Last updated: July 9, 2026

Privacy policy

How OceanSkill collects, uses, and protects account data, skill libraries, billing records, and MCP keys.

Data we process

  • Account information such as email, display name, and avatar.
  • Usage data such as enabled skills, collections, MCP calls, usage events, and credit ledger entries.
  • Billing information needed to reconcile credit top-ups through payment providers.
  • Creator-provided content when publishing private or public skills.

How we use data

  • Authenticate users and protect the dashboard.
  • Check skill access before an agent receives content through MCP.
  • Record usage for credit accounting, abuse prevention, and troubleshooting.
  • Display public metadata such as reviewer name, avatar, and review text when a user actively reviews a skill.

Protecting keys and sensitive data

  • Raw MCP API keys are shown only once at creation; the system stores a hash for later authentication.
  • Service role keys, webhook secrets, and payment secrets must stay in server-side environment variables, never in the client or repository.
  • Skill content is protected by entitlement checks; browser clients do not receive storage secrets.

Data sharing

  • We do not sell personal data.
  • Data may be sent to infrastructure, authentication, database, payment, or observability providers when needed to operate the service.
  • Public information such as author profiles, skill metadata, reviews, and public avatars may be shown on the website.

Your choices

  • You can update your display name and avatar in the dashboard.
  • You can revoke MCP keys at any time.
  • You can contact us to request review, export, or deletion of your data where allowed by law and operational obligations.