SkillTrust
legal

Data Deletion

How to remove scan results, disconnect GitHub, opt out of telemetry, or request account/data deletion.

Effective date: May 27, 2026

Delete individual scans

If you are signed in, use your dashboard or scan history to delete scans you own where the product exposes a delete action. Deleting a scan removes its stored findings and disables its public share link.

If you cannot delete a scan in-product, email us from the account email with the scan URL or scan id.

Turn off public sharing

For scans you own, turn off sharing or delete the scan to make the public share URL inaccessible. Public repository badges and landing pages use public scan/corpus data only and may update separately from individual share links.

Uninstall the GitHub App

Uninstall SkillTrust from GitHub to stop future repository access, webhooks, PR comments, and check runs. GitHub installation tokens expire quickly and are not stored by SkillTrust.

After uninstall, SkillTrust marks the installation deleted. Some installation, repository, PR/check/comment, webhook, and audit metadata may remain for security, abuse prevention, debugging, or legal reasons unless you request deletion.

Delete your account

Email the contact below from your SkillTrust account email with subject “SkillTrust data deletion”. Include your GitHub login if you used GitHub OAuth. We may ask for verification before deleting or anonymizing account data.

Account deletion normally removes or anonymizes account records, sessions, verification/reset tokens, owned scan history, and GitHub installation links where deletion is technically and legally possible.

Action telemetry

The GitHub Action heartbeat uses a hashed repository identifier and coarse run metadata, so it may not be directly searchable by repository name. To request deletion, send the repository URL, approximate run dates, and proof that you control the repository.

To stop future telemetry, set telemetry: false in your SkillTrust Action workflow.

Public corpus or gallery removal

SkillTrust scans public skill repositories to maintain public security signals. If you own a public repository and want a public corpus/gallery entry removed or refreshed, email us with the repository URL and proof of control.

We may keep aggregate, non-identifying statistics and security/audit records even after removing a public page.

Timing and exceptions

We aim to acknowledge deletion requests within 7 days and complete verified requests within 30 days, unless the request is complex or we must retain data for security, fraud prevention, legal, accounting, backup, or operational reasons.

Backups and logs may take longer to expire through normal rotation, but deleted data is not restored to active systems except when needed for security, legal, or disaster-recovery reasons.

Contact

For privacy, terms, deletion, or security-process questions, email legal@skilltrust.app.