Last updated: 2026-09-04
SkillsLLM is an informational directory and discovery service for open-source AI skills, related tools, security information, courses, and community features.
Privacy, data protection, account deletion, content-removal, and security enquiries can be sent to hello@skillsllm.com.
SkillsLLM aims to collect and process only the information reasonably necessary to operate, secure, and improve the service.
SkillsLLM uses a self-hosted instance of Umami at analytics.skillsllm.com to produce aggregate statistics about the use of the service.
Analytics may include page views, referrer, browser and operating system family, approximate country derived from network information, and events such as clicks or newsletter signup outcomes. SkillsLLM configures this analytics service without cross-site advertising tracking or behavioral advertising.
Purpose: understanding service usage and improving SkillsLLM.
Legal basis: our legitimate interest in operating, understanding, and improving the service.
SkillsLLM uses technical cookies and similar storage mechanisms necessary to provide requested functionality, such as authentication, session management, security, and remembering interface preferences.
Authentication cookies may be set when using GitHub sign-in or other account features. SkillsLLM may also use localStorage to remember interface preferences such as light or dark theme.
SkillsLLM does not use advertising cookies or third-party analytics cookies. Website analytics are provided through the self-hosted Umami instance described above.
When you choose to sign in with GitHub, SkillsLLM may receive and store information provided through GitHub OAuth, including your GitHub user ID, username, name, avatar URL, email address, provider account identifier, OAuth scope information, and authentication data associated with the linked account.
The current GitHub authorization is limited to profile and email access. SkillsLLM does not request repository write permission through the user sign-in flow.
Our authentication adapter may store a GitHub OAuth access token as part of the linked account record. SkillsLLM's application currently uses its own server-side GitHub credential for catalog and repository operations rather than using individual users' OAuth access tokens for those operations.
Account information is used to authenticate you and associate community activity such as votes, bookmarks, comments, feedback, and skill submissions with your account.
Purpose: authentication and delivery of account and community features.
Legal basis: providing the service you request and our legitimate interest in preventing abuse and maintaining the integrity of community features.
When you submit feedback, SkillsLLM stores the feedback type, message, your user account identifier, submission time, and any optional contact email you provide.
If necessary to respond to a request, we may use the email address associated with your signed-in account when no separate reply address was provided.
Administrative notifications may be sent to a private SkillsLLM Telegram chat. These notifications are designed to contain only limited information, such as the feedback type and account display name. The full feedback message and reply email are not intentionally included in Telegram notifications.
Purpose: responding to feedback, support, security, privacy, and content-removal requests and preventing abuse.
Legal basis: our legitimate interests in providing support, administering the service, handling rights requests, and protecting SkillsLLM and its users. Where processing is required by law, the applicable legal obligation also applies.
If you subscribe to the SkillsLLM newsletter, we process your email address, the page or feature from which you subscribed, the date of consent, the applicable consent version, and information needed to manage your subscription and unsubscribe request.
Newsletter signup notifications sent to Telegram do not intentionally contain the subscriber's email address.
Purpose: sending the SkillsLLM newsletter.
Legal basis: your consent. You may withdraw your consent at any time by using the unsubscribe mechanism included with newsletter communications. Withdrawal does not affect processing that occurred before consent was withdrawn.
When you request a public repository security scan, SkillsLLM processes the GitHub repository URL and technical information needed to perform and protect the scanning service.
We derive an anti-abuse identifier from the requesting IP address. The original IP address is not stored in the PublicSecurityScan database record. The derived identifier is used to enforce scan rate limits and protect the service from automated abuse.
Public scan records may include the repository owner, repository name and URL, scan status, scan report, share identifier, creation time, and the IP-derived anti-abuse identifier.
Purpose: providing security scan results, caching recent scans, sharing scan reports, rate limiting, and preventing abuse.
Legal basis: providing the requested scanning service and our legitimate interest in securing SkillsLLM and preventing abuse.
SkillsLLM indexes information from publicly available GitHub repositories and related public sources. This may include repository owner names or usernames, repository names and URLs, descriptions, stars, forks, topics, programming language, license information, repository content relevant to an AI skill, and security-related metadata.
