Privacy and Cookies Policy
How Skill2Web collects, uses, shares, stores, and protects information.
Version 1.1 · Effective and last updated: July 25, 2026
Introduction and scope
This Privacy and Cookies Policy explains how Skill2Web (“Skill2Web,” “we,” “us,” or “our”) handles information. Skill2Web is the data controller for information covered by this policy.
This policy applies to https://skill2web.com and to any Skill2Web website, web application, API, or other interface that links to it (collectively, the “Platform”), including the AI chat, Skill conversion, account, billing, and support services made available through the Platform.
1. Information collected through the Platform
Log and device information: when you use the Platform, our systems may automatically record IP address, timestamp, browser type, device type, operating system, language, time zone, referring page, pages and features used, session and cookie identifiers, approximate location inferred from IP, request performance, and error or security events.
Usage and AI information: we process selected models, prompts, conversation messages and outputs, conversation settings, token and cost metrics, credit usage, Skill files or repository details submitted for conversion, rights confirmations, and related diagnostics. Private conversations are not published as indexable pages.
BYOK information: if you save your own API credential, we process the provider, configuration, masked key details, and encrypted credential. The credential is sent over HTTPS and stored with server-side AES-256-GCM encryption. Plaintext keys are not returned by ordinary APIs or included in analytics and application logs.
We may combine information collected through the Platform when reasonably necessary to deliver a request, maintain account and transaction history, measure reliability, detect abuse, and improve the user experience.
2. Information you provide and how we use it
You may provide your name, email address, password credential, account preferences, support messages, feedback, reports, prompts, files, and other content. Password credentials are stored as one-way hashes rather than readable text. If you choose Google or GitHub sign-in, we receive the basic profile and account identifier that provider makes available.
Payment and billing information may include product, amount, currency, order and transaction identifiers, payment status, subscription period, refund status, credit ledger entries, and limited billing contact information. Waffo Pancake processes complete card numbers and card security codes; Skill2Web does not store them.
Providing information is optional, but some information is required to create an account, complete a purchase, use a requested feature, or receive support.
We use this information to provide and maintain the Platform; deliver AI conversations, Skill conversion, BYOK, credits, and subscriptions; authenticate and secure accounts; process billing and refunds; respond to questions; personalize language and settings; diagnose errors; analyze and improve performance; prevent fraud or abuse; enforce our Terms; protect users and rights holders; meet applicable obligations; and send essential account, billing, security, and policy messages.
The Platform is intended for users aged 18 or older. Skill2Web does not knowingly collect personal information from anyone under 18. Contact support@skill2web.com if you believe a minor has provided information.
3. How we share information
Skill2Web does not sell personal information. We share information only when reasonably necessary to operate the Platform, complete a transaction, provide a feature you selected, protect users or the Platform, or comply with applicable requirements.
Waffo Pancake acts as our payment processor and Merchant of Record and receives the buyer, checkout, order, subscription, tax, refund, fraud, and payment information needed to complete transactions. Card data is processed by Waffo Pancake and is not stored on Skill2Web servers.
Conversation content and request metadata are sent to the AI provider used for a request. Platform mode uses the provider configured by Skill2Web; BYOK mode sends content to the OpenAI, Anthropic, or Moonshot endpoint you select. These providers process information under their own terms and privacy policies.
Where enabled, service providers may support hosting, database operation, private file storage, transactional email, authentication, error monitoring, analytics, customer support, advertising, or other technical and operational functions. They receive only the information reasonably needed for that function and are subject to their own privacy commitments and our applicable agreements.
Information may also be disclosed in connection with a sale, merger, financing, reorganization, change of control, or transfer of the Platform; to respond to valid legal process or a good-faith request from an authority; to investigate suspected unlawful activity or prevent harm; or for another purpose with your prior consent.
4. Cookies, pixel tags, and similar technologies
Cookies are small data files stored on a browser or device and used as identifiers. Pixel tags, also called web beacons, are small technologies that can record that a page or message was viewed. Similar software tools may perform comparable functions. When enabled, these technologies help remember you, keep a session secure, understand Platform use, measure performance, and provide relevant content.
Strictly necessary cookies support secure sign-in, account protection, payment return flows, anonymous rate limits, language and interface preferences, and storage of your cookie choices. They are required for core operation.
