Skip to content

Privacy Policy

What SkillBundle collects, why it collects it, who else processes it, and how to get it deleted.

Last updated 8 September 2026

SkillBundle is operated by Jonathan Coronel as an individual, not through a company. This policy explains what happens to your data when you use skillbundle.dev. Questions about anything here go to support@skillbundle.dev.

1. What we collect

You can browse the entire skill catalog without an account. Nothing in this section applies until you sign up.

Account information. When you create an account, our authentication provider stores your email address, your display name, and a profile image if you set one. If you sign in with Google or GitHub, we receive the same fields from that provider instead of a password. Passwords, when used, are stored and verified by the authentication provider and are never visible to us.

What you create. The bundles you build, the skills in them, whether each bundle is shared by link, and when you last opened each one. That last timestamp is how the app can tell you what changed since your previous visit.

Contributions. If you add a skill to the public catalog, your account is recorded as the one that added it, so that a bad entry can be traced and removed.

Subscription status. If you subscribe, we store which plan you are on and whether it is active. We never receive or store your card details. Payments are handled entirely by Polar, which acts as merchant of record.

Usage analytics. We record which pages are viewed, using a privacy-focused analytics service that sets no cookies and does not build cross-site profiles of you. This is not tied to your account. These requests pass through our own servers, which strip your session before forwarding them, so the analytics provider receives the page and your IP address and nothing that identifies your account.

Repositories you point us at. If you use repository matching, we read the public file listing of the repository you specify in order to work out which technologies it uses. We read public repository contents only, we do not store the file contents, and we never request write access.

2. What we don't do

We do not sell your data. We do not share it with advertisers. We do not send you marketing email. SkillBundle sends no email of its own at all: the only messages you will receive are account emails from our authentication provider, such as a sign-in code, and payment receipts from Polar. Change notifications for the skills you watch appear in the app, not in your inbox.

3. Why we're allowed to hold it

For account data, bundles, and subscription status, the basis is performing the contract you entered into by signing up. The product cannot show you your bundles without storing your bundles. For analytics and abuse prevention, the basis is our legitimate interest in understanding whether the product works and in keeping the public catalog usable.

4. Who else processes your data

Running SkillBundle means using other companies for hosting, authentication, payment, and search. Each one is listed below with what it is used for and a link to its own privacy policy.

  • Vercel: Website hosting and delivery.
  • Convex: Application database and backend functions.
  • Clerk: Account creation, sign-in, and session management.
  • Polar: Subscription payments, as merchant of record.
  • Typesense (Railway): Catalog search. Receives your search queries, not your identity.
  • OpenPanel: Privacy-focused, cookieless product analytics.
  • GitHub: Reading public repository contents to index skills, and optional sign-in.
  • Voyage AI: Generating embeddings of public skill text for search and matching.

One of these is worth calling out because it is unusual. Catalog search runs directly from your browser to our search provider rather than passing through our servers, which is what makes it fast. That means your search queries and your IP address reach that provider directly. It receives no account information with them.

5. How long we keep it

Account data and bundles are kept until you delete them or delete your account. Analytics are aggregate and not linked to your account. Records that we are required to keep for tax or accounting reasons, such as payment records held by Polar, are kept for as long as that obligation lasts, regardless of whether you close your account.

6. Your rights

You can access and correct your account details, and delete your account outright, from your account settings. Deleting your account removes your profile and your bundles from our database. Skills you contributed to the public catalog remain in the catalog, because they describe someone else's public repository rather than you, but the link between those entries and your account is removed with it.

Depending on where you live, you may also have the right to a copy of your data in a portable format, to object to certain processing, or to complain to a data protection authority. To exercise any of these, email support@skillbundle.dev and we will respond within 30 days.

7. Where your data is held

Our providers operate in the United States and elsewhere, so your data may be processed outside your own country. Each provider linked in section 4 documents its own transfer safeguards.

8. Children

SkillBundle is a tool for software developers and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, email us and we will remove it.

9. Changes to this policy

If this policy changes in a way that meaningfully affects you, we will update the date at the top of this page and, for significant changes, show a notice in the app. Continuing to use SkillBundle after a change means you accept the updated policy.

10. Contact

Email support@skillbundle.dev for anything covered by this policy, including data access and deletion requests.