Privacy Policy

Our Privacy Policy was last updated on June 11, 2026.

This Privacy Policy applies to https://getskein.ai and the Skein service operated by Artificer Innovations, LLC ("Company," "we," "our," or "us"). It covers visitors to our public website, account holders, and subscribers.

Our commitment: we do not train on your memory

We do not use your thought content, embeddings, or other memory data to train AI models, ours or any third party's.

This commitment applies to everything you store in Skein, including text you capture, vectors we generate for search, and entities we extract to improve retrieval.

Who we are

Artificer Innovations, LLC is the data controller for Skein.

Artificer Innovations, LLC
Email: support@getskein.ai
Phone: +1-425-522-3038
Mailing address: Artificer Innovations LLC, 522 W Riverside Ave Ste N, Spokane, WA 99201, United States

What Skein is

Skein is a personal AI memory service. It lets you capture, search, and recall thoughts across connected AI tools via the Model Context Protocol (MCP). Skein is not a general-purpose cloud storage or file-hosting product.

You can browse our marketing pages and learn about Skein without creating an account. An account is required to capture and store memory and to connect AI clients.

Information we collect

Website visitors (no account required)

When you visit our public website, including the landing page, pricing information, and (in the future) documentation or help content, we may collect:

Information you voluntarily provide

  • Waitlist or marketing signup: email address and any information you submit on a waitlist or contact form
  • Support inquiries: name, email, and message content if you contact us

Technical information collected automatically

When you interact with our Site, our hosting infrastructure and application may collect non-personal or technical information such as:

  • Browser name and version
  • Device type and operating system
  • Internet service provider
  • IP address
  • Pages visited, links clicked, and time spent on pages
  • Referring website or campaign information
  • Error and performance diagnostics (see Sentry below)

You may visit many parts of our Site without providing personal information. We collect personal information from visitors only when you voluntarily provide it (for example, joining a waitlist or emailing support). Choosing not to provide personal information may prevent you from using account-based features, but you can still read our marketing pages.

Account and authentication

When you create an account or sign in, we collect information needed to authenticate you and operate your account, such as your email address, authentication identifiers, and (if you use Google sign-in) basic profile information provided by Google through Supabase Auth.

We record when you accept our Terms of Service, Privacy Policy, and Refund Policy at signup (timestamp and policy version in your account metadata).

Your memory data

To provide the service, we store:

  • Thoughts: text content you capture through the web app, mobile app, MCP clients, import, or other supported surfaces
  • Embeddings: vector representations of your thoughts used for semantic search
  • Entities: structured information extracted from thoughts at capture time (for example, people or topics) to improve retrieval
  • Namespaces: labels and organization you assign to group thoughts
  • Capture metadata: such as capture time, source (web, MCP, import, etc.), and optional connection labels

MCP connections

When you connect an AI client through OAuth consent, we store MCP connection metadata, including the OAuth client identifier, the connection label you choose, and timestamps for creation, revocation, and last use. We also maintain an MCP access log recording which tools were called and when, for security and abuse prevention.

When you approve MCP OAuth consent, we record that you agreed to our policies and authorized access (timestamp, policy version, and client identifier in your account metadata).

Billing and usage

If you subscribe to a paid plan, we process billing information through Stripe (payment method details are held by Stripe, not stored directly by us). We record subscription status, plan tier, and usage metering (for example, thought captures and storage counts) to enforce plan limits.

Email marketing

If you join our waitlist, sign up for product updates, or otherwise opt in to marketing communications, we sync your email address and relevant tags (for example, waitlist status or plan interest) to Kit (ConvertKit), our email marketing provider, so we can send onboarding messages, product updates, and promotional emails. You can unsubscribe using the link in any marketing email.

Transactional emails are separate from marketing opt-in:

  • Account emails (signup confirmation, password reset, email-change notices): sent by Supabase Auth using Resend as the SMTP delivery provider
  • Waitlist invite emails: sent through Resend
  • Billing receipts: sent by Stripe for paid subscriptions

Support communications

If you contact us, we collect the information you provide in your message and any correspondence needed to resolve your request.

