Privacy Policy
SkillDen · last updated 2026-08-16
What we collect
Stored durably (tied to your immutable GitHub account ID): your GitHub username, display name, primary verified email, avatar URL, notification preference, and first-seen / last-seen timestamps. If you issue a credential, we also store aggregate stats (commit/PR counts, language mix, activity tier) — never repo names, never your code.
Held only in your browser (a signed cookie, not on our servers): your username, avatar, and your GitHub access token, encrypted. The token is never logged.
Fetched from GitHub to build your graph, held briefly, then discarded (not written to disk): your public profile, public repositories (names, languages, stars, descriptions), contribution counts, and public activity.
Accessed but never stored or shown: with the repo
permission we read your private repositories only to compute your
full-view aggregates — never written to disk, never shown by name,
never in a credential. Public project names appear on your card; private ones never do.
Feedback: optional messages, reply emails, and page URLs are capped and retained for 90 days by default. Technical: your IP address is used transiently for rate-limiting. Application logs do not include email addresses, feedback bodies, access tokens, or full request bodies.
We never collect your code/file contents, private repo names, or passwords (there are none — GitHub sign-in only).
Why we collect it
- To provide the service you asked for — your SkillDen profile and graph.
- To support account and app-related communications when those communications are introduced. Email collection is intentional, but your email is never sold or used for marketing without a separate opt-in.
GitHub permissions we request
repo (read, to compute your full-view aggregates including private
repos — which we never store), read:user (profile), and
user:email (your primary email).
Retention
We keep your identity and email record while your account is active and refresh it when you sign in. Feedback is retained for 90 days by default. Publication state, credentials, snapshots, and caches are revoked or invalidated when you delete your account. External copies made by other people or services cannot be recalled by SkillDen.
Your rights
- Delete / erasure: remove your identity, email, publication state, credentials, snapshots, caches, and session at Your data (signed in), or by emailing us.
- Unsubscribe: opt out of account/app notification emails at Your data; this keeps your account.
- Revoke: remove SkillDen under your GitHub Settings → Applications at any time.
Security
Your GitHub access token is encrypted at rest (AES-GCM) and never logged. Public credentials use Ed25519 signatures, remote PostgreSQL certificate validation is enabled, and publication authorization uses immutable GitHub account IDs rather than usernames.
Contact
Questions or requests: privacy@skillden.cv.