Last updated: July 18, 2026
This Privacy Policy explains how AIEmployees ("AIEmployees", "we", "us", or "our"), the operator of Terminal Skills — our AI-agent-skills marketplace, open-source skills library, and Agent Playground available at terminalskills.io — collects, uses, shares, and protects personal data. "You" or "Customer" means the visitor, account holder, or contributor using Terminal Skills.
AIEmployees is the business name under which an independent entrepreneur operates; it is a sole proprietorship, not an incorporated or registered company, and not a separately registered legal entity. "Terminal Skills" and "AIEmployees" are unregistered trade names, and "Terminal Skills" is an unregistered trademark. Nothing in this Policy asserts any corporate, state, or trademark registration.
This Policy applies to our website, the Terminal Skills application (including accounts, billing, and the Agent Playground), the public skills library, and our command-line and programmatic interfaces. For the terms governing your use of the service, see our Terms of Service.
Terminal Skills has three parts, and how much data we process depends on which you use:
We aim to collect as little personal data as reasonably possible for each of these.
We collect personal data that you provide directly, data we collect automatically as you use the service, and a limited amount of data we receive from third parties such as Stripe.
mailto: link and GitHub links) — there is no web contact form, and we do not store contact messages in the application.We do not collect or store full payment-card numbers, CVV, or bank details anywhere. See Section 2.3 for how payment is handled.
We do not perform UTM/attribution capture or server-side logging of personal request data in our application code.
No third-party social login exists. Authentication is email + password only — there is no Google, GitHub, or other OAuth/single-sign-on login.
We use personal data to:
Where the EU/UK GDPR applies, we rely on the following legal bases:
We do not sell personal information for money. We share personal data with the service providers ("sub-processors") below, each of which processes data on our behalf or as an independent controller under its own privacy policy. This list reflects only the vendors actually used by Terminal Skills.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Google LLC — Google Cloud / Vertex AI (Gemini) | Powers the Agent Playground: all agent reasoning runs on Gemini models via Vertex AI; the "forge" pipeline may use Google Search grounding for research. | Your task prompts, staged SKILL.md content, tool-call inputs/outputs, generated outputs, and (in forge mode) research queries. | Google Cloud, region set to "global" (multi-region routing). |
| Stripe, Inc. | Payment processing for credit packs and the Pro subscription, the billing portal, and subscription webhooks. | Your email, an internal reference to your account and the pack/credits purchased, and card/payment details entered directly on Stripe-hosted checkout. Stripe returns customer/subscription IDs to us. | United States (global processing). |
| GitHub, Inc. (Microsoft) | Hosts the public open-source skills library, powers the sync pipeline and CLI downloads, and (when explicitly enabled) receives forge-mode pull requests. | Repository reads (no personal data); contributor GitHub usernames as skill "author" metadata; generalized, PII-stripped skill content in optional pull requests. | United States. |
| Google LLC — Google Tag Manager | Client-side tag/analytics container loaded on every page. | Browsing behavior, page views, IP address, device/user-agent, and cookies configured within the container. | Google (global). |
| Google LLC — Google Fonts | Web fonts. Fonts are self-hosted at build time (no runtime user request to Google); separately, dynamic social-preview image routes fetch a font file server-side. | Build-time font download (no user data); server-to-server font fetch (server IP only, no end-user PII). | Google (fonts.gstatic.com). |
| jsDelivr (CDN) | Loads the API-reference viewer script on a single API-docs page only. | Your browser's IP and user-agent when you visit that one page (no application data). | Global CDN. |
| Hetzner Online GmbH + self-hosted Coolify | Underlying compute and hosting for the entire platform, its self-hosted MongoDB database, and per-run agent workspaces. | All platform data at rest and in transit lives on this infrastructure. | Hetzner (Germany-based provider); exact data-center region is confirmed with the operator on request. |
Our database (MongoDB) and authentication are self-hosted on our own infrastructure — we do not use a managed database service (such as MongoDB Atlas) or a third-party identity provider. We do not use a third-party object-storage or CDN service for your uploaded files; run workspaces are stored on the platform's local filesystem.
We may also disclose personal data to comply with law, enforce our agreements, protect the rights, property, or safety of AIEmployees, our users, or the public, or in connection with a merger, acquisition, or sale of assets.
Our hosting infrastructure (Hetzner via self-hosted Coolify) is provided by a Germany-based provider, while several of our sub-processors (Stripe, GitHub, Google Cloud with a "global" region) process data in the United States and other regions. Where personal data is transferred out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses (and the UK Addendum / Swiss adaptations) where required. The exact data-center region of our hosting is available from us on request.
