Privacy Policy
How Outro CX LLC collects, uses, and protects information in SkillFabrIQ.
Effective 2026-07-28
1. Scope and roles
This policy covers SkillFabrIQ, our website, and the public readiness assessment.
For account information and website visitors, we are the controller of the data. For content your organization puts into the product — practice sessions, transcripts, recordings, results — your organization is the controller and we act as its processor, handling that data on its instructions. If you are a learner or a candidate, contact your organization first about data it holds; we will support them in responding.
2. What we collect
Account information. Your email address and name. We support sign-in by password or by emailed one-time code; we never see your password in readable form, and we do not collect social or third-party login profiles.
Organization content. Scenarios, skills, criteria, teams, assignments, and other material your organization creates or uploads.
Practice and assessment data. Transcripts of practice conversations, scores, written feedback, timestamps, and progress. Where assessments are used for candidates, this includes the candidate's responses and results.
Voice. When a participant uses voice practice, microphone audio is streamed to our speech-to-text provider and converted to text in real time. We keep the resulting transcript. Where you upload a recording of a real conversation for analysis, we store the audio file only until it has been transcribed and then delete it — the transcript is retained, the audio is not.
Billing. Subscription status, plan, seat count, and renewal dates. Card details go directly to our payment processor and are never stored on our systems.
Readiness assessment. If you complete the public assessment, we store your answers, the resulting scores, an email address if you choose to give one, a hashed form of your IP address, and your browser's user-agent string. We store a hash rather than the raw IP. Results are retrieved by an unguessable link rather than by logging in.
Technical data. Server logs necessary to operate and secure the service, including error diagnostics and records of AI usage for billing and abuse prevention.
Marketing page analytics. On our public pages — the homepage, blog, pricing, comparisons, and the readiness assessment — we count visits and record which page was viewed, the site you arrived from, approximate country, and browser and device type. Where a page address contains a private link token, that token is removed before the visit is recorded. This applies to the public pages only.
3. What we do not do
We do not use third-party advertising trackers anywhere, and we run no analytics inside the product itself. No analytics provider is loaded on any page behind sign-in, so none of them sees your practice sessions, your team's results, or your organization's content. We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use your organization's content to train our own models.
Your browser stores a session token so you stay signed in. That is functional, not tracking, and clearing site data removes it. On our public marketing pages, analytics stores an identifier in your browser so repeat visits are not double-counted. No advertising cookies are set, and clearing site data removes that too.
4. How we use information
- To provide the service — running practice sessions, grading, and reporting.
- To authenticate users and enforce role-based access within an organization.
- To bill subscriptions and manage seats.
- To send transactional email such as invitations and account notices.
- To secure the service, investigate abuse, and diagnose faults.
- To understand how our public marketing pages are found and used.
- To meet legal obligations.
Where we rely on legitimate interests — security, fault diagnosis, product operation — we balance those against your rights. Where consent is the basis, you can withdraw it.
5. AI processing
Core features send content to third-party AI providers: simulated dialogue, grading and written feedback, scenario authoring, transcript parsing, and speech-to-text. In practice this means practice transcripts and uploaded conversation content are transmitted to those providers to be processed and returned.
We use these providers through their business APIs. We do not permit them to use your content to train their models, and we send only what a given feature requires.
Before an uploaded conversation is analyzed, we attempt to remove personal data from the transcript: pattern matching strips things like card numbers, national identifiers, email addresses, and phone numbers, and a further automated pass looks for names, addresses, and account references that patterns miss. This reduces exposure but is not guaranteed to catch everything, which is why our terms ask you not to upload sensitive personal data in the first place.
6. Who we share it with
We share data with service providers who process it on our behalf, under contract, for the purposes below — and otherwise only where required by law, or in connection with a merger or acquisition (in which case this policy continues to apply until replaced with notice).
| Category | Purpose |
|---|---|
| Cloud infrastructure and hosting | Runs the application and stores its data, including databases, file storage, authentication, and server-side functions. |
| AI model providers | Generate simulated dialogue, score practice sessions and produce written feedback, author and validate scenario content, and interpret uploaded transcripts. |
| Speech-to-text provider | Converts spoken audio to text during voice practice and when transcribing an uploaded recording. |
| Payment processor | Handles subscription billing, card payments, and the billing portal. Card details go to this provider directly and are never stored on our systems. |
| Transactional email provider | Delivers account email such as team invitations, assessment invitations, and service notices. |
| Website analytics providers | Count visits to our public marketing pages and show which pages people read and where they arrived from. These providers operate only on the public pages — they are not present anywhere behind sign-in and receive nothing about practice sessions, results, or organization content. |
Each provider is bound by contract to process data only on our instructions and to protect it. Customers and prospective customers who need the specific providers named — for a data processing agreement or a security review — can request the current list from privacy@skillfabriq.com.
7. International transfers
Our providers operate internationally, so data may be processed outside your country, including in the United States. Where data protection law requires a transfer safeguard, we rely on the mechanisms offered by those providers, such as standard contractual clauses.
8. How long we keep it
- Uploaded call audio — deleted once transcription completes.
- Practice and assessment data — kept for as long as your organization's account is active, or until it deletes the data.
- Account records — kept while the account exists, then removed after a short window that allows for export or restoration.
- Readiness responses — kept so the result link keeps working, and deletable on request.
- Billing records — retained as long as tax and accounting law requires.
- Logs — retained on a short rolling basis for security and diagnostics.
9. Security
Data is encrypted in transit. Each organization's data is isolated at the database level by access rules enforced by the database itself rather than only by application code, and access within an organization is limited by role. Server-side operations verify that a caller belongs to the organization whose data they are acting on. Uploaded files are held in private storage reachable only through short-lived signed links.
No system is perfectly secure. If a breach affects your personal data, we will notify you and any regulator as required by law.
10. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, object to or restrict certain processing, and withdraw consent. If you are in the EU or UK, you may also lodge a complaint with your data protection authority. If you are in California, you have rights of access, deletion, correction, and portability, and the right not to be discriminated against for exercising them — we do not sell personal information or share it for cross-context behavioural advertising.
To exercise a right, email privacy@skillfabriq.com. If the data belongs to an organization's workspace, we will refer the request to that organization and support them in answering it. We may need to verify your identity, and we respond within the period the applicable law requires.
11. Children
The service is for workplace use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We update this policy when the product or our providers change. Material changes will be notified by email or in the application before they take effect, and the effective date at the top of this page always reflects the current version.
13. Contact
Privacy questions and requests: privacy@skillfabriq.com. General support: support@skillfabriq.com. You can write to us at c/o Northwest Registered Agent, LLC, 9905 S Pennsylvania Ave, Ste A, Oklahoma City, OK 73159.
