← BACK TO SKILL GARDEN

Privacy, without the fog.

What we process

When you choose GitHub sign-in, GitHub provides your public account ID, login name and avatar, plus a short-lived user access token. The token is used only to check whether your account has starred CodeSoul-co/Plasmod and CodeSoul-co/Hypha.

How sessions work

Session data is encrypted and stored in an HttpOnly, SameSite cookie. It is not available to browser scripts. We do not ask for your email, password, private repository access or permission to star repositories for you.

Private Skill downloads

Downloads are fetched by the server using a separate CodeSoul GitHub App installation limited to read-only contents access for the two Skill repositories. Your GitHub identity is never granted access to those private repositories.

Retention and control

The service stores a non-reversible keyed hash of your numeric GitHub ID, first and last activity times, authentication count, the most recent two-star result, and download events. Product metadata is retained for up to 180 days by default. Security events are retained for up to 14 days. Signing out clears the encrypted session cookie.

Export my data

What we do not store

We do not store your email, real name, GitHub login, full IP address, raw user agent, browser fingerprint, OAuth access token, refresh token or private repository data in the metadata database.

Contact

For privacy or access questions, contact the CodeSoul organization through its official GitHub profile.