How we use your information

We use the information above to:

  • Operate Skein: capture, store, search, and retrieve your memory
  • Generate embeddings and extract entities to power semantic search
  • Fulfill MCP tool calls from clients you have approved
  • Process subscriptions and enforce usage limits
  • Send product, onboarding, and marketing communications (with unsubscribe options where required)
  • Maintain security, prevent abuse, and troubleshoot issues
  • Respond to support requests
  • Comply with legal obligations

We do not sell your personal information.

Connected AI clients

When you approve an MCP OAuth connection, the connected client can read and write memory within the scope you grant (in v1, read/write access to your default-namespace memory). Thoughts captured via MCP may record which connection was used (for example, in a via field or metadata). You choose which clients to connect and can revoke connections at any time from Settings → Connections.

We are not responsible for how third-party AI tools use memory they retrieve from Skein once you have granted access.

Third-party processors

We use trusted service providers to operate Skein. They process data only to provide services to us under our instructions:

Provider Role
Supabase Application database, authentication (email/password, Google OAuth, password reset, JWT issuance, refresh tokens, and MCP OAuth 2.1 authorization). On the web app, your Supabase session is stored in your browser's local storage on the Skein origin, not as a first-party HTTP cookie.
Amazon Web Services (AWS) Static website hosting and content delivery (S3 and CloudFront) for https://getskein.ai and related deploy environments. May process technical request data (such as IP address and browser user-agent) in CDN access logs.
OpenAI text-embedding-3-small for embeddings and gpt-4.1-nano for entity extraction at capture time
Stripe Payment processing, subscription management, and billing receipt emails
Resend Transactional email delivery (account confirmation, password reset, email-change notices, and waitlist invite emails). Supabase Auth uses Resend as its SMTP provider.
Kit Email marketing lists, tags, and campaign delivery (waitlist and product communications)
Sentry Error monitoring, performance tracing, and technical diagnostics for the web application
Plausible Analytics Anonymous web usage statistics (pageviews, referrer, device type, country) for the public web app; cookieless, no cross-site advertising tracking

We do not share your memory content with these providers for their own model training or unrelated purposes.

No model training

As stated above, we do not use your thoughts, embeddings, entities, or other memory data to train AI models, including models operated by us or by third parties. Our AI processors (such as OpenAI) are used solely to deliver features you request, such as search and extraction, under our contractual instructions.

Data retention

  • Active account data is retained while your account is open and as needed to provide the service.
  • Waitlist entries are retained until you are approved, converted, or request deletion, subject to our operational needs.
  • Deleted thoughts are hidden immediately when you soft-delete them. You can restore for at least 30 days via Settings → Recently deleted, mobile (when available), or MCP restore_thought. You may also permanently delete a tombstone anytime from Settings → Recently deleted before automatic cleanup. The recoverable window may be slightly longer than 30 calendar days because automatic permanent removal runs on the next daily cleanup after the retention cutoff (typically up to ~31 days).
  • After that cleanup, memory content is permanently deleted: thought body, embedding vector on the row, edit revisions, entity links, and processing queue rows.
  • A minimal deletion receipt (thought id, soft-delete and purge timestamps, channel, namespace name when known) remains in Settings → Deletion history until you delete your account; receipts do not include thought text.
  • Account closure: You may delete your account from Settings → Data. We encourage you to export your memory there first. When you request deletion, your account enters a 7-day inert period: you cannot sign in or use MCP/API, active shares and credentials are revoked, and your thoughts are not accessible through the product. Memory rows remain stored until hard deletion, which typically runs within about 24 hours after the 7-day period ends (daily automated job). During the inert period, recovery is operator-only — contact support@getskein.ai if you need to cancel deletion. After hard deletion, your thoughts, deletion receipts, and other account data are removed from active systems; connected services such as Kit are updated where applicable. We retain a minimal audit record (request identifiers, timestamps, and your account email snapshot; no thought content) for compliance. If you cannot access your account, email support@getskein.ai to request deletion.
  • Backups: Like most hosted services, encrypted database backups and point-in-time recovery may retain copies of deleted data for a limited operational window before those backups rotate. We use backups only for disaster recovery and integrity, not to restore deleted content to active use.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your personal information.

