Legal
Terms of service
Last updated Sep 23, 2026.
The service
SkilVault hosts a curated library of agent skills and distributes them to your development tools. Skills are provided as-is; we do not claim they are safe for every use — we claim each was reviewed before publishing, and can be pulled from distribution.
Your account
You're responsible for your API keys and machines. Keys carry your subscription's access — keep them private, revoke any that leak.
Subscriptions & cancellation
Pro is billed monthly in advance through Stripe. Cancelling keeps access until the period ends. Skills already installed on your machines remain yours to use — distribution-time entitlement is what ends.
Skill licences
Each skill carries its own licence, included in the manifest metadata distributed with every pack. Your use of a skill follows its licence, not ours.
Using skills
Skills are provided to your account, for use by you and your agents in your own work. Unless a skill's own licence says otherwise, you may not copy skills out of SkilVault in bulk, republish, resell or share them with people outside your account, or use them to build a competing library. Each skill your client reads is marked “Licensed to account … via SkilVault” with a short reference to your account; please leave it in place. We watch for unusual download patterns, such as one account downloading many different skills in a short time, and may pause or close an account that copies skills this way.
Privacy policy
Last updated Sep 23, 2026.
What we collect
Account data: email, name, password hash, billing status via Stripe. Usage data: marketplace fetches, pack downloads and searches per API key — timestamps, skill names, the text of your searches and the request's IP address, not your code or prompts. Your client also reports each time a skill is used: the skill, its version, which command-line tool used it (such as Claude Code or Codex) and when — never your code, prompts or file paths. This is on by default; turn off Report which skills you use on the Install page to stop it. If you turn on project suggestions, your client also sends the stack keywords it reads from a project's dependency files (such as “nextjs” or “stripe”); never file contents or code. A search or stack keyword that finds nothing useful may also be kept, in a simplified lower-case form without your name, so we can consider adding a skill for it; those records are deleted after 90 days. If you turn on Help improve skills with what my agent learns (off by default), your client also sends each lesson your agent confirmed about a skill: one sentence, with project names, file paths, email addresses and anything that looks like a secret removed first. Otherwise nothing about your agent's sessions is collected; skill execution, the lessons your agent records, and matching your prompts against your library all happen entirely on your machine.
How long we keep it
Account data until you delete your account. Usage events for 90 days, then deleted. Invoices as long as tax law requires.
Your rights
Export or delete your account data at any time — email support. Deletion removes keys immediately and ends distribution.