Privacy
隐私政策
本政策说明 SkillsBase 在你浏览、注册、使用第三方账号登录、发布或认领 Skill、收藏、评论、订阅通知、使用 Ultra 功能、创建 API key、导出数据或联系我们时会如何收集、使用和保护信息。
最后更新:2026年7月14日Privacy
Privacy Policy
This policy explains how SkillsBase collects, uses, and protects information when you browse, register, use social sign-in, publish or claim skills, favorite items, comment, subscribe to notifications, use Ultra features, create API keys, export data, or contact us.
Last updated: July 14, 2026概览
SkillsBase 是一个用于发现、发布、认领和讨论 Agent Skill 的社区目录。我们尽量只收集提供服务、保护账号、处理订阅和维护社区所必需的信息,不出售个人信息,也不把个人信息用于跨站行为广告。
我们收集的信息
- 账号信息:昵称、邮箱、密码哈希、邮箱验证状态、邀请码或兑换码使用状态、订阅等级、订阅有效期、通知偏好、角色和登录会话时间;使用 Google、GitHub 或 LINUX DO 登录时,我们只保存提供商名称、稳定账号标识以及登录和展示所需的邮箱、显示名称和头像地址。LINUX DO 不提供可直接信任的邮箱验证状态,因此首次通过 LINUX DO 注册时,SkillsBase 会自行发送邮箱验证邮件,并同时要求邮件令牌与原浏览器的授权凭据;验证成功前不会创建账号或绑定身份。首次授权后的待注册凭据通常在 15 分钟后失效;提交 LINUX DO 邮箱验证后,哈希验证状态在 30 分钟后失效,并在下一次定期或 OAuth 清理周期从活动系统删除。
- 你主动提交的内容:Skill 标题、简介、分类、标签、仓库或文档链接、安装说明、封面图、认领验证信息、评论、收藏、关注、关键词或主题监控词,以及相关编辑和管理记录。
- 订阅与权益信息:如果你使用兑换码、注册渠道福利或管理员授予的订阅,我们会保存必要的计划、有效期、兑换码使用状态和权益状态标识。
- API 与导出信息:API key 名称、公开前缀、哈希、创建时间、撤销状态、最近使用时间、只读 API 的限流记录,以及你请求的数据导出类型和格式。
- 邮件与通知信息:邮箱验证、密码重置、周报、关注动态提醒和关键词提醒的发送记录,例如通知类型、周期、发送状态和时间。我们使用这些记录避免重复发送和排查投递问题。
- 运行与安全信息:请求时间、IP 相关的限流记录、会话令牌或标识、错误日志、同步日志以及用于防滥用和排障的基础技术信息。
- 公开来源信息:我们会从 GitHub 等公开来源读取仓库名称、描述、stars、forks、topic、license、语言、头像和最近更新时间。
- 本地浏览器存储与测量:SkillsBase 使用 localStorage 保存登录令牌和语言偏好;产品事件仅在有获批准的第一方采集器时发送,目前不加载第三方分析脚本。另以 25% 采样率收集归一化页面类型、粗粒度设备类别、Cloudflare 边缘地区以及 TTFB、LCP、INP、CLS 等性能数值。性能样本不含 IP、用户/会话标识、原始 URL 或查询参数,尊重 DNT/GPC 并保存 30 天。
我们如何使用信息
- 创建和保护账号,验证邮箱,重置密码,管理会话和通知偏好。
- 展示 Skill 目录、详情页、排行榜、收藏、评论、动态、周报预览、监控匹配、导出和只读 API 结果。
- 处理兑换码、计划有效期、权益开通和订阅功能访问。
- 发送必要的服务邮件,例如邮箱验证、密码重置、周报、关注动态提醒和你选择接收的关键词提醒。
- 检测滥用、限制高风险请求、排查故障、维护站点稳定性和改进内容质量。
- 同步公开 GitHub 数据,让目录和排行保持可用和及时。
服务提供商
我们会使用必要的服务提供商来运行 SkillsBase,包括 Cloudflare 托管、数据库和对象存储,Resend 或类似邮件投递服务,Google 身份服务、GitHub OAuth/API 以及 LINUX DO Connect。服务提供商只应在提供、保护或支持服务所需范围内处理信息。
在法律要求、处理滥用、保护用户或维护服务安全时,我们也可能披露必要信息。我们不会出售个人信息,也不会为了跨站行为广告共享个人信息。
保存与安全
密码和 SkillsBase API key 以哈希形式保存。完整的 SkillsBase API key 只在创建时显示一次;登录会话可在“我的主页”中查看和退出,SkillsBase API key 可由你撤销。Google、GitHub 和 LINUX DO 的访问令牌、刷新令牌和 ID token 仅用于登录回调期间读取必要身份信息,不会保存到 SkillsBase 数据库;提供商返回的 api_key 和 external_ids 也不会保存。
我们会根据提供服务、安全、防滥用、合规、审计和备份需要保存信息;当信息不再需要时,会删除、匿名化或从常用系统中移除。邮件发送记录、兑换码/订阅状态记录和限流记录会按排障、幂等处理和安全需要保留。
没有任何互联网服务能保证绝对安全。如果你发现安全问题,请尽快通过本政策末尾的邮箱联系我们。
你的选择
- 你可以在“我的主页”修改昵称、密码、通知偏好,查看并退出会话,管理关键词监控、API key、兑换码权益和数据导出。
- 你可以删除自己发布的社区 Skill 或评论,撤销 API key,取消不需要的通知偏好。公开 GitHub 数据来自第三方公开来源,删除请求可能需要在来源处一并处理。
- 你可以联系我们请求访问、更正、导出或删除账号数据。我们可能需要验证你的身份后再处理请求。
- 你可以在浏览器中清除 localStorage;清除后需要重新登录并重新选择语言偏好。
儿童隐私
SkillsBase 不面向 13 岁以下儿童。如果你认为未成年人向我们提交了个人信息,请联系我们,我们会尽快处理。
政策更新
我们可能会随着功能、服务提供商或法律要求变化更新本政策。重大变更会在本页更新日期,并在适当情况下通过站内或邮件方式提示。
联系我们
隐私、账号数据、删除请求或安全问题,请发邮件至 support@skillsbase.cc。
Overview
SkillsBase is a community directory for discovering, publishing, claiming, and discussing Agent Skills. We try to collect only the information needed to provide the service, protect accounts, process subscriptions, and maintain the community. We do not sell personal information or use it for cross-site behavioral advertising.