Export

You can export your memory at any time from Settings → Data. Exports use the Skein-native JSON format (skein-export v1) and include your thoughts, namespaces, capture metadata, and entity snapshots. Embeddings are not included in exports (they can be regenerated on import). Export is available on every plan, including Free.

Deletion

You can delete individual thoughts from the app (soft-delete). Restore them within 30 days from Settings → Recently deleted, or permanently delete a tombstone there anytime. To delete your entire account, use Settings → Data → Delete account, or email support@getskein.ai if you cannot sign in.

Marketing opt-out

You can unsubscribe from marketing emails using the link in any Kit message, or contact us at support@getskein.ai.

Other rights

EU/UK users may have rights under GDPR (including access, rectification, erasure, restriction, portability, and objection). California and other U.S. state residents may have additional rights under applicable privacy laws. We process your data primarily to perform our contract with you (providing Skein) and for legitimate interests such as security and fraud prevention.

To exercise your rights, contact support@getskein.ai. We will respond within the timeframes required by applicable law.

International data transfers

Skein is operated from the United States. If you access the service from outside the U.S., your information may be transferred to, stored in, and processed in the United States and other countries where our processors operate.

Cookies and similar technologies

We do not use advertising cookies or sell data for cross-site behavioral advertising. We do not use third-party analytics trackers such as Google Analytics on the Skein web app. We do use privacy-focused usage analytics (see Usage analytics below) that do not use advertising cookies or cross-site tracking.

Strictly necessary storage

To keep you signed in, the web app stores your Supabase authentication session in your browser's local storage (not an HTTP cookie on our domain). This includes access and refresh tokens managed by Supabase Auth. Signing out removes this session data from your browser.

Functional storage

We use local storage for display preferences (such as light/dark theme) and session storage for short-lived sign-in flow state (for example, redirect-after-login, password-recovery flags, or legal-acceptance staging during OAuth signup). Session storage is cleared when you close the browser tab.

Third-party cookies during sign-in and payments

If you sign in with Google or complete Stripe checkout, Google and Stripe may set cookies on their websites during those redirects. Supabase (our authentication provider) may also use cookies on the authentication host during OAuth. Their use is governed by their respective privacy policies:

Error monitoring

We use Sentry to collect error reports, performance traces, and technical diagnostics when the web application fails or runs slowly. Sentry may use cookies or similar technologies subject to Sentry's privacy policy. We configure Sentry to hash user identifiers and avoid capturing IP addresses where possible.

Usage analytics

We use Plausible Analytics on the Skein web app to collect anonymous usage statistics such as pageviews, referrer, device type, and country. Plausible is cookieless and does not sell data for cross-site behavioral advertising. See Plausible's privacy policy for how they handle data.

Your choices

You can clear site data through your browser settings; doing so will sign you out. Blocking local storage will prevent the web app from maintaining a signed-in session.

Children's privacy

Skein is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us and we will take steps to delete it.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "last updated" date at the top of this page and may update the policy version identifier (currently 2026-06-11). Material changes may also be communicated through the service or by email where appropriate.

Contact us

Questions about this Privacy Policy or requests to exercise your rights:

Artificer Innovations, LLC
Email: support@getskein.ai
Phone: +1-425-522-3038
Mailing address: Artificer Innovations LLC, 522 W Riverside Ave Ste N, Spokane, WA 99201, United States


This Privacy Policy is effective as of June 11, 2026.