Privacy Policy
Anbu Corp., doing business as Sky (“Sky,” “we,” “us,” or “our”), provides a macOS sales assistant that helps authorized business users work with email, customer relationships, sales calls, calendars, files, follow-ups, and related workflows. This Privacy Policy explains what information Sky processes, why we process it, the service providers involved, how information is protected, and the controls available to customers and users.
This Policy applies to Sky’s desktop application, websites, APIs, support interactions, and other services that link to it. It does not govern a third-party service’s independent processing under that service’s own terms and privacy policy.
1. Our role
For content submitted to or synchronized with a customer workspace (“Customer Content”), Sky generally acts as a service provider or processor on behalf of the organization that controls the workspace (“Customer”). The Customer decides which users and accounts to connect, which features to enable, and the business purposes for which Sky is used.
Sky acts independently for limited account administration, website operation, billing, service security, fraud prevention, legal compliance, and direct support communications. If you use Sky through an employer or another organization, that organization may administer your workspace and its content. Questions about its practices should be directed to that organization.
2. Information we process
Account and workspace information
We process names, business email addresses, authentication identifiers, profile information, workspace membership, roles, invitations, preferences, device identifiers, and session information. Authentication is provided using Neon Auth and supported identity providers such as Google.
Connected email, calendar, file, and CRM services
When an authorized user enables an integration, Sky may process the information needed to provide that integration, including:
- Email messages, bodies, subjects, snippets, participants, headers, labels, drafts, attachments, and mailbox identifiers
- Calendar event titles, descriptions, attendees, times, locations, conferencing details, and related metadata
- File names, links, metadata, permissions, and file content deliberately accessed through an enabled feature
- CRM contacts, companies, deals, notes, stages, tasks, and activity history
- OAuth credentials and connected-account identifiers required to maintain the authorized connection
Calls, transcription, and Signals
When call features are enabled, Sky may process participant information, live or completed transcripts, speaker labels, notes, summaries, Signal events, relationship facts, objections, next steps, and follow-up drafts. Raw call audio is not durably retained by Sky by default. Audio may be transmitted transiently to an approved speech-processing provider to produce transcription or voice output.
The Signals event ledger records operational metadata such as workspace and call scope, timing tier, safe move category, confidence, lifecycle outcome, and opaque source identifiers. It does not store raw audio or transcript text as a Signal event, and routine product analytics do not receive rendered Signal text.
The user controls when call listening, transcription, or Signals are active and can stop it. The Customer and user are responsible for providing any legally required notice and obtaining any legally required consent from call participants. A pause or stop prevents new capture and provider work after the control takes effect; it cannot recall data already transmitted for processing before that boundary.
Relationship and sales records
Sky may create Customer Content derived from enabled sources, including contacts, customer profiles, relationship history, summaries, rapport, objections, deal context, next actions, reminders, playbooks, CRM suggestions, and provenance showing where a fact came from.
Prompts, outputs, and approved actions
We process prompts, instructions, relevant workspace context, generated outputs, user edits, approvals, and audit records necessary to provide AI assistance. Outbound communications and covered external or CRM actions require user confirmation before execution.
Device and local context
Sky uses macOS permissions such as Accessibility, Screen Recording, and Microphone only when enabled by the user. Raw screen capture remains local by default and is not continuously streamed to Sky. Local context may include application names, window titles, accessibility text, OCR, and screenshots. When a user deliberately invokes a feature that requires server-side processing of local context, Sky transmits the context needed to answer that request or perform that feature.
Session credentials are stored in the macOS Keychain. Local context and audit information are subject to the controls and retention behavior presented in the application.
Usage, security, and support information
We process feature usage, request counts, timestamps, connection status, subscription tier, application version, performance information, security events, error codes, and audit records to operate and protect the service. If you contact support, we process your communications and any information you deliberately provide.
Billing and website information
Our payment provider processes payment method and transaction information. Sky receives subscription status, invoices, and limited billing metadata, but does not store complete payment-card numbers. Our website may process device, browser, referral, pageview, and download-event information through limited analytics tools.
