Privacy policy
Last updated :
STH respects your privacy. This policy describes the data we collect, why we collect it, and the rights you have under Regulation (EU) 2016/679 (GDPR).
Service in Alpha
STH is currently in public Alpha. This document may evolve quickly as the service progresses. Any substantial change will be notified to users.
1. Data controller
The data controller is the site's publisher, whose contact details appear in the legal notices.
For any question about the processing of your data, you can write to contact@skillsth.com.
2. Principles
STH is designed to minimise data collection. The CLI runs entirely locally: it sends no data to our servers, except the usage telemetry you have explicitly enabled (anonymous or connected modes, disablable at any time via sth telemetry off). Only the (optional) web dashboard processes identifying data.
We never store the contents of your Git repositories, your skills, or your secrets (tokens, API keys). These stay on your machine or with your Git provider (GitHub, GitLab, Azure DevOps, Bitbucket).
3. Data collected
When you use the web dashboard, we process the following categories:
| Category | Data | Source |
|---|---|---|
| Account | Email address, display name, Clerk identifier | User input / SSO provider |
| Organisation | Name, member identifiers, roles | User input |
| Preferences | Theme (light/dark/system), language | Cookie / settings |
| CLI usage | Anonymised counters, CLI version, last activity | Opt-in CLI telemetry |
| Billing (Pro/Team — upcoming) | Billing address, last digits of the card | Stripe (subprocessor) |
| Technical logs | IP address, user-agent, request timestamps | Hosting provider |
4. Purposes and legal bases
- Service provision (performance of the contract, art. 6.1.b GDPR): authentication, organisation management, display of licenses and CLI usage statistics.
- Billing (performance of the contract, art. 6.1.b GDPR): issuing and tracking invoices for paid plans.
- Security (legitimate interest, art. 6.1.f GDPR): fraud detection, abuse prevention, connection logging.
- Product improvement (consent, art. 6.1.a GDPR): aggregated, anonymised CLI telemetry, disablable at any time.
- Product communication (consent, art. 6.1.a GDPR): emails about releases, the waitlist, or the end of beta. One-click unsubscribe.
5. Retention period
| Data | Period |
|---|---|
| User account | For the lifetime of the account, then 30 days after deletion |
| Organisation data | For the duration of the contract, then 30 days |
| CLI usage statistics (detailed policy) | Rolling 30 days, then automatic deletion |
| Invoices | 10 years (accounting obligation, article L.123-22 of the French Commercial Code) |
| Technical logs | 12 months maximum (LCEN article 6-II) |
6. Subprocessors & recipients
We rely on the following subprocessors, all bound by a processing agreement compliant with article 28 of the GDPR:
- Clerk (Clerk Inc., United States) — authentication. Clerk DPA.
- Supabase (Supabase Inc., United States; EU infrastructure) — database and storage. Supabase policy.
- Stripe (Stripe Payments Europe Ltd., Ireland) — payments and billing for paid plans. Stripe policy.
- Vercel (Vercel Inc., United States) — dashboard hosting. Vercel policy.
7. Transfers outside the European Union
Some subprocessors are established in the United States. Transfers are governed by the standard contractual clauses adopted by the European Commission (decision 2021/914/EU) and, where applicable, by adherence to the EU-U.S. Data Privacy Framework. You can obtain a copy of these safeguards on request at contact@skillsth.com.
8. Security
Technical and organisational measures in place:
- TLS 1.3 encryption on all communications.
- Encryption at rest of database data (Supabase, AES-256).
- RLS (Row-Level Security) policies in the database: a user can only access their own organisations.
- No secret stored in the CLI: tokens come from your environment.
- Audit log of sensitive actions (organisation deletion, role change).
- Daily backups of user data, kept 30 days in encrypted buckets in the EU region.
9. Your rights
Under articles 15 to 22 of the GDPR, you have the following rights over your data:
- Right of access — obtain a copy of the data concerning you.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure — request deletion of your data (subject to legal retention obligations).
- Right to restriction of processing.
- Right to portability — retrieve your data in a structured, commonly used, machine-readable format.
- Right to object to processing based on legitimate interest.
- Right to withdraw your consent at any time, where processing relies on it.
- Right to set post-mortem directives (article 85 of the French Data Protection Act).
You can exercise these rights at any time from your dashboard (Settings tab) or by writing to contact@skillsth.com. A response will be sent to you within one month.
11. Complaint
If you believe the processing of your data does not comply with the regulation, you can lodge a complaint with the CNIL (French data protection authority) — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr.