Third Party Index

Snapshot 25503

Document
Privacy policy
URL
https://www.skydive.com/privacy
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
71886 bytes
SHA-256 (raw)
5d47f02bbd804176eab4a436c5d2f3ed1e3b536785c08d38e17372323fabd1f1
SHA-256 (normalized text)
5c97ccf0f3027f98b85a46cb7f27d91c3140ae94c0e959bb673ce4df551d2e4b

Normalized text

Scripts and page chrome removed; this is what change detection compares.

SKYDIVE PRIVACY POLICY
Last Updated: July 29, 2026
Create, Inc. ("Create," "we," "us," or "our") provides Skydive, a platform for creating and operating AI agents that run in the cloud and can work across the web, Slack, email, text messaging, APIs, and other surfaces (together with our websites at skydive.com and related applications and services, the "Services"). This Privacy Policy explains what personal information we collect through the Services, how we use and share it, and the rights and choices available to you.
Because Skydive agents can hold credentials, connect to your accounts on other services, browse the web, run code, and take actions on your behalf, this Privacy Policy describes some categories of data, such as agent transcripts, connected-account data, and network logs, that go beyond what a typical application collects. Please read it carefully.
1. Applicability of This Privacy Policy
If you use the Services as an authorized user of a Skydive customer's workspace (for example, your employer), that customer is responsible for its workspace and its agents, and its own privacy notices and policies govern its handling of your information. We process workspace data on the customer's behalf, except that we process account and usage data for the limited purposes described in this Privacy Policy. Order Form customers can review the version of our Data Processing Addendum (DPA) identified in their Order Form at skydive.com/dpa. This Privacy Policy does not supersede the customer's notices. Workspace administrators may be able to access, monitor, export, restrict, and delete activity and content in their workspace, including agent transcripts and logs.
If you interact with an agent that a Skydive customer has deployed in the customer's own channels (for example, a bot in a company's Slack workspace, email, or text messages), the customer, not Create, is responsible for that deployment, including providing you with any required notices and obtaining any required consents. We process that data as a service provider to the customer.
To the extent not superseded as described above, this Privacy Policy applies to the Services and to any other Create products and services that link to it.
2. Personal Information We Collect
Information you provide to us.
Account and profile information, such as your name, email address, password or single-sign-on identifiers, organization and workspace details, and preferences.
Payment and billing information, such as your name, payment card details, and billing address. Payment information is processed by our payment processor (currently Stripe), and we do not store full card numbers.
Agent instructions and content, such as the prompts, instructions, messages, files, and other materials you submit to or through your agents, and the configurations and code you (or your agents) create.
Secrets and credentials you choose to store for use by your agents, such as API keys, tokens, and login credentials. These are stored in secrets-management infrastructure and used as described in "Connected Accounts, Secrets, and OAuth" below.
Channel identities, such as the Slack handles, email addresses, and phone numbers used to reach you or your agents on each channel.
Feedback and correspondence, such as support requests and survey responses.
Information generated through your use of agents.
Transcripts and outputs: the conversations, tasks, tool calls, actions, and outputs of your agents.
Agent memory: information your agents store to maintain context and personalization over time.
Agent code and repositories: code and files created or modified by you or your agents in connection with the Services.
Sandbox and session data: data generated inside the cloud environments where your agents run, including browser sessions your agents operate.
Information from Connected Accounts. When you connect a third-party account (such as Slack, Google, GitHub, or other services) or provide credentials for your agents to use, your agents may access content and data from those accounts as authorized by you (for example, messages, emails, files, calendar entries, contacts, tickets, or records) to perform the tasks you direct. The "Connected Accounts, Secrets, and OAuth" section below describes this in detail.
Data about other people. Your agents may process personal information about people other than you, for example the senders and recipients of messages in accounts you connect, or contacts referenced in your files. We process that information on your behalf to provide the Services you direct; we do not use it to train models or for advertising; and we apply the same security and retention protections described in this Privacy Policy. If you believe an agent has processed your information at someone else's direction, contact us and we will refer the request to the responsible customer or handle it as required by law.
