Draft Data Disclosure · Pre-Production

SkillOS / Data handling

Privacy is a product boundary.

This notice describes what the current application stores, sends to configured providers, and does not yet support. It is an operational account of the platform—not a substitute for a production legal review.

Current behavior

Data by feature

Account and access data

GitHub or Google sign-in creates an account record with the identity data returned by that provider, such as name, email address, avatar, and provider account identifier. Account role and plan data are stored to enforce access controls.

Answer Studio research

A submitted question is sent to the configured research provider to retrieve evidence. For signed-in users, SkillOS stores the question, generated evidence summary, citations, confidence, and limitations in answer history. Anonymous questions are not written to that history, but the research provider handles submitted queries under its own terms and privacy practices.

Skill Studio recordings

Guided chat responses are stored in a Skill Recording once you send them. Audio and video chosen for transcription are forwarded to the configured transcription provider and are not written to the SkillOS database or filesystem. The resulting text appears for your review before you send it into the recording transcript.

API keys and connectors

API-key plaintext is shown once and is not stored; SkillOS stores a SHA-256 hash and a display prefix. Connector credentials are encrypted with server-side AES-256-GCM before storage and are not returned by connector APIs. Revoking a connector or key disables it but does not currently provide a general account-data deletion workflow.

Your available controls

What you can manage today

You can revoke API keys and configured connector credentials from your dashboard. Workflow drafts are inactive by default and do not send data to external services until a separately configured execution environment is enabled.

Data minimisation

Keep sensitive data out of prompts and recordings.

Do not submit credentials, private keys, medical records, legal case files, payment-card data, or confidential third-party material unless you have a lawful basis, the relevant provider agreement, and an approved retention process.