Data and privacy
Privacy
This notice explains how Skill Native handles information when you use skillnative.ai, the Skill Native practice platform, or a service connection supplied through it.
Last updated .
Information we handle
We handle information you or an authorised user provide to operate a practice: contact details, enquiries, messages, uploaded files, customer and work records, approvals, billing records, and instructions given to agents. We also handle limited technical records needed to secure, operate, diagnose, and account for the service.
Google Search Console data
Skill Native can provide a managed Google SEO connection. A practice enables it by granting the Skill Native Google identity access to an exact Search Console property; the practice never gives a Google password or OAuth credential to a Gadget.
The current connection requests only https://www.googleapis.com/auth/webmasters.readonly. It can read:
- the bound site or domain property and Skill Native’s permission level;
- search-performance dimensions and measures, including queries, pages, dates, countries, devices, search appearance, clicks, impressions, click-through rate, and average position;
- URL inspection and indexing information; and
- sitemap status and errors.
The provider connection is read-only. It cannot submit a sitemap or otherwise change a Search Console property. Each capability is bound to one practice and one site, and requests are checked against that boundary before they reach Google.
Skill Native uses this information to provide SEO search, analysis, monitoring, recommendations, and authorised practice workflows. We do not sell Google user data or use it for advertising. Skill Native’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Where information is processed
The Skill Native platform is hosted in Skill Native’s Cloudflare account. Practice state may be held in Cloudflare Durable Objects, content-addressed R2 storage, and permission-scoped search indexes. The managed Google refresh token is available only to a route-less provider Worker through Cloudflare Secrets Store; short-lived Google access tokens exist only in that Worker’s memory.
Cloudflare processes information to host and secure the service, and Google processes requests to its APIs. When an authorised practice task uses an AI model, the information needed for that task may be routed through Cloudflare AI Gateway to the model provider selected for the service. We otherwise disclose information only when an authorised customer directs us to, when a supplier must process it to provide the service, or when law requires it.
Retention and control
Practice records and Search Console observations are retained with the practice while they are needed to provide the service, preserve its audit history, meet security or accounting requirements, or resolve a dispute. The managed OAuth credential is retained until it is revoked or replaced. A practice can remove Skill Native from its Search Console property at any time and can ask us to disconnect its capability or delete associated practice data.
The Google account holder can also revoke the Skill Native OAuth grant from their Google Account. Revocation stops new API access; it does not by itself delete records already retained for the purposes above.
Your choices and rights
You can ask what personal information we hold about you, request a correction, or ask us to delete information that no longer needs to be kept. Where New Zealand’s Privacy Act 2020 applies, you may also exercise the rights it provides or raise a concern with the Office of the Privacy Commissioner.
Changes to this notice
We will update this page when the service or its use of data materially changes. The date at the top shows the latest published version.
Contact
Email callum@skillnative.ai for a privacy question, access or correction request, disconnection, or deletion request.