Automatic data collection. We and our service providers automatically log information about your use of the Services, including:
Device and usage data, such as operating system, browser type, IP address, unique identifiers, pages viewed, and interactions with the Services;
Network and security logs: network traffic to and from agent sandboxes may be routed through network controls that we operate, which may log request and response metadata and, where reasonably necessary for security, credential protection, debugging, and abuse prevention, content. To enforce the security rules you configure, automated systems that may include AI models may inspect the content of outbound requests; we use this inspection only to apply your rules and to detect and prevent abuse. Metering and billing rely on metadata rather than content. Content-level network logs are retained for no more than 30 days unless reasonably necessary for an active security investigation, billing dispute, or legal obligation;
Usage and metering records, such as model and compute consumption, message volumes, feature usage, and operational telemetry including agent execution traces, task trajectories, and tool-invocation records (these records exclude the contents of your communications, files, and outputs), which we use for billing, capacity, and service improvement;
Administrative and support activity, such as admin actions in a workspace and support interactions;
Cookies and similar technologies: we use cookies, local storage, and similar technologies to operate the Services, keep you signed in, remember preferences, and analyze usage. See "Cookies and online tracking" below for your choices.
Sensitive information. Operating AI agents means you may submit, and your agents may encounter, information that is sensitive, including credentials and secrets, private communications, code, files from connected accounts, and business-confidential material. By using the Services, you direct us to process this information to operate your agents as described in this Privacy Policy. Some of this information, including account credentials and authentication tokens, is "sensitive personal information" under certain U.S. state privacy laws. We collect it by design (it is how agents access your accounts), and we use and disclose it only for purposes permitted by those laws, such as providing the Services you request, security, and fraud prevention, not for advertising or profiling. Please do not submit sensitive personal information (such as health, biometric, or government-identifier data) unless it is necessary for your use case and permitted under your agreements and applicable law; where you do, we process it only to provide the Services.
3. Connected Accounts, Secrets, and OAuth
This section explains how Skydive handles access to third-party accounts you connect. It applies to every third-party service for which Skydive offers a connection, including services we add in the future.
How connections work. Skydive registers applications with third-party services (such as Slack and Google) so you can connect your accounts using OAuth, and also lets you store credentials for other services. When an agent needs access to a service, it requests the specific permission scopes it needs for your task. Access is granted only after you approve the request through the third-party provider's own authorization screen. Scopes may be read-only or read-write depending on the task; agents request scopes based on what you ask them to do, and you can decline any request.
What we access and why. Your agents access connected-account data solely to perform the tasks you direct, for example reading messages you ask an agent to triage, drafting documents, updating records, or sending communications you authorize. Each permission scope an agent requests maps to a user-facing feature: read scopes let the agent retrieve and work with the content you point it at, and write scopes let the agent draft, update, or send content you direct. Agents request the narrowest scopes available for the task. We do not access connected accounts for any purpose other than operating the Services at your direction, securing the platform, and complying with law.
Token and credential storage. OAuth tokens, API keys, and credentials are stored in secrets-management infrastructure with encryption at rest. For API-based connections, our systems are designed to inject credentials into requests at execution time through the network controls we operate, so that raw secrets are not exposed inside the agent's working context. Where you direct an agent to sign in to a website using stored credentials in its browser session, those credentials are necessarily used within that session; we isolate browser sessions and redact known credential patterns from logs.
Sharing. Connected-account data is shared only with the subprocessors needed to operate the Services (for example, transmitting the content you direct an agent to process to an AI model provider for inference), and is never sold or used for advertising. The routing limits that apply to this data, including the commitments in the Google user data and Slack data paragraphs below, are described in "AI model providers in detail" in Section 5 and in "AI, research, and model training" in Section 4.
Revocation and disconnection. You can review and revoke an agent's access to any connected account at any time, in full or for a single provider or scope, through the Services, and you can also revoke Skydive's access entirely from the third-party provider's own security settings. When you disconnect an account, we stop accessing it and delete the associated tokens. Data previously retrieved into your workspace (such as transcripts referencing it) remains subject to this Privacy Policy and your retention choices; you can delete it at any time through the Services or by contacting us, and it is deleted when you delete it or close your account, on the schedule described in "Retention" below.
