Legal
Privacy Policy
Last updated 21 August 2026
skuer is a retail shelf reporting service. This page describes what we collect from you, what we do with it, and how to get it back or have it deleted. It describes this service specifically — if something here is vague, treat that as a bug and tell us.
What we collect
- Your account. Email address and a password stored only as a salted hash. We never see or store your password itself.
- Your subscription. The brand name you asked us to track, your report schedule, and the identifiers Stripe gives us for your customer and subscription records.
- Your payment details are never sent to us. Card entry happens on Stripe's own checkout page. We receive a token and a status, not a card number.
- Server logs. Ordinary web-server records — IP address, user agent, timestamps, the URL requested — kept for security and debugging.
- What you type into the signup form, even if you never finish. If you type your email address and business name into our signup form and then leave without creating an account, we keep those two values so we can follow up with you. We capture them when you move out of the field — not as you type — and we never capture your password. Ask us and we will delete them.
- An email address you give us for a discount code. If you ask for a discount code on our home page, we store the address you typed so we can send you the code and, occasionally, write to you about the service. You never have to give it, you do not need an account to use the code, and you can ask us to delete it at any time by emailing us. We do not sell it or pass it to anyone but the provider that delivers the message.
- Anything you type into report chat. Your questions, and the contents of the report they are about, are sent to our language-model provider to answer them.
What we do not collect
We do not ask for, and have no use for, your sales data, your customer lists, or your distributor agreements. If you choose to send us a SKU or UPC file, we use it only to identify your products and you can ask us to delete it at any time. We run no session recording and no third-party analytics suite on this site — we do not record your keystrokes, your mouse, or a replay of your visit. We do keep the email address and business name you type into the signup form even if you do not finish it, which is described above. We do run Google’s advertising tag, on our public pages and your account page only — the Cookies section below sets out exactly where it runs and what it is for.
What the reports themselves read
Our reports are built by reading retailers' own public storefronts — the same product pages, prices and availability any shopper can see. That data is about products on shelves, not about people. We do not collect personal information about shoppers, store staff, or anyone else in the course of producing a report.
Cookies
We set a session cookie to keep you logged in and a CSRF token to stop other sites submitting forms as you. Both are strictly necessary and there is no way to use an account without them. Your light/dark theme preference, and whether you have already dismissed the discount offer, are stored in your browser's local storage and never sent to us.
We also run Google's advertising tag, which sets advertising cookies. It lets us tell whether someone who clicked one of our adverts went on to subscribe. It runs on our public pages and on your account page — and nowhere else. It is deliberately absent from your reports, your downloads and the rest of the application, so which retailers you look at, and when, is not shared with an advertising network.
We do measure which adverts lead to a subscription, and we do it from our own server rather than from your browser. When a subscription starts we tell OpenAI's advertising system that a purchase happened, along with the time, an internal reference, the amount, the plan, and a one-way cryptographic hash of your email address. A hash cannot be turned back into your address, but it can be matched against an address they already hold — so we treat it as information about you rather than as anonymous, and we are telling you about it here rather than calling it anonymised. We do not send your name.
Who else processes your data
| Processor | What it handles |
|---|---|
| Stripe | Payments, card data, subscription billing |
| Resend | Sending your scheduled reports and account email |
| Anthropic | Answering report chat questions and interpreting brand names at signup |
| OpenAI | Measuring which adverts lead to a subscription |
| Google Ads | Measuring which adverts lead to a subscription |
| Google Cloud | Hosting the application and storing your reports |
All six are US-based. Using skuer means your data is processed in the United States.
How long we keep it
Account and subscription records are kept while your account is open. Generated reports are kept so you can go back to them. Server logs are kept for a short operational window. When you close your account we delete your account record, your subscriptions and your reports; billing records that we are required to retain for tax and accounting purposes are kept by Stripe.
Your choices
You can ask us for a copy of everything we hold about you, ask us to correct it, or ask us to delete your account and its data. Email michael@skuer.ai from your account address and we will action it. Depending on where you live you may have additional rights under the GDPR or the CCPA; we apply the same process to everyone rather than gating it on where you are. We do not sell personal information and never have.
Security
Traffic is encrypted in transit. Passwords are hashed. Report downloads are served against single-purpose links rather than public URLs, and every page that could carry one tells search engines not to index it. No system is perfect; if you find a problem, please report it to michael@skuer.ai and we will treat it as urgent.
Changes
If we change this policy we will update the date at the top, and we will email you before any change that materially affects what we do with your data.