Privacy Policy
Version 1.6 · Effective July 7, 2026
This privacy policy explains how SkillRepo LLC, a Texas limited liability company (“SkillRepo,” “we,” “us,” “our”), collects, uses, stores, and protects your information when you use the SkillRepo platform (the “Service”). We act as the data controller for the personal data described in this policy.
We believe in being straightforward about data practices, so we have written this policy in plain language.
1. Information We Collect
Account Information
When you sign up using GitHub or Google OAuth, we receive and store your profile information from those providers. This typically includes your name, email address, and avatar image. We do not receive or store your passwords from these providers.
Content You Publish
SkillRepo is a distribution layer for AI agent skills. When you publish a skill, we store the content you provide, including SKILL.md files, YAML frontmatter metadata, and any supporting files you upload (scripts, reference documents, and static assets). This content is stored so it can be discovered and consumed by other users and AI coding agents.
Note: If you publish content that contains personal data of third parties, you are responsible for ensuring you have the legal right to share that data.
Usage Data
We collect usage events to help you understand how your skills are being used and to improve the platform. This includes skill activation events, file download events, and API call records, each with associated timestamps.
Product Analytics on Public Pages
We use PostHog to understand how visitors discover and navigate the public, unauthenticated parts of SkillRepo — the home page, pricing, public documentation, the public skills catalog (/skills), and other marketing pages. This data is only collected after you provide consent via our cookie consent banner. On those pages, with your consent, we collect:
- Page views and navigation paths between public pages
- Anonymous click, scroll, and form-interaction events captured by PostHog’s autocapture
- Session recordings of mouse movement, scrolling, and DOM interactions. Password fields are always masked; other form-input values entered on public pages are included in the recording
- A randomly-generated anonymous identifier stored in your browser’s
localStorageand a PostHog cookie (see Section 6) - Your IP address, which PostHog uses to derive approximate geographic location (city and country level) and which may be stored alongside the associated events
- Browser type, operating system, device class, and the referring URL
Legal basis and retention. For all visitors, our legal basis for this analytics processing is your consent, obtained through our cookie consent banner before any analytics data is collected. You may withdraw your consent at any time through the cookie settings link in our website footer. Analytics data is retained for up to 12 months, and is deleted sooner if you withdraw consent or make a verified deletion request as described in Sections 5 and 6.
This PostHog collection is scoped to public pages only. PostHog capture and session recording do not run on any /app route, on sign-in or sign-up pages, or on the authenticated dashboard. The PostHog SDK does load globally to keep the anonymous identifier consistent if you cross between public and authenticated pages, which is why the cookie below is set on every visit; however, capture only occurs on public pages. By consenting, you are agreeing to an identifier that persists across all pages, though data collection only occurs on public pages.
Vercel Web Analytics and Speed Insights
Separately from PostHog, we use Vercel’s built-in Web Analytics and Speed Insights, which are provided by our hosting platform. These run on all pages of the site, including authenticated /app pages. They collect:
- Aggregate page-view counts and the routes visited
- Referrer and approximate (country-level) location
- Device type, operating system, and browser
- Performance measurements (Core Web Vitals such as load and interaction timings)
Vercel Web Analytics and Speed Insights do not set cookies, do not record sessions, and are not used to build individual visitor profiles. They are used to understand aggregate traffic and to monitor site performance. Our legal basis for this processing is our legitimate interest in maintaining site performance and availability (see Section 2 for more detail on our balancing assessment).
Audit Logs
We maintain audit logs of significant account activity for security purposes. These logs cover events such as sign-in and sign-out activity, account and team settings changes, team membership changes, and skill publishing events.
API Keys
If you create API keys for programmatic access, we store a cryptographic hash of each key along with its associated name, scopes, and creation date. We do not store API keys in plain text after initial generation.
Session Data
We use session tokens to keep you signed in. Session data is tied to your authenticated account and is used solely to maintain your login state.