Google user data. Skydive's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide and improve user-facing features of the Services that you request, is not used for advertising, is not used to train generalized AI or machine-learning models, and is transferred to third parties only as necessary to provide those features, for security, or to comply with law. The routing disclosures elsewhere in this Privacy Policy do not override this commitment. Google user data is never routed to a provider on terms that permit training.
Google data we access. The specific Google permission scopes an agent requests depend on what you ask it to do, and are limited to:
Google Calendar — read your calendars and events to answer scheduling questions and check availability, and create, update, move, or cancel events and secondary calendars when you ask Skydive to schedule or manage meetings, including applying your existing calendar sharing when you ask to share an event.
Gmail — read and search the messages you ask about, and draft, send, label, archive, or organize email at your direction, and manage settings such as filters, signature, or vacation responder when you ask.
Google Drive — find, read, and organize your files, and create or edit files at your direction. Skydive accesses only files you can already access, and only when you initiate the task.
Google Docs, Sheets, and Slides — read, summarize, create, and edit the documents, spreadsheets, and presentations you reference or ask Skydive to produce.
Google Forms — read your forms and their responses when you ask Skydive to work with them.
Google Contacts — look up contacts and your Google Account email addresses to resolve the people you name, and add or edit contacts when you ask.
Google Tasks — read your tasks and create or update them at your direction.
Consistent with the commitments above, this data is used only to perform the actions you request, is never used to train generalized AI or machine-learning models or for advertising, and you can revoke access at any time as described in "Revocation and disconnection."
Slack data. When you sign in with Slack or connect Slack, Skydive accesses Slack data as authorized by the OAuth scopes approved by you and, where applicable, your Slack workspace administrators, such as your Slack profile and user ID, the channels the agent is invited to, and the messages and files needed to perform the tasks you direct. Skydive uses Slack data only to provide the features you request. That includes transmitting relevant message content to our AI model providers to generate responses. Those providers are contractually prohibited from using it to train their models. We do not route Slack data to a provider on terms that permit training, and we do not use Slack data to train our own models. Slack data is stored only as needed for those features and is deleted as described in "Retention" below. You can disconnect Slack at any time from the Services or from your Slack workspace settings, and you can contact [email protected] with questions.
Questions. Contact [email protected] with any questions about connected-account data.
4. How We Use Personal Information
Service delivery. To provide, operate, maintain, secure, and improve the Services, including to: run your agents and execute the tasks you direct; route content to AI model providers for inference; operate sandboxes, browsers, and channels; store and apply agent memory and personalization; meter usage and process payments; provide support; and communicate with you about the Services.
Security, policy enforcement, and abuse prevention. To protect the Services, our customers, and third parties, including inspecting and filtering agent network traffic through the network controls we operate (using automated systems that may include AI models to evaluate outbound requests against the security rules you set), detecting compromised agents and credentials, enforcing our Terms of Service and policies, and investigating abuse.
AI, research, and model training. We may use your content to operate and improve the Services. This includes research and development, including using data to train, fine-tune, reinforce, or evaluate the models that power the Services. Training is on by default. You can turn it off at any time at the workspace or organization level. When a workspace or organization turns training off, that choice applies to all of its users. For enterprise customers, an Order Form may include a binding no-training covenant that supersedes these settings. We use commercially reasonable measures to de-identify data before training, and we do not try to re-identify it. For customers whose Order Form incorporates our DPA, the terms of the DPA apply. Whatever your data is classified as, and whether or not training is on, we will never use any of the following to train, fine-tune, reinforce, or evaluate a model: data accessed through the Google or Slack APIs, and any data to the extent derived from it; data accessed through any other connected account to the extent the applicable third-party service's terms prohibit that use; End User data; and Secrets. How data reaches or passes through our infrastructure, including the network controls described in Section 5 of the Terms, does not change these rules. We use content collected under an earlier version of this Privacy Policy for model development only as permitted by the version in effect when it was collected or after it has been de-identified.
Research and development. We use operational telemetry (such as agent execution traces and tool-invocation records) and other de-identified or aggregated information to evaluate and improve the Services. Information used this way is aggregated or de-identified so that it does not identify you, and we do not re-identify it. This does not include training our models on your content, which is governed by the training section above.
