Privacy Policy
Version 2026-09 · Effective 7 September 2026
Skillfull Inc runs the Skillfull learning platform at www.skillfull.com. This policy says what personal information we collect, why, who we share it with, where it goes, how we protect it, how long we keep it and what you can do about it. It describes what the software does today.
1. Who we are and what this covers
1.1 Skillfull Inc is incorporated in Delaware and operates from 114 Shadewell Dr, Danville, CA 94506. Our Employer Identification Number is 87-1902205.
1.2 This covers www.skillfull.com and its subdomains, our marketing website and the email we send. "Personal information" means information about an identified or reasonably identifiable individual. "Customer" means the organization or creator holding a subscription.
1.3 Two groups are covered. For customer staff who hold accounts, we decide what we collect and why, and answer to you directly. For learners a customer enrolls, we act on that customer's instructions under its privacy notice, not ours: it decides who is enrolled, what is recorded and who sees it. Ask it first to change a learner record.
2. What we collect, and where we get it
2.1 Account details: name, email address, alias, hashed password, profile settings, billing and organization details. What you create: courses, lessons, forms, files, videos, images, tickets and messages. Learning records: enrollments, progress, completion, due dates, cohorts, quiz and assessment attempts, results, certificates and, where assessment features are used, observation records, signed declarations, decisions and appeals. Live sessions: attendance, recordings, transcripts, speaker-attributed captions and chat. Technical records: an Internet Protocol (IP) address and browser user agent per sign-in, multi-factor secrets, your recorded acceptance of this policy, and analytics events.
2.2 Card numbers go straight to our payment processor; we never see or store one. Live session attendance is captured whether or not a person is signed in, and turning recording off stops neither attendance nor the transcript.
2.3 We get this from you, from the customer that enrolled you, from your use of the platform, from services a customer connects, and, for business development only, from business contacts published on company websites. Connecting Zoom brings meeting details, participant names and email addresses, recordings and transcripts, and stores that person's Zoom identifier, login email address, scopes and encrypted tokens. Where we send a named business contact a link to a preview page built for them, we measure how that page is read, including that it was opened, the time and the referring share address, a scrambled form of the browser user agent, how many seconds the page was open, how far down it was scrolled, how many sections were seen, and whether a video was played or a button clicked. Our sales team is alerted when that happens.
2.4 Sensitive information. Voice models, created only after we record who consented, when, from what address and browser, and when consent expires. Live session content, which can reveal almost anything unintentionally. And, where a customer uses our optional vocational training fields, date of birth, home address, disability and ethnicity indicators and a government-issued student identifier. That identifier is never our own identifier for a person, never printed on a certificate, and disclosed only to the customer that recorded it.
2.5 The same list, in the words California law uses. In the preceding 12 months we have collected the categories below. For each one, the sources are those in clause 2.3, the business purposes are those in clause 3.1, and the categories of recipients are those in clause 4. We have not sold or shared any of them, as clause 3.2 says.
- Identifiers. Name, alias, email address, account identifier and Internet Protocol address.
- The personal records category in California Civil Code section 1798.80(e). Name, postal address, telephone number, education and employment information.
- Protected classification characteristics. Date of birth, disability information and racial or ethnic origin, and only where a customer fills in the optional fields described in clause 2.4.
- Commercial information. Subscriptions, invoices, course purchases and refunds.
- Biometric information. Voice samples and the voice models built from them, and only where the speaker has consented.
- Internet or other electronic network activity. Pages viewed, analytics events, browser user agent, and the preview page measures in clause 2.3.
- Audio, electronic and visual information. Live session recordings, transcripts, captions, chat and images.
- Professional or employment-related information. Job role, employer, cohort and training completed.
- Education information. Enrollments, progress, results, certificates and assessment evidence.
- Inferences. Limited ones drawn from progress and completion records.
2.6 Of those, the ones California treats as sensitive personal information are racial or ethnic origin, biometric information in the form of voice models, and the contents of a live session. We handle the government-issued student identifier in clause 2.4 to the same standard.
