Privacy Policy

SkillDen · last updated 2026-07-23

What we collect

Stored durably (tied to your GitHub login): your GitHub username, display name, primary verified email, avatar URL, and first-seen / last-seen timestamps. If you issue a credential, we also store aggregate stats (commit/PR counts, language mix, activity tier) — never repo names, never your email.

Held only in your browser (a signed cookie, not on our servers): your username, avatar, and your GitHub access token, encrypted. The token is never logged.

Fetched from GitHub to build your graph, held briefly, then discarded (not written to disk): your public profile, public repositories (names, languages, stars, descriptions), contribution counts, and public activity.

Accessed but never stored or shown: with the repo permission we read your private repositories only to compute your full-view aggregates — never written to disk, never shown by name, never in a credential. Public project names appear on your card; private ones never do.

Technical: your IP address is used transiently for rate-limiting and may appear in standard server logs.

We never collect your code/file contents, private repo names, or passwords (there are none — GitHub sign-in only).

Why we collect it

GitHub permissions we request

repo (read, to compute your full-view aggregates including private repos — which we never store), read:user (profile), and user:email (your primary email).

Retention

We keep your record while your account is active and refresh it when you sign in. We delete it when you ask, or when you revoke the app's access on GitHub.

Your rights

Security

Your GitHub access token is encrypted at rest (AES-GCM) and never logged. We store the minimum described above and nothing more.

Contact

Questions or requests: privacy@skillden.cv.