Skillberg is an AI-infrastructure company operating a knowledge graph for skills intelligence. This policy describes the data we collect, store, share, and retain when you use the Skillberg API at api.skillberg.app, the developer console at console.skillberg.app, and the MCP connector at mcp.skillberg.app — including when that connector is used as the Skillberg app inside ChatGPT (OpenAI Apps SDK) or inside Claude. It applies to all Skillberg-hosted services. For the equivalent French version (politique de confidentialité), email support@skillberg.app.
When you sign in (via Auth0 OAuth or via the MCP authorization flow), we receive and store: your email address, your display name, and your Auth0 subject identifier (a stable opaque ID). We do not receive or store your authentication password.
For every authenticated request to the Skillberg API we record: timestamp, route, HTTP status, response time, the API key used, and (where applicable) the auth0_sub of the authenticated user. We do not retain the bodies of requests or responses by default.
When you authorize the Skillberg connector inside ChatGPT, Claude, or any other MCP-compatible client, we additionally store: the authorization grant, the bearer access tokens we issue (signed JWTs), and a per-connection API key (labelled with the client and date, e.g. Claude MCP — YYYY-MM-DD) that lets us attribute and bill usage of the connector against your account. The contents of your conversation with the AI assistant are not received by Skillberg — only the tool arguments the model decides to forward (e.g. the search query passed to search_skills, or the résumé object passed to enrich_cv). See CV and job-offer content below for how that forwarded content is handled.
Several tools process the content you submit to them: the skill enrichment, CV evaluation, and CV-to-job matching tools (enrich_cv, evaluate_cv, enrich_job, match_cv_to_jobs) accept a résumé or a job offer and return a structured analysis mapped onto our knowledge graph. A résumé may contain personal data — including the personal data of a third party (for example a candidate a recruiter is screening), such as name, contact details, work history, and education.
We process this content to perform the analysis you requested and for that purpose only. By default it is processed transiently: the payload is sent to our knowledge-graph service, the result is returned to you, and the submitted content is not persisted after the request completes. We do not use submitted CVs or job offers to train models. If you choose to upload a CV to your Skillberg account (so that match_cv_to_jobscan reference it later), that uploaded file is stored under your account and is subject to the retention rules in section 4.
Data minimisation — what not to send. Only submit the information needed for the analysis. Do not submit, and we do not knowingly collect, special-category data (health, racial or ethnic origin, religion, sexual orientation), government identifiers, payment-card numbers, or authentication credentials. If you submit personal data about someone else, you are responsible for having a lawful basis to do so.
If you subscribe to a paid plan, payment processing is handled by Mollie. We receive only confirmation events from Mollie (subscription started, payment captured, etc.) — we never see or store full card numbers.
All Skillberg services run on Scaleway infrastructure in fr-par (Paris), with European Union data residency. The application database (MongoDB) and the knowledge graph (Neo4j) are both hosted in the same region. The frontend console (console.skillberg.app) is delivered via Vercel's edge network and may be cached close to your geographical location.
We share the minimum data necessary with the following processors, all of whom are bound by data-processing agreements:
console.skillberg.app.We do not sell personal data. We do not share account data with advertisers.
Under the GDPR, you have the right to access, correct, export, or delete your personal data. To exercise any of these rights, email support@skillberg.app from the address tied to your account. We will reply within 30 days. You can also revoke MCP-connector access at any time from /mcp/connections in the developer console — no email required.
All traffic to and from Skillberg services is over HTTPS with TLS 1.2 or higher. API keys and OAuth secrets are stored hashed-at-rest where we can, and behind Scaleway Secret Manager otherwise. Database backups are encrypted. We do not currently hold an external security certification, but we follow OWASP Top 10 mitigations and run dependency-vulnerability scans on every CI build.
Skillberg services are not directed at children under 16. We do not knowingly collect personal data from minors.
Material changes will be announced 14 days before they take effect by email to all account-holders and via a dated banner on this page. The current version is identified by the “Last updated” date at the top.
MV PROG SAS (operating as Skillberg) · SIREN 985 040 401 · 75 Bd Vauban, 59000 Lille, France · support@skillberg.app
Data Protection contact: support@skillberg.app — please put “Privacy” in the subject line so we can route it correctly.