3. Why we use it, and what we do not do
3.1 To run and secure the platform; to deliver what the customer asked for, including enrollment, reporting and export; to draft course material, images, transcripts and narration from what a customer supplies; to take payment; to support you; to see in aggregate which parts are used; to send service and marketing messages; and to meet legal obligations.
3.2 We do not sell personal information, share it for cross-context behavioral or targeted advertising, or profile learners for advertising, and have not in the preceding 12 months, so we have no actual knowledge of doing so for anyone under 16. Sensitive personal information is used only to run and secure the service and comply with the law.
3.3 We do not use one customer's content to train models for another customer or for ourselves, though provider terms are theirs to set.
3.4 Marking, and what a machine decides. Quizzes are marked against the answer key the course author wrote. One optional feature marks a written answer automatically: the answer and the author's rubric go to a text generation model, and the learner is shown a score and written feedback straight away, with no person looking at it first. An assessment decision, the formal kind that becomes evidence, records the person who made it by name. Where a customer has turned the practitioner register check on, the platform refuses a decision from someone the register does not back. In the setting we ship, the platform records the decision and flags it for review instead.
4. Who we share it with
4.1 The customer that enrolled you sees a learner's records, through the administrators, trainers and assessors it permits. These providers each receive only what their job needs:
- Amazon Web Services, Inc. Hosting, database, storage, email, speech to text, video processing, and text and image generation through Amazon Bedrock, using models from Anthropic, Amazon, Meta and Stability AI.
- Stripe, Inc. Payments, subscriptions, invoicing, refunds, payouts and tax calculation.
- Zoom Communications, Inc. Live meetings, recordings and transcripts. Provisioning a host seat sends Zoom that person's name and email address.
- OpenAI, L.L.C. and ElevenLabs Inc. Narration turned into audio; ElevenLabs also holds voice models built from consented samples.
- Cloudflare, Inc. The automated abuse check on our sign-in, registration and contact forms.
- Google LLC and Vimeo, Inc. Outbound email on some routes, and video metadata lookups. Migadu, a Swiss company, hosts our own mailboxes on servers in Europe.
- Slack Technologies, LLC and GitHub, Inc. Internal operational and error alerts, which can name an organization. Slack also receives a person's name and email address when they create an account or send us a message through a form on our website, so that a real person picks it up.
4.2 Where a course carries continuing education credit we send the awarding body the learner's account email address, the credited activity number and the completion date. Today that is the Federal Aviation Administration WINGS Pilot Proficiency Program, and no other registry is enabled unless a customer asks.
4.3 We also share to a destination a customer nominates, which is then its responsibility; with our lawyers, accountants and insurers; with an acquirer, subject to this policy continuing to apply; and on valid legal process.
5. Where it is stored
5.1 We keep the database, files, videos, transcripts and backups in Amazon data centers in the United States, in the US East (Northern Virginia) region. Image generation runs in Amazon's US West (Oregon) region. Text generation goes through Amazon's global routing, which Amazon may serve from outside the United States, and that text can include course content, a transcript or a learner's typed question.
5.2 Skillfull Inc operates from the United States and stores this deployment's data there. If you use the platform from another country, your information is transferred to and processed in the United States, where privacy laws differ from the laws of your own country. Live session audio does not leave our network: the platform refuses to start unless the speech recognition service is at an internal address in our own infrastructure. Our providers are United States companies except Migadu, and for learners in Europe or the United Kingdom we agree a separate written transfer arrangement with the customer.
6. Cookies, browser storage and marketing email
6.1 We run no advertising tags, no pixels and no cross-site tracking, which is why you see no cookie banner. The cookies we set are these: one that keeps you signed in for eight hours after your last activity; one that protects forms against cross-site request forgery; one that authorizes private video playback; one that admits an invited guest; and, on a personalized preview page we send to a named business contact, one that ties that reader's visit to the page so we can record how it was read, as clause 2.3 describes. That last cookie is our own, is readable only by our server, and lasts six hours. Our abuse check provider may set one of its own. Your browser also stores an appearance preference and an analytics session identifier.
