Privacy Policy
DRAFT — NOT LEGAL ADVICE. DO NOT RELY ON THIS DOCUMENT.
This page is an AI-drafted starting point, written to describe this application’s actual data handling as accurately as possible. It has not been reviewed by a lawyer. It must be reviewed and approved by a qualified attorney before Ahood’s real public launch, and before it is relied upon for any compliance purpose. Do not remove this notice until that review has happened.
What we collect
- Account information — the email address you sign up with, and a password (stored hashed by our authentication provider, Supabase Auth; we never see or store it in plain text).
- GitHub identity — if you sign in with “Continue with GitHub”, we receive and store your GitHub username and avatar URL to display on your public profile and skill pages.
- Profile information — display name, bio, and avatar, if you choose to add them.
- Published content — any skill packages, versions, changelogs, and metadata (name, tagline, tags, license) you publish. This content is public by default and, for organization private registries, visible to holders of that organization’s access token.
- Activity data — which skills you star, your points balance and points history, and a log of your downloads.
- Download IP addresses — we log the IP address associated with each download of a skill package. This is used for abuse detection (for example, detecting artificial download/star rings designed to farm points) and basic operational security, not to build a profile of individual users.
- API tokens — if you create a personal API token for CLI use, we store a hash of it (not the token itself) along with its scopes and creation time.
Why we collect it
We use this information to operate the core product: authenticating you, attributing published skills to their author, computing and displaying points and download counts, serving search and browse pages, and detecting abuse of the points system (for example, a single account or ring of accounts inflating download counts to earn unearned points). We do not use any of this data for advertising, and we do not build behavioral profiles for marketing purposes.
Billing information (forward-looking)
Ahood’s paid organization plans are designed to run through Paddle, who would act as merchant of record for the checkout transaction itself (payment card details, tax calculation, and fraud checks on the transaction). Billing is not live in this version of the product. When it is enabled, this section will be updated to describe what Paddle handles and what we handle. To be clear even now: Paddle’s merchant-of-record status covers only the checkout transaction — it does not cover, and was never intended to cover, the account, activity, and content data described above, which Ahood itself collects and is responsible for under this policy.
How long we keep it
We retain account and activity data for as long as your account is active. Download logs (including IP addresses) are kept as an append-only operational record to support points integrity and abuse investigation; they are not displayed publicly and are never shown attributed to a specific downloader. If you delete your account, see the section below on what happens to your data.
Account deletion
Deleting your account does two distinct things:
- Your underlying login credential is disabled: your sessions are revoked and your email/GitHub sign-in identity is detached, so you can never log in to the account again.
- Your profile row is anonymized in place, not deleted outright. Your username is replaced with a generic placeholder, and your display name, avatar, bio, and GitHub username are cleared. The underlying profile record is kept only as an attribution placeholder for any skills you published, so that other users who depend on your published packages (for example, via a version pinned in their lockfile) aren’t left with broken references — the same approach GitHub itself takes for deleted accounts with public contributions. We do not cascade-delete your published skills, since other people’s installs may depend on them.
Past download-log entries associated with your account (including logged IP addresses) are retained after deletion as operational/security records supporting the integrity of other users’ points, and are not displayed attributed to you. If you have concerns about this, contact us using the details below.
If you own an organization at the time you request deletion, you will need to transfer ownership or delete the organization first — we do not silently reassign organization ownership as a side effect of an account deletion.
We do not sell your data
We do not sell, rent, or trade your personal information to third parties.
Cookies
We currently use only strictly-necessary session cookies, set by our authentication provider (Supabase Auth) to keep you logged in. We do not currently use analytics, advertising, or marketing cookies. If that changes, this policy and the site will be updated accordingly, including a cookie-consent mechanism if required.
Your rights
Depending on where you live, you may have rights to access, correct, export, or request deletion of your personal data. You can delete your own published skills, unstar content, and revoke your own API tokens directly from your account settings at any time. For an account-level access or deletion request beyond what self-service settings provide, contact us using the details below.
Contact
Questions about this policy or requests regarding your data: privacy@example.com (REPLACE WITH REAL CONTACT EMAIL before launch).