If you join the Field Notes mailing list, we process the email address you provide together with the signup source, consent version, subscription status, and relevant timestamps. We use this information only to deliver the updates you requested, administer the list, and honor opt-out requests.
3. How we use information
We process information to:
- Provide the inbox, calls, CRM, calendar, file, search, Signals, drafting, and AI features requested or enabled by users
- Authenticate users and enforce workspace permissions
- Synchronize and act through authorized connected services
- Generate user-facing summaries, recommendations, drafts, relationship memory, and sales assistance
- Execute confirmed actions and preserve appropriate audit and undo history
- Maintain availability, troubleshoot failures, prevent abuse, and protect customers and the service
- Provide support, administer subscriptions, and communicate with users
- Send requested Field Notes or marketing updates and maintain subscription preferences
- Comply with applicable law and enforce our agreements
Sky does not sell Customer Content, use Customer Content for targeted advertising, or use Google Workspace information for credit decisions or unrelated profiling.
Sky does not use Customer Content to train a generalized AI model. We use business or API offerings from AI providers and require them to process Customer Content only to provide the requested service, subject to their applicable data-processing terms.
4. Google Workspace information
Sky uses Composio as an integration service provider to connect authorized Google Workspace accounts, including Gmail, Google Calendar, and Google Drive. When a user connects a Google account, Composio may facilitate the OAuth authorization process, store and refresh OAuth credentials, and transmit authorized requests and results between Google and Sky.
Depending on the enabled feature, information processed through Composio may include email content and metadata, calendar information, Drive file information, attachments, and actions the user directs Sky to perform. Sky and Composio process this information only as necessary to provide user-facing features requested or enabled by the user.
Sky’s use and transfer of information received from Google Workspace APIs will adhere to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.
Human access to Google Workspace information is prohibited except when the user has given documented consent for support involving specific information, when access is necessary for security or abuse investigation, or when legally required.
5. AI and speech providers
Sky sends approved AI, embedding, transcription, or voice providers only the information reasonably required to provide the feature requested by the user. Depending on the feature, this may include prompts, email excerpts, transcripts, CRM context, files, or transient audio.
When call listening and live notes are enabled, Sky may send bounded excerpts of final call transcripts to an AI provider, including OpenAI, during the call to extract evidence-linked notes. This processing is separate from Signals: Signals’ pushed Instant and Beat decisions do not use a generative model. Raw call audio is sent only to the enabled speech provider and is not used as the live-notes model input.
AI-generated content may be inaccurate or incomplete. Sky requires user review and confirmation before sending communications or completing covered external actions. We do not place raw Customer Content in advertising systems or routine product analytics.
Speech-provider processing and retention are governed by the enabled provider, selected processing region, account controls, and applicable agreement. Sky does not treat a model name alone as a retention promise and does not claim provider-side zero retention unless the corresponding account and contractual controls have been verified.
6. Service providers and disclosures
We disclose information only as needed to operate Sky, at the Customer’s direction, for security, in a corporate transaction subject to appropriate protections, or when legally required. Depending on the features enabled, our service providers may include:
- Neon for database infrastructure and authentication
- Fly.io for application hosting
- Amazon Web Services for key management and infrastructure
- Composio for connected-service authorization and API execution
- Google for authentication and enabled Gmail, Calendar, and Drive features
- AI providers, including OpenAI and other providers enabled for a requested feature
- Speech providers, including AssemblyAI, ElevenLabs, or Deepgram when enabled
- People Data Labs for optional business-contact enrichment
- Stripe for subscription and payment processing
- PostHog and Vercel for limited website or product analytics when enabled
A provider receives only the information needed for its function. We require providers that process Customer Content for us to protect it and limit their use contractually. Customers may request current information about subprocessors by contacting us.
We may disclose information when we reasonably believe disclosure is necessary to comply with law, respond to valid legal process, protect the safety or rights of users or others, investigate abuse, or protect the service. Where legally permitted, we will direct governmental requests to the Customer or notify the Customer before disclosure.
7. Security and access
Sky uses safeguards designed for the sensitivity of Customer Content, including encryption in transit, workspace authorization, tenant-scoped access controls, secure credential handling, audit records, and application-layer envelope encryption for protected content before durable production database storage.
