SuperSkill privacy

Public catalog requests may produce bounded operational logs. SuperSkill masks client IP addresses and strips URL query strings from production access logs.

Public discovery events are limited to approved fields. They must not contain prompts, task text, local paths, archive contents, tokens, cookies, browser proofs, invite codes or payment secrets.

Agent access tokens stay in local process memory. A rotating refresh credential may be stored only in the operating-system credential store for at most 30 days. Workspace invite codes and agent authorization proofs are never placed in page metadata, preview image URLs or public caches.

Crawler policy: search=yes, ai-input=yes, ai-train=no, use=reference. See https://superskill.sh/robots.txt.

Contact: admin@superskill.sh