This Privacy Policy describes how Skyline (by Airova Inc.) collects, uses, discloses, and protects information in connection with the Skyline platform available at skyline-portal.com and related services, including our website, web application, mobile-responsive interfaces, and APIs (collectively, the "Service").
This policy applies to:
- Account Holders — professionals, business owners, and team members who create a Skyline account;
- Signers/Recipients — clients, buyers, sellers, or other parties who receive a document via Skyline for review or signature, even if they never create an account; and
- Visitors — anyone browsing skyline-portal.com.
If you do not agree with this Privacy Policy, please do not use the Service.
1. Information We Collect
1.1 Information You Provide Directly
- Account information: name, email address, phone number, password, company/organization name, role, and profile details.
- Document and contract content: files, contracts, addenda, and related text you upload, prepare, or send through the Service, including the fields, clauses, comments, and notes you add to them.
- Signature data: your electronic signature, initials, typed/drawn signature images, and the metadata associated with signing (timestamp, IP address, device/browser information, and signing order) for each signer on a document.
- Identity verification data: if identity verification is enabled on a document, you or a signer may be asked to upload a government-issued photo ID and a live selfie/biometric scan. This is collected and processed through our identity verification sub-processor, Stripe Identity (see Section 3). We receive a verification result (verified/not verified) and limited identity attributes; we do not store raw ID images or biometric scans ourselves.
- Voice data: if you use voice notes or voice-command features, we capture the audio you record and a text transcript generated from it.
- Payment and billing information: billing name, address, and subscription plan. Card and bank details are collected and processed directly by our payment processor, Stripe; we do not store full card numbers.
- Communications: messages sent within the platform (e.g., to clients or team members), support tickets, demo requests, and sales inquiries.
- Client/contact records: information you add about your clients to manage deals and communications (e.g., name, email, phone, transaction details).
1.2 Information Collected Automatically
- Usage and engagement data: pages viewed, features used, time spent, clicks, document view/open events, and similar interaction data.
- Device and log data: IP address, browser type, operating system, device identifiers, referring URLs, and timestamps.
- Cookies and similar technologies: used for authentication (keeping you signed in), security (bot/fraud protection via Cloudflare Turnstile), and measuring site performance. See Section 5 (Cookies).
1.3 Information About Signers Who Are Not Account Holders
If you send a document to someone who does not have a Skyline account, we collect the minimum information needed to deliver and process the signing request: their name, email address, the document content, their signature, and audit-trail metadata (IP address, device information, timestamps). If identity verification is required for that document, the relevant identity data described in Section 1.1 also applies to them.
1.4 Information We Do Not Knowingly Collect
We do not knowingly collect personal information from children under 16. The Service is intended for business use by adults using the Service for professional or business purposes.
2. How We Use Information
We use the information described above to:
- Create and manage accounts, authenticate users, and provide customer support;
- Generate, send, route, sign, store, and certify documents and contracts, and produce audit trails and certificates of completion;
- Provide AI-powered features, including contract analysis, AI-assisted rewriting, auto-preparation of documents, and deal/risk insights (see Section 4);
- Transcribe and process voice notes/commands;
- Verify signer identity where requested by you or required for a transaction;
- Process payments, manage subscriptions, and administer billing;
- Send transactional communications (e.g., signature requests, reminders, notifications, receipts);
- Send product updates and marketing communications, where permitted, and in accordance with your preferences;
- Monitor, maintain, and improve the security, stability, and performance of the Service;
- Detect, investigate, and prevent fraud, abuse, and unauthorized access;
- Comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information, and we do not use the content of your documents to train our own machine-learning models.
3. How We Share Information
We share information only as described below. We do not sell personal information to third parties.
3.2 Other Parties to Your Transaction
If you send a document through Skyline, the other parties to that document (e.g., co-signers, counterparties, clients) will see the content and signatures relevant to that document.
3.3 Brokerage/Team Administrators
If your account belongs to an organization or team, designated administrators on that account may have visibility into your documents, clients, and activity within the team workspace.