Protected content is encrypted using authenticated encryption. Workspace and data-domain keys are protected separately using AWS Key Management Service and are unavailable to Postgres. Production is designed to fail closed rather than persist protected content without the required encryption. Ordinary database-console, SQL, dump, or backup access should therefore expose ciphertext and operational metadata, not readable Customer Content.
Sky’s authorized application runtime temporarily decrypts content when necessary to serve an authorized user or perform an enabled feature. Sky is therefore not a zero-knowledge or end-to-end-encrypted service. A compromised production runtime or a person able to deploy arbitrary production code could technically access content while the service uses it.
Sky does not provide employees or contractors with a routine content browser. Exceptional access is limited to what is necessary for documented support, security, or legal purposes and is subject to access controls and logging. No system is perfectly secure. Report suspected vulnerabilities to waseem@sky.bz.
8. Retention, disconnection, and deletion
We retain information only while reasonably necessary to provide the service, satisfy the Customer’s instructions, maintain security, resolve disputes, or meet legal obligations. Retention depends on the information and the workspace’s configuration:
- Account and workspace information: retained while the account or workspace is active and then deleted or de-identified, subject to legal and operational requirements
- Customer Content: retained until deleted by an authorized user, the workspace is deleted, or an applicable retention setting or agreement requires deletion
- Raw call audio: not durably retained by Sky by default
- Local screen context: retained on the user’s Mac according to in-app controls and local storage behavior
- Security and audit records: retained for the period reasonably needed to protect the service, investigate incidents, and meet accountability obligations
- Billing records: retained as required for accounting, tax, fraud prevention, and legal compliance
- Mailing-list information: retained while subscribed and afterward only as needed to preserve an unsubscribe or consent record
Disconnecting an integration stops future authorized access but does not necessarily delete Customer Content already created or synchronized into Sky. An authorized user must use available deletion controls or request workspace deletion to remove retained copies and derived records.
Self-service account deletion removes the individual account and, where the individual is the sole member of a workspace they own, the associated workspace data. An owner of a workspace with other members must transfer ownership or remove those members before deleting the workspace. Removing one user from a shared workspace does not delete information controlled by that workspace.
Deletion removes information from active systems without undue delay. Residual encrypted copies may remain temporarily in backups, security records, or disaster-recovery systems until overwritten through their normal lifecycle, unless longer retention is legally required. We do not restore deleted Customer Content from backup except when necessary for disaster recovery and subject to reapplying the deletion.
9. Your choices and rights
Depending on your relationship with Sky and applicable law, you may:
- Access, correct, or update your account information
- Disconnect a connected service or revoke provider permissions
- Pause local capture, call processing, or microphone access
- Delete individual records, local context, or your account
- Request access, export, correction, deletion, or restriction of personal information
- Withdraw consent where processing depends on consent
- Unsubscribe from Field Notes and other marketing updates at any time
- Object to certain processing where applicable
- Complain to the applicable privacy regulator
If your information is controlled by a Customer workspace, submit your request to that Customer first. We will assist the Customer with verified requests as required by contract and law. We may need to verify identity and authority before completing a request.
10. International processing
Sky and its service providers may process information in Canada, the United States, and other countries where they operate. Those countries may have privacy laws different from those where the user or Customer is located. We use contractual and technical protections appropriate to the information and applicable law.
11. Legal bases where required
Where applicable law requires a legal basis, we process personal information to perform a contract, at the Customer’s documented direction, with consent, for legitimate interests such as operating and securing the service where those interests are not overridden, or to comply with law.
12. Children
Sky is a business service and is not directed to anyone under 18. We do not knowingly permit children to create accounts or intentionally collect their personal information through the service.
13. Changes to this Policy
We may update this Policy to reflect changes in the service, providers, or law. We will post the revised version and update the date above. We will provide additional notice before a material change takes effect where required by law or contract.
14. Contact
Anbu Corp., doing business as Sky, is responsible for the privacy practices described in this Policy.
Privacy questions and data requests: waseem@sky.bz
Security reports: waseem@sky.bz