Marketing. We may send you product and marketing communications about the Services; you can opt out as described below. We do not use the contents of your agents, transcripts, or connected accounts for advertising.
Compliance and protection. To comply with applicable law and legal process; to protect our, your, or others' rights, privacy, safety, or property; to enforce agreements; and to prevent, investigate, and deter fraud and illegal activity.
5. How We Share Personal Information
Subprocessors and service providers. We share personal information with third parties that help us operate the Services, only as needed for them to perform their functions. We maintain our current list of subprocessors at skydive.com/subprocessors. For Order Form customers, enterprise notice and objection rights for new or replacement subprocessors are described in the DPA. As of the date of this Privacy Policy, our subprocessors and service providers include: sandbox and execution infrastructure (E2B; Vercel); AI model providers and routing (Anthropic; OpenAI; Google; xAI; OpenRouter; Vercel AI Gateway); agent tooling (Exa for web search; Pierre for agent code repositories); cloud hosting and storage (Amazon Web Services, including S3 and RDS); content delivery and DNS (Cloudflare); communication channels (Slack; AgentMail; Linq; Resend); analytics and error monitoring (Segment; PostHog; Sentry); billing and payments (Stripe; Metronome); and customer support (Intercom). Customer-selected third-party services with which you contract directly or for which you provide the connection or keys are not subprocessors and are addressed separately under Third-party services you connect below.
AI model providers in detail. When an agent runs, the content needed to generate a response is sent to the AI model provider handling the request. We identify in the Services which models we manage (the managed set). For the managed set, our agreements with those providers, or our routing configuration, do not permit them to train their models on your content. We reach these providers directly or through routing services such as OpenRouter and Vercel AI Gateway, configured to use providers that do not train on or retain your content. If you use your own provider keys or select a model outside the managed set, that provider's terms govern, and we cannot control or guarantee whether it trains on your data. Providers process data under their API terms and may retain it temporarily for security and abuse monitoring. Each request is processed in isolation. Your data is not visible to other customers. Whatever model or keys you select, we never route the categories of data described in "AI, research, and model training" in Section 4 to a provider on terms that permit training.
Third-party services you connect. When you connect an account or direct an agent to interact with a third-party service, you are instructing us to transmit relevant data to that service on your behalf. That service's own terms and privacy policy govern its handling of the data.
Workspace owners and administrators. If you use the Services in a workspace owned by an organization, that organization and its administrators may access your activity and content in the workspace.
Professional advisors. Lawyers, auditors, bankers, and insurers, in connection with professional services.
Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of the transaction, subject to this Privacy Policy.
Affiliates. Current and future affiliates of Create, consistent with this Privacy Policy.
Government authorities; legal process. Where required for the compliance and protection purposes described above.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
6. Legal Bases for Processing
If you are in the United Kingdom or European Economic Area (EEA), we process your personal information only when we have a legal basis to do so: (a) we need it to provide the Services under our contract with you, including operating your agents and connected accounts at your direction; (b) it satisfies a legitimate interest that is not overridden by your data protection interests, such as securing the platform, preventing abuse, improving the Services, and metering and billing; (c) you give us consent for a specific purpose; or (d) we need to process it to comply with a legal obligation. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
7. Cross-Border Transfers
Create is headquartered in the United States, and we store and process personal information in the United States and in other locations where we and our subprocessors operate. These jurisdictions may not provide the same level of data protection as your home jurisdiction. Where we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum (or successor mechanisms), and on adequacy decisions where applicable. You may request a copy of relevant safeguards by contacting us.
8. Your Rights and Choices
Personal information requests. Depending on where you live, you may have rights to: learn more about the personal information we process; access it; correct it; delete it; receive a portable copy; restrict or object to certain processing; opt out of certain disclosures; and withdraw consent where processing is based on consent. To make a request, email [email protected]. We will verify your request and respond as required by law; we may decline requests where retention is required (for example, security logs and billing records) or where an exception applies. If you use the Services through a customer's workspace, we may redirect your request to that customer, which controls workspace data.
In-product controls. You can delete agents, transcripts, memory, files, and secrets, and disconnect connected accounts, through the Services or by contacting us at [email protected]. Deleted content is removed from our active systems within 30 days and from backups on backup expiration.
