Legal
Privacy Policy
Data We Collect
We collect the following categories of data to provide the Service:
Account & profile
Your name, email address, password hash (for credential accounts) or identity-provider identifier (for Google, Microsoft, or GitHub sign-in), and any profile details or avatar you add.
Workspace & membership
The workspaces you belong to, your role in each, invitations, and verified workspace domains used for auto-join.
Content you create
Skills and skill sets, including names, descriptions, prompt bodies, tags, version history, comments, and dependency relationships.
Operational records
- Telemetry logs — skill execution events such as counts, success rates, and latency, used to power your telemetry dashboard.
- Audit logs — a record of who performed which create, update, or delete action, when, and the before/after state, kept for security and accountability.
- API keys — workspace-scoped keys used to authenticate CLI installs.
- Technical data — IP address and basic request metadata captured for security, rate limiting, and abuse prevention.
How We Use Data
- To provide, maintain, and secure the Service and your workspace.
- To authenticate you and enforce role-based access controls.
- To process subscriptions and payments through our payment processor.
- To render telemetry dashboards and maintain audit trails for your workspace.
- To communicate with you about your account, security, and service updates.
- To detect, prevent, and respond to abuse, fraud, and security incidents.
We do not sell your personal data, and we do not use it for advertising or third-party behavioral profiling.
Back to topLegal Basis & Purpose
Where data-protection law such as the GDPR applies, we process personal data on these bases:
- Performance of a contract — to deliver the Service you or your workspace signed up for.
- Legitimate interests — to secure the Service, prevent abuse, and improve reliability, balanced against your rights.
- Legal obligation — to comply with tax, accounting, and other legal requirements.
- Consent — where we ask for it specifically; you can withdraw consent at any time.
Third-Party Processors
We share data with a small set of service providers who process it on our behalf, only as needed to run the Service:
Stripe
Payment processing and subscription billing. Handles card data directly; we never receive full card numbers.
Identity providers
Google, Microsoft, and GitHub, when you choose to sign in with them, to verify your identity.
Cloud hosting
Our infrastructure and database providers, which store and serve the Service.
Email delivery
Transactional email for verification, password resets, and account notices.
We do not permit these processors to use your data for their own purposes. We do not sell data to third parties.
Back to topData Retention & Soft Deletes
We keep personal data for as long as your account or workspace is active, and as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.
Soft deletes
When you delete a skill, skill set, or workspace, we perform a “soft delete”: the record is marked with a deletion timestamp and hidden from normal use, but retained for a limited period so it can be restored if the deletion was accidental. After that period, or on a verified deletion request, the data is purged from active systems. Backups are rotated on a regular schedule.
Audit logs and certain security or billing records may be retained longer where required for legal, accounting, or security purposes.
Back to topYour Rights
Depending on your location, you may have the right to:
Access & portability
Request a copy of the personal data we hold about you in a portable format.
Correction
Update inaccurate profile or account information, directly or by contacting us.
Deletion
Request deletion of your account and associated personal data, subject to retention limits above.
Objection & restriction
Object to or restrict certain processing, and withdraw consent where processing relies on it.
To exercise any of these rights, contact skillvalit@gmail.com. If your data is managed within a workspace, we may direct your request to that workspace as the controller of its data. You also have the right to complain to your local data-protection authority.
Back to topCookies & Sessions
We use only the cookies necessary to run the Service. In particular, we use a session cookie to keep you signed in: authentication is handled by NextAuth using a JSON Web Token (JWT) session stored in a secure, HTTP-only cookie. We also store a small preference in your browser's local storage to remember your selected workspace and theme.
We do not use advertising cookies, cross-site trackers, or non-essential analytics that profile you across other websites.
Back to topChildren's Privacy
The Service is intended for professional and business use and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
Back to topInternational Transfers
We and our processors may store and process data in countries other than where you live. When we transfer personal data across borders, we rely on appropriate safeguards, such as standard contractual clauses or equivalent mechanisms, to protect it in line with applicable data-protection law.
Back to topChanges to This Policy
We may update this Privacy Policy as the Service evolves. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Service or by email. We encourage you to review this policy periodically.
Back to topContact & Controller
For privacy questions or to exercise your rights, contact skillvalit@gmail.com. The data controller for the Service is Skill Valit, an individual acting as a sole proprietor and based in Thailand. See also our Terms of Service.
Back to top