Privacy Policy
Last updated: March 6, 2026
This privacy policy explains how Skills Hub (“we,” “us,” “our”) collects, uses, stores, and protects your information when you use our platform. We believe in being straightforward about data practices, so we have written this policy in plain language.
1. Information We Collect
Account Information
When you sign up using GitHub or Google OAuth, we receive and store your profile information from those providers. This typically includes your name, email address, and avatar image. We do not receive or store your passwords from these providers.
Content You Publish
Skills Hub is a registry for AI agent skills. When you publish a skill, we store the content you provide, including SKILL.md files, YAML frontmatter metadata, and any supporting files you upload (scripts, reference documents, and static assets). This content is stored so it can be discovered and consumed by other users and AI coding agents.
Usage Data
We collect usage events to help you understand how your skills are being used and to improve the platform. This includes skill activation events, file download events, and API call records, each with associated timestamps.
Audit Logs
We maintain audit logs of significant account activity for security purposes. These logs cover events such as sign-in and sign-out activity, account and team settings changes, team membership changes, and skill publishing events.
API Keys
If you create API keys for programmatic access, we store a cryptographic hash of each key along with its associated name, scopes, and creation date. We do not store API keys in plain text after initial generation.
Session Data
We use session tokens to keep you signed in. Session data is tied to your authenticated account and is used solely to maintain your login state.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the service. Your account information lets you sign in. Your published content is stored and served so others can discover and use your skills via MCP connections from their IDEs.
- Analytics and insights. Usage data helps you understand how your skills are being adopted and helps us understand platform-wide usage patterns to improve the service.
- Security and integrity. Audit logs and session data help us protect your account, detect unauthorized access, and investigate potential abuse.
- Communication. We may use your email address to send you important service notifications, such as security alerts or changes to our terms. We do not send marketing emails without your consent.
What We Do Not Do
We want to be explicit about what we do not do with your data:
- We do not sell your data. Your information is never sold to anyone, for any reason.
- We do not use your data for AI model training. The skills and content you publish are not used to train artificial intelligence or machine learning models.
- We do not serve advertising. There are no ads on Skills Hub, and we do not share data with advertising networks.
- We do not share your data with third parties beyond the infrastructure providers described in Section 4 below.
3. How We Store and Protect Your Information
Your data is stored using industry-standard cloud infrastructure with the following security measures:
- Encryption in transit. All data transmitted between your browser or IDE and our servers is encrypted using TLS.
- Encryption at rest. Database records and stored files are encrypted at rest by our infrastructure providers.
- Hashed credentials. API keys are stored as cryptographic hashes, not in plain text.
- Access controls. Internal access to production systems is restricted and follows the principle of least privilege.
- Serverless architecture. Our deployment model reduces the attack surface compared to traditional server infrastructure.
While we take reasonable measures to protect your data, no system is completely immune to security risks. We encourage you to protect your account by safeguarding your OAuth credentials and API keys.
4. Third-Party Services
We rely on a limited set of infrastructure providers to operate Skills Hub. These providers process your data only as necessary to deliver their services to us:
- Vercel — Application hosting, serverless functions, and file storage. Vercel processes request data and stores uploaded skill files.
- Neon — PostgreSQL database hosting. Neon stores your account records, skill metadata, usage events, and audit logs.
- Upstash — Redis-compatible data store used for rate limiting. Upstash processes request metadata for operational purposes.
- GitHub and Google — OAuth authentication providers. These services process your authentication requests when you sign in. We receive only the profile information described in Section 1.
We do not use any analytics services, advertising platforms, or data brokers.
5. Your Rights
Access and Export
You can access the skills you have published, your account information, and your usage data through the Skills Hub dashboard at any time. We support data export upon request.
Deletion
You may request deletion of your account and associated data by contacting us at the address provided in Section 8. Upon receiving a verified deletion request, we will:
- Delete your account and profile information
- Delete all skills you have published
- Delete your usage data, audit logs, and API keys
- Remove your session data
Deletion requests are processed within 30 days. Some data may be retained in encrypted backups for a limited period as part of our disaster recovery procedures, after which it is permanently purged.
Correction
If any of your account information is inaccurate, you can update it through your OAuth provider (GitHub or Google), and the changes will be reflected in Skills Hub upon your next sign-in.
6. Cookies and Sessions
Skills Hub uses cookies strictly for functional purposes:
- Session cookies. We use a session cookie to keep you signed in after authentication. This cookie contains a session identifier and does not track your activity across other websites.
- Security cookies. We may use cookies to protect against cross-site request forgery (CSRF) and other security threats.
We do not use tracking cookies, advertising cookies, or third-party analytics cookies. We do not participate in cross-site tracking.
Because we only use cookies that are strictly necessary for the service to function, we do not display a cookie consent banner in jurisdictions that exempt essential cookies from consent requirements.
7. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or for legal and regulatory reasons. When we make changes, we will update the “Last updated” date at the top of this page.
For significant changes that materially affect your rights or how we use your data, we will make reasonable efforts to notify you in advance, such as through an in-app notification or an email to the address associated with your account.
8. Contact
If you have questions about this privacy policy, want to exercise your data rights, or have concerns about how your information is handled, you can reach us at:
Email: privacy@skillshub.io
We aim to respond to all privacy-related inquiries within 14 business days.