Politique de confidentialité
Skrybo ne collecte que les données strictement nécessaires au fonctionnement de votre API d'e-mail transactionnel, de vos domaines d'envoi vérifiés et de vos boîtes webmail. Cette politique explique lesquelles, comment elles sont protégées et quels choix vous avez.
Dernière mise à jour : juillet 2026
Ce document n'est publié qu'en anglais. Le texte anglais fait foi ; les traductions du résumé ci-dessus sont fournies à titre indicatif.
1. Overview
This Privacy Policy explains what Skrybo collects, why, how it is protected, and the choices you have. It applies to the hosted Service at skrybo.com and to self-hosted instances running the same software.
For self-hosted deployments, Skrybo the organisation has no access to your data — everything runs on your own infrastructure. The information below describes the hosted Service.
2. Data we collect
Account data. Name, email address, password (scrypt hash only), preferred language, role, and email-verification state. Optional Google OAuth profile if you sign in with Google.
Session data. Session token, IP address, and user agent stored with each session for security and abuse prevention.
Usage data. Per-account monthly counters for emails sent, verified domains, provisioned mailboxes, contacts, and seats. These counters enforce plan limits.
Product data. Sending domains you add, DKIM public selectors, outbound message logs, mailboxes (via WildDuck), contacts, audiences, broadcasts, templates, webhook endpoints, suppressions, and API keys. This is the working data the Service produces for you.
Billing data. Subscription tier, invoices, and credit-ledger entries. Card details are handled by Polar; Skrybo does not store full card numbers.
Vendor credentials. Per-tenant Cloudflare DNS tokens (when you enable one-click DNS), DKIM private keys generated per sending domain, developer API keys (SHA-256 hashed), and webhook signing secrets. These are encrypted at rest with AES-256-GCM under a master key.
Contact-form messages. If you use the contact form, the message content and your email address are delivered to our support inbox via Resend.
3. How we use your data
We use the data above to:
- Provision and operate your account, sending domains, mailboxes, and message delivery.
- Enforce plan limits and prevent abuse through rate limiting and cross-account isolation.
- Process payments through Polar and maintain an invoice and credit-ledger history.
- Send transactional email: verification, password reset, cap warnings, delivery failure alerts, and deletion warnings. Marketing email is opt-out and only sent if the corresponding preference is enabled.
- Route product email through your own verified sending domains and deliver replies into your webmail mailboxes. Skrybo does not read message bodies for its own purposes.
- Maintain audit logs for security. Audit logs never record email addresses, request bodies, headers, or sensitive parameters.
5. Data sharing and sub-processors
Skrybo shares data only with the sub-processors required to run the Service:
- Polar — payment processing and subscription management. Receives product IDs, customer references, and webhook events. Does not receive your outbound logs or mailbox contents.
- Cloudflare — one-click DNS record management, per-tenant and only when you authorize a token. Receives only the DNS record set for your sending domain.
- Resend — platform-owned transactional notifications only (email verification, password reset, contact form). Product email flows through your own Skrybo-run MTA.
Each sub-processor is bound by its own data-protection terms. Skrybo does not sell your data.
6. Security safeguards
- Vendor secrets and refresh tokens are encrypted at rest with AES-256-GCM using a master key.
- Passwords are hashed with scrypt via Better Auth; plaintext passwords are never stored.
- Cross-account isolation: every product route verifies ownership and returns 404 (not 403) for foreign resources so existence never leaks.
- Rate limits on authentication and webhook routes reduce brute-force and volumetric abuse.
- Two-factor authentication (TOTP + backup codes) is available on all accounts and required for admins.
- Better Auth enforces Origin and trusted-origins checks on account endpoints; every unsafe cookie-authenticated product request also uses the double-submit cookie.
No system is perfectly secure. If you believe you have found a vulnerability, please contact security@skrybo.com before public disclosure.
7. Data retention
Skrybo retains product data (outbound logs, mailboxes, contacts, audiences, broadcasts, templates) for as long as your account is active. Inactive accounts may have cached delivery events pruned to free space, but your owned data remains until you export or delete it.
Billing records (invoices, credit ledger) are retained for the period required by tax law in the operating jurisdiction.
Audit logs that carry security-relevant metadata are retained on a rolling basis and never contain email addresses or request bodies.
8. Your rights (GDPR and similar)
Depending on your jurisdiction (EU/EEA, UK, California, etc.) you may have the right to:
- Access a copy of your personal data.
- Correct inaccurate data.
- Export your data — the structured JSON export covers account, product, deliverability, usage, team, billing, and audit records while deliberately excluding credential hashes and encrypted secrets. Mailbox messages remain available through webmail and IMAP during the grace period.
- Delete your account. Deletion enters a 30-day grace period during which you can cancel through
/api/legal/cancel-deletion. A confirmation email states the exact deadline. At that deadline, reusable credentials are revoked, active billing is stopped, and the durable purge removes product and identity data. A legal hold may delay deletion where required by law. - Object to or restrict certain processing, and withdraw consent for marketing email at any time via notification preferences.
- Lodge a complaint with your supervisory authority if you believe processing violates applicable law.
To exercise any of these rights, use the in-app data-rights endpoints (/api/legal/*) or contact privacy@skrybo.com.
Invoices and financial-ledger evidence that must be retained under tax law are reassigned to a random, non-user-derived identifier. The mapping back to your account is destroyed when the purge completes.
9. International data transfers
Your data may be processed by Skrybo and its sub-processors in jurisdictions outside your country of residence. Where the EU/EEA is involved, transfers rely on appropriate safeguards such as Standard Contractual Clauses or another lawful transfer mechanism.
Self-hosted deployments keep all data on your own infrastructure; no transfer to Skrybo occurs.
10. Children’s privacy
The Service is not directed to children under 16. Skrybo does not knowingly collect personal data from children. If you believe a minor has registered, contact privacy@skrybo.com and the account will be removed.
11. Self-hosted deployments
On a self-hosted instance you control the infrastructure, the encryption keys, and the vendor integrations. Skrybo the organisation does not receive data from your instance. You are responsible for compliance with this Policy’s obligations (including data-subject requests) for data you process on your own deployment.
12. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be announced by email (to verified accounts) or in-app at least 30 days before taking effect. The “Last updated” date below reflects the most recent revision.
13. Contact
Questions about this Privacy Policy or a data-subject request? Contact privacy@skrybo.com.