Privacy, without the fog.
Effective 24 July 2026 · CodeSoul Skill Garden
What we process
When you choose GitHub sign-in, GitHub provides your public account ID, login name and avatar, plus a short-lived user access token. The token is used only to check whether your account has starred CodeSoul-co/Plasmod and CodeSoul-co/Hypha.
使用 GitHub 登录时,站点会接收公开账号 ID、用户名、头像以及短期用户令牌;该令牌仅用于 核验你是否为 Plasmod 和 Hypha 点过 Star。
How sessions work
Session data is encrypted and stored in an HttpOnly, SameSite cookie. It is not available to browser scripts. We do not ask for your email, password, private repository access or permission to star repositories for you.
会话数据经加密后存放在 HttpOnly、SameSite Cookie 中,浏览器脚本无法读取。站点不会索取 邮箱、密码、用户私库权限,也不会代替用户点 Star。
Private Skill downloads
Downloads are fetched by the server using a separate CodeSoul GitHub App installation limited to read-only contents access for the two Skill repositories. Your GitHub identity is never granted access to those private repositories.
私有 Skill 由服务器使用独立的 GitHub App 安装令牌获取,该令牌只具备两个 Skill 仓库的 Contents read 权限;你的 GitHub 账号不会因此获得私库权限。
Retention and control
The service stores a non-reversible keyed hash of your numeric GitHub ID, first and last activity times, authentication count, the most recent two-star result, and download events. Product metadata is retained for up to 180 days by default. Security events are retained for up to 14 days. Signing out clears the encrypted session cookie.
本站保存由 GitHub 数字 ID 经过带密钥哈希生成的不可逆用户键,以及首次和最近访问时间、 登录次数、最近一次双 Star 结果和下载事件。产品元数据默认最多保留 180 天,安全事件最多 保留 14 天。退出登录会清除加密会话 Cookie。
What we do not store
We do not store your email, real name, GitHub login, full IP address, raw user agent, browser fingerprint, OAuth access token, refresh token or private repository data in the metadata database.
元数据库不保存邮箱、真实姓名、GitHub 用户名、完整 IP、原始 User-Agent、浏览器指纹、 OAuth Access Token、Refresh Token 或私有仓库内容。
Contact
For privacy or access questions, contact the CodeSoul organization through its official GitHub profile.