Legal
FrançaisPrivacy policy
What this server keeps about you, why, for how long, who else sees it, and your rights.
Last updated .
Who is responsible
Maël Belliard runs this server and is responsible for the personal data it processes (the data controller). For any question about your data, or to exercise your rights, write to contact@maelbelliard.fr.
What is kept, and why
Your account
- Your email address, your password (only as a scrypt hash, which can’t be turned back into it), your role, when the account was created and when you last signed in. They’re needed to give you an account (the contract between you and the operator).
- Your sign-in session: a random token in a cookie,
skillspector_session, kept 30 days or until you sign out. It’s needed for the site to work, so it doesn’t need your consent. Vercel BotID, which protects the scan form from automated abuse, sets its own security cookies (namedKP_…). There are no advertising or tracking cookies. - If you create them: your API tokens (their name and when they were last used; the token itself only as a hash), your Claude key (encrypted with AES-256-GCM, only ever used for your own scans, and shown back only as its last characters), and your GitHub connection (your GitHub username, and its access tokens, encrypted, used only to read the repositories you chose, for your scans).
- If you sign in with GitHub: your GitHub account’s numeric ID, which links it to your account here, and its username, to show on your account page. Signing in gives this server no access to your repositories, and the token GitHub hands over is revoked as soon as your email is read.
Your scans
- What you submit to be scanned (a link, a skill’s name in a registry, or a file), the options you chose, the report, the scan’s log, and how many AI tokens it used. They’re needed to give you the service. Your scans are private to you unless you share them.
- An uploaded file is deleted as soon as it has been scanned, whatever the outcome; only its name stays in your history.
- A key you paste for one scan, instead of saving it, is held only while that scan runs, encrypted, and deleted once it has run.
Security
- An activity log of events on accounts: sign-ups, password changes and resets, API tokens, Claude keys and GitHub connections being added or removed, results being shared or put on a badge, and what admins change. It’s kept 365 days, to investigate abuse or a security incident (the operator’s legitimate interest in keeping the service safe).
- Your IP address, to limit how often sign-ins, scans and shared pages can be requested, which stops abuse. It’s stored only for the length of the limit it counts towards, at most 5 minutes. The host also records requests, with their IP address, in its own logs.
- When you submit a scan, Vercel BotID checks that the request comes from a browser rather than an automated script.
Audience measurement
- Vercel Web Analytics counts visits without cookies. It receives the kind of page visited, never its address (which can hold a scan or a shared link), and three events: an account being created, a scan being started (whether it was a link, an upload, a GitHub repository or an MCP server, and whether AI review was on) and a result being viewed (its verdict). Never what was scanned, your email or any identifier.
- Vercel Speed Insights measures how fast pages load, with the same page kinds.
- This helps the operator see how the service is used and improve it (legitimate interest).
In your browser
The scan form remembers your last choices (the source, whether AI review was on, the provider and model, never a key), and the site remembers your light or dark theme, in your browser’s local storage. It never leaves your browser.
What is public
Nothing, unless you make it so. A result you share can be opened by anyone with its link, which shows the report, not who scanned it, until you revoke it. A result you put on a status badge shows its verdict to anyone who views the badge.
Who else receives it
- Vercel Inc., which hosts the server, stores uploaded files until they’re scanned, and runs each scan in an isolated sandbox.
- Neon, which hosts the database.
- Mailgun, which sends password reset and sign-up emails.
- The AI provider you choose, only when you turn on AI review for a scan: it receives the content of the skill being scanned (Anthropic, with your own key), under its own terms.
- GitHub, if you sign in with it (it then knows you signed in here), or connect your account, to read the repositories you chose. The code hosts of the links you scan see the server fetch them, not you.
- The admins of this server, who can see accounts’ email addresses and API token names, scans (not the content of a scan of a private repository) and the activity log, to run the service.
Your data is never sold, and never used for advertising. Some of these providers are based in, or process data in, the United States; transfers there rely on the safeguards the GDPR provides, such as the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses.
How long it’s kept
- Your account, its keys, tokens and connections: until you delete it, or an admin does.
- Your scans: until you delete them or your account.
- Sessions: 30 days, or until you sign out.
- Password reset links: 24 hours, or until they’re used.
- Sign-up links, with the email and password hash they’ll create the account with: 24 hours, or until they’re used.
- The activity log: 365 days.
- Uploaded files: until they’re scanned, usually a few minutes; 7 hours at most if a scan never runs.
- IP addresses for rate limits: at most 5 minutes.
Database backups made by the hosting providers can hold deleted data a little longer, until they expire.
Your rights
Under the GDPR, you can access your data, have it corrected or deleted, restrict or object to its processing, and receive it in a portable format.
- Delete your account yourself, from your Account page: your scans and their reports, shared links and badges, keys, tokens and connections are deleted at once, and the activity log keeps its entries without your email.
- Delete a scan from its result page, and download any report there.
- For anything else, write to contact@maelbelliard.fr. You’ll get an answer within a month.
If you think your data isn’t handled properly, you can complain to the CNIL (https://www.cnil.fr).
How it’s protected
Passwords are hashed, keys and tokens are encrypted or hashed, connections use HTTPS, and the session cookie can’t be read by scripts on the page. Scans run in a sandbox that holds none of the server’s secrets.
Changes
This policy changes when the service does. The date at the top says when it last did.