Privacy Policy
Last updated: September 24, 2026
Data controller
SkillRouter (skillrouter.org) is operated by Shinerain LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA. Data requests: [email protected].
What we collect
Account: your email for login and notices. Membership and payment status — payments are processed by third-party providers; we never store your card number or account passwords. Agent access: your api_key and Skill entitlements. Outcome events and install reports (bounded fields; see the next two sections). Anonymous visit statistics (self-hosted Plausible; no cross-site tracking, no advertising). Retired services may retain conversation logs and delivered results that you previously uploaded.
How we use it
Current skills and website tools run on your device, so their business content is not sent to SkillRouter. We use only account, order, entitlement and necessary diagnostic data to provide the service. We do not train models on it or sell it.
Outcome events (on by default)
To rank skills for a task and to publish author stats, the CLI reports bounded **outcome events**: an event version, an event kind (pick / run_ok / run_fail / ok / wrong / fallback / requery / nofit / blocked), the UTC day, an optional rank position, and whether a request id was present (stored as a boolean). Each one carries only the skill or command id it refers to — **never your need sentence, page text, inputs, outputs or arguments**. The unique key is (skill_id, day, subject, event), so one subject counts once per kind per day. There are two subject kinds: for a signed-in, bound account a **de-identified stable subject** (derived with a server key, stable across days, containing no account identifier itself); otherwise a **UTC-day-rotating anonymous subject** that cannot be linked across days. Timestamps land on the UTC day's midnight, never on a precise behavioural instant. The retention window is 97 UTC days, after which a prune job deletes the rows. To turn it off: `sr feedback off` stops reporting immediately and clears the unsent queue; set SR_JOURNAL=off to stop the local journal too. If you set SR_OUTCOME_QUERY=1, verdict events also carry your need in normalized form to improve search; this is off by default.
Install reports
When a third-party skill or one of our website tools is installed, the CLI writes one local ensure-journal line (skill, target, state, code, changed, source) that **never leaves the machine**. The optional install receipt carries only content identity and the install outcome (skill id, content hash, status and reason enum) — no page content, arguments or output — and the server retains it for 35 UTC days. Set SR_EXTERNAL_NO_REPORT=1 to skip the receipt; skipping never changes the exit code.
Server-side download aggregates
The server records the download and rate-limit aggregates it needs (which content identity was requested, when, and the result) so it can serve the packs, plan capacity and stop abuse. This is necessary to deliver a download and is independent of the optional reporting above.
Start-page progress (optional)
This feature is off by default and its switch is stored on your account; nothing is recorded unless you explicitly turn it on. When on, the start page records: the channel identifier (ch), source locale (cn/us), the chosen task handle, and timestamps for arrival, copying install/connection commands, copying the sample, and self-reported completion. Once you turn it off it stays off across reloads and stops new records (history is kept). It records no raw URL, referrer, full task text, IP, or local machine state.
Attribution cookie and checkout source
We set two first-party-only cookies on your device: the attribution cookie (_sr_acquisition), 30-day and HttpOnly, holding only three short slugs — channel (ch), locale (cn/us), and task handle; and the legacy channel cookie (_sr_ch), 30-day and not HttpOnly, holding only the channel identifier and used to record the channel when a cart and order are created. Neither contains raw UTM strings, full URL, or referrer. At checkout after sign-in we write your account's channel and locale source, and set bounded fields (customer/plan identifiers plus those channel, locale, and task slugs) in the Stripe Checkout Session and the subscription metadata, so a successful subscription is attributed to the right source. This is independent of the Save-progress switch. We do not collect your payment keys, business text, or full URLs on this site.
Storage & deletion
Account and transaction data lives on servers we rent, with daily database backups. Historical content from retired services remains private; request export or deletion at [email protected], except for transaction records we must retain by law.
Your rights
You can export or delete your content, rotate your api_key, and close your account at any time (closing deletes the account and associated content, except transaction records we must retain by law).
Browser extension (SkillRouter Bridge)
The extension runs entirely on your device: it only relays automation commands and page data between your browser and the local daemon (loopback address only). It sends nothing to our servers or any third party, and contains no analytics. The debugger, tabs, and cookies permissions are used solely to execute automation steps you initiate yourself via the CLI. Communication with skillrouter.org (fetching operation steps, failure reports) is performed by the CLI you run separately, under the terms above.