Privacy policy
Last updated: 29 August 2026
In short
The public site sets no tracking cookie and runs no analytics. The personal data we process is your account data (email address, name, hashed password), the skills you store in your directory, the inventory the command line client sends from your machines, and the email address you leave to hear about the team plan.
Cookies
A single cookie is set, and only once you sign in: the session cookie that keeps you signed in. It is strictly necessary for the service, so no consent is required. No advertising tracker, no analytics tool.
Data we process
Account: email address, display name, password (stored as a hash only). If you sign in with GitHub, we receive the identifier, name and email address of your GitHub profile. Legal basis: performance of the contract that starts when you create the account.
Directory: the content of the skills you submit or approve (SKILL.md and related files), their version history and your review comments. This content is yours and is read by nobody outside you and the members of your organization.
Inventory: the command line client sends the list of skills found in ~/.claude/skills and in the project folders you registered, with a hash of their content and the machine name. It sends neither the content of your projects nor any other file. Legal basis: performance of the contract.
Device tokens: the tokens you create for the command line client are stored hashed. We keep their label and last-used date.
Waiting list: if you leave your address to hear about the team plan, it is used for that message only. Legal basis: your consent, which you can withdraw at any time by writing to us.
Emails: we only send the emails the service needs (address verification, password reset). They go through Resend.
Retention
Your account and directory data are kept as long as the account exists. Deleting the account, available in settings, removes the account, its tokens, its inventories and the directory you are the only member of.
The waiting list address is deleted at most three months after the team plan launches, or as soon as you ask.
Technical logs and error reports are kept for at most 90 days.
Processors
Vercel Inc. (United States): hosting of the site and the application.
Neon Inc. (United States, data stored in the European Union): database.
Resend Inc. (United States): verification and password reset emails.
Sentry, by Functional Software Inc. (United States): technical error reports, without IP address or visitor identifier.
GitHub Inc. (United States): only if you choose GitHub sign-in.
Vercel Inc., Neon Inc., Resend Inc., Functional Software Inc. and GitHub Inc. are established in the United States: transfers outside the European Union rely on the EU-US Data Privacy Framework these providers adhere to, or on the European Commission's standard contractual clauses.
Your rights
Under the GDPR you have the right to access, rectify, erase, port and object to the processing of your data. You can delete your account yourself from the settings. For any other request, write to hello@hubskillz.com.
You can also lodge a complaint with the French data protection authority, the CNIL (cnil.fr).
Changes to this policy
If the tools or the data collection described here change, this policy is updated before any new collection, with its revision date.