Privacy Policy
Effective 28 July 2026 ยท Applies to skillingmain.com
This policy explains what personal data SkillingMain collects, why we collect it, and what you can do about it. We have tried to describe our actual system rather than list every category a business might conceivably collect.
1. What we collect
| Data | Why we hold it |
|---|---|
| Name and email address | To create your account, sign you in, and contact you about your purchases. |
| Password (hashed with bcrypt) | To authenticate you. We never store or see your plaintext password. |
| API keys (stored only as a SHA-256 hash) | To authenticate CLI, REST API and MCP requests. We cannot recover a key once issued โ only verify it. |
| Purchases, orders and subscription status | To give you access to what you paid for, and for accounting. |
| Usage records (skill installs, API and MCP call counts, timestamps) | To enforce plan quotas and show your usage. Tied to your account. |
| Skills you author | To publish and sell them on your behalf. |
| Server logs (IP address, request metadata) | Security, abuse prevention, rate limiting, and debugging. |
We do not collect or store your payment card details. Card data goes directly to Stripe; we receive only a customer reference, the subscription status, and the outcome of a payment.
We do not want your third-party credentials. The cloud and identity credentials described in our setup guides โ AWS keys, Microsoft Graph secrets, Google service-account keys โ are configured in your environment and are never sent to us. Do not paste secrets into skills you publish or into support emails.
2. Cookies
We use a single essential cookie (skillingmain_session) to keep you signed in. It is HTTP-only, and marked Secure in production. We do not use advertising or third-party tracking cookies, and there is no cross-site behavioural profiling โ which is why you are not seeing a consent banner.
3. Legal bases (UK/EU GDPR)
- Contract โ account, purchases, delivery of skills, support.
- Legitimate interests โ security, fraud and abuse prevention, quota enforcement, and improving the Service.
- Legal obligation โ retaining transaction records for tax and accounting.
- Consent โ optional product emails, where we send them. You can withdraw consent at any time.
4. Who we share data with
We share only what each provider needs to do its job:
- Stripe โ payment processing, subscription billing, and refunds.
- DigitalOcean โ application hosting and the managed database storing your account.
- GitHub โ source hosting and deployment (no customer data).
We do not sell personal data, and we do not share it for advertising. We may disclose data where legally required, or to protect our rights, users, or the security of the Service.
5. International transfers
Our infrastructure is hosted in the United States. If you are outside the US, your data will be transferred and processed there. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses operated by our providers.
6. How long we keep it
- Account data โ while your account exists, then deleted within 30 days of closure.
- Purchase and transaction records โ retained up to 7 years where required by tax and accounting law, even after account closure.
- Usage records โ retained for up to 24 months for quota and abuse analysis.
- Server logs โ typically 30โ90 days.
- Published skills โ remain available to people who licensed them; we can unpublish on request.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your data, to data portability, and to withdraw consent. California residents have rights under the CCPA/CPRA, including the right to know and to delete; we do not sell or share personal information as those terms are defined.
Exercise any of these by emailing [email protected]. We will respond within 30 days. You may also complain to your local data protection authority โ in the UK, the ICO.
8. Security
- All traffic is served over HTTPS.
- Passwords are hashed with bcrypt; API keys are stored only as SHA-256 hashes.
- Database access is restricted and credentials are held as deployment secrets.
- Session cookies are HTTP-only to reduce the impact of cross-site scripting.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority where the law requires it. If you find a vulnerability, please report it to [email protected] rather than disclosing it publicly.
9. Children
The Service is not directed at children under 16. If you believe a child has given us personal data, contact us and we will delete it.
10. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by purely automated means. Quota enforcement is automated but affects only usage limits on your plan.
11. Changes
We will post material changes here and update the effective date, and give notice before they take effect where the change is significant.
12. Contact
SkillingMain โ [email protected]
Before you rely on this document
This is a good-faith draft written for a small software business, not legal advice, and it has not been reviewed by a lawyer. Consumer-protection, distance-selling, and data-protection rules differ by country โ particularly in the EU and UK โ and some clauses here may be unenforceable in your jurisdiction. Have a qualified lawyer review these terms before you rely on them commercially, and fill in the registered entity details in src/components/Legal.tsx.