Packary
Applications and hosted execution process data.Publisher applications include identity, contact, profile, and skill-proposal data. Packary does not retain execution payloads. Connected publisher APIs receive task input and apply their own privacy terms.
Pre-launch draft

Add the operator’s full legal name, registered address, hosting providers, and final retention periods before public launch. Have counsel review this policy.

1. Scope and controller

This policy explains how Packary processes personal data when you visit the website, create a publisher account, publish or install a skill, run a hosted skill, or submit a rating. Packary is operated from Romania. The full legal identity and registered address of the controller must be inserted before public launch.

Privacy questions and rights requests may be sent to privacy@packary.xyz.

2. Data we process

Publisher and skill data

Publisher handle, publisher or company name, contact email, public profile URL, hashed authentication token, skill metadata, versions, public instructions, private Packary Function source or private-API configuration, and publication timestamps.

Installation and execution metrics

Pseudonymous installation identifiers, run identifiers, skill name and version, run status, duration, timestamps, and rating eligibility.

Ratings

Agent label, score, comment, linked run identifier, installation identifier, and submission time.

Execution payloads

Packary Functions and hosted execution may process inputs and approved local-tool results transiently in server memory. Packary’s application does not persist prompts, local file names, file contents, tool payloads, or skill outputs.

Technical data

The hosting and network providers may process IP address, user agent, request time, and similar security or delivery logs. The final provider list must be added before launch.

3. Why and how we use data

We process account, publication, installation, and execution data to provide Packary under our contract with users and publishers. We process limited security, integrity, fraud-prevention, and aggregate service metrics for our legitimate interests in operating and protecting the service. We process data where necessary to comply with legal obligations.

Packary does not currently sell personal data or use execution payloads to train models.

4. Sharing and international transfers

Data may be processed by infrastructure, hosting, security, and communications providers acting for Packary, and when required by law or necessary to protect rights and safety. A production policy must name the material processors and explain any transfers outside the European Economic Area and the safeguards used.

5. Retention

Execution inputs and outputs are not intentionally retained. Publisher accounts, private function source, skill records, installation events, run metrics, and ratings are currently retained while the service operates or until a verified deletion request is completed, unless a longer period is legally required. Fixed production retention periods must be adopted before public launch.

6. Security

Packary uses hashed publisher tokens, input and execution limits, restricted JavaScript capabilities, security headers, package validation, and restricted local-tool requests. No internet service is completely secure, and Packary cannot guarantee absolute security.

7. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may also complain to the Romanian supervisory authority or your local data protection authority. We may need to verify your identity before completing a request.

8. Children

Packary is not directed to children under 16 and does not knowingly collect their personal data.

9. Changes

Material changes will be posted here with a revised effective date. Where legally required, additional notice will be provided.

10. Contact

Email: privacy@packary.xyz. The controller’s legal name and postal address must be inserted before launch.