Privacy · usage records
What we record when your agent uses a skill
One line per tool call. Enough to show creators how their skills are used, nothing about your work.
Recorded per call
- Tool name
- list_active_skills, get_skill or read_skill_file
- Skill and version
- e.g. @ana/code-review 2.1.0
- File path
- only for read_skill_file, and only if the file exists in that skill
- Your account
- so your own activity and the Connect test work
- Time
- when the call reached PerkHubs
- Agent app
- the name and version your agent reports about itself (e.g. claude-code 2.1); “unknown” if it reports nothing
Never recorded
- Your prompts, questions or task description
- Code, files or anything else your agent works on
- What the agent does with a skill afterwards
- Which AI model you use — we don't infer or guess it
- Any other argument your agent sends
Who sees it
- You — your own calls, on Connect.
- Creators — totals for their own skills only: weekly users, agent apps, versions, files read. Never who. Any group smaller than five people shows as “<5”.
- PerkHubs admins — product-wide totals such as weekly active users and retention.
Recording happens after your agent already has its answer, so it never slows a skill down, and a failed record never blocks one. Deleting your account in Settings deletes your usage records with it.
Full policy · last updated 8 October 2026 · applies wherever you live
Who is responsible
PerkHubs is run by an individual in Thailand, who decides how this data is used (the “controller” under laws such as the GDPR, UK GDPR and Thailand's PDPA). Contact: the Report or This is my work button on the skill page, or Settings for your own data.
Account data
- From GitHub when you sign in: your username, display name, avatar and email address. PerkHubs never writes to your GitHub account.
- GitHub access token: kept for 8 hours in a secure browser cookie, only to check your access to a repository you import. It is never stored in our database.
- What you create: your Loadout and its settings, follows, notifications, reports and ownership claims, and skills you publish with their files and license.
- Personal tokens: stored only as a one-way hash; nobody, including PerkHubs, can read them back.
Why we use it, and on what basis
- To provide the service you signed up for — sign-in, your Loadout, serving skills, notifications (performing our agreement with you).
- To keep it safe and working — scanning, abuse and takedown handling, rate limits, totals for creators and product metrics (our legitimate interest in running a secure service; these use totals, not profiles of you).
- To meet legal obligations, such as answering lawful requests.
We don't sell or share your personal information for advertising, show ads, build advertising profiles, make automated decisions with legal effect on you, or use your data to train AI models.
Cookies
Only cookies the site needs to work: your sign-in session, your Use/Create mode, and the short-lived GitHub token above. No analytics or advertising cookies, so there is nothing to opt out of.
Who processes it for us
- Supabase — database, sign-in and file storage.
- Vercel — hosting the website and MCP endpoint.
- GitHub — sign-in and repository imports.
These providers may process data outside your country, including outside the EU/EEA, the UK and Thailand. We rely on the contractual safeguards they offer for such transfers, such as Standard Contractual Clauses where they apply.
How long we keep it
As long as your account exists. When you delete your account in Settings, your profile, Loadout, tokens, follows, notifications, usage records and published skills are deleted. Copies in our providers' logs and backups expire on their own schedules.
Your rights
Wherever you live, you can ask us to:
- give you a copy of your data in a portable format — you can download it yourself in Settings;
- correct it, or delete it;
- restrict or object to a use of it;
- withdraw a consent you gave, without affecting earlier use.
Write to the Report or This is my work button on the skill page, or Settings for your own data from, or mentioning, your PerkHubs account so we can confirm it's you. We answer within 30 days, free of charge, and never treat you differently for using these rights. You can also complain to your local data protection authority — for example your EU or UK supervisory authority, the California Privacy Protection Agency, or Thailand's PDPC.
Children
PerkHubs isn't meant for anyone under 16, or under the age your country sets for using online services alone. If you believe a child has signed up, tell us and we'll delete the account.
Security
Connections use HTTPS, database access is limited per user by row-level security, skill files sit in private storage and are served only if they match their scanned fingerprint, and tokens are stored as hashes. No system is perfectly secure; if a breach affects you, we'll tell you and the authorities where the law requires.
Changes
We'll update the date above and announce material changes on the site before they apply. See also the Terms.