Legal
Privacy Policy
Version 1.0 · Last revised October 1, 2026
Who we are and what this covers
SkillsRegistry is operated by Cognium Labs, Inc. (“we”, “us”). This policy explains what information we collect when you use the website at https://skillsregistry.net, the API and MCP endpoint at https://api.skillsregistry.net, the catalog export, and the publisher tool (together, the “Site”), and what we do with it.
You can search and read the Site without an account. We do not use cookies or browser storage on the website, we do not show advertising, and we do not sell personal information.
Information we collect
What we collect depends on what you do. We do not ask for your name, e-mail address or payment details.
| When you | We collect |
|---|---|
| Visit the website | Anonymous usage events: which action was taken (for example, a copy button), the page path, campaign tags, the referring site’s host name, and the country and data-center region of the request. No cookies, identifiers or search terms. |
| Call the API or MCP endpoint | Request records: method, route, status, duration, client name and version, user-agent string, country and region. Your IP address is held for about two minutes to enforce rate limits. |
| Search | The search text, the results returned and their scores. Search text is stored without your IP address or any account identifier. |
| Use MCP tools | The tool called, its arguments (truncated), the skill it resolved to, whether it succeeded and how long it took. |
| Give feedback or star a skill | The feedback or star, the skill, and any identifier your client supplies with it. |
| Sign in to publish | Your GitHub account ID and username, and when you verified. We read your GitHub profile once to confirm the account and its two-factor status, then discard the GitHub token. |
| Create a signing key | The public half of the key, when it was issued, and the IP address it was issued to. Your private key never leaves your machine. |
| Publish a skill | Everything in the manifest and bundle you submit, and the signature. If a publish attempt is unsigned or fails verification, we also record the IP address of the request. Published content is public and is shown with your GitHub username. |
Information about people who did not submit it. Much of the catalog is indexed from public registries and public source repositories. Those listings can include author names and usernames as published at the source.
How we use it
We use this information to run the Site and keep it safe:
- to answer searches and requests, and to rank and improve results;
- to verify who published a skill, and to record which key signed it;
- to scan published content for security problems and compute trust scores;
- to enforce rate limits and investigate abuse or misuse of signing keys;
- to understand, in aggregate, how the Site is used.
We do not use it for advertising, and we do not build profiles of individual visitors.
Who we share it with
We share information only with the providers that run the Site for us, and where the law requires it.
| Provider | What it does for us |
|---|---|
| Cloudflare | Hosts the website and API, stores bundles and caches, provides usage analytics, and runs the models that turn search text into search vectors. |
| Neon | Hosts the database. |
| GitHub | Confirms your identity when you sign in to publish. |
| Amazon Web Services | Hosts the systems that scan published content for security problems. |
Search text and published content are also processed by analysis and ranking systems that Cognium Labs, Inc. operates itself.
Published skills, their metadata, their trust scores and the publisher’s GitHub username are public. Anyone can read them on the website, through the API and in the catalog export.
We may disclose information if required by law, to protect the Site or its users, or as part of a merger or sale of the business.
How long we keep it
Usage records are deleted after 90 days. Publishing records are kept for as long as the published content is listed.
| Information | Kept for |
|---|---|
| IP address used for rate limiting | About two minutes |
| Search text, feedback, tool-call and usage records | 90 days, then only daily totals remain |
| Sign-in session | 15 minutes |
| GitHub account ID and username | While you have a publisher identity with us |
| Signing keys (public half) and signatures | While the content they signed is listed |
| Key-issuance and signature audit records, including IP address | No fixed period; kept while needed to secure the Site and investigate abuse |
| Published skills | Until removed |
Request logs and aggregate usage statistics held by our hosting provider are kept for a short period that the provider sets.
Your choices and rights
You can ask us what we hold about you, to correct it, or to delete it, by writing to hello@cognium.net. We aim to answer within 30 days.
- Publishers. You can retire your signing keys at any time with the publisher tool. You can ask us to remove your publisher identity and your published skills.
- Authors of indexed listings. If a listing we indexed from a public source names you and you want it corrected or removed, write to us or use the appeal page.
- Website analytics. Add
?analytics=offto a page address to switch off usage events for that visit.
Depending on where you live, you may have further rights under local law, such as the right to object to processing or to complain to a data-protection authority.
Security, children and international users
Security. Traffic to the Site is encrypted in transit. Your signing key is generated on your own machine and we only ever receive its public half. No system is perfectly secure, and we cannot guarantee that information will never be accessed or disclosed.
Children. The Site is not directed to children, and is intended for users aged 18 or over. We do not knowingly collect information from anyone under 18.
International users. We are based in the United States, and our providers process information in the United States and other countries. By using the Site you understand that your information will be processed there.
Changes and contact
If we change this policy in a way that matters, we will post a notice on the Site before the change takes effect. The date at the top shows when it was last revised.
Questions and requests go to Cognium Labs, Inc. at hello@cognium.net, or by mail to 3001 Bishop Drive, San Ramon, California 94583.