Privacy
Last updated 2026-07-30
Reading this directory needs no account, and we do not track you while you do it.
There is no analytics script on any page, no advertising network, no session recording, and no third-party embed. The content security policy on every response allows connections to this origin only, so a tracker could not load even if one were added by accident. The only cookie the site sets is the one that keeps you signed in, and only after you choose to sign in.
If you only browse
We store nothing that identifies you. Cloudflare, which serves the site, records the ordinary request logs any web server keeps, including your IP address, and we use those only to keep the service running and to investigate abuse. We do not build a profile from them and we do not join them to anything else.
If you sign in
Signing in uses GitHub. We ask GitHub for your profile and your verified email address, and for nothing else: no repository access, no write scopes, no organisation membership. From that we keep your GitHub user id, your username, your display name, your email address, and your avatar URL.
We keep those because a published skill needs an author who can be identified and contacted. Your username and display name appear publicly on skills you publish. Your email address does not, and we use it only to reach you about a submission.
The sign-in cookie holds a random identifier and nothing else. Everything about your session is held on our side, so signing out revokes it immediately rather than waiting for a token to lapse. It expires after 30 days.
Access tokens
If you create a token for the MCP server, we store a SHA-256 hash of it and the first few characters so you can tell your tokens apart. We never store the token itself, which is why we can show it to you once and never again. Anyone who reads our database finds hashes rather than credentials.
What you submit
A submitted skill is intended for publication, so treat everything in it as public. That includes the file itself and the site it targets. The note you write for the reviewer is the exception: it goes to a curator and is never published.
We keep submissions after a decision, including rejected ones, because the record of why something was or was not published is the only way to answer that question later.
Logs
Our own application logs carry operational metadata: which route ran, a request identifier, a status code, and identifiers such as an account or submission id. They deliberately exclude token values, session identifiers, and skill bodies. That rule is written into the working agreement for this repository, not just intended.
Who else sees any of this
Two companies, both because the service could not run without them. Cloudflare hosts everything, including the database, so it holds the data at rest. GitHub sees that you authorised this application, because that is what signing in means.
We do not sell anything, and we have no advertising or analytics partners to share it with.
Deleting your account
Write to us and we will remove your account, your tokens, and your submissions. Skills that were already published are a harder question, and we would rather be straight about it than promise something we cannot do. A published skill may already be cached in browsers and mirrored elsewhere, so we can unpublish it and remove your name from it, but we cannot recall copies that left our servers.
Contact
For anything on this page, including access and deletion requests, write to [contact email not set].
The service is operated by [operating entity not set].
Changes
When this page changes in a way that affects what we collect, we will update the date at the top. The Skylark browser has its own privacy handling, which is separate from this one.