Purpose: operating the SkillsLLM directory, discovery, comparison, categorization, and security features.
Legal basis: our legitimate interest in providing an informational directory of publicly available open-source resources.
When a paid SkillsLLM feature is available and you choose to purchase it, payment processing is handled by Stripe. SkillsLLM may store transaction-related information such as the relevant product or course, Stripe session identifier, amount, currency, associated SkillsLLM user account, and transaction date.
SkillsLLM does not store full payment card details.
Purpose: processing purchases, granting access, administering paid features, accounting, fraud prevention, and compliance with applicable legal obligations.
Legal basis: performance of the purchase contract and compliance with applicable legal obligations.
Our infrastructure may process standard request and security metadata such as requested URL, timestamp, response status, IP address, and user-agent information for service operation, troubleshooting, security, and abuse prevention.
Legal basis: our legitimate interest in maintaining a reliable and secure service.
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, taking into account service, security, dispute-resolution, and legal requirements.
SkillsLLM uses service providers where necessary to operate the service. Depending on how you use SkillsLLM, these may include:
These providers process information according to their respective roles, agreements, privacy terms, and applicable data protection requirements.
Some service providers may process information in countries outside your country of residence or outside the European Economic Area. Where required by applicable data protection law, SkillsLLM relies on appropriate transfer mechanisms and safeguards made available by the relevant provider, such as adequacy decisions, contractual safeguards, or Standard Contractual Clauses.
The SkillsLLM Badge browser extension injects a small badge onto GitHub repository pages indicating whether the repository is indexed in the SkillsLLM catalog.
{owner}/{repo}.The extension makes a request to the SkillsLLM lookup API for the repository being viewed. The extension does not intentionally attach GitHub authentication credentials to that request.
Lookup results may be cached in memory for the current browser-tab session. The extension does not intentionally use Chrome storage, IndexedDB, localStorage, or its own tracking cookies to build a user profile.
Depending on applicable law and your circumstances, you may have the right to request access to your personal data, correction of inaccurate information, deletion, restriction of processing, data portability, or to object to certain processing.
Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Where we rely on legitimate interests, you may have the right to object to the processing based on your particular situation.
To exercise a privacy right, contact hello@skillsllm.com. We may request reasonable information necessary to verify your identity before acting on a request.
You also have the right to lodge a complaint with the data protection supervisory authority applicable to you, including the supervisory authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.
You may request deletion of your SkillsLLM account by contacting hello@skillsllm.com.
Repository owners, developers, copyright holders, and other rights holders may also request correction or removal of indexed content. SkillsLLM may request reasonable evidence of identity, ownership, or authority before processing such a request.
Account or content deletion does not require SkillsLLM to erase information that must be retained under applicable law or information reasonably necessary for the establishment, exercise, or defense of legal claims.
For more information about third-party repository content and removal requests, see our Terms of Service.
SkillsLLM may use artificial intelligence and other automated tools to assist with research, summarization, drafting, categorization, metadata generation, editorial workflows, security analysis, and other service functions.
AI-assisted or automated processing may be used in connection with editorial content, news-related content, public repository information, skill categorization, metadata, and security or prompt-injection analysis.
Where appropriate, SkillsLLM provides additional information about the use of artificial intelligence through its AI Transparency page or through disclosures associated with particular content.
Automated analysis may be incomplete or inaccurate and should not be interpreted as a professional, legal, or security determination.
SkillsLLM does not currently use artificial intelligence to make solely automated decisions about individual users that produce legal effects or similarly significant effects on them.
SkillsLLM uses technical and organizational measures intended to protect information against unauthorized access, misuse, alteration, or loss. No internet service or storage system can be guaranteed to be completely secure.
We may update this Privacy Policy when SkillsLLM, its service providers, or applicable legal requirements change. The current version and its last-updated date will be published on this page.
Privacy questions, data protection requests, account deletion requests, content-removal requests, and security reports may be sent to hello@skillsllm.com.