SkillSpillNEURAL SECURITY PROTOCOL v1.0

SYSTEM DOCUMENT

Privacy
Policy

Your data, your rules. This policy explains exactly what we collect, why we collect it, how long we keep it, and how you can take control of it at any time.

EFFECTIVE DATE

01 January 2026

LAST UPDATED

30 May 2026

// Who We Are

1.1

SkillSpill Inc. ("SkillSpill", "we", "us", "our") operates the SkillSpill platform — a skill-first career marketplace for software engineering talent and technical recruiters.

1.2

This Privacy Policy applies to all users of the platform, including visitors, registered Talent, and Recruiters. It covers data collected through our website, mobile interfaces, APIs, and any connected services.

1.3

For privacy-related questions, contact us at privacy@skillspill.com.

// Data We Collect

We collect data in three ways: data you provide directly, data generated by your activity on the platform, and data from connected third-party services.

DIRECTLY PROVIDED

2.1

Account data: full name, email address, username, password (stored as a salted hash, never plain text).

2.2

Profile data: bio, location, years of experience, skills, portfolio URLs, resume file.

2.3

Recruiter data: company name, company size, industry, website, phone number, job listings, and posted bounties.

2.4

Communications: messages sent through the platform's chat system, support tickets, and feedback forms.

AUTOMATICALLY COLLECTED

2.5

Usage data: pages visited, features used, search queries, time spent, click patterns, and session duration.

2.6

Device data: IP address, browser type and version, operating system, screen resolution, and timezone.

2.7

Performance data: error logs, load times, and crash reports used to improve platform stability.

FROM THIRD-PARTY SERVICES

2.8

GitHub OAuth: public profile data, repository metadata, contribution graphs, and programming language statistics when you connect your GitHub account.

2.9

OAuth providers: basic profile info (name, email, avatar) from any OAuth provider you use to sign in.

// How We Use Your Data

3.1

To create and manage your account and authenticate your identity.

3.2

To power AI-driven skill matching between Talent and Recruiters based on verified abilities.

3.3

To display your public profile to recruiters and other users who have access to the platform.

3.4

To send transactional emails — account verification, password resets, match notifications, and bounty updates.

3.5

To analyze platform usage and improve features, performance, and user experience.

3.6

To enforce our Terms of Service, detect fraud, and maintain platform security.

3.7

To comply with legal obligations and respond to lawful requests from authorities.

3.8

We do not sell your personal data to third parties. We do not use your data for advertising targeting on external platforms.

// GitHub & OAuth Data

4.1

When you connect your GitHub account, we request read-only access to your public profile and public repositories. We do not request access to private repositories, write permissions, or the ability to act on your behalf.

4.2

GitHub data we process includes: username, avatar, public bio, follower/following counts, public repository names and descriptions, primary programming languages, contribution frequency, and star counts.

4.3

This data is used exclusively to generate and update your skill score and to improve match quality. It is not shared with recruiters in raw form — only the derived skill score and language summary are visible.

4.4

You can revoke SkillSpill's GitHub access at any time from your GitHub account settings under "Authorized OAuth Apps." Revoking access will pause GitHub-based score updates but will not delete previously derived scores.

4.5

To delete GitHub-derived data from our systems entirely, submit a data deletion request to privacy@skillspill.com.

// AI Processing & Scoring

5.1

SkillSpill uses AI models to analyze your portfolio, GitHub activity, skill declarations, and assessment results to produce a skill score and a match compatibility rating with job listings and recruiters.

5.2

AI-generated scores are probabilistic estimates, not definitive evaluations. They are one input among many that recruiters use, and are not intended to be the sole basis for hiring decisions.

5.3

Your data may be used to train or fine-tune our AI models in an anonymized or aggregated form. We do not use personally identifiable information directly in model training without explicit consent.

5.4

You have the right to request a human review of any AI-generated decision that significantly affects your access to opportunities on the platform. Submit such requests to privacy@skillspill.com.

// Data Sharing

6.1

With Recruiters: Your public profile, skill scores, portfolio links, and match rating are visible to verified Recruiter accounts. You control which profile fields are public via your privacy settings.