Functional cookies remember optional preferences. Analytics and performance technologies help count visits and understand how features are used. Marketing or targeting technologies, if enabled, may record visits and interactions to measure campaigns or make content more relevant.
Non-essential analytics, marketing, affiliate, advertising, and optional support tools remain disabled until you consent. Depending on the Platform configuration, these may include Google Analytics (https://policies.google.com/privacy), Plausible Analytics (https://plausible.io/data-policy), Vercel Analytics (https://vercel.com/legal/privacy-policy), Crisp (https://crisp.chat/en/privacy/), or Tawk.to (https://www.tawk.to/privacy-policy/).
5. Your choices and opt-out options
You can accept, reject, or choose categories in the cookie banner and change your choice through “Cookie settings” in the site footer. Browser controls can also block or delete cookies, although disabling necessary cookies may make account or payment features unavailable.
If Skill2Web sends marketing communications, you may opt out through the unsubscribe link, available account or cookie preferences, or support@skill2web.com. Opting out of marketing does not stop essential verification, receipt, billing, security, support, or policy messages.
You can review conversations and saved API credentials in your account and can delete conversations or credentials using available controls. Requests concerning account information may also be sent to support@skill2web.com.
6. Third parties on the Platform
The Platform may contain embedded third-party content, links, or integrations. Third parties operate independently and may collect information under privacy policies that differ from this one. Skill2Web is not responsible for their privacy or security practices. Review the relevant policy before using an external service or providing information to it.
7. Data protection measures
Skill2Web uses safeguards designed to protect information against unauthorized access, alteration, interference, disclosure, or destruction. Measures include HTTPS/TLS in transit, password hashing, encryption for stored API credentials, private object storage, least-privilege access, rate limits, signed payment webhooks, audit records, sensitive-information filtering, and error monitoring designed to avoid collecting conversations or API keys.
No security system is perfect. Skill2Web cannot guarantee that information will never be disclosed inadvertently or accessed through a sophisticated attack, but we review risks and improve safeguards as the Platform evolves.
If an incident is likely to affect your privacy rights, Skill2Web will investigate, mitigate, and provide notifications within the period required by applicable law.
8. Data retention
Conversation message content and question-derived titles are normally erased 30 days after creation. Non-content usage ledger entries may remain for billing reconciliation, fraud prevention, capacity planning, and accounting. A conversation shell may remain without message content when linked usage records must be preserved.
A saved BYOK credential is retained until you delete or replace it, close the account, or ask Skill2Web to delete it. Imported Skill source files and rights records are retained while the Skill is active and ordinarily for up to three years afterward for versioning, security, and rights complaints.
Account information is retained while the account is active. After a verified deletion request, Skill2Web aims to remove or anonymize active account data within 90 days, while encrypted backups may age out within a further 90 days. Support and privacy-request records are normally kept for two years, and security and application logs for up to 12 months unless an investigation requires longer retention.
Order, transaction, tax, refund, and credit-ledger records are normally retained for seven years after the relevant transaction, or longer when an applicable requirement, dispute, fraud investigation, or Merchant-of-Record obligation requires it. Cookie-consent records may be retained for five years. At expiry, information is deleted, anonymized, or securely archived while a valid retention obligation continues.
9. Cross-border data transfers
Skill2Web and its service providers may process or store information in multiple jurisdictions. Privacy rules in a processing location may differ from those where you live.
Where an international transfer requires additional protection, Skill2Web uses appropriate contractual, organizational, or legally recognized safeguards. Regardless of processing location, Skill2Web handles information according to the principles described in this policy.
10. Your privacy rights
Depending on applicable law, you may request access to or a copy of personal information, correction of inaccurate information, deletion, restriction, portability, objection to certain processing, withdrawal of consent, or review of a decision based solely on automated processing. You may also have the right to make a complaint to an appropriate privacy authority.
Send a request from the account email to support@skill2web.com. Skill2Web may request information reasonably needed to verify identity and protect the account. We aim to respond within 30 calendar days or the period required by applicable law and will explain a permitted extension or refusal.
11. Policy updates and contact
Skill2Web may revise this Privacy and Cookies Policy as the Platform, providers, or applicable requirements change. The current version and effective date will be posted here. Material changes may also be highlighted by email or an in-product notice. Continuing to use the Platform after a revision takes effect means you acknowledge the updated policy.
Data controller and legal entity: Skill2Web · Website: https://skill2web.com · Privacy, account, and support requests: support@skill2web.com.

