RemoteSkill

Privacy policy

RemoteSkill is a private, personal library for Agent Skills. This policy describes what the service stores, why, and how to remove it. Use of your data is limited to what is described here.

What we store

  • Account. When you sign in with Google, GitHub, or email, we receive your email address, your name when the sign-in method provides one, and a stable account identifier. Our own records tie your catalog to that identifier and hold no other profile data.
  • Skill content. The files of every skill you import or upload are stored so they can be served to you and your agents. Skills are private to your account unless you share one. Sharing a skill creates a link that lets anyone who has it read that skill and add it to their own library, for as long as you leave sharing on. Shared skills are not listed, searched, or indexed anywhere, and turning sharing off ends access to the link.
  • GitHub connection. If you install our read-only GitHub App, we store a reference to the installation so we can read the repositories you granted, and only those, to import and refresh skills. We only read from your repositories, never write to them.
  • API keys and connections. An API key is shown once when you create it. We store a hash of the key, its label, and its last four characters, never the key itself. Connected apps sign in through OAuth. An OAuth access token used directly against our API can only read. Connecting an app to our MCP server gives it more than that: it can list and read your skills, create a skill, and write, edit, or delete files inside skills hosted here. Which skills it may change is decided the same way it is for you: only a skill hosted here, with nothing updating it. It cannot delete a skill, detach one, change what you share, import or export anything, or change a skill that updates from a repository or from someone else.

How it is used

Stored data exists to run the product: serving your skills to your agents, showing your catalog, and syncing from sources you connected. We do not sell data, share it with advertisers, or use skill content for anything beyond serving it to you.

Third parties

Third parties process data on our behalf to run the service: Clerk for sign-in, Convex for application data, Cloudflare for file storage, Vercel for hosting, and GitHub when you connect it. Each processes data only as needed to provide its part of the service.

Deletion

Deleting a skill removes it from your catalog immediately. Its stored files and content are then erased by a background cleanup, normally within minutes, with an hourly sweep that finishes anything interrupted. Deleting your account removes your catalog and its stored files the same way, along with your API keys and our record of your GitHub App installation. GitHub keeps its own record of the App, removed with the button GitHub labels Uninstall, in your GitHub settings. Any skill that still has content can be exported as a ZIP before you delete it. A skill you added from someone who has since stopped sharing it holds no content of its own, so there is nothing left to export.

A skill you share can be downloaded as a ZIP by anyone holding the link, so we build that archive once and keep the built copy for at most a day before it is erased and rebuilt on demand. Deleting the skill, or your account, erases it straight away. The archive is never a way around turning sharing off: every download is checked against the live share before any bytes leave, so the moment you stop sharing, the link stops working whether an archive exists or not.

One small record is kept after that. When an account closes we store a one-way hash of its sign-in identifier and the date it closed. It holds no email address, no name, and nothing about what the account contained, and it cannot be turned back into the identifier it came from. It exists because access tokens issued before the closure stay valid for up to a day afterwards, and without it one of those tokens could quietly create a fresh account for an identity that had just been deleted. How long we keep it depends on how the account ended. When you delete your sign-in account, that identity stops being able to issue tokens at all, so we keep the record for 30 days, well past the life of any such token, and then delete it too. When we close an account ourselves and your sign-in identity still exists, we keep the record for as long as the service runs, because that identity could otherwise sign in and start a new account, and this record is the only thing that keeps the closed one closed.

One other thing can outlive an account, and it is somebody else's record rather than yours. If you shared a skill and another person added it to their library, their copy stores the name you were shown under at that moment, so they can still tell where their own skill came from after yours is gone. It stays in their library until they delete that skill, and we do not reach into another person's library to change it. Where your sign-in method gave us no name to show, that stored name can be your email address. Nothing else about you is kept anywhere after deletion.

Contact

Questions about this policy can be sent to the operator at leeornahum@gmail.com.