Privacy Policy
Last updated: 2026
1. What Crosses the Boundary
Skill Federation is private by design. When your agent needs a skill, only an abstract wish is sent to the search service:
- A one-line description of the capability needed
- A few vocabulary-varied paraphrases of that description
- 1–5 keywords
That is the complete set of data used to search the catalog.
2. What Never Crosses
The following are never transmitted to or stored by the Service:
- Your source code, code snippets, or file contents of any kind
- Your plan, brief, prompts, or reasoning traces
- Your agent's outputs
- File paths, directory structures, or repository names
- Project names, product names, or internal tool names
Your work never leaves your machine. Retrieved skills are installed and run locally.
3. How Search Works
The abstract wish is embedded and compared against a vetted catalog of publicly sourced skills. The Service returns the best matches — each with its license class, provenance, source, and any security flags — for you to review and approve.
Catalog skills are ingested from public repositories, copied, deduped, and scanned before promotion. This ingestion pipeline operates on public data, not on your private inputs.
4. Data Storage
Service infrastructure is hosted in AWS US regions with encryption at rest and TLS in transit. We store only the minimum operational data needed to run the search service and, for team customers, workspace membership and access controls.
5. Third Parties
Catalog vetting relies on independent security scanners, including Cisco AI Defense and NVIDIA SkillSpector, which operate on catalog candidates (public skills), not on your private inputs. Embedding and matching may use model providers under endpoints that do not train on submitted data.
We do not sell your data. We do not use third-party advertising or cross-site tracking.
6. Your Rights
Because the finder runs locally and free use requires no account, there is little personal data to manage. For team and enterprise accounts you may delete your account and associated credentials, and export any submission history retained for your workspace.
8. Changes to This Policy
We will provide reasonable notice before making material changes to this policy. Continued use of the Service after the notice period constitutes acceptance of the updated policy.
Questions? Contact us at privacy@qstarlabs.io.