Legal
Privacy Policy
How SKILLRSS collects, uses, shares, and protects your account, subscription, payment-related, and technical information.
1. Overview
This Privacy Policy explains how SKILLRSS (“we”, “the Service”) collects, uses, stores, shares, and protects information about you on skillrss.com and related services. By using the Service you acknowledge the practices described here; our processing of personal information is also governed by the Terms of Service.
SKILLRSS helps practitioners track and understand AI agent skills hosted on public GitHub. We aim to collect only the data needed to provide the Service, and selling personal information is not part of our business model.
2. Controller and Contact
The controller of personal information is the entity operating SKILLRSS. Send privacy-related requests to support@skillrss.com (a subject line mentioning “privacy request” helps).
3. Information We Collect
Depending on how you use the Service, we may process the following categories of information:
- Account information: email address, display name, password hash (we never store plaintext passwords), bio, and other details you choose to provide.
- Authentication and sign-in: email verification code/OTP records, sessions and cookies, sign-in times and basic security logs; if you use GitHub OAuth, we receive the identifier, username, verified email, and other information within the authorized scope that GitHub provides.
- Subscriptions and product usage: the public GitHub links you submit, the interpretation targets you pick, subscription relationships, unread state, plan tier, and slot usage.
- Payment and billing: identifiers needed for checkout and plan state (such as the link between a buyer identity and our account, order/recurring lifecycle events, plan expiry and renewal-cancellation state). Card numbers and full bank card data are handled by the payment provider (Waffo); we do not persist full card numbers in our own systems.
- Communications: support emails, feedback, and interpretation issue reports you send, plus metadata about the emails we send for account verification, security, and service notices.
- Technical and log data: IP address, browser/device type, request times, error logs, and performance and security events. Our cloud hosting platforms also produce operational logs.
- Public source material: to generate interpretations, we read the files and history of the public GitHub repositories you point to at specific commit states. This material is generally already public; we feed it to the analysis pipeline and, by product design, produce shared interpretations that multiple users can reuse.
We never intentionally ask for private repository credentials or non-public code. Do not submit sensitive personal information you are not authorized to handle.
4. How We Use Information
We use the information above to:
- create and maintain accounts, and complete authentication and sign-in;
- provide subscriptions, the console, interpretation generation, and access control (including plan and slot boundaries);
- process billing events for payment, renewal, renewal cancellation, downgrades, and fraud prevention;
- send verification codes, security notices, and transactional email you request or the Service requires;
- keep the Service secure, troubleshoot, prevent abuse, and improve reliability and product experience;
- meet legal obligations, respond to valid legal process, and establish, exercise, or defend legal claims;
- produce statistics and service improvements after de-identification or aggregation (reducing identifiability where feasible).
We do not sell your personal information to data brokers. If we introduce optional marketing email in the future, it will include a way to opt out, and marketing consent will not be bundled with access to core features (except where applicable law provides otherwise).
5. AI Processing and Shared Interpretations
When generating skill guides, suite overviews, and evolution interpretations, we may send material related to public repository states through a cloud AI gateway to third-party model providers for inference. The goal is evidence-based interpretation; by product design:
- public GitHub sources are processed in preference to your private codebases;
- the same source state can yield a shared interpretation reused by multiple subscribers, reducing duplicate computation;
- application-side persistence focuses on structured results and the metadata needed for auditing, avoiding long-term user profiles built from full raw prompts/responses or whole-repository copies (subject to implementation and operational policy);
- AI output can be wrong — always check it against the repository source.
7. Cookies and Similar Technologies
We use cookies, local storage, and similar technologies to keep you signed in, remember essential preferences, protect security, and understand basic traffic. These are generally required for a signed-in service; you can restrict cookies in your browser, but sign-in and other features may then break.
We do not currently deploy advertising tracking pixels for the purpose of selling personal data. If we introduce analytics or marketing cookies in the future, we will update this policy and obtain consent where applicable law requires it.
8. Retention
We keep information for as long as needed for the purposes described here: account data for the life of the account; payment and billing records for the periods law or audits require; security logs for a reasonable troubleshooting and protection window. After you delete your account or request deletion, we delete or anonymize data within a reasonable time, unless the law requires retention or a dispute needs it.
Shared interpretations and analysis artifacts derived from public repositories may continue to exist as service content for other users who still have access; that is not the same as retaining your account data.
9. Security
We take reasonable technical and organizational measures to protect information, such as encryption in transit (HTTPS), password hashing, access controls, and signature verification on payment webhooks. No online transmission or storage is perfectly secure; please use a strong password and protect your email and GitHub accounts.
10. Your Rights
Depending on the law where you live, you may have rights such as access, correction, deletion, restriction of processing, portability, objection to certain processing, or withdrawal of consent. You can exercise them through in-product features (updating your profile, unsubscribing, cancelling renewal) or by emailing support@skillrss.com. We will verify your identity and respond within a reasonable time, unless the law allows us to decline.
Where we process data based on consent, you may withdraw it without affecting the lawfulness of processing before withdrawal. Some core features may stop working without the necessary data.
11. Children
The Service is intended for adults with full legal capacity and users old enough to use online services under local law; it is not directed at children. If we learn we collected a child’s personal information without the required guardian consent, we will take steps to delete it.
12. International Transfers
Our infrastructure, payment, and AI providers may be located outside your country or region, which means your information may be transferred to, processed, and stored in other jurisdictions. We apply appropriate safeguards to the extent applicable law requires (for example, contractual clauses or the providers’ compliance mechanisms).
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in the product, the law, or our processing practices. Updates are posted on this page with a revised “Last updated” date. For material changes we may add an in-product notice or email. Continuing to use the Service after a change takes effect means you acknowledge the updated policy; if you disagree, stop using the Service and contact us about your account.
14. Contact Us
Privacy questions and personal-information requests: support@skillrss.com. Website: https://skillrss.com.
This policy exists to describe the product’s data practices transparently and to support payment and platform compliance reviews; it is not legal advice from an attorney. Where your region has mandatory privacy rules, those rules prevail within their mandatory scope.
Questions about this page? Contact support@skillrss.com。