Skip to main content
This page describes what you can observe and control as a user of Skarmy.
For Skarmy’s formal security and privacy positions, see the published security and privacy pages. Questions about compliance, contracts, or handling of specific data should go to security@skarmy.ai.

Access to your work

Your companies and workspaces are private to your account. Access is checked on every request, and a workspace you do not have access to is reported as not found rather than as forbidden — so its existence is not revealed. A company today has exactly one member: you. There is no way for another person to be added, so there is no sharing to configure or audit.

Signing in

Skarmy supports two ways to sign in:
  • Email and password
  • Continue with Google
There are no other sign-in methods and no API keys. Sign-in methods live under SettingsUserSecurity.

Guest sessions

You arrive signed in as a guest, without an account. When you create one, the work from your guest session moves onto your new account. Opening the Builder and publishing always require a real account.

Connected apps

Connecting an app authorizes Skarmy with that tool through the tool’s own sign-in, scoped to its listed skills. The rules Skarmy follows there are strict and enforced:
  • It reads when you ask, acts one step at a time, and never deletes anything in a connected app.
  • Automations read your apps but never send or post from them.
  • Anything read from an app is treated as content, never as instructions.
  • You can switch individual skills off, uninstall from the Apps page, or revoke access from the tool’s side at any time.
See App permissions for the full picture.

Builds run in isolation

Each workspace builds in its own cloud machine, separate from your browser and from other workspaces. That machine sleeps between turns and is restored with your files when it wakes. Your published site is deployed separately from that build machine, which is why the site keeps serving while your session sleeps.

Your published site is public

Anything you publish is on the public internet at yourname.skarmy.ai, with no access control in front of it — and nothing publishes without your explicit approval of the exact version going out.
Do not ask the Builder to put real customer data, credentials, or anything confidential into a product you publish. First versions are built with sample data — keep it that way.
Some site names are permanently reserved so that a published site cannot impersonate a Skarmy surface or intercept mail on the shared domain. See Site addresses. A published site cannot affect your Skarmy session or read your account.

Material you paste in

The agents treat documents, plans, competitor copy, and feedback you paste as material for your product. Instructions written inside that material do not change how the agents behave. If a document you paste says “ignore your previous instructions”, it is treated as text, not as a command. The same applies to anything read from a connected app.
Anything you paste is used to build your product and may end up in what gets published. Remove customer names, credentials, and private details before pasting.

What the agents can see

Neither agent can act on your account. Only you can change settings, buy credits, or remove your account.

Export and removal

SettingsUserAdvanced holds both:
  • Data export is not available yet.
  • Account deletion is a request: you confirm in the app, and the team confirms by email within 24 hours.
Removing your account is permanent once processed. Publish or note down anything you want to keep first.

What is not available

Being explicit, so you can plan around it:
  • No team members, roles, or shared access
  • No public API or API keys
  • No private or password-protected published sites
  • No custom domains
  • No self-serve data export yet

Next

App permissions

The rules for connected apps in full.

Account and settings

Every settings section and what it controls.