Skip to content

legal

Privacy Policy

Effective August 5, 2026

This policy explains what Skena Labs AB, organisation number 559285-0654 ("Skena Labs", "we"), collects, why, and what we deliberately never see. It covers the skena.ai websites, Skena accounts, the Skena Servant desktop app, the Servant companion app and its cloud relay, and Skena Cloud.

The short version: Servant is built local-first. Your automations, your conversations with the built-in local AI, your voice audio, and your secrets stay on your machine. We collect what we need to run your account, your subscription, and the relay that connects your phone to your desktop, and little else.

1. Who we are

Skena Labs AB, organisation number 559285-0654, is a company registered in Sweden. We are the data controller for the personal data described in this policy, except for data inside apps hosted on Skena Cloud, where we act as a processor on the app owner's behalf (see section 6). You can reach us at hello@skena.ai.

2. What this policy covers

  • The skena.ai websites, including the app.skena.ai dashboard.
  • Skena accounts.
  • The Skena Servant desktop app for macOS.
  • The Servant companion app for phones and the cloud relay that connects it to your desktop.
  • Skena Cloud, hosting for apps published with the Skena builder, and, when it launches, cloud-run Servant automations.

3. Data we collect

  • Account: your email address, an optional name, your password (stored only as a hash, we never see or store it in plain text), email-verification status, account role, plan tier, feature quotas, and account status (for example whether the account is suspended). Creating an account requires verifying your email address.
  • Sign in with Google (optional): if you choose it, Google shares your email address and a Google account identifier so we can create or link your account. We receive nothing else from Google.
  • Billing: payments are handled by Stripe. Card details are entered on Stripe-hosted pages and never touch our servers. We store only your Stripe customer reference and a snapshot of your subscription (status, plan, current period end).
  • Devices and the relay: when you pair a phone or computer, we store a device record, a device identifier, platform, a device name, its push-notification token (if you enable notifications), its trust status, and when it was last seen. Device access tokens and pairing codes are stored only as cryptographic hashes.
  • Webhook events: if you point an external service's webhooks at the relay, we store each event for up to 14 days so it can be delivered to your desktop even if it is briefly offline. Authentication and signature headers are discarded before the event is stored, only a small, non-sensitive subset of headers is kept with it.
  • Audit log: security-relevant account events (signup, verification, suspension, plan and quota changes) are kept in an append-only audit log.
  • Waitlist and support: if you join a waitlist we store your email address and nothing else. If you email us, we keep the correspondence.

4. What never leaves your device

Servant is local-first by design:

  • Conversations with the built-in local AI model run entirely on your machine. We never receive your prompts, outputs, files, or the contents of your automations.
  • Voice dictation is transcribed locally (by Whisper on your Mac, or Apple's on-device speech recognition in the native iPhone app). In the installed iOS web app, short microphone-audio windows travel over encrypted connections through the relay to your paired Mac for local transcription and are not stored by the relay.
  • Secrets and API keys you give Servant are encrypted at rest using your operating system's keychain and used locally. They are never sent to Skena Labs.
  • Your workspace, capabilities, workflows, schedules, notes, and local databases, lives in files on your Mac.

On first use, the desktop app downloads AI model files directly from their publisher (Hugging Face) to your machine. That request fetches the model file only; none of your data is included.

If you connect your own third-party coding agent (for example Claude Code, Codex, or OpenCode), your prompts go directly from your machine to that vendor under your own account and their privacy terms. We do not proxy, receive, or store that traffic.

5. What the relay can and cannot see

The relay exists so your phone can reach your desktop when they are not on the same network. It moves bytes between your devices; it does not run your automations.

  • Live traffic between your phone and desktop (commands, notifications, agent output, screen frames) is encrypted in transit (TLS) and routed in memory. It is not stored.
  • The remote screen-approval channel is additionally end-to-end encrypted between your desktop and your phone (an ephemeral key exchange with per-message encryption), the relay cannot read those frames.
  • Other relayed traffic is readable by the relay service only to the extent needed to route it. We do not log or store its content.
  • Webhook events are the exception: they are queued for up to 14 days for reliable delivery, as described in section 3.