3.4 Legal and Safety
We may disclose information if required by law, subpoena, or legal process, or where we believe disclosure is necessary to protect the rights, property, or safety of Airova, our users, or the public.
3.5 Business Transfers
If Airova is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections.
4. AI Features — How They Use Your Data
Skyline's AI-powered features (Auto Prepare, AI Rewrite, AI Intelligence/risk analysis, Deal Insights, and voice transcription) work by sending the relevant document text, clause content, or audio to our AI sub-processors (Anthropic and OpenAI, listed above) to generate output for you.
We do not authorize these providers to use your content to train their general-purpose models, and outputs are returned to you within the Service.
AI-generated analysis (risk flags, summaries, suggested edits) is provided for informational purposes only and does not constitute legal advice. You remain responsible for reviewing any document before sending or signing it.
5. Cookies and Similar Technologies
We use cookies and similar technologies for:
- Essential functions: keeping you logged in and securing your session;
- Security: bot and fraud detection (Cloudflare Turnstile);
- Analytics: understanding how the Service is used so we can improve it.
You can control cookies through your browser settings. Disabling essential cookies may prevent parts of the Service (such as staying logged in) from working correctly.
6. Data Retention
We retain personal information for as long as necessary to provide the Service and for legitimate business or legal purposes, including:
- Account data: retained while your account is active and for a reasonable period after closure for record-keeping and legal compliance.
- Signed documents, signatures, and audit trails/certificates of completion: retained for a period consistent with applicable statute-of-limitations and ESIGN/UETA/PIPEDA evidentiary requirements to preserve the legal validity and evidentiary record of executed agreements.
- Identity verification results: retained per our agreement with Stripe Identity and applicable recordkeeping requirements; we do not retain raw ID images/biometric data ourselves.
- Voice recordings: retained as needed to deliver the feature unless deleted earlier by the user.
- Skyline Convert files: uploaded bank statements and converted export files (QBO, OFX, IIF, CSV) are processed in your browser session and are not stored on our servers. Once your conversion is complete and downloaded, we do not retain a copy of the file — only a log entry (filename, format, and transaction count) is kept in your Convert history for your reference.
We may retain information longer where required by law, for dispute resolution, or to enforce our agreements.
Data Deletion
- Account deletion: If you delete your Skyline account, all associated personal information is erased immediately.
- Contracts & records: If you delete a document or record, it is removed from our systems immediately.
- Signed documents, signatures & audit trails/certificates of completion: retained for 2 years after execution as a convenience so you can access or re-download them, or deleted sooner at your request. You are responsible for downloading and retaining your own copies of any signed document you may need beyond this period.
7. Data Security
We have implemented appropriate technical, physical, and organizational measures to protect your personal information from misuse or accidental, unlawful, or unauthorized destruction, loss, alteration, disclosure, acquisition, or access — including encryption of data at rest and in transit, database-level access controls, and role-based permissions (e.g., agent vs. admin vs. signer access).
8. Your Privacy Rights
Depending on your location, you may have some or all of the following rights regarding your personal information:
United States
Where applicable state privacy laws apply (e.g., California, Colorado, Connecticut, Virginia, etc.):
- Right to know/access the personal information we hold about you;
- Right to request correction of inaccurate information;
- Right to request deletion of your personal information;
- Right to opt out of the sale or "sharing" of personal information for cross-context behavioral advertising (we do not sell personal information);
- Right to non-discrimination for exercising these rights.
Canada (PIPEDA)
- Right to access personal information we hold about you and request corrections;
- Right to withdraw consent for certain uses, subject to legal or contractual restrictions;
- Right to file a complaint with the Office of the Privacy Commissioner of Canada.
Other Jurisdictions
If you are located in a jurisdiction with its own data protection law (for example, the EU/UK GDPR, UAE data protection law, or Saudi Arabia's PDPL), you may have similar rights to access, correct, delete, or restrict processing of your personal information, and to lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us using the details in Section 10. We may need to verify your identity before fulfilling a request.
9. Children's Privacy
The Service is not directed to individuals under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us so we can delete it.
10. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised version with an updated "Last Updated" date, and where changes are material, we will provide additional notice (such as an email or in-app notification).