We do not currently display a cookie-consent banner, and analytics is not gated behind consent. We want to be transparent rather than overstate our controls:
ts_session — a first-party, httpOnly, SameSite=Lax authentication cookie (marked Secure in production) that holds your signed session and expires after 7 days. It is strictly necessary to keep you signed in.GTM-KZ98N24T) loads on every page for every visitor as soon as the page loads. Whatever tags are configured inside that container — which may include Google Analytics — run and may set their own first- or third-party cookies (for example _ga) and collect analytics data. The specific tags and cookies are defined in the remote container, not in our source code.sessionStorage (for skipping the intro animation, restoring scroll position, and preserving a pending playground task across login). These stay in your browser and are never sent to our servers.We do not currently operate a consent-management mechanism or automatically process Global Privacy Control (GPC) signals; analytics tags load for all visitors as described above. Your only current control is to block or clear these cookies through your browser settings or a tracker-blocking extension, and the site remains fully functional without analytics. Our fonts are self-hosted, so browsing the site does not send your IP to Google for fonts. For a categorized breakdown of every cookie and storage key we use, see our Cookies Policy.
We periodically review the personal data we hold and delete or anonymize data that is no longer needed for the purposes described in this Policy, consistent with the legitimate-interests and legal-obligation bases in Section 4.
Because our current retention of accounts and run summaries is indefinite, and self-service deletion is not yet available (see Section 10), you can ask us to delete your data by emailing us; we will honor valid requests as described below.
We protect personal data with the following measures, described accurately rather than aspirationally:
httpOnly cookie and expiring after 7 days. Because sessions are stateless, an individual token cannot be centrally revoked before it expires; logging out clears the cookie, and administrative role changes are re-checked against the database on every privileged request.Secure in production.We do not currently apply field-level or application-layer encryption to data at rest; any at-rest protection is provided at the database/host layer. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If you are in the EEA or UK, you may have the right to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent where we rely on it. You may also lodge a complaint with your local supervisory authority.
If you are a resident of a US state with a comprehensive privacy law (such as California, Colorado, Connecticut, Virginia, Texas, and others), you may have the right to know/access, correct, delete, and port your personal data; to opt out of the "sale" or "sharing" of personal data and of targeted advertising and certain profiling; to control sensitive data; to appeal a denied request; and not to be discriminated against for exercising these rights. We do not sell personal information for money. To the extent that loading analytics could be considered "sharing," note that we do not currently operate a consent-management mechanism or automatically honor the Global Privacy Control (GPC) browser signal; you may opt out by contacting us at support@terminalskills.io or by blocking cookies in your browser or with a tracker-blocking extension.
We do not sell your personal information for money. Because we load Google Tag Manager (see Section 5), that activity could, under some US state laws, be considered "sharing" for targeted advertising. As we do not yet operate a consent-management mechanism or automatically honor GPC signals, you can exercise your Do-Not-Sell/Share opt-out by blocking cookies in your browser or with a tracker-blocking extension, or by emailing us at support@terminalskills.io (subject "Attn: Privacy"). For more detail, see our Do Not Sell or Share My Personal Information page.
Because self-service account deletion and data export are not yet built into the product, please send rights requests to support@terminalskills.io (subject line "Attn: Privacy") or through our contact page, or to AIEmployees at aiemployees.us. We will verify your request and respond within the timeframes required by applicable law (generally one month under GDPR, 45 days under US state laws, extendable where permitted). Note that public open-source contributions are handled on a best-effort basis (see Section 13).
Terminal Skills is not directed to children. You must be at least 18 years old to create an account or use the Agent Playground. We do not knowingly collect personal data from anyone under 18; if you believe a minor has provided us personal data, contact us and we will delete it.
The Agent Playground runs AI agents on third-party AI models (Google Gemini via Vertex AI). AI output is inherently probabilistic and may be incomplete, inaccurate, or unsafe. You are responsible for reviewing any code, command, skill, or other output an AI agent produces before relying on it or executing it — especially in a production environment. Avoid submitting sensitive personal data, secrets, or confidential material into task prompts or uploaded files, since that content is transmitted to our AI sub-processor to perform the task you request. Skills you obtain frequently invoke other third-party platforms and APIs; each is governed by its own terms and privacy policy.
When you contribute a skill, use case, fix, or other content to our public GitHub repository, your GitHub username, commit metadata, and the content you contribute become part of the public open-source repository and its public Git history, which is retained indefinitely and mirrored by others outside our control. Public Git history cannot be selectively rewritten without breaking project integrity, so requests to erase public contributions are addressed on a best-effort basis only. Skills authored by the Agent Playground's "forge" mode are, when contribution is explicitly enabled, published to the public repository as deliberately generalized, PII-stripped content and labeled as agent-generated.
The terminal-skills command-line tool and our public MCP server and API expose only the public skills catalog; they do not read your account, playground runs, or billing. Where programmatic access touches account-scoped data, it is limited to your own account and remains subject to this Policy, our Terms of Service, and our Acceptable Use Policy.
We may update this Policy as the product evolves. The "Last updated" date at the top reflects the most recent revision, and material changes will be highlighted on the website. Continued use of the service after an update constitutes acceptance of the revised Policy.
Questions about this Policy or your personal data can be sent to support@terminalskills.io (subject "Attn: Privacy"), through our contact page, or to AIEmployees at aiemployees.us. You can also review our related policies: Terms of Service, Cookies Policy, Data Processing Addendum, Acceptable Use Policy, and Do Not Sell or Share My Personal Information.