6. Skena Cloud hosted apps, you own them, we host them

If you publish an app to Skena Cloud, that app's database, including any personal data of its own users, belongs to you. For that data you are the data controller and Skena Labs is your processor: we store and serve it on your behalf and do not use it for anything else. You are responsible for giving your app's users their own privacy policy.

  • Each hosted app runs in its own isolated database instance.
  • Backups are taken continuously and nightly to off-site object storage and are rotated out after roughly 30 days.
  • Traffic analytics for hosted apps come from aggregate edge metrics (request counts, countries, status codes) provided by our CDN. We do not inject analytics scripts, beacons, or cookies into your app.

7. Cookies, analytics & tracking

  • The skena.ai marketing site currently uses no analytics and no advertising trackers.
  • The app.skena.ai dashboard stores your session token in your browser so you stay signed in, that is all.
  • The companion app contains no trackers and declares no data collection in its App Store privacy manifest.

We may add a web-analytics provider (such as Google Analytics) to our websites in the future. If we do, we will update this policy, list the provider in section 9, and ask for your consent before any analytics cookies are set.

8. Why we process your data (legal bases)

  • To provide the services you signed up for, your account, subscription, the relay, and hosting (performance of a contract).
  • To keep the services secure and prevent abuse, hashed tokens, device approval, the audit log, quotas, and suspension (our legitimate interests).
  • To send you what you asked for, verification emails and waitlist updates (contract and consent).
  • To meet legal obligations, bookkeeping and tax records connected to payments.

We do not sell personal data, and we do not use your data to train AI models.

9. Who we share data with (subprocessors)

We share personal data only with the service providers below, and only for the purposes stated. We name the current provider for each role; we may switch to an equivalent provider and will keep this list current.

  • Stripe, payments, subscriptions, and invoicing. Receives your email address and payment details; Skena Labs never stores card data.
  • Cloudflare, DNS, TLS, and content delivery for our domains and hosted apps, custom domains, and the source of aggregate traffic metrics.
  • Hosting providers, our control plane, the relay, and Skena Cloud run on cloud infrastructure from established providers (currently Hetzner, DigitalOcean, or Google Cloud), hosted in the EU where practical.
  • Object storage, an S3-compatible provider holds off-site backups.
  • Resend, sends transactional email such as verification messages.
  • Apple, push notifications to the companion app are delivered through Apple's push service, which receives your device's push token.
  • Google, only if you choose "Continue with Google" to sign in.
  • Hugging Face, AI model files are downloaded by your device directly from Hugging Face; we send them nothing about you.

We disclose personal data to authorities only where the law requires it. If Skena Labs is involved in a merger or acquisition, personal data may be transferred as part of that transaction and this policy will continue to apply to it.

10. International transfers

We host in the EU where practical. Some providers (for example Stripe, Apple, Cloudflare, Google, and Hugging Face) may process data in the United States; those transfers rely on the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses.

11. How long we keep data

  • Account data: for as long as your account exists, then deleted.
  • Live relayed traffic: not stored.
  • Webhook events: up to 14 days.
  • Backups: rotated out after roughly 30 days.
  • Audit log: kept while relevant for security and as required by law.
  • Billing records: as long as Swedish bookkeeping law requires (currently seven years).
  • Waitlist emails: until the launch messaging you signed up for ends, or you ask us to remove you.

12. Your rights

Under the GDPR you can ask us to access, correct, delete, or export your personal data, to restrict or object to processing, and to withdraw consent you have given. Email hello@skena.ai and we will respond within a month. You can also lodge a complaint with the Swedish Authority for Privacy Protection (IMY, imy.se) or your local EU data-protection authority.

13. Security

  • TLS on every connection.
  • Device tokens and pairing codes stored only as cryptographic hashes.
  • A new phone or computer must be explicitly approved from an already-trusted device before it can connect.
  • Secrets encrypted with the operating system's keychain, on your device.
  • End-to-end encryption on the remote screen-approval channel.
  • Suspension and device revocation take effect immediately.

No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and the authorities as the GDPR requires.

14. Children

Our services are not directed to children under 16, and we do not knowingly collect their data.

15. Changes to this policy

We will post changes here and update the date above. For material changes we will notify you by email or in the product before they take effect.

16. Contact

Skena Labs AB, organisation number 559285-0654, hello@skena.ai.