Better Agent Skills

Privacy policy

This policy covers Better Agent Skills: this website, the BAS app for macOS, the bas command line tool and the API they use. It says what we collect, why, and who sees it.

Your account

When you sign in we receive your name, email address and organization memberships from WorkOS, which runs sign-in for us. We use them to show who published a skill and to decide which skills you can see and install.

Skills you publish

When you publish a skill we store its files, its versions and the visibility you chose. A public skill can be seen and installed by anyone; an organization or team skill only by its members; a private skill only by you. We also record which versions are installed, so owners can see how many people use each one.

Issue reports

Agents and people file issue reports about a skill with bas report. A report holds only its category, severity, summary, details and suggested fix, the skill, its version and who filed it. Secrets such as API keys, tokens, private keys and passwords in URLs are removed on your Mac before the report is saved. No conversation, transcript, file contents or repository name is attached. By default the app shows you each report before it is sent.

Only the skill's owner sees its reports. For a skill added from GitHub, its repository's verified maintainers see them, and only while you leave sharing with maintainers on.

Usage counts

Agents log each use of a skill on your Mac. The app sends only the number of uses per skill version and day, never what the skill was used for. You can turn usage sharing off in the app's settings.

GitHub

If you connect GitHub on the website, we ask GitHub whether your account can write to a repository, to confirm you maintain its skills. GitHub tokens we hold are stored sealed (encrypted) and used only to call GitHub. A personal access token you add in the app stays in your Mac's keychain and is sent only to GitHub.

What we do not collect

There are no analytics, advertising or tracking scripts, and no cookies beyond the ones sign-in needs. We do not sell your data. Besides the processors below, reports and usage counts reach only the people named above: a skill's owner and, for a skill from GitHub, its verified maintainers.

Processors

  • WorkOS: accounts, sign-in and organization membership.
  • Cloudflare: the API and the storage for skills, reports and usage counts.
  • Vercel: hosting for this website.
  • GitHub: app downloads and, when you connect it, the repository access check.

Deleting your data

You can delete skills you published at any time. When you delete your account, your account data is removed; reports you filed stay with the skill's owner with your name removed.

Changes

When this policy changes we update this page and the date below.

Last updated September 26, 2026