Legal

Privacy Policy

Last updated: August 13, 2026

1. Who we are

MasterSkills operates masterskills.dev, a private registry for AI agent skills. This policy explains what personal data we handle and why. Data protection questions: [email protected].

2. What we collect

  • Account data — when you sign in with GitHub or Google we receive your name, email address, and avatar. We never see or store passwords.
  • Organisation data — organisation name, memberships and roles, kits, and an audit log of actions (who published, installed, or changed what, and when).
  • Device data — the name and platform of devices you authorise for the CLI. Device tokens are stored only as SHA-256 hashes; the token itself never touches our database.
  • Content — the skill packages your organisation publishes (files, manifests, versions), stored so we can distribute them to the people you authorise.
  • Billing data — payments run through Paddle, our merchant of record. Card details go to Paddle, never to us; we store only your plan and subscription status.
  • Technical logs — server logs with IP address and user agent, kept short-term for security and operations.

3. What we never do

  • No selling or renting of personal data.
  • No advertising and no third-party analytics trackers.
  • No training of AI models on your private skills.
  • No reading of your repositories — Git integrations use scoped, read-only, revocable tokens limited to the skill files you choose.

4. Why we process data

We process data to provide the service (contract), to secure it and prevent abuse (legitimate interest), to bill paid plans (contract), and to meet legal obligations. We do not use your data for profiling or automated decision-making.

5. Cookies

We set session cookies for authentication only. There are no advertising or cross-site tracking cookies, which is why the site shows no cookie banner.

6. Who processes data for us

We share data only with the providers needed to run the service:

  • Paddle — payments, invoicing, and tax, as merchant of record.
  • Cloudflare — DNS, network security, and object storage for skill packages.
  • Our hosting provider — the servers the service runs on.
  • GitHub / Google — sign-in; they act as identity providers under their own policies.

These providers may process data in the EU and the US under their own compliance frameworks. We disclose data to authorities only when legally required.

7. Retention

Account and organisation data is kept while your account exists. When you delete a skill version, an organisation, or your account, the data is removed from production promptly and leaves backups as they rotate. Audit logs live with the organisation they belong to. Technical logs are kept for a short operational window.

8. Security

Traffic is encrypted with TLS. Device tokens are stored only as hashes. Organisations are isolated from one another, and published packages are scanned for accidentally included secrets before they go live. Access to production systems is limited to the people who operate the service.

9. Your rights

Under the GDPR, the Turkish KVKK, and similar laws you can request access to, correction of, deletion of, or a portable copy of your personal data, and you can object to specific processing. Email [email protected] and we will respond within 30 days. You also have the right to complain to your local data-protection authority.

10. Children

The service is built for professional teams and is not directed at children under 16.

11. Changes to this policy

We may update this policy as the service evolves. Material changes are announced by email or in the product before they take effect; the date at the top always reflects the current version.

12. Related documents

Use of the service is governed by the Terms of Service.