2. How We Use Your Information and Legal Bases
We use the information we collect for the following purposes. For each purpose, we identify the legal basis under the GDPR and applicable laws:
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Providing the service | Account information, published content, session data | Performance of contract (Art. 6(1)(b)) |
| Analytics and insights (first-party usage data) | Usage events, activation data | Legitimate interest (Art. 6(1)(f)) — understanding how skills are adopted |
| Analytics on public pages (PostHog) | Page views, interactions, session recordings | Consent (Art. 6(1)(a)) |
| Aggregate traffic and performance monitoring (Vercel) | Aggregate page views, performance metrics | Legitimate interest (Art. 6(1)(f)) — maintaining site availability |
| Security and integrity | Audit logs, session data, API key hashes | Legitimate interest (Art. 6(1)(f)) — protecting accounts and detecting abuse |
| Communication (service notifications) | Email address | Performance of contract (Art. 6(1)(b)) |
| Communication (marketing, if applicable) | Email address | Consent (Art. 6(1)(a)) |
Legitimate Interest Balancing Assessment
Where we rely on legitimate interest, we have conducted a balancing test considering:
- Our interest: Maintaining platform security, understanding aggregate performance, and providing usage insights to skill publishers.
- Impact on data subjects: Minimal, as the data is either aggregated (Vercel), limited to security events (audit logs), or directly useful to the data subject (first-party usage data for their own published skills).
- Safeguards: Data minimization, limited retention, access controls, and the availability of opt-out mechanisms.
We have concluded that our legitimate interests do not override your fundamental rights and freedoms in these contexts.
What We Do Not Do
We want to be explicit about what we do not do with your data:
- We do not sell your data. Your information is never sold to anyone, for any reason. We do not sell or “share” (as defined under the California Consumer Privacy Act) your personal information with third parties for cross-context behavioral advertising.
- We do not use your data for AI model training. The skills and content you publish are not used to train artificial intelligence or machine learning models.
- We do not serve advertising. There are no ads on SkillRepo, and we do not share data with advertising networks.
- We do not share your data with third parties beyond the infrastructure and analytics providers described in Section 4 below.
- We do not use your personal data for automated decision-making or profiling that produces legal effects or similarly significantly affects you.
We do not send marketing emails without your consent.
3. How We Store and Protect Your Information
Your data is stored using industry-standard cloud infrastructure with the following security measures:
- Encryption in transit. All data transmitted between your browser or IDE and our servers is encrypted using TLS.
- Encryption at rest. Database records and stored files are encrypted at rest by our infrastructure providers.
- Hashed credentials. API keys are stored as cryptographic hashes, not in plain text.
- Access controls. Internal access to production systems is restricted and follows the principle of least privilege.
- Serverless architecture. Our deployment model reduces the attack surface compared to traditional server infrastructure.
While we take reasonable measures to protect your data, no system is completely immune to security risks. We encourage you to protect your account by safeguarding your OAuth credentials and API keys.
4. Third-Party Services (Sub-Processors)
We rely on a limited set of infrastructure providers to operate SkillRepo. These providers process your data only as necessary to deliver their services to us, and are bound by data processing agreements:
| Provider | Purpose | Data Processed | Privacy Policy | Location |
|---|---|---|---|---|
| Vercel | Application hosting, serverless functions, file storage, web analytics, and speed insights | Request data, uploaded skill files, aggregate traffic metrics | vercel.com | United States |
| Neon | PostgreSQL database hosting | Account records, skill metadata, usage events, audit logs | neon.com | United States |
| Upstash | Redis-compatible data store for rate limiting | Request metadata | trust.upstash.com | United States |
| GitHub / Google | OAuth authentication providers | Authentication requests, profile information | docs.github.com | United States |
| PostHog | Product analytics on public pages (with consent) | Page-view, autocapture, and session-recording events from public pages only | posthog.com | United States |
| Stripe | Payments, analytics, and other business services. | Transactional data, personal data, identifying information about devices that connect to its services. | stripe.com | United States |
| Resend | Personal data; usage data | resend.com | United States |
We do not use advertising platforms or data brokers.
International Data Transfers
PostHog, our analytics provider, processes and stores data on infrastructure located in the United States. If you access the public parts of SkillRepo from the European Economic Area, the United Kingdom, or another region with cross-border data-transfer restrictions, the analytics data described in Section 1 is transferred to and stored in the United States. Our other infrastructure providers may also process data in the United States.
