SkillPilot privacy policy
Effective date: 2026-09-20. This policy covers the SkillPilot iOS app (bundle id com.ygl.skillpilot.app) and the SkillPilot website at www.skillpilot.biz. Both are made by YGL. Contact: yacov@ygl.co.il.
The short version: the app has no accounts, stores nothing about you, sends no identifiers anywhere, contains no analytics or advertising SDKs, and does not track you. The website is a public catalog that may keep standard server logs.
1. Who we are
SkillPilot is published by YGL, contact Yacov, yacov@ygl.co.il. YGL is the data controller for any personal data described in this policy.
2. The iOS app
2.1 What the app does
SkillPilot shows a catalog of open-source AI developer tools (agents, skills, MCP servers, CLIs and repositories), health and version status for a set of monitored tools, and alerts about breaking changes and security advisories. It is read-only: it never installs, runs or changes anything on your device or your computer.
2.2 Data the app collects
None. The app has no sign-in, no user profile, no forms and no user-generated content. It does not ask for your name, email, contacts, location, photos, microphone, camera or any other permission. It does not use the advertising identifier. Its privacy manifest declares no collected data types, no tracking and no tracking domains.
2.3 Data the app stores on your device
The app ships with a bundled copy of the catalog so it works offline. It does not write any files, preferences or database entries about you. Actions such as marking an alert as resolved are kept in memory for the current session only and are gone when the app is closed.
2.4 Network requests the app makes
The app makes two kinds of network requests, both over HTTPS, and neither carries an identifier for you or your device beyond what any HTTPS request carries by nature:
- Catalog data from our own backend: www.skillpilot.biz/api/v1/skills, /api/v1/alerts and /api/v1/videos. These are plain GET requests with no query parameters, no cookies and no request body. If the backend is unreachable the app falls back to the bundled catalog.
- Owner avatars from GitHub: github.com/<owner>.png, where owner is the public GitHub account of an open-source project shown in the catalog. This request goes to GitHub, and GitHub's own privacy statement applies to it.
When you tap "Open repository" or an alert's evidence link, the app hands the URL to iOS, which opens it in your default browser. From that point the site you visit, usually GitHub, governs your data.
2.5 Third-party SDKs
The app links no analytics, crash reporting, advertising or attribution SDKs. It uses only Apple's frameworks (SwiftUI, Foundation, URLSession, UserNotifications).
2.6 Notifications
Version 1.0.0 does not request notification permission and does not send notifications. If a later version adds alert notifications, the app will ask for permission first and this policy will be updated.
2.7 Children
The app is rated 4+ and does not collect data from anyone, including children.
3. The website (www.skillpilot.biz)
3.1 Hosting and server logs
The website and its API are hosted on Vercel. Like any web host, Vercel may record standard server logs for each request: IP address, request URL and method, response status, time, user agent and referrer. These logs are used to keep the service running, to diagnose faults and to defend against abuse. They are retained for the period set by the hosting provider and are not combined with any other data about you. Vercel's privacy policy is at vercel.com/legal/privacy-policy.
3.2 Cookies and analytics
The website does not set cookies for tracking and does not run advertising. If we add a privacy-preserving visit counter in the future, this section will say so.
3.3 Content in the catalog
The catalog lists public open-source projects. The information shown about each project (repository name, owner, description, star and fork counts, README excerpt, release and advisory data) comes from the public GitHub API and the public npm and PyPI registries. The owner shown is a public GitHub account name, not a private individual's personal data collected by us. If you are a project owner and want an entry corrected or removed, email yacov@ygl.co.il and we will act within 48 hours.
4. Legal basis and your rights
Because the app collects no personal data, there is nothing for us to access, correct, export or delete on request. For website server logs, our legal basis is our legitimate interest in operating and securing the service. If you are in the EU, UK or another jurisdiction with data protection rights, you may ask us what we hold about you, ask for correction or deletion, or object to processing, by emailing yacov@ygl.co.il. You may also complain to your local supervisory authority.
5. Data sharing and sale
We do not sell, rent or share personal data. The only third parties that see any request are the hosting provider (Vercel) and GitHub as described above, each acting under its own policy.
6. Security
All app and website traffic uses HTTPS. The app holds no credentials, tokens or secrets.
7. Changes to this policy
We will post any change on this page with a new effective date. Material changes affecting the app will also appear in the App Store release notes.
8. Contact
YGL, Yacov, yacov@ygl.co.il. We answer privacy questions within 48 hours.