Legal
Privacy Policy
How SkillGild collects, uses and protects your data across accounts, hosted skill execution, support and email.
At a glance
- We collect what we need to run your account, execute the skills you invoke and keep the platform secure.
- Skill inputs and outputs are stored on the execution record and sent to the configured model provider.
- Only strictly necessary cookies — no advertising, profiling or third-party analytics cookies.
- We never sell personal data, and you can ask us to access, export or delete yours at any time.
This summary is for orientation only. The numbered sections below are the terms that apply.
Who this policy covers
This policy explains how SkillGild handles personal data when you visit skillgild.dev, create an account, install or run hosted skills, apply to become a creator, or contact support. It applies to the SkillGild website, API, command-line interface and client libraries.
It does not cover the coding agents you connect SkillGild to, such as Claude Code, Codex, Cursor or Gemini CLI. Those tools are operated by their own providers under their own privacy policies.
Owner input required: the registered legal entity name, company number and registered address of the SkillGild data controller still need to be inserted here before publication.
Data we collect
Account data
When you register we store your name, email address and, where you sign in with Google or GitHub, the account identifier that provider returns to us. If you register with an email and password, we store a hash of that password, never the password itself. We also record whether your email address has been verified.
Workspace data
We store the organizations you belong to and your role in them, the API keys you create (as hashed secrets plus a label and prefix), the devices you authorise through the device connection flow, and any webhook endpoints you configure.
Skill execution data
Running a hosted skill creates an execution record. That record holds the input you submitted, the output returned, the skill and version used, the status of the run and its timestamps, linked to your account so we can enforce quota and entitlements and help you debug a failed run.
Support, reports and creator applications
We keep the content of support cases, the skill reports and appeals you submit, the notifications we send you, and the information you provide in a creator application.
Technical data
Our servers process standard request data such as IP address, user agent, timestamps and error information in order to operate the service, apply rate limits and investigate abuse. Catalog search is recorded only as privacy-preserving daily counters — the number of searches, how many returned nothing and how long queries were — and never as the query text itself. This aggregation is off by default and is controlled by a runtime policy setting with a configurable retention window.
How we use data
- To create and secure your account, and to authenticate you and your devices.
- To execute hosted skills you invoke, and to enforce free-run quotas and paid entitlements.
- To send transactional email, such as email verification, password reset and account notifications.
- To answer support cases and to review reports, appeals and creator applications.
- To detect, investigate and prevent abuse, fraud and attempts to extract protected skill configuration.
- To keep audit records of privileged administrative actions.
- To maintain, debug and improve the reliability and performance of the service.
We do not sell personal data, and we do not use your data to serve behavioural advertising.
Hosted skill execution and model providers
Hosted skills do not run on your machine. When you invoke a skill, SkillGild combines your input with the skill’s configuration and sends the resulting request to the model provider configured for the platform, which is an OpenAI-compatible inference API. The provider processes that request under its own terms and privacy policy and returns a response, which we store on the execution record.
Do not submit personal data, credentials or confidential material in skill inputs unless you are willing for them to be transmitted to that provider and stored on the execution record.
To protect creators against systematic extraction of their skills, we derive a keyed, one-way fingerprint of input patterns using a secret HMAC key. The fingerprint cannot be reversed into the original input and is used only to spot repeated extraction behaviour.
Owner input required: name the production model provider and its region here once the production runtime provider is fixed, so this section states which company receives skill inputs.
Legal bases for processing
Where data protection law requires a legal basis, we rely on the following:
- Performance of a contract — creating your account, running the skills you invoke, providing support and sending transactional email.
- Legitimate interests — keeping the platform secure, preventing abuse and extraction, maintaining audit logs, and improving reliability.
- Legal obligation — retaining records we are required by law to keep and responding to lawful requests.
- Consent — where we ask for it explicitly, for example before enabling any optional communication. You can withdraw consent at any time.
Owner input required: confirm which privacy regimes SkillGild is operating under (for example UK GDPR, EU GDPR, CCPA) so this section and section 11 can be finalised.
Who we share data with
We share personal data only with service providers that help us run SkillGild, and only to the extent they need it. These currently fall into the following categories:
- Cloud hosting and infrastructure for the application, database, cache and object storage.
- The model provider that executes hosted skills, as described in section 4.
- Transactional email delivery, used for verification, password reset and notification email.
- Identity providers you choose to sign in with, namely Google and GitHub.
We may also disclose data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims. If SkillGild is ever involved in a merger or acquisition, we will tell you before your data becomes subject to a different privacy policy.
Owner input required: publish the named sub-processor list (vendor, purpose, location) once the production hosting, email and inference vendors are contracted.
Cookies
SkillGild sets strictly necessary cookies only. These keep you signed in, protect authentication flows and preserve your session across page loads. They are required for the service to function and cannot be turned off from within the product.
We do not currently run advertising, profiling or third-party analytics cookies, which is why you are not asked for cookie consent. If that changes, we will update this section and ask for consent before setting any non-essential cookie.
How long we keep data
We keep account data for as long as your account exists. Execution records, support cases, reports and audit logs are retained while they remain useful for quota accounting, abuse investigation, dispute resolution and our own legal obligations. Aggregated catalog search counters are kept for the retention window set in the runtime policy, which is capped at one year.
When you ask us to delete your account, we remove or irreversibly anonymise personal data that we are not required to keep, and we remove active credentials such as API keys and device grants immediately.
Owner input required: set concrete retention periods per data category once the production backup and log-retention schedule is agreed.
How we protect data
Protected skill configuration is encrypted at rest using envelope encryption, with a managed key service in production, and is never included in the wrapper installed on your machine. Passwords are stored only as hashes, and API keys are stored only as hashes alongside a short display prefix.
Access to production data is restricted to the roles that need it, privileged administrative actions are written to an audit log, and the runtime checks your account, entitlement and quota before any protected configuration is loaded.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulator where the law requires it.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to receive a portable copy, to restrict or object to certain processing, and to withdraw consent you have given.
To exercise any of these, email support@skillgild.dev from the address on your account so we can verify the request. You also have the right to complain to your local data protection authority.
International transfers
SkillGild relies on infrastructure and model providers that may process data outside the country you live in. Where personal data is transferred internationally, we rely on the transfer mechanisms permitted by the applicable law, such as standard contractual clauses with the receiving provider.
Owner input required: state the production hosting regions and the specific transfer mechanism in place with each provider.
Children
SkillGild is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as the product changes. The date at the top of this page always reflects the current version. If a change materially affects how we handle your personal data, we will tell you through the product or by email before it takes effect.
Contact us
For any privacy question or request, email support@skillgild.dev. Our Terms of Service govern your use of SkillGild alongside this policy.
Owner input required: add the postal address for privacy correspondence, and the name of a data protection officer or EU/UK representative if one is appointed.