We protect these transfers using the following safeguards:
- EU-U.S. Data Privacy Framework: Where our providers are certified under the EU-U.S. Data Privacy Framework, we rely on that certification as an adequate transfer mechanism.
- Standard Contractual Clauses (SCCs): Where providers are not covered by an adequacy framework, we have entered into the European Commission’s Standard Contractual Clauses (Module 2: Controller to Processor) to ensure appropriate safeguards for transferred data.
You may request a copy of the relevant transfer safeguards by contacting us at the address in Section 11.
5. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy. Specific retention periods are as follows:
| Data Category | Retention Period |
|---|---|
| Account information | Duration of your account, plus 30 days after deletion request |
| Published skill content | Duration of your account; deleted upon verified account deletion request |
| Usage data (skill activations, downloads) | 24 months after the event date |
| PostHog analytics data | 12 months from collection |
| Vercel analytics data | Controlled by Vercel; aggregated and not individually identifiable |
| Audit logs | 18 months from the event date |
| Session data | Expires upon sign-out or 30 days of inactivity |
| API key hashes | Duration of your account or until you revoke the key |
| Encrypted backups containing deleted data | Purged within 90 days of the deletion request |
After the applicable retention period expires, data is permanently deleted or irreversibly anonymized.
6. Cookies and Similar Technologies
SkillRepo uses cookies and browser storage for the following purposes:
Strictly Necessary (No Consent Required)
- Session cookies. A session cookie keeps you signed in after authentication. This cookie contains a session identifier and is not used to track activity across other websites.
- Security cookies. We use cookies to protect against cross-site request forgery (CSRF) and other security threats.
- Analytics cookies and storage (Consent Required). PostHog sets a cookie (named like
ph_<token>_posthog) and writes to your browser’slocalStorageto maintain an anonymous identifier across visits. This identifier is used to deduplicate sessions and stitch a single visitor’s page views together on public pages. It is not used for advertising or cross-site tracking.
Your Cookie Choices
When you first visit SkillRepo’s public pages, you will be presented with a cookie consent banner that allows you to:
- Accept analytics cookies
- Reject analytics cookies
- Customize your preferences by category
You can change your preferences at any time by clicking the “Cookie Settings” link in our website footer. If you reject analytics cookies, PostHog cookies will be cleared, PostHog will not load, and no analytics data will be collected from your visit.
We do not use advertising cookies and do not participate in cross-site advertising networks.
7. Your Rights
Depending on your location, you may have some or all of the following rights regarding your personal data:
All Users
- Access and Export. You can access the skills you have published, your account information, and your usage data through the SkillRepo dashboard at any time. You may also request a machine-readable export of your data.
- Deletion. You may request deletion of your account and associated data by contacting us at the address provided in Section 11. Upon receiving a verified deletion request, we will delete your account and profile information, all skills you have published, your usage data, audit logs, API keys, and session data. Deletion requests are processed within 30 days.
- Correction. If any of your account information is inaccurate, you can update it through your OAuth provider (GitHub or Google), and the changes will be reflected in SkillRepo upon your next sign-in. You may also contact us to request correction.
Additional Rights for EEA and UK Residents (GDPR)
- Right to Restrict Processing. You may request that we restrict processing of your personal data in certain circumstances (e.g., while we verify the accuracy of data you have contested).
- Right to Data Portability. You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Right to Object. You have the right to object to processing based on our legitimate interests. If you object, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. You may object at any time by contacting us at hello@skillrepo.dev.
- Right to Withdraw Consent. Where processing is based on your consent (e.g., PostHog analytics), you may withdraw consent at any time via the Cookie Settings link in our footer or by contacting us. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.
- Right to Lodge a Complaint. You have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at edpb.europa.eu.
Additional Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to Know. You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete. You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct. You may request that we correct inaccurate personal information.
- Right to Opt-Out of Sale/Sharing. We do not sell your personal information or share it for cross-context behavioral advertising. No opt-out is necessary, but you may contact us to confirm this at any time.
