Skip to content

Privacy Policy

Last updated: March 2026

1. Data Collection

We collect minimal data necessary to operate the platform: GitHub profile information (username, email, avatar) when you sign in via OAuth, skill submission data, reviews you post, and basic usage analytics. We also collect IP addresses for rate limiting and security purposes. We do not sell or share your personal data with third parties for marketing purposes.

2. Profile Information

When you sign in, we may ask you to share information about yourself: profession, industry size, AI experience level, the AI agents you use, the skill categories that interest you, your goals on the site, your region in Israel, how you heard about us, and (optionally) your company name. This information is used for two purposes: to tailor what content we show you, and to understand our audience in aggregate so we can decide which categories and tools to invest in. You can edit any field, delete all of this information, or skip every question, at any time from your profile page. We never sell this data and never share it with third parties beyond the analytics processors listed above.

3. Usage Data

We automatically collect certain information when you visit the Platform, including: pages viewed, links clicked, install command copies, search queries, browser type, device information, and referring URLs. This data is collected through standard analytics services, Microsoft Clarity, and our own first-party anonymous analytics system. Microsoft Clarity collects session recordings and heatmap data to help us understand how users interact with the Platform. Clarity masks sensitive content by default and does not collect personal input data. Our anonymous analytics cannot identify individual users. IP addresses are anonymized in all analytics.

4. Try Skill chat data

When you open a chat with a skill demo bot, we collect: your chat messages and the bot's replies; the skill or bundle name being demoed, the conversation language, and timing; usage metrics that help us monitor cost and detect abuse. Retention: For guest users, the conversation is held in temporary cache for up to 24 hours and then deleted. For signed-in users, conversations are kept until you delete them, which you can do from the /chats page or by starting a new chat. Who can access: You can always view and delete your own conversations. Skills-IL admins can access a conversation only if it has been reported or automatically flagged for suspected abuse, and every such access is recorded in our audit log. Third parties: chat content is processed by a third-party AI service that runs the language model, under that provider's terms of service. The bot may also issue web search queries on your behalf to gather live information; those queries reach a third-party search service and may be visible to it. Security: conversations are protected by HTTPS, role-based access controls, and admin-only audit access. They are not end-to-end encrypted. Your rights: You can export your entire chat history from the profile page and delete individual conversations from /chats. For additional requests under Israeli Privacy Protection Law Amendment 13, contact alex@agentskills.co.il.

5. AI Mode (Conversational Search)

When you use AI Mode at /ai, your questions are sent to our LLM provider (Google Gemini) so it can recommend tools from our catalog. We do not store the content of your questions or responses. The conversation context lives in ephemeral memory (Redis) for 30 minutes only, with a hard cap of 10 turns per session, then is discarded. We record anonymous usage metrics (message count, masked cost, timestamp) for quota enforcement and abuse detection — never the message content. Daily message quotas apply: 3/day for guests, 10/day for signed-in users, with separate counters from the Try Skill quota. We recommend you don't share personal info like ID numbers or bank details. Our LLM provider (Google) commits to zero content retention on our paid plan, but they are a third party subject to their own terms of service.

5. Cookies & Consent

Following Israel's Privacy Protection Law Amendment 13 (in force August 2025) and GDPR, we ask for explicit opt-in consent before running non-essential tracking. The consent banner lets you accept all, reject all, or toggle three categories: Analytics (aggregate usage), Session replay (Microsoft Clarity), and Error monitoring (Sentry). Essential cookies (sign-in, bot protection, your consent choice itself) always run so the site works. You can change your preferences anytime via the Privacy preferences link in the footer.

6. Third-Party Services

We use third-party services for authentication, data storage, hosting, usage analytics, and transactional emails. Our data infrastructure is hosted within the European Union. Each service operates under its own privacy policy and terms. We select providers that meet our security and privacy standards.

7. Data Retention

We retain your account data for as long as your account is active. Reviews and submissions are retained indefinitely as part of the public directory. Usage analytics data is retained according to the policies of our analytics providers (up to 26 months for Google Analytics, up to 5 years for Mixpanel, up to 30 days for Microsoft Clarity session recordings). You may request deletion of your personal data at any time.

8. Data Security

We implement reasonable security measures to protect your personal data, including encrypted connections (HTTPS), secure authentication via OAuth, and access controls on our database. However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.

9. Your Rights

Under the Israeli Privacy Protection Act (1981) and GDPR, you have the right to: access the personal data we hold about you; correct inaccurate personal data; request deletion of your personal data; object to processing of your data; request data portability; and withdraw consent at any time. To exercise these rights, contact us at privacy@agentskills.co.il. We will respond to requests within 30 days.

10. Children's Privacy

The Platform is not intended for users under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on the Platform. Your continued use of the Platform after changes are posted constitutes acceptance of the updated policy.

12. Skill Generator (/create)

When you use /create, we store the description you typed, its language, the locale, a salted SHA-256 hash of your IP, a salted hash of an anonymous cookie, and usage stats (generation latency, cost, whether you downloaded the result). We retain this for 90 days, after which it is deleted automatically. We do not share descriptions with third parties. To request immediate deletion of a record, email alex@agentskills.co.il.

13. Contact

For privacy inquiries or to exercise your rights, contact us at privacy@agentskills.co.il.