Additional disclosures for U.S. residents. If you reside in a U.S. state with a consumer privacy law (such as California, Virginia, Colorado, Connecticut, or Texas), you have the rights described above to know, access, correct, delete, and obtain a portable copy of your personal information, and the right not to be discriminated against for exercising your rights. We do not "sell" personal information or "share" it for cross-context behavioral advertising as those terms are defined under applicable law, and we do not use or disclose sensitive personal information for purposes other than those permitted by law. Where required, we honor opt-out preference signals such as Global Privacy Control.
Additional disclosures for EEA and UK residents. You have the right to lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office). You may authorize an agent to exercise your rights on your behalf with written, signed permission.
Marketing opt-out. You may opt out of marketing communications by using the unsubscribe link in any marketing email or contacting us. We may still send you transactional and service communications.
Cookies and online tracking. Most browsers let you remove or reject cookies; doing so may affect Service functionality. You can also use privacy plug-ins or browser settings to limit tracking. We currently do not respond to "Do Not Track" signals, though we honor Global Privacy Control where required by law.
9. Retention of Personal Information
We retain personal information for as long as appropriate to fulfill the purposes for which it was collected, including providing the Services, complying with legal obligations, resolving disputes, maintaining security, and enforcing agreements. In general:
Account data and customer content (transcripts, memory, agent code, files) are retained for the life of your account, subject to your in-product deletion choices.
After account termination or cancellation, exportable content (including transcripts, agent memory, agent code, and files) is available for export for 60 days, and customer content is deleted from our active systems within 90 days of termination, except as noted below.
Secrets and OAuth tokens are deleted when you delete them, disconnect the account, or terminate your account, subject to backup cycles.
Network, security, and metering logs are retained for limited periods appropriate to security, abuse prevention, billing, and legal compliance: content-level network logs are retained for no more than 30 days (absent an active investigation, billing dispute, or legal obligation), and metadata, metering, and security logs are retained for up to 12 months.
Backups are retained for a limited period and deleted on expiration; billing and tax records are retained as required by law; and we may preserve information subject to a legal hold or as needed to protect rights and safety.
10. Security
We use organizational, technical, and administrative measures designed to protect personal information, including encryption in transit and at rest, secrets-management infrastructure with execution-time credential injection, sandbox isolation for agent execution, network controls that monitor and filter agent traffic, access controls, and logging. We are pursuing SOC 2 compliance. For purposes of this incident-notice commitment, the terms Personal Data Breach and Customer Personal Data have the meanings in the DPA. If we become aware of a Personal Data Breach involving Customer Personal Data, we will notify the affected customer without undue delay, and in no event later than forty-eight (48) hours after becoming aware of it, consistent with applicable law. We become aware of a Personal Data Breach when our incident response lead, security officer, or legal counsel knows of facts reasonably indicating that a Personal Data Breach has occurred; initial notice may be preliminary and will not be delayed pending a completed investigation. A Personal Data Breach includes a security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, including a compromise of its confidentiality, integrity, or availability. No system is completely secure; if you have reason to believe your interaction with us is no longer secure, notify us immediately at [email protected].
11. Children
The Services are not intended for, and may not be used by, anyone under 18 years of age. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it. Contact us if you believe a minor has used the Services.
12. Other Sites and Services
The Services contain links to and interoperate with websites, applications, and services operated by third parties, including the services your agents browse and act in. This Privacy Policy does not apply to third-party services, and we are not responsible for their practices. Review the privacy policies of services you connect or direct your agents to use.
13. Changes to This Privacy Policy
We may modify this Privacy Policy at any time. If we make material changes, we will notify you by email or prominent in-product notice before the changes take effect, and where required by law we will provide additional advance notice or obtain consent. Material changes to how we use previously collected personal information will not be applied retroactively without your consent. For other changes, we will update the date at the top of this page. Your continued use of the Services after the effective date constitutes acceptance of the updated Privacy Policy.
14. Contact Us
Please direct questions or comments about this Privacy Policy or our privacy practices to [email protected], or by mail to: Create, Inc., 214 Grant Ave, Suite 301, San Francisco, CA 94108.