Privacy
Google sign-in is handled by Supabase Auth. We store the account identifier and email required for authentication, workspace membership, and short-lived encrypted login handoffs.
Workspace skills
Skill files added by an owner are stored in private object storage with their exact release identity and redacted review findings. They are available only through the authenticated workspace flow.
What SuperSkill never receives
Task text, prompts, summaries, matching reasons, conversation history, repository paths, project files, source content, datasets, and generated outputs stay in your agent session. Before approval, SuperSkill returns workspace catalog metadata only. After approval, it returns only the chosen temporary instruction resources.
Account connection
Your agent stores the OAuth credential through its native connection flow. SuperSkill does not store host refresh tokens in workspace tables.