Last updated: July 9, 2026
Privacy policy
How OceanSkill collects, uses, and protects account data, skill libraries, billing records, and MCP keys.
Data we process
- Account information such as email, display name, and avatar.
- Usage data such as enabled skills, collections, MCP calls, usage events, and credit ledger entries.
- Billing information needed to reconcile credit top-ups through payment providers.
- Creator-provided content when publishing private or public skills.
How we use data
- Authenticate users and protect the dashboard.
- Check skill access before an agent receives content through MCP.
- Record usage for credit accounting, abuse prevention, and troubleshooting.
- Display public metadata such as reviewer name, avatar, and review text when a user actively reviews a skill.
Protecting keys and sensitive data
- Raw MCP API keys are shown only once at creation; the system stores a hash for later authentication.
- Service role keys, webhook secrets, and payment secrets must stay in server-side environment variables, never in the client or repository.
- Skill content is protected by entitlement checks; browser clients do not receive storage secrets.
Data sharing
- We do not sell personal data.
- Data may be sent to infrastructure, authentication, database, payment, or observability providers when needed to operate the service.
- Public information such as author profiles, skill metadata, reviews, and public avatars may be shown on the website.
Your choices
- You can update your display name and avatar in the dashboard.
- You can revoke MCP keys at any time.
- You can contact us to request review, export, or deletion of your data where allowed by law and operational obligations.