Privacy Policy
Last updated 2 September 2026.
This describes what TheSkillz stores about you, who else touches it, and how to get it back or get it deleted. It covers the website at https://theskillz.dev and nothing else — a skill you download runs on your own machine, under your own agent, and we have no visibility into it.
What we store
The short version: an account row, a session row, a purchase row per skill you buy, and whatever you publish. There is no shadow profile and no tracking beyond the analytics named below.
Account
- Email address — from your sign-in provider. Used to identify your account, to send transactional email, and as the buyer email at checkout. Not public.
- Username, display name, bio, website and avatar — your public profile. The username is required and unique; the rest you fill in yourself and can clear at any time. An avatar is either a URL from your sign-in provider or a file you uploaded, which is stored in our own file storage.
- GitHub account id and login — only if you signed in with GitHub, so we can attribute your skills and link your profile.
- Role and account creation date — whether you are a regular user or an admin, and when the account was made.
Purchases and payouts
- Purchase records — for each skill you buy: the payment provider, the order and checkout id, the skill, the gross amount, the processor fee, the platform and creator split, the currency, whether it is paid or refunded, and the timestamp. This is how we know what is in your library, and it is what the creator’s earnings are calculated from.
- Payment provider customer id — a Polar customer id, or a Stripe account id for creators who have onboarded, so repeat transactions line up.
- Creator payout details — if you are a creator being paid manually, the payout note you give us (for example a Wise email or bank details) and a record of each payout: amount, currency, method, reference and date. Visible only to you and to admins.
Sessions and sign-in
- Session rows — a random session id, the user it belongs to, when it was created and when it expires. Deleting a session signs that device out.
- Login tokens — where an email sign-in link is used, a hashed token and the email address, both short-lived and deleted on use or expiry.
What you publish
- Skills — the
SKILL.mdyou submit, its metadata, bundled files, the security scan report and the content hash. Published skills are public. - Reviews and stars — your rating, title and text, whether it is a verified purchase, and which skills you starred. Reviews are public and carry your profile name.
Technical
- Request and error logs — kept by Cloudflare as part of serving the site. These include IP addresses and user agents. We do not join them to your account.
- Webhook receipts — the id and type of each payment webhook, so a payment event is never processed twice. No personal data beyond the event id.
- Download and star counts — aggregate counters per skill, not per person.
We do not store card numbers, sell or rent your data, run advertising or ad-tech, build behavioural profiles, or share your email with creators.
Cookies and browser storage
ss_session— our own session cookie. HttpOnly, so scripts cannot read it, and it contains only an opaque session id. Strictly necessary: without it you cannot stay signed in, and there is no way to opt out and still have an account.- Firebase Authentication storage — during sign-in, Firebase keeps its own tokens in your browser (local storage / IndexedDB) under the Google domain it uses. Signing out clears it.
- Google Analytics cookies (
_gaand_ga_*) — set only when an analytics measurement id is configured for the deployment, with IP anonymisation on. If the id is not configured, no analytics script is loaded and no analytics cookie is set. You can block these with your browser settings, a content blocker or Google’s opt-out add-on without losing any site functionality.
We set no advertising, retargeting or cross-site tracking cookies.
Why we process it
- To run your account and give you what you bought — performance of the contract between us: sign-in, sessions, library, downloads, receipts.
- To operate the store — legitimate interests: security scanning and review of submissions, fraud and abuse prevention, keeping the site available, and calculating creator earnings.
- To send transactional email — sign-in links, submission and purchase notifications. We do not send marketing email.
- To measure traffic — consent, where consent is required in your jurisdiction; otherwise legitimate interests in understanding aggregate usage.
- To keep financial records — legal obligation: sales and payout records have to be retained for tax and accounting.
Who else processes your data
These are the only third parties involved. Each acts as a processor or, for payments, as a controller in its own right under its own privacy policy.
| Service | Role | What it sees |
|---|---|---|
| Firebase Authentication (Google) | Sign-in and identity | Your email address, your password (stored and verified by Google — we never see or store it), and the profile Google or GitHub returns when you use those buttons. We exchange the resulting Firebase token for our own session cookie. |
| Cloudflare | Hosting, database, file storage | The site runs on Cloudflare Workers; account, skill, purchase and session records live in Cloudflare D1; skill files and uploaded avatars live in Cloudflare R2. Cloudflare processes request metadata (IP address, user agent, timing) to serve and protect the site. |
| Polar | Payments and merchant of record | For paid checkouts: your name, email address, billing and tax location, and payment details. Polar is the seller of record and handles VAT and sales tax. Card details go to Polar and never reach our servers. We store the resulting order id and a Polar customer id. |
| Stripe | Payments and creator payouts, where enabled | Not used for buyer checkout in the current configuration. Where Stripe Connect is switched on for a creator, Stripe collects that creator's identity and payout details directly and we store only the resulting account id and onboarding status. |
| Google Analytics 4 (Google) | Traffic measurement | Page views, referrer, approximate location, device and browser, with IP anonymisation enabled. Only active when an analytics measurement id is configured for the deployment; no analytics scripts load otherwise. |
| Resend | Transactional email | The recipient address and the message content for sign-in and notification emails. |
| GitHub | Optional sign-in | Only if you choose the GitHub button. GitHub returns your account id, login and public profile through Firebase; we store the id and login so we can attribute skills to you. |
We may also disclose data where the law requires it, or to establish or defend a legal claim.
Where it is processed
These providers are US-headquartered and operate globally, so your data may be processed outside your country, including in the United States. Cloudflare serves the site from whichever edge location is nearest you, and the database and file storage sit in Cloudflare’s network. Transfers rely on the providers’ own transfer mechanisms — standard contractual clauses and equivalent frameworks.
How long we keep it
- Account and profile — until you delete the account.
- Sessions — until they expire or you sign out. Login tokens are minutes.
- Purchase and payout records — kept after account deletion, in reduced form, for as long as tax and accounting law requires. These records are what prove a sale happened and what a creator was paid.
- Published skills — for as long as they are listed. Buyers keep access to what they already bought.
- Analytics — under Google Analytics retention settings for the property.
Your rights, and how to use them
Depending on where you live you have some or all of these rights: to see the data we hold, to correct it, to have it deleted, to get a portable copy, to object to or restrict certain processing, to withdraw consent for analytics, and to complain to your data protection authority.
Some of it you can do yourself:
- Edit or clear your name, bio, website and avatar in account settings.
- Delete a review you wrote, or unstar a skill, from the skill page.
- Block analytics cookies in your browser at any time.
For access, export or deletion, email support@theskillz.dev from the address on your account. On a deletion request we remove your profile, uploaded avatar, sessions, stars and reviews (or detach the reviews from your identity where a skill’s rating history has to stay intact), unpublish skills you authored, and delete the linked Firebase identity. We keep the minimum purchase and payout records described above, and any outstanding payout balance is settled before the account is closed. We will respond within 30 days.
Children
TheSkillz is not intended for children under 16 and we do not knowingly collect their data. If you believe a child has an account, tell us and we will delete it.
Security
Sessions use an HttpOnly cookie holding an opaque id. Passwords are handled by Firebase and never reach us. Card details are handled by the payment provider and never reach us. Payment webhooks are signature-verified and replay-protected. Every submitted skill is scanned before a human reviews it. No system is perfect; if you find a vulnerability, mail support@theskillz.dev rather than disclosing it publicly.
Changes
If this policy changes, the date at the top changes with it and material changes get a notice on the site.
Contact
Privacy questions, data requests, or anything else about this page: support@theskillz.dev. The commercial side is covered by the Terms of Use.