Information We Collect
- Account information: name, email address, password hash, email verification state, invite or redeem code state, subscription tier, subscription expiration, notification preferences, role, and session timestamps. When you use Google, GitHub, or LINUX DO sign-in, we store only the provider name, stable account identifier, and the email, display name, and avatar URL needed for sign-in and presentation. LINUX DO does not provide an email-verification state we can trust directly, so first-time registration requires both a SkillsBase email token and the original browser's authorization credential; no account or identity binding is created before both checks pass. Pending registration credentials normally become unusable after 15 minutes; after a LINUX DO email-verification request, hashed verification state becomes unusable after 30 minutes and is removed from active systems during the next scheduled or OAuth cleanup cycle.
- Content you submit: skill titles, summaries, categories, tags, repository or documentation links, install notes, cover images, claim verification information, comments, favorites, follows, keyword or topic watch terms, and related edit or moderation records.
- Subscription and entitlement information: if you use redeem codes, receive a registration-channel benefit, or receive an admin-granted subscription, we store the necessary plan, expiration, redeem-code usage state, and entitlement status identifiers.
- API and export information: API key names, public prefixes, hashes, creation time, revocation state, last-used time, read-only API rate-limit records, and the dataset and format you request for exports.
- Email and notification information: delivery records for email verification, password reset, weekly digest, followed-activity alerts, and keyword alerts, such as notification type, period, status, and timestamp. We use these records to avoid duplicate sends and troubleshoot delivery.
- Operational and security information: request times, IP-related rate-limit records, session tokens or identifiers, error logs, sync logs, and basic technical information used for abuse prevention and troubleshooting.
- Public-source information: we read repository names, descriptions, stars, forks, topics, licenses, languages, avatars, and update times from public sources such as GitHub.
- Browser storage and measurement: SkillsBase uses localStorage for your login token and language preference. Product events are sent only when an approved first-party collector is available; third-party analytics scripts are currently not loaded. We also sample 25% of eligible page loads for normalized page type, coarse device class, Cloudflare edge region, and performance values such as TTFB, LCP, INP, and CLS. Performance samples exclude IP, user/session identifiers, raw URLs, and query strings, respect DNT/GPC, and are retained for 30 days.
How We Use Information
- Create and protect accounts, verify email addresses, reset passwords, and manage sessions and notification preferences.
- Show the skill directory, detail pages, rankings, favorites, comments, activity feeds, digest previews, watch matches, exports, and read-only API results.
- Process redeem codes, plan expiration, entitlement activation, and subscriber-feature access.
- Send necessary service emails, such as email verification, password reset, weekly digests, followed-activity alerts, and keyword alerts you choose to receive.
- Detect abuse, rate-limit risky requests, troubleshoot issues, keep the site stable, and improve content quality.
- Sync public GitHub data so the directory and rankings stay useful and current.
Service Providers
We use necessary service providers to run SkillsBase, including Cloudflare hosting, database and object storage, Resend or similar email delivery services, Google identity services, GitHub OAuth/API, and LINUX DO Connect. Service providers should process information only as needed to provide, protect, or support the service.
We may also disclose necessary information when required by law, to handle abuse, to protect users, or to maintain service security. We do not sell personal information or share it for cross-site behavioral advertising.
Retention and Security
Passwords and SkillsBase API keys are stored as hashes. Full SkillsBase API keys are shown only once at creation. Active sessions can be reviewed and revoked from your profile page, and SkillsBase API keys can be revoked by you. Google, GitHub, and LINUX DO access tokens, refresh tokens, and ID tokens are used only during the sign-in callback to read necessary identity data and are not stored in the SkillsBase database; provider-returned api_key and external_ids fields are not stored either.
We retain information as needed to provide the service, secure the site, prevent abuse, comply with obligations, support audits, and maintain backups. When information is no longer needed, we delete it, anonymize it, or remove it from active systems. Email delivery records, redeem-code/subscription status records, and rate-limit records are retained as needed for troubleshooting, idempotency, and security.
No internet service can guarantee absolute security. If you discover a security issue, contact us promptly using the email below.
Your Choices
- You can update your name, password, notification preferences, active sessions, keyword watches, API keys, redeem-code entitlements, and data exports from your profile page.
- You can delete community skills or comments you authored, revoke API keys, and turn off notification preferences you no longer want. Public GitHub data comes from third-party public sources, so removal may also need to happen at the source.
- You can contact us to request access, correction, export, or deletion of account data. We may need to verify your identity before acting on a request.
- You can clear localStorage in your browser. You will need to sign in again and reselect your language preference afterward.
Children's Privacy
SkillsBase is not intended for children under 13. If you believe a child has submitted personal information to us, contact us and we will handle it promptly.
Policy Updates
We may update this policy as features, service providers, or legal requirements change. Material updates will change the date on this page and, when appropriate, will be announced in the product or by email.
Contact
For privacy, account data, deletion requests, or security issues, email support@skillsbase.cc.