- Right to Limit Use of Sensitive Personal Information. We do not collect sensitive personal information as defined under the CPRA beyond what is necessary to provide the Service.
- Right to Non-Discrimination. We will not discriminate against you for exercising any of your CCPA/CPRA rights. You will not receive different pricing, a different quality of service, or be denied service for making a rights request.
Categories of personal information collected (CCPA categories):
| CCPA Category | Examples | Sold? | Shared for Advertising? |
|---|---|---|---|
| Identifiers | Name, email, anonymous analytics ID | No | No |
| Internet/electronic activity | Page views, usage events, session recordings | No | No |
| Geolocation data | Approximate city/country from IP | No | No |
| Professional information | Published skills, team membership | No | No |
Additional Rights for Texas Residents (TDPSA)
If you are a Texas resident, the Texas Data Privacy and Security Act provides you with rights to access, correct, delete, and obtain a portable copy of your personal data. You also have the right to opt out of:
- The sale of your personal data (we do not sell personal data)
- Targeted advertising (we do not engage in targeted advertising)
- Profiling in furtherance of decisions that produce legal or similarly significant effects (we do not engage in such profiling)
If we decline a rights request, you have the right to appeal our decision. To appeal, email us at hello@skillrepo.dev with the subject line “TDPSA Appeal.” We will respond within 60 days. If your appeal is denied, you may contact the Texas Attorney General at texasattorneygeneral.gov.
Exercising Your Rights
To exercise any of the above rights, contact us at hello@skillrepo.dev. We will verify your identity before processing your request. We aim to respond to all rights requests within 30 days (or within the shorter timeframe required by applicable law). If we need additional time, we will notify you of the extension and the reasons for the delay.
8. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (where required under GDPR Article 33).
- Notify the Texas Attorney General within 60 days of determination that a breach has occurred (as required under Texas law), if the breach affects 250 or more Texas residents.
- Notify affected individuals without unreasonable delay where the breach is likely to result in a high risk to your rights and freedoms, or as otherwise required by applicable law.
Breach notifications to individuals will include:
- A description of the nature of the breach
- The categories and approximate number of records concerned
- The likely consequences of the breach
- The measures taken or proposed to address the breach
- Contact information for follow-up questions
9. Children’s Privacy
SkillRepo is not directed at children. You must be at least 16 years of age to create an account or use the Service. We do not knowingly collect personal data from children under 16 (or under 13 where COPPA applies).
If we become aware that we have inadvertently collected personal data from a child under the applicable age threshold, we will take prompt steps to delete that data. If you believe a child has provided us with personal data, please contact us at hello@skillrepo.dev.
10. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or for legal and regulatory reasons. When we make changes, we will update the version number and effective date at the top of this page.
For significant changes that materially affect your rights or how we use your data, we will:
- Provide reasonable advance notice before the changes take effect
- Notify you through an in-app notification or an email to the address associated with your account
- Where a change affects processing based on your consent, obtain fresh consent where required by applicable law
Your continued use of the Service after the effective date of an updated policy constitutes acceptance of the changes, except where consent is required.
11. Contact
If you have questions about this privacy policy, want to exercise your data rights, or have concerns about how your information is handled, you can reach us at:
Email: hello@skillrepo.dev
Mailing Address:
SkillRepo LLC
9901 Brodie Lane, Suite 160, PMB 786
Austin, Texas 78748
We aim to respond to all privacy-related inquiries within 14 business days and to rights requests within 30 calendar days (or the shorter period required by applicable law).
12. Supplemental Notices
For EEA and UK Residents
- Data Controller: SkillRepo LLC, contactable at the address above.
- Supervisory Authority: You may lodge a complaint with your local supervisory authority. For a list of EU authorities, visit edpb.europa.eu. For the UK, contact the Information Commissioner’s Office (ICO) at ico.org.uk.
For California Residents
This policy serves as our notice at collection under the CCPA. The categories of personal information we collect and our purposes for collection are described in Sections 1 and 2 above. We have not sold or shared personal information in the preceding 12 months.
For Texas Residents
This policy constitutes our privacy notice under the Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024. We conduct data protection assessments for processing activities that present a heightened risk to consumers, as required under TDPSA § 541.105.