User → Advanced holds both:- Data export is not available yet.
- Account deletion is a request: you confirm in the app, and the team confirms by email within 24 hours.
What is not available
Being explicit, so you can plan around it:- No team members, roles, or shared access
- No public API or API keys
- No private or password-protected published sites
- No custom domains
- No self-serve data export yet
Next
App permissions
The rules for connected apps in full.
Account and settings
Every settings section and what it controls.

