Saucekit privacy notice — internal invite-only version
This page truthfully describes the current internal product. It does not open unknown-creator approval or claim legal compliance.
1. Status, operator, and contact
This working notice describes the invite-only Saucekit product as implemented today. It has not been approved by qualified legal counsel and does not claim compliance with a particular privacy regime. Unknown-creator approval remains disabled until qualified review accepts this notice and the creator agreement.
Saucekit is operated by Luke Toledo. Privacy, access, correction, export, deletion, and consent questions can be submitted at the request path below or emailed to support@saucekit.so.
2. Creator and account data
Creator requests collect an email address, display name, optional skill context, timestamps, and rate-control evidence derived from the request source. Creator accounts store email, display name, creator URL, a password hash, account state, agreement and notice evidence, and audit history.
Skill intake stores the submitted public repository URL or uploaded files, normalized skill content, private rules, examples, manifest data, validation results, versions, and lifecycle state. Saucekit does not ask creators to include secrets, customer data, or third-party confidential material.
3. Buyer, email, and consent data
Buyer access collects an email address and stores email-link records, canonical buyer identity, grant and install-token hashes, session records, captured-email evidence, skill and creator scope, and timestamps. Creators can see verified product-access email evidence for their own skills.
Product-access email is required to issue and recover the grant. It is not creator marketing consent. Optional creator marketing consent is a separate, seller-scoped event the signed-in buyer can grant or withdraw in the buyer library. Saucekit access-interest email is stored for follow-up; optional Saucekit marketing is a separate unchecked choice.
4. Runtime, analytics, support, security, and payment data
Runtime records identify the buyer reference, grant, skill and version, provider and model, token counts, cost when known, funding party, outcome, safe error code, and time. Saucekit does not intentionally persist the buyer's provider key, request text, or generated answer in D1 usage records.
Security and operations records include audit events, hashed or keyed request-source evidence, redacted email-delivery events, lifecycle state, and bounded error information. A privacy request stores the requester's email, request type, optional details, source hash, status, notice version, and timestamps. Support email is processed through the email providers used by the operator.
Live payment is disabled for this invite-only release. The codebase can store Polar customer, checkout, subscription, and webhook identifiers if payment is later enabled; this notice does not represent that live checkout currently collects payment data.
5. Purposes
Saucekit uses the records above to review creator requests; create and secure accounts; validate, host, publish, install, and run skills; verify buyer access; show truthful creator analytics; send transactional email; prevent abuse; investigate errors; answer support and privacy requests; preserve lifecycle and agreement evidence; and recover or suspend the service.
Saucekit uses an email for Saucekit marketing only after the separate optional choice is granted. A creator receives a buyer email for creator marketing export only after the buyer separately grants that creator's consent.
6. Current service providers and disclosures
Cloudflare provides Workers execution, D1 storage, static assets, request delivery, and transactional Email Service. GitHub serves public repository content when a creator chooses public-repository intake. Anthropic or OpenRouter receives the hosted private rules and the buyer request only when live inference through that provider is enabled. Klaviyo receives the email only when optional Saucekit marketing consent is selected.
Creators receive verified buyer emails and seller-scoped activity for their own skills. Saucekit does not sell personal data. Polar is not an active payment collector in this release. Provider roles, terms, and infrastructure may differ; qualified review must confirm the final processor and subprocessor disclosures before unknown admission.
7. Storage locations, retention, and safeguards
Cloudflare and the other providers determine the infrastructure locations used by their services. Saucekit has not configured or promised a single storage country. Creators and buyers should not rely on this internal notice as a cross-border-transfer assessment.
Core account, grant, skill, consent, agreement, audit, usage, and request records currently have no automatic deletion schedule. They are retained while the related account or access is active and while needed for support, safety, recovery, audit, or legal review. One-time links expire, but redacted lifecycle evidence may remain. A deletion request triggers review rather than immediate destructive deletion; required audit evidence and backups may remain until safely removable.
Current safeguards include hashed one-time secrets, scoped grants, bounded uploads, seller isolation, separate buyer and creator identity, non-destructive pause and suspension, redacted delivery events, and request-local provider credentials. Saucekit does not claim a certification, guaranteed availability, or perfect security.
8. Access, correction, export, deletion, and consent choices
Use the privacy request form for access, correction, export, deletion, or Saucekit marketing withdrawal. Saucekit records the request as pending verification and must verify control of the relevant account or email before disclosing, changing, exporting, or deleting data.
A signed-in buyer can grant or withdraw optional creator marketing consent in the buyer library. Account email correction uses the verified email-change flow. Creator skill deletion stays non-destructive until admin review considers active buyer access, recovery, audit, and any legal obligations.
9. Versions and changes
Collection surfaces link the current notice and store its version and content digest with key notice or consent events. Material text changes require a new notice version. The internal legal-review gate stays closed until a qualified reviewer accepts the operative version.
Submit a privacy or consent request · Email support@saucekit.so