6.2

With Service Providers: We share data with trusted third-party vendors who help us operate the platform — cloud infrastructure (Azure), real-time messaging (Pusher), email delivery (SMTP providers), and AI services (Groq). These vendors are contractually prohibited from using your data for their own purposes.

6.3

For Legal Compliance: We may disclose data if required by law, court order, or to protect the rights, property, or safety of SkillSpill, our users, or the public.

6.4

Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.

6.5

We never sell, rent, or trade your personal data to third parties for their own marketing or commercial purposes.

// Cookies & Tracking

7.1

SkillSpill uses cookies and similar technologies (localStorage, sessionStorage) to maintain your session, remember your theme preference, and improve platform performance.

7.2

Essential cookies are required for authentication and core platform functionality. They cannot be disabled without breaking the platform.

7.3

Analytics data (usage patterns, feature interactions) is collected to help us understand how the platform is used. This data is processed in aggregate and is not linked to your identity.

7.4

We do not use third-party advertising cookies or cross-site tracking technologies.

7.5

You can clear cookies and local storage at any time via your browser settings. Doing so will log you out of your session.

// Data Retention

We retain different categories of data for different periods based on necessity and legal requirements.

DATA TYPEPURPOSERETENTION
Account dataCore platform operationUntil deletion request
Profile & portfolioRecruiter matchingUntil deletion request
MessagesCommunication record2 years after last activity
GitHub sync dataSkill scoringUntil OAuth revoked + 30 days
Usage logsAnalytics & security12 months rolling
Error logsPlatform stability90 days
Payment recordsLegal / accounting7 years (legal requirement)
Support ticketsIssue resolution3 years

After the retention period expires, data is securely deleted or anonymized. You can request early deletion at any time (see Your Rights).

// Your Rights

You have the following rights over your personal data. To exercise any of them, email privacy@skillspill.com. We will respond within 30 days.

9.1

Right of Access — Request a copy of all personal data we hold about you.

9.2

Right to Rectification — Request correction of inaccurate or incomplete data.

9.3

Right to Erasure — Request deletion of your account and associated personal data. Some data may be retained where required by law.

9.4

Right to Portability — Request your profile and activity data in a machine-readable format (JSON or CSV).

9.5

Right to Object — Object to processing of your data for AI scoring or analytics purposes.

9.6

Right to Restrict Processing — Request that we pause processing your data while a dispute is resolved.

9.7

Right to Human Review — Request human review of any significant AI-generated decision affecting your platform experience.

// Data Security

10.1

Passwords are hashed using industry-standard algorithms. We never store plain-text passwords.

10.2

All data in transit is encrypted via TLS 1.2 or higher. Data at rest is encrypted using AES-256 on our cloud infrastructure.

10.3

Access to production data is restricted to authorized personnel on a need-to-know basis, with audit logging enabled.

10.4

In the event of a data breach that affects your personal data, we will notify you within 72 hours of becoming aware of the breach, as required by applicable law.

10.5

No method of electronic storage or transmission is 100% secure. While we implement strong safeguards, we cannot guarantee absolute security against all threats.

// Children's Privacy

11.1

SkillSpill is not intended for users under the age of 16. We do not knowingly collect personal data from anyone under 16.

11.2

If you believe a minor has created an account, please contact us immediately at privacy@skillspill.com and we will delete the account and associated data promptly.

// Changes to This Policy

12.1

We may update this Privacy Policy from time to time. When we make significant changes, we will notify you via email and display a notice on the platform at least 14 days before the changes take effect.

12.2

Your continued use of SkillSpill after the effective date of an updated policy constitutes acceptance of the changes. If you do not agree, you may close your account before the effective date.

12.3

The date at the top of this page always reflects when the policy was last updated. Prior versions are available on request.

// Contact

For any privacy-related questions, data requests, or concerns, reach out to us:

You also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

RELATED DOCUMENT

Terms of Service

Platform rules, Talent Protocol, Recruiter Assignment Terms.

READ TERMS →

© 2026 SKILLSPILL INC. ALL RIGHTS RESERVED.

← RETURN TO PLATFORM