6.2 Do Not Track and Global Privacy Control. Since we do not sell or share personal information or do behavioral advertising, an opt-out preference signal has nothing to switch off, and we do not currently act on one. If that changes, we will honor those signals and say so here first.
6.3 Service email about security, billing, enrollment and this policy cannot be turned off while you hold an account. Marketing email can be, through the unsubscribe link every message carries. Our marketing email is meant to carry our name and postal address beside that link as well. That text comes from a configuration setting the software does not check at startup, so the only thing we can promise in every message is the unsubscribe link itself.
6.4 When you unsubscribe we add your address to a do-not-contact list and stop emailing you. That list holds your address in plain text, because matching it against the next send is what makes the opt-out work. Only a scrambled form of the address passes between our regions, so an opt-out in one region is honored in the others without the plain address leaving the region you dealt with.
7. How we protect it
7.1 This clause states what our systems do. We hold no security certification and claim none. Traffic uses Transport Layer Security. A password set or changed on our current scheme uses PBKDF2 (Password-Based Key Derivation Function 2) with SHA-256, 600,000 iterations and a unique salt, so we cannot read yours; a password still stored under our older scheme is upgraded to the current one the next time its owner signs in. Tokens for connected services use AES-256-GCM (Advanced Encryption Standard, 256 bit key, Galois/Counter Mode), and the platform refuses to store a secret if the key is missing.
7.2 The database is encrypted at rest with a customer-managed key in Amazon Key Management Service with rotation on, has no direct route from the internet, and keeps automated backups for 35 days. Multi-factor authentication is available but off by default. Sessions can be revoked, and changing a password ends every session. A web application firewall with managed rules and rate limiting sits in front of the platform, access is by role, and sign-ins, administrative actions and billing events are written to audit records.
7.3 Three limits worth stating. Files, videos and transcripts rely on the encryption Amazon applies by default, with no separate customer-managed key, and material meant to be public, such as cover images, is readable by anyone with the link. Names, email addresses, learning records, transcripts and captions sit in plain text in the database, because the application must read them. Support and system administration staff can view the platform as one of your users to investigate a fault; that is written to our audit records. An administrator can read their own organization's audit log inside the platform, but a support sign-in is recorded against us rather than against your organization, so it is not yet shown to you there.
8. How long we keep it
8.1 Courses, videos, transcripts, learning records, assessment evidence, attendance and certificates do not expire, and nothing deletes them on a schedule. Training records often fall under a customer's own record-keeping obligations, which can run for years, so we keep them until the customer says otherwise. Canceling a subscription stops billing but deletes nothing. An administrator can export the organization's data for 30 days after a subscription ends. After that we keep it until an authorized administrator asks us in writing to delete it, which we do by hand. We run no job that deletes a former customer's content after a fixed period, and we do not want to publish a period we have not built.
8.2 An account holder can request deletion from their profile. It waits 30 days, can be canceled in that time, then runs automatically. Deletion makes the record anonymous rather than erasing it: the email address becomes a non-deliverable placeholder, the name becomes "Deleted User", credentials, sessions and settings are cleared, and your name and email address are redacted from tickets, messages, attendance records and live session invitations. In a session transcript the words stay while the link to you goes.
8.3 Deletion has known gaps. It does not reach files, videos and transcripts in file storage. It does not reach the copies our providers hold: we send no automatic deletion instruction to a provider, but will help you ask. It does not reach a platform invitation sent to you, which keeps the name and email address it was addressed to. And it does not reach our sign-in records or our analytics events, which keep an Internet Protocol address and a browser user agent against your account; deletion revokes the sessions but leaves those rows, and we clear them by hand.
8.4 We refuse deletion where a person is recorded as having made assessment decisions about other learners and no separate practitioner record explains them.
