SkillOps Privacy Policy
Last updated: July 10, 2026
This Privacy Policy explains how Enchiridion Labs LLC, a California limited liability company, unless another contracting entity is identified in an Order Form ("SkillOps," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you visit our websites, use SkillOps, communicate with us, or otherwise interact with our services (the "Service").
SkillOps is a business-to-business service. When an organization uses SkillOps, that organization controls much of the information submitted by its users. In that context, we generally process personal information in Customer Data on behalf of the customer organization.
1. Personal Information We Collect
We may collect the following categories of personal information.
Account And Identity Information
- name;
- email address;
- organization name;
- role, title, group, and permission information;
- SSO, OAuth, OIDC, or identity-provider identifiers;
- login timestamps and authentication metadata; and
- administrator and billing-contact information; and
- legal-document versions, acceptance time, business-use attestation, and authority attestation associated with self-service signup.
Customer Content And Configuration
Customers and users may submit or generate:
- skill instructions, Markdown files, supporting assets, drafts, versions, and packages;
- review comments, approvals, rejections, ownership assignments, and workflow metadata;
- organization settings, SSO settings, gateway configuration, and policy configuration;
- MCP gateway requests, skill-resolution metadata, feedback, checkpoints, and usage records; and
- audit logs and evidence references.
Customer content may include personal information if a customer or user includes it in skills, prompts, files, comments, logs, or workflow records.
Usage, Device, And Log Information
We may collect:
- IP address;
- browser, device, and operating-system information;
- pages, features, API routes, and documentation accessed;
- timestamps, session identifiers, request IDs, and error logs;
- product telemetry, usage counters, and audit events; and
- security, fraud-prevention, and diagnostic logs.
Billing Information
Payments are processed by Stripe. We may receive billing email, Stripe customer ID, subscription ID, invoice metadata, plan, payment status, tax information, and hosted invoice or portal links. We do not store full payment-card or bank account numbers.
Communications
If you contact us, we may collect your contact information, message contents, support requests, feedback, and related metadata.
Website And Cookie Information
Our websites and Service use cookies, local storage, or similar technologies only as needed for authentication, security, preferences, and product operation. At launch, SkillOps does not use marketing, advertising, cross-context behavioral, or third-party analytics cookies. If that changes, we will update this policy and provide any required notices or choices before enabling them.
2. How We Use Personal Information
We use personal information to:
- provide, operate, secure, and support the Service;
- authenticate users and enforce customer-configured permissions;
- create, review, approve, publish, and distribute skill content;
- operate the managed MCP gateway and related host shims;
- maintain audit trails, usage records, billing records, and compliance evidence;
- process subscriptions, invoices, renewals, cancellations, and payment status;
- communicate about accounts, support, security, product updates, and billing;
- monitor, debug, protect, and improve the Service;
- develop new features using deidentified, aggregated operational telemetry;
- detect abuse, fraud, security incidents, or policy violations; and
- comply with legal obligations and enforce agreements.
3. How We Share Personal Information
We may share personal information with:
- the customer organization that controls the workspace or account;
- authorized users and administrators within that customer organization, based on configured roles and permissions;
- service providers and subprocessors that host, secure, process, support, or operate the Service;
- payment processors such as Stripe;
- identity providers or integration partners configured by Customer;
- professional advisors, auditors, insurers, and legal counsel;
- government authorities or third parties when required by law or necessary to protect rights, safety, security, or the Service; and
- a successor in connection with a merger, acquisition, financing, reorganization, or sale of assets.
We do not sell personal information for money. We do not knowingly share personal information for cross-context behavioral advertising. If that changes, we will update this policy and provide required opt-out choices.
SkillOps does not use Customer Data to train machine-learning or generative-AI models or to improve products for other customers. Human access to Customer Data is limited to authorized support, security, or legally required work.
4. Customer Data And Processor Role
For personal information in Customer Data, the customer organization is usually the controller or business, and SkillOps is usually the processor, service provider, or contractor. We process that information according to the customer's instructions, the Terms, the Security Appendix and Data Processing Addendum, and applicable law.
If you are an end user of a customer organization and want to access, correct, delete, or restrict personal information in that organization's workspace, you should contact the customer organization first. We will assist the customer as required by applicable law and our agreements.
5. Data Retention
We retain personal information for as long as needed to provide the Service, maintain audit trails, comply with legal obligations, resolve disputes, enforce agreements, protect the Service, and support legitimate business purposes.
Customer administrators may export or delete certain Customer Data through the Service or by contacting us, subject to retention needed for security, legal, billing, backup, or audit purposes. Backup copies may persist for a limited period before deletion through normal backup rotation.
Default retention posture, unless an Order Form or legal hold requires otherwise:
- Customer content is retained while the account is active and for up to 30 days after termination;
- backups are deleted through normal rotation within 90 days;
- security and audit records are retained for up to 24 months;
- support correspondence is retained for up to three years; and
- billing, tax, and accounting records are retained for up to seven years.
6. Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information. No service can guarantee absolute security. Customers are responsible for managing authorized users, protecting credentials, configuring SSO and gateway access securely, and reviewing third-party AI-agent and host environments.
Additional security commitments are described in the Security Appendix.
7. International Transfers
The initial SkillOps self-service offering is limited to United States business customers. We and our service providers may process personal information in the United States and other locations where they operate. We will implement any required transfer mechanism before intentionally offering the Service in a jurisdiction that requires one.
8. California Privacy Notice
Depending on our business size, data volumes, and customer base, some California privacy laws may or may not apply directly to SkillOps. We nevertheless provide the following California-style notice.
In the preceding 12 months, we may have collected the categories of personal information described above, including identifiers, commercial information, internet or electronic network activity information, professional or employment information, and inferences from usage information. We collect and use that information for the business and commercial purposes described in this policy.
We do not sell personal information for money. We do not knowingly share personal information for cross-context behavioral advertising. We do not knowingly collect personal information from children under 13.
California residents may have rights to request access, correction, deletion, portability, restriction, or information about certain disclosures. To exercise rights, contact vh@vivekhaldar.com. We may need to verify your identity and, where the data is controlled by a customer organization, direct your request to that organization.
California Online Tracking Disclosures
SkillOps does not track individuals' online activities over time and across third-party websites or services for advertising or profiling. Because SkillOps does not perform that tracking, it does not currently respond differently to a browser's "Do Not Track" signal. Payment, identity, hosting, and other service providers may receive technical information necessary to perform their services, but SkillOps does not authorize them to use that information for cross-site behavioral advertising on SkillOps' behalf.
9. Other Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, port, object to, restrict, or withdraw consent for certain processing of your personal information. You may also have the right to lodge a complaint with a data-protection authority.
To make a request, contact vh@vivekhaldar.com. We will respond as required by applicable law.
10. Children
The Service is not directed to children and is not intended for users under 16. We do not knowingly collect personal information from children.
11. Changes To This Policy
We may update this Privacy Policy from time to time. Material changes will be posted in the Service or otherwise communicated as required by law. The updated policy will be effective on the date stated above unless otherwise indicated.
12. Contact
Privacy contact:
Enchiridion Labs LLC vh@vivekhaldar.com
Operational support: vh@vivekhaldar.com