PRIVACY
Privacy Policy
Effective date: September 9, 2026
What SkillLock processes
Local-folder scans happen in your browser. SkillLock does not upload those selected files to its server. Public GitHub scans send the public GitHub URL you enter to SkillLock, which fetches supported text files from that public repository to produce a report. If you connect GitHub for a private scan, SkillLock uses a GitHub App session to read only the repositories you selected when installing the app.
What SkillLock does not do
SkillLock does not execute scanned code, create GitHub repositories, modify repository content, or sell scan reports. GitHub access tokens are encrypted and authenticated before being kept in a Secure, HTTP-only browser cookie. They are not readable by browser JavaScript or sent to any other website. The product is not designed for entering passwords or API keys.
Temporary processing
Public GitHub scan content may be held temporarily in server memory for up to five minutes to reduce repeat requests. Private repository content is never placed in the shared scan cache. GitHub connection cookies expire within eight hours or when you disconnect. Service providers may process routine technical data required to operate the website, such as network and security logs.
Your choices
Do not submit a URL containing private credentials. Use local scanning for files you do not want to share. You may stop using the service at any time.
Changes
This policy may change as SkillLock develops. The effective date above will be updated when material changes are made.