Privacy Policy
Last updated · 24 August 2026
This Privacy Policy describes how SkillForge ("SkillForge," "we," "us") handles information when you use https://skillforge-jet-chi.vercel.app and related APIs. SkillForge is an index of public AI agent skills (SKILL.md files) from GitHub. This page is informational and is not legal advice.
1. Information we collect
We aim to collect only what we need to operate the registry:
- Skill index data from public GitHub (names, descriptions, paths, stars, licenses, content hashes).
- Install events when you use install tracking: skill identity and a one-way hash of IP (not the raw IP stored for ranking).
- Server and security logs (timestamps, request paths, coarse technical metadata) for abuse prevention and reliability.
- Admin session data if you are an authorized operator (HMAC-signed session, not a public account system).
We do not require you to create an account to browse the catalog. We do not intentionally collect special-category data (health, religion, biometrics). Skills themselves are third-party content from public repositories.
2. How we use information
- Operate and improve the catalog, search, and install experience.
- Rank skills and show install metrics (labeled live or estimated).
- Detect abuse, enforce rate limits, and secure admin surfaces.
- Run automated crawling of public GitHub skill files.
- Respond to reports and operational requests.
Legal bases we rely on where GDPR may apply include legitimate interests (operating a public index, security, analytics that are strictly operational) and, where required, consent for non-essential cookies if we add them later.
3. Cookies and similar tech
Essential cookies or storage may be used for security and admin sessions. We do not currently run third-party advertising cookies. If we add analytics cookies, we will update this policy and provide choices where required.
4. Sharing and processors
We share data only as needed to run the service:
- Hosting and edge: Vercel.
- Database: Supabase (PostgreSQL).
- Source content: public GitHub repositories (not private data we upload from you).
We do not sell personal information.
5. Retention
Install and log data are kept only as long as useful for rankings, security, and operations, then deleted or aggregated. Skill index records persist while the skill remains listed; removed skills may be dropped from the public catalog.
6. Your rights
Depending on where you live (including GDPR/UK GDPR and CCPA/CPRA regions), you may have rights to access, correct, delete, restrict, or object to certain processing, and to lodge a complaint with a supervisory authority. To exercise rights related to data we control, contact us using the details below. We will respond within applicable timelines (e.g. roughly one month under GDPR where it applies).
7. International transfers
Infrastructure may process data in the United States or other regions where our providers operate. Where required, we rely on appropriate safeguards offered by those providers.
8. Children
SkillForge is directed at developers and professionals. It is not intended for children under 16. We do not knowingly collect personal data from children.
9. Changes
We may update this policy as the product changes. The "Last updated" date at the top will change when we do. Continued use after updates means you should review the revised policy.
10. Contact
Privacy questions: open an issue or discussion on github.com/Rustys90/skillforge. For skill takedown or safety reports, use the in-product report controls where available or contact via the same repository.
[Legal review recommended] Operator legal entity name, registered address, and a monitored privacy email should be filled in before relying on this policy for formal compliance.