Legal
Privacy Policy
Last updated July 8, 2026. How Skala collects, uses, and protects your data.
Skala, Inc. ("Skala," "we," "our," or "us") provides a real-time fraud scoring API. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
Data We Collect
Skala collects only what is necessary to deliver real-time fraud scoring. When you send an event to our API, we process:
- IP address — hashed (SHA-256) before storage; only the /24 subnet is retained for cluster detection
- Email address — hashed (SHA-256) before storage; raw email addresses are never persisted by the scoring engine
- Device ID — optional identifier you provide; stored as-is
- User agent — truncated to 512 characters
- Form fill timing — milliseconds, if provided
- Event metadata — arbitrary key-value pairs you attach
For account holders, we store your name, email, and organization details via our authentication provider (Better Auth) to manage your account and billing.
How We Use Your Data
Your data is used exclusively for:
- Real-time risk scoring — computing a 0–100 risk score and allow / step_up / block decision
- Fraud pattern detection — identifying velocity abuse, disposable emails, device reuse, and subnet clustering
- Reputation signals — building per-identifier reputation scores that decay over time
- Model improvement — aggregated, anonymized scoring outcomes are used to tune signal weights and thresholds across the platform
- Billing — counting scored events against your plan limits
We do not sell, rent, or share individual event data with third parties.
Data Retention
Skala operates a sliding-window retention model:
- Scoring events — retained for 90 days, then permanently deleted from our database
- Graph edges (identifier relationships) — retained for 30 days, then permanently deleted
- Reputation scores — decay with a 7-day half-life; stale scores are naturally expunged
- ASN cache — expires after 24 hours
- Session tokens — expire per your session configuration
- Account data — retained while your account is active; deleted within 30 days of account closure
Automated cleanup jobs run hourly to enforce these retention windows.
Security
We take security seriously:
- All API communication is encrypted in transit (TLS)
- Email addresses and IP addresses are hashed before storage — we never retain raw PII in our scoring pipeline
- API keys are hashed in our database; plaintext keys are never stored
- Webhook payloads are signed with HMAC-SHA256 per-tenant secrets
- We run on Cloudflare's global edge network with DDoS protection and WAF rules
- Rate limiting is enforced at both the CDN and application layer
Your Rights
Under applicable data protection laws (GDPR, CCPA), you have the right to:
- Access — request a copy of the data we hold about you
- Deletion — request deletion of your account and associated data
- Portability — export your event data in standard formats
- Rectification — correct inaccurate account information
- Objection — object to processing of your data for specific purposes
To exercise these rights, contact us at contactskala@varityweb.com.
Data Deletion
You can request immediate deletion of your data at any time:
- Account data is deleted within 30 days of account closure
- Scoring events are automatically purged after 90 days
- Graph edges are automatically purged after 30 days
- Reputation scores decay to zero within weeks of last activity
For bulk deletion requests or DPA inquiries, email contactskala@varityweb.com.
For questions about this policy, contact us at contactskala@varityweb.com.