Privacy Policy

SkillDen · last updated 2026-08-16

What we collect

Stored durably (tied to your immutable GitHub account ID): your GitHub username, display name, primary verified email, avatar URL, notification preference, and first-seen / last-seen timestamps. If you issue a credential, we also store aggregate stats (commit/PR counts, language mix, activity tier) — never repo names, never your code.

Held only in your browser (a signed cookie, not on our servers): your username, avatar, and your GitHub access token, encrypted. The token is never logged.

Fetched from GitHub to build your graph, held briefly, then discarded (not written to disk): your public profile, public repositories (names, languages, stars, descriptions), contribution counts, and public activity.

Accessed but never stored or shown: with the repo permission we read your private repositories only to compute your full-view aggregates — never written to disk, never shown by name, never in a credential. Public project names appear on your card; private ones never do.

Feedback: optional messages, reply emails, and page URLs are capped and retained for 90 days by default. Technical: your IP address is used transiently for rate-limiting. Application logs do not include email addresses, feedback bodies, access tokens, or full request bodies.

We never collect your code/file contents, private repo names, or passwords (there are none — GitHub sign-in only).

Why we collect it

GitHub permissions we request

repo (read, to compute your full-view aggregates including private repos — which we never store), read:user (profile), and user:email (your primary email).

Retention

We keep your identity and email record while your account is active and refresh it when you sign in. Feedback is retained for 90 days by default. Publication state, credentials, snapshots, and caches are revoked or invalidated when you delete your account. External copies made by other people or services cannot be recalled by SkillDen.

Your rights

Security

Your GitHub access token is encrypted at rest (AES-GCM) and never logged. Public credentials use Ed25519 signatures, remote PostgreSQL certificate validation is enabled, and publication authorization uses immutable GitHub account IDs rather than usernames.

Contact

Questions or requests: privacy@skillden.cv.