Skylar Sabo
HomeVerdictsMethodClient loginBook

Privacy

What is collected, exactly.

Last updated: July 5, 2026

This policy is written the same way the reports are: it states what is actually measured — here, what is actually collected — and where the answer is "nothing", it says nothing.

1. The public site

skylarsabo.com is a static site. It sets no cookies and runs no advertising or third-party trackers. Aggregate traffic counts come from Cloudflare Web Analytics, which is cookieless and does not profile individual visitors.

2. The client portal

If you are a client, the portal stores: the email address and password you chose at setup (the password is stored only as a scrypt hash — I cannot read it), your engagement details (name or fund, target venue and assets), the files and reports of your engagement, and any messages you send through the portal thread.

The portal sets one cookie: a session cookie that keeps you signed in. It exists only for that purpose, is scoped to the portal host, and dies with your session. The operator console works the same way, with one session cookie of its own.

3. The access log

For security and engagement records, the portal keeps a per-client log of access events — sign-ins, setup, file downloads, messages — with timestamps and the connecting IP address. This is the same log your engagement's "access history" is built from. It is used to protect your engagement and to answer "who touched this and when", and for nothing else.

4. Email

If you email me, I keep the correspondence like any professional would — for context, records, and follow-up. Email is handled by Google (Gmail), so their infrastructure processes it in transit and at rest.

5. Who else touches the data

Four infrastructure providers, no more: Cloudflare (TLS, caching, and security in front of every request — they see traffic metadata as any CDN does), DigitalOcean (the server the portal runs on), Google (email), and Formspree (the inquiry form — name, email, venue/project details, and any message you write are delivered through their service to reach my inbox; see their privacy policy). No analytics brokers, no ad networks. Your data is never sold or shared for marketing — to anyone, ever.

6. Retention and deletion

Engagement records are kept while the engagement is active and afterwards as business records — a signed verdict is only worth something if the evidence behind it is kept. If you want your account and engagement data deleted, request it through the contact form or the portal; deletion removes your portal access, files, messages, and logs. I may retain the minimum needed to meet legal or accounting obligations.

7. Security

Everything is served over TLS through Cloudflare, with the origin server firewalled so it answers only to Cloudflare. Passwords are scrypt-hashed; operator access requires a second factor (TOTP); deliverables carry SHA-256 checksums you can verify yourself. No system is unbreachable, and I will not pretend otherwise — if a breach affects your data, I will tell you directly and promptly.

8. Your rights

Ask and you will get: a copy of what is held about you, a correction if something is wrong, or deletion as described above. Use the contact form and mark the note “Privacy request.” Existing clients may use the portal message thread. Depending on where you live, these may also be statutory rights (GDPR, CCPA, and kin); either way, the answer here is the same.

9. Changes

If this policy changes, the date above changes with it, and material changes affecting active clients will be communicated directly.

Skylar Sabo

Independent capital-safety diligence

Book a ScanMethodVerify a reportTermsPrivacy© 2026

Independent diligence by a named operator. Not investment advice and not a security guarantee. Where something was not measured, it is reported as UNKNOWN — never as zero. The signed human verdict is the product; the instrument gathers evidence and drafts.