Privacy policy

How McBourne Enterprises handles personal information in shareskills. Written to be read, not to be survived.

Last updated: 27 July 2026

Who we are

shareskills is operated by McBourne Enterprises, an Australian company. This policy explains what personal information we collect when you use shareskills, why we collect it, who else handles it, and what you can ask us to do about it.

We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). If you are in the EU or the UK, we also describe our lawful bases below.

What we collect

We collect the minimum needed to run a team tool. There is no advertising, profiling or data brokerage anywhere in this product.

  • Account details: your email address, your display name, and an avatar (an emoji we assign by default, or an image URL if you set one).
  • Your password, stored only as a scrypt hash. We never store, log or transmit the password itself, and we cannot recover it.
  • If you sign in with Google: the account identifier Google gives us, your email address, whether Google has verified it, your display name, and your Google Workspace domain if you have one. We record the email and domain as they were when you first connected, so we can answer questions later about how an account came to be linked.
  • Content you create: skills (their files and text), version history, suggested changes, review decisions and the notes attached to them.
  • Organisation details: your organisation’s name, its members and their roles, and the email addresses of people invited to it.
  • Sign-in records: for each session, the time, your IP address and your browser’s user-agent string, so you and we can tell legitimate access from suspicious access.
  • Abuse-prevention records: your email address and IP address against short-lived counters that rate-limit sign-in, sign-up and password-reset attempts.
  • An audit trail of significant actions in your organisation — who did what, when, and to which item.
  • Transactional emails we have queued or sent to you (verification, password reset, invitations, notifications), including their contents.

If you sign in with Google

Signing in with Google is optional. If you use it, Google tells us the account identifier, your email address, whether Google has verified that address, your name, and your Workspace domain if you have one. That is all we ask for.

We never see or receive your Google password, and we do not request access to Gmail, Drive, Calendar, Contacts or any other Google service. We do not ask Google for offline access, so we hold no long-lived Google credential and cannot act on your Google account when you are not signing in.

If your email address already has a shareskills account, we connect the two rather than creating a second one — but only when Google confirms it has verified that address. That check exists so nobody can claim an address that is not theirs.

We send nothing back to Google about what you do in shareskills.

AI tools you connect

This one deserves your attention, because it is the part of shareskills that sends your content somewhere we do not control.

shareskills exists so AI tools — Claude Code, Claude Desktop, Cursor, VS Code with GitHub Copilot, and others — can fetch your team's skills on demand. When you connect such a tool and it requests a skill, we send that skill's contents to the tool you connected. The tool, and the AI provider behind it, then handle that content under their own terms and privacy policies, not ours.

Two consequences worth being deliberate about. Do not put credentials, secrets or personal information about other people into a skill. And treat a skill you install from the public directory as untrusted text written by a stranger: read it before you let an AI assistant act on it.

We record which client connected and when, so you can review access. We do not receive or store the conversations you have with your AI tool.

What we don’t do

Stated plainly, because these are the questions people actually have:

  • We do not sell, rent or trade your personal information, and we never will.
  • We do not serve advertising and we do not build advertising profiles.
  • We run no third-party analytics, no tracking pixels and no session-recording tools. There is no Google Analytics on this site.
  • We do not read your skills, or use your content to train any AI model.
  • We set no advertising or cross-site tracking cookies.

Cookies

We use a small number of strictly functional cookies. None of them track you across other sites, which is why you are not asked to consent to a banner full of vendors.

  • sbx_session — keeps you signed in. Expires after 30 days, or when you log out.
  • sbx_team — remembers which organisation you are currently working in, if you belong to more than one. Expires after 30 days.
  • sbx_google_flow — exists only during a Google sign-in, to make sure the response we get back matches the request we started. Expires after 10 minutes.
  • Cloudflare Turnstile, which checks that sign-in and sign-up attempts are made by a person, may set a short-lived entry of its own for the same purpose.

Who else handles your information

We keep the list of suppliers deliberately short. Each one only receives what its job requires.

  • Fly.io — hosting and storage. Your data lives on a single machine and volume in Sydney, Australia.
  • Resend — delivers our transactional email. It receives the recipient address and the message contents.
  • Cloudflare — provides the Turnstile bot check on sign-in, sign-up and invitation pages. It receives your IP address and a challenge token.
  • Google — only if you choose to sign in with Google, and only for that sign-in.
  • Any AI tool you connect yourself, as described above.

Where your information is stored

Your account and content are stored in Sydney, Australia.

Some of the suppliers above operate outside Australia, so limited information (an email address for delivery, an IP address for a bot check, your Google account details during sign-in) may be processed overseas. We take reasonable steps to ensure they handle it consistently with the Australian Privacy Principles.

How long we keep it

We keep your account and content for as long as your account exists. Short-lived items expire on their own:

  • Sign-in sessions: 30 days, or immediately when you log out or change your password.
  • Email verification links: 48 hours. Password reset links: 2 hours. Both are single-use.
  • Sign-in codes for connected AI tools: 5 minutes. Access keys: 1 hour, refreshed automatically. Refresh keys: 90 days.
  • Rate-limiting counters: a rolling window of minutes, not retained afterwards.
  • The audit trail is deliberately kept even if an organisation is deleted, because a record of significant actions — including the deletion itself — has to outlive the thing it describes. It contains who did what and when, and no content or secrets.

Your choices and rights

You can view and correct your name, email and avatar at any time from your profile. An organisation owner can export their organisation’s data as a single file, and can delete the organisation.

You can ask us to give you a copy of the personal information we hold about you, correct it, or delete it. Write to privacy@shareskills.ai and we will respond within 30 days. We may need to verify who you are first.

Some information we cannot delete on request: the audit trail described above, and records we are required to keep by law. If we refuse a request we will tell you why.

If you are in the EU or the UK: we process your information to perform our contract with you (providing the service), on the basis of our legitimate interests (securing accounts, preventing abuse), and to comply with legal obligations. You have the rights of access, rectification, erasure, restriction, portability and objection.

If you are unhappy with how we have handled your information, please tell us first so we can put it right. You can also complain to the Office of the Australian Information Commissioner at oaic.gov.au, or to your local data protection authority.

How we protect it

Passwords are stored as scrypt hashes, never in a recoverable form. Session tokens, API tokens and sign-in codes are stored only as cryptographic digests, so a copy of our database does not yield a working credential. All traffic to the site is encrypted in transit.

Access within an organisation follows roles: owners and admins can write, members can author their own skills, viewers can read. Private skills are visible only to the people they are shared with, and every significant action is recorded in the audit trail.

No system is perfectly secure. If a breach ever affects your personal information, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

Children

shareskills is a workplace tool and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects how we handle your personal information, we will tell account holders by email before it takes effect.

Contact us

Privacy questions and requests: privacy@shareskills.ai. Everything else: support@shareskills.ai. We are McBourne Enterprises, an Australian company.

Privacy policy — shareskills