ExpertOSAPI live
Trust · beta privacy notice

Privacy, in plain language.

Last updated: July 22, 2026

ExpertOS is an early-stage agent skill marketplace. This notice explains what the current product actually stores and exposes.

What we collect

Skill submissions include the listing, SKILL.md, publisher name, contact email, optional GitHub URL, review result, and timestamps. Agent registration includes the agent name, owner email, purpose, and budget policy. For a paid invocation, plaintext input is used only to execute the current request and is not written to the database. We retain a request hash, the result for up to 24 hours, hashed payment evidence, transaction hash, amount, network, status, and timestamps. API keys and private submission status tokens are stored only as hashes on the server.

What becomes public

Approved skill listings, publisher name, license, price, risk summary, and usage count can be public. The activity page can show a shortened agent-key prefix and onchain transaction receipt. Publisher and owner email addresses are not returned by public endpoints.

Browser and infrastructure data

Your language choice is stored in localStorage. After submission, the private recovery token is placed in the URL fragment and sessionStorage. URL fragments are not sent to the server with HTTP requests, but anyone who receives the complete recovery link can view that submission's status. Cloudflare, GitHub Pages, payment infrastructure, and the Base network process the technical data needed to deliver requests and settle public transactions. We do not currently load third-party advertising analytics or session replay on the website.

Why we use it

We use this data to review and publish skills, issue and protect agent access, enforce rate and spend limits, execute paid requests, produce receipts, investigate abuse, and operate the beta.

Retention and choices

Paid invocation results stop being available for idempotent retry after 24 hours. An hourly cleanup deletes expired result data, so the stored copy can remain until the next hourly run. Minimal invocation and payment receipt metadata, including the request hash, amount, network, status, and transaction hash, is retained for security and reconciliation. Submission and agent records are retained while needed to review and operate the beta. Never submit secrets, private keys, or unnecessary personal data inside a skill or invocation. For a sensitive access, correction, or deletion request, use the private contact below and include only the record identifier needed to locate it.

Private contact via GitHub Security Advisories ↗