Privacy Policy
Last updated: September 24, 2026
SkillDeck is a local-first desktop app for managing the Agent Skills you install for AI coding agents. It is developed and provided by independent developer Liu Feiyu ("we", "us"). This policy explains what data SkillDeck handles, where that data lives, and when any of it leaves your device. It covers both the SkillDeck app and this website.
SkillDeck has no accounts. There is nothing to sign up for, and we do not build a profile of you.
1. Data that stays on your device
The following data is stored only on your own device and is never uploaded to our servers:
- The Skills you add, their source information, and revision history
- Which Skills are enabled for each agent
- App settings, including interface language, translation configuration, and the analytics switch
- Cached translations
- The translation service credentials you configure (see Section 5)
2. When SkillDeck connects to the network
Adding Skills from a local folder never needs the network. The following do:
- Adding, inspecting, or updating a source — SkillDeck uses your system
gitexecutable or HTTPS to reach the address you entered. Requests go straight to the service you chose (for example GitHub, GitLab, or your own Git server) and are never relayed through us. For private repositories,gitauthenticates with the configuration already on your system (for example your SSH keys). - Automatic Skill update checks — after launch, if more than 24 hours have passed since the last full check, SkillDeck checks your sources for new versions in the background. You can also check manually at any time. These requests also go straight to each source.
- App update checks — at launch and roughly every 6 hours after that, SkillDeck fetches an update feed from our update server. The request carries only the ordinary information an update check needs (such as the app version) and never your Skills, settings, or files. When a new version is found you are notified, and an update is installed only after its signature has been verified.
- Translating a document — only when you start and confirm it; see Section 4.
- Anonymous product analytics — see Section 3. You can turn this off in Settings.
3. Anonymous product analytics
To understand basic usage and improve the product, SkillDeck turns on a small set of anonymous product analytics by default. Events are sent to a Matomo instance that we run ourselves, not to a third-party analytics platform. You can turn analytics off in Settings at any time; SkillDeck then stops sending events and discards any that have not been sent yet.
The current version records only these events: app start, workspace setup, source inspection, Skill installation, and external Skill adoption. Event types are fixed in advance and cannot carry anything extra.
Analytics events never include: Skill names or content, file paths, source addresses, repository names, custom agent names, search text, credentials, diagnostic logs, stack traces, or operation IDs.
Each event carries only:
- The event itself: platform, app version, source type, install scope (global or project), a count range (such as "2–5"), the outcome and duration, and a fixed error code when something fails
- Runtime environment: screen resolution, system language, the local time of the event, and a User-Agent containing only the app name, version, and platform (for example
SkillDeck/1.0.1+7 (macos)) - A visitor identifier: a random visitor ID generated on your device and stored locally, used to tell installations apart and count returning visits. It is not derived from your hardware or any account, we never attach a user ID to it, and we never match it to your identity
Pending events are held in memory only and never written to disk; anything unsent is discarded when the app quits.
As with any network request, the analytics server receives your IP address. IP anonymization is enabled on our Matomo server and set to mask 4 bytes.
Analytics data is used only to understand, in aggregate, how SkillDeck is used and how stable it is. It is not used for advertising, not sold, and not shared with any third party.
4. Translation and your documents
Translation requires you to configure your own provider in Settings first (an OpenAI-compatible API or the Anthropic Messages API). Every translation is started by you: a confirmation dialog shows the provider, endpoint host, and target language before anything is sent, and the translation applies only to the document you have selected. Reopening a document, reconnecting to the network, or bringing the app back to the foreground never starts or retries a translation on its own.
What leaves your device:
- Fenced code blocks always stay local and are never sent.
- From YAML frontmatter, only the top-level
descriptionfield is sent; the delimiters,name, and all other fields stay local. Malformed or unsupported frontmatter stays local entirely. - All other body text is sent as-is to the provider you configured. SkillDeck does not automatically redact secrets. Generic redaction silently breaks legitimate instructions, placeholders, examples, and documentation about credentials, so this call is left to you: before translating, make sure the document contains nothing you are not willing to send.
Your provider handles what it receives under its own privacy and data policies, which this policy does not govern.
Translations are cached separately on your device and never modify the original Skill files — agents always read the original. You can delete a Skill's cached translation from its detail view at any time.
5. Credentials
The translation credentials you configure (such as API keys) are stored in your operating system's secure storage (the Keychain on macOS) and are used only to send requests to that provider. You can clear them in Settings at any time.
Credentials are never written to the translation cache, settings files, analytics events, or logs. SkillDeck also never logs environment variables, raw process output, response bodies, request headers, or user information embedded in URLs.
6. Who receives data
We do not sell your data or share it with advertisers or data brokers. Data leaves your device only in these cases:
- The code hosts or HTTPS addresses you specify — contacted when you add, inspect, or update a source, and during automatic update checks. They handle requests under their own privacy policies.
- The translation provider you configure — contacted only after you confirm a translation, and governed by that provider's policies.
- Our Matomo analytics server — receives the anonymous events described in Section 3. We run and manage it ourselves.
- Cloudflare — hosts and delivers this website, app downloads, and app updates, and processes access logs under its own practices.
- Legal requirements — we may disclose information we hold where required by law, or when lawfully requested by judicial or government authorities.
7. About this website
This website sets no cookies, shows no ads, does no cross-site tracking, and embeds no analytics script. Web fonts are served by Google Fonts, so your browser makes a request to Google when loading them. The website, installers, and update files are hosted and delivered by Cloudflare.
8. Retention and deletion
Local data stays until you delete it in the app (for example by removing a Skill, deleting a cached translation, or clearing a credential) or uninstall SkillDeck and remove its app data. On macOS, app data lives in ~/Library/Application Support/com.feiyuliu.skilldeck/ and credentials live in the Keychain.
Turning analytics off stops any new analytics data from being created. Because analytics data contains no identity information and IP addresses are anonymized, we generally cannot pick out which records belong to you.
9. Your rights
- Turn off anonymous analytics in Settings at any time.
- Delete your local Skills, cached translations, and credentials, or uninstall SkillDeck, at any time.
- For questions about this policy or your data, or to ask us to access, correct, or delete information, email us at the address in Section 13. We will reply as soon as we can.
10. Children's privacy
SkillDeck is a tool for developers. It is not directed at children under 14, and we do not knowingly collect their personal information. If you believe we have collected such information by mistake, contact us and we will delete it.
11. Security
We reduce risk by encrypting data in transit (all communication with our services uses HTTPS), storing credentials in system secure storage, and collecting as little as possible. No method of transmission or storage is completely secure.
Whether a Skill source is safe depends on the source you choose. Only add sources you trust.
12. Changes to this policy
We may update this policy as features change, and we will update the last-updated date at the top of this page. If a change affects the types of data collected or how they are used, we will also point it out in the app's release notes or on this website.
13. Contact us
Developer: Liu Feiyu
Email: [email protected]
The terms that accompany this policy are in the User Agreement.