Data Deletion

How to remove scan results, disconnect GitHub, opt out of telemetry, or request account/data deletion.

Effective date: September 7, 2026

Delete individual scans

There is no in-product delete action. Email us with the scan URL or scan id and we will delete the report. Deleting a scan removes its stored findings and disables its public share link.

An anonymous pasted or uploaded report is deleted after 30 days without any request from you, even if it was shared publicly.

Turn off public sharing

For scans you own, turn off sharing or delete the scan to make the public share URL inaccessible. Public repository badges and landing pages use public scan/corpus data only and may update separately from individual share links.

Uninstall the GitHub App

Uninstall SkillTrust from GitHub to stop future repository access, webhooks, PR comments, and check runs. GitHub installation tokens expire quickly and are not stored by SkillTrust.

After uninstall, SkillTrust marks the installation deleted. Some installation, repository, PR/check/comment, webhook, and audit metadata may remain for security, abuse prevention, debugging, or legal reasons unless you request deletion.

Delete your account

Email the contact below from your SkillTrust account email with subject “SkillTrust data deletion”. Include your GitHub login if you used GitHub OAuth. We may ask for verification before deleting or anonymizing account data.

Account deletion normally removes or anonymizes account records, sessions, verification/reset tokens, owned scan history, and GitHub installation links where deletion is technically and legally possible.

Action telemetry

The GitHub Action heartbeat uses a hashed repository identifier and coarse run metadata, so it may not be directly searchable by repository name. To request deletion, send the repository URL, approximate run dates, and proof that you control the repository.

To stop future telemetry, set telemetry: false in your SkillTrust Action workflow.

Analytics withdrawal and erasure

Use Analytics settings on the Privacy Policy page to reject optional analytics or withdraw consent. Withdrawal immediately stops future persistent analytics and replay and removes PostHog storage from that browser; it does not erase events or recordings already retained.

If you accepted analytics, Analytics settings shows this browser's opaque PostHog distinct id. Include that id in an erasure request to legal@skilltrust.app so we can delete the associated PostHog person, events, and recordings. The id is never joined to your SkillTrust account. Rejected cookieless events have no stable browser id and rotate daily, so they cannot be isolated across days for an individual lookup.

Public corpus or gallery removal

SkillTrust scans public skill repositories to maintain public security signals. If you own a public repository and want a public corpus/gallery entry removed or refreshed, email us with the repository URL and proof of control.

We may keep aggregate, non-identifying statistics and security/audit records even after removing a public page.

Timing and exceptions

We aim to acknowledge deletion requests within 7 days and complete verified requests within 30 days, unless the request is complex or we must retain data for security, fraud prevention, legal, accounting, backup, or operational reasons.

Backups and logs may take longer to expire through normal rotation, but deleted data is not restored to active systems except when needed for security, legal, or disaster-recovery reasons.

Contact

For privacy, terms, deletion, or security-process questions, email legal@skilltrust.app.