8.5 Fixed periods we apply: backups 35 days, previous versions of stored files 90 days, application logs one week. Anything deleted from the live database stays in backups until they roll off. Analytics events have no automatic deletion today; we will publish a fixed period here once that is automated. Disconnecting Zoom revokes our access at Zoom and erases the stored tokens, Zoom user identifier, login email address and scopes. Removing our app from inside your Zoom account does the same: Zoom tells us, and we erase them. Either way, recordings, transcripts and courses already imported are left alone.
9. Your rights and how to use them
9.1 Which state privacy statute applies to us turns on our revenue and on how many residents of that state we handle data about, and those figures change. Rather than make you work it out, we give these rights to any United States resident we can identify. You may ask us to tell you what we hold about you, its categories, sources, purposes and categories of recipients; give you a copy in a portable format; correct what is wrong; delete it, subject to clause 8; opt out of any sale or sharing and of targeted advertising, none of which we do; limit the use of sensitive personal information; and appeal our decision. Nevada residents may direct us not to sell covered information, which we do not do.
9.2 Write to support@skillfull.com or to the postal address in clause 11. There is no form and no required wording. Your account settings also let you see, export and request deletion of your own data, and an administrator with the export permission can export the organization's records, with passwords, tokens, keys and stored credentials permanently excluded. If an organization enrolled you, ask it first; if you come to us, we pass the request on and act on its instruction unless the law requires otherwise.
9.3 Authorized agents. You may use an authorized agent to make a request for you. We will ask the agent for written proof of its authority, such as a permission signed by you or a power of attorney, and we may ask you to confirm the authorization with us directly. We may also verify you yourself, as clause 9.4 describes.
9.4 Before acting we take reasonable steps to confirm you are that person or are authorized to act for them, usually by your replying from the address on the account. We ask for no more than we need to verify you, and we use what you give us for that and nothing else. We acknowledge within 10 business days and answer within 45 days, telling you beforehand if we need longer. We may decline where the law allows, where we cannot verify you, where the record is the assessment evidence in clause 8.4, where acting would reveal another person's information, or where a request is manifestly unfounded.
9.5 Appeal by replying to our answer: a different person reviews it, gives written reasons, and tells you how to complain to your state attorney general if we uphold the refusal. We will not deny you the service, charge you a different price, give you a worse standard of service, or treat you differently as an applicant, a student or an employee because you exercised a privacy right.
10. Children, incidents and changes
10.1 Skillfull is a workplace and professional training platform, not directed to children under 13, and we do not knowingly collect personal information from one. If we learn we hold it without the consent federal law requires, we delete it and tell the customer that uploaded it. Customers must not enroll learners under 13 without a separate written agreement covering verifiable parental consent or school authorization.
10.2 We record, triage and alert on operational incidents, but we have no automated breach assessment or notification workflow: handling a breach is a manual process. Where we hold personal information for a customer we will notify that customer without undue delay once we know of a breach affecting their data, as California law separately requires of anyone holding personal information it does not own. Where the law requires notice to individuals or a regulator we give it in the period and form that law requires. We publish no fixed number of hours, because a deadline published and then missed is both a broken promise and a separate legal problem.
10.3 For a complaint, tell us first at support@skillfull.com. We acknowledge it, investigate, and answer in writing within 30 days. If that does not satisfy you, escalate to your state attorney general, to the Federal Trade Commission at reportfraud.ftc.gov, or, if you are a California resident, to the California Privacy Protection Agency at cppa.ca.gov.
10.4 We review this policy at least once every 12 months and update it whenever our practices change. The version and effective date at the top tell you which version you are reading. We give at least 30 days notice by email before a material change takes effect, including when we add or replace a service provider handling personal information, and ask you to accept a new version at your next sign-in.
11. How to contact us
11.1 By email: support@skillfull.com, which is also where to report a suspected security vulnerability, marked as such in the subject line so it reaches our engineers quickly. By post: Privacy Contact, Skillfull Inc, 114 Shadewell Dr, Danville, CA 94506. We do not run a telephone line for privacy requests, so we have not published a number nobody would answer. We aim to respond promptly.