LLMSkillHub

Privacy

What this catalogue stores about you, where it lives, and how to get rid of it.

Last updated 21 September 2026

The short version

Signing in gives us your name, email and avatar from Google or GitHub. Your email is never shown to anyone else. Publishing a skill makes your handle and that skill public, because that is what publishing is. The site itself sets no cookies and the API never records your IP address. Firebase Analytics is the one third party that watches you, and it only runs on the live site.

What we collect, and when

Nothing, until you sign in. Browsing the catalogue, reading a skill, downloading one — none of that is tied to a person. The API does not log IP addresses or user agents; every request writes one line recording the method, the path, the status code and how long it took, and nothing else.

When you sign in with Google or GitHub, that provider tells us who you are and we keep: your handle, your display name, your email address, a link to your avatar image, and the identifier the provider uses for you. We never see your password — the whole point of signing in this way is that you type it into Google or GitHub and not into us.

While you are signed in we hold a session token, valid for fourteen days, and any personal access tokens you create for the command line. Both are stored so that the server can recognise them again; the copy in your browser lives in local storage, not a cookie.

When you publish or review we record it in an audit log: who acted, what they did, which skill it was and when. That is what makes a catalogue of other people’s instructions accountable, and it is kept for as long as the skill is.

What is public

Your handle, display name and avatar. The skills you publish, their versions, what is in them, how many times they have been downloaded, and the outcome of each review. Assume anyone can see all of it, including people who are not signed in and automated agents reading the catalogue over the API.

Your email address is not in that list. It is returned only to you, on your own account page.

Where it is kept

Account records and the catalogue live in a PostgreSQL database on Google Cloud, in their Mumbai region. Published packages are stored in Cloudflare R2. The website is served by Cloudflare. That means your data is processed in India and, depending on where you are reading this, crosses a border to get to you.

Who else sees it

Nobody else. We do not sell anything to anyone, and there is no advertising on this site to sell it for.

Mirrored authors

Some pages here were created for people who have never visited. When a skill is copied from a public repository, a placeholder account is made in the author’s name so the work is attributed to them rather than to us. Those accounts hold only what the repository already said in public: a username and an avatar. No email address, because we were never given one.

If one of those is you, you can claim the account and it becomes yours — or ask us to remove the page, and it goes.

Deleting things

You can remove a skill yourself from its page at any time. Existing downloads keep working, deliberately: withdrawing a package should not break someone’s build this afternoon.

For your account and everything attached to it, write to hello@llmskillhub.com from the address you signed up with. We will confirm before anything is deleted, because an account deletion arriving by email is exactly the sort of request that should not be taken at face value.

One thing survives deletion: the audit log keeps a record that an action happened, with the account identifier removed. Losing the fact that a version was approved would undo the only evidence that anyone checked it.

Asking what we hold

Write to hello@llmskillhub.com and we will tell you, and send you a copy. Most of it is already visible on your account page.

Changes

If this page changes in a way that affects what is collected or who sees it, the date at the top changes and we say so on the site rather than quietly editing the text.

This page describes how LLM SkillHub actually works and what it undertakes to do. It was not drafted by a lawyer and is not legal advice. If you need it to carry legal weight in a particular jurisdiction, have someone qualified read it first.