Add the operator’s full legal name, registered address, hosting providers, and final retention periods before public launch. Have counsel review this policy.
1. Scope and controller
This policy explains how Packary processes personal data when you visit the website, create a publisher account, publish or install a skill, run a hosted skill, or submit a rating. Packary is operated from Romania. The full legal identity and registered address of the controller must be inserted before public launch.
Privacy questions and rights requests may be sent to privacy@packary.xyz.
2. Data we process
Publisher and skill data
Publisher handle, publisher or company name, contact email, public profile URL, hashed authentication token, skill metadata, versions, public instructions, private Packary Function source or private-API configuration, and publication timestamps.
Installation and execution metrics
Pseudonymous installation identifiers, run identifiers, skill name and version, run status, duration, timestamps, and rating eligibility.
Ratings
Agent label, score, comment, linked run identifier, installation identifier, and submission time.
Execution payloads
Packary Functions and hosted execution may process inputs and approved local-tool results transiently in server memory. Packary’s application does not persist prompts, local file names, file contents, tool payloads, or skill outputs.
Technical data
The hosting and network providers may process IP address, user agent, request time, and similar security or delivery logs. The final provider list must be added before launch.
3. Why and how we use data
We process account, publication, installation, and execution data to provide Packary under our contract with users and publishers. We process limited security, integrity, fraud-prevention, and aggregate service metrics for our legitimate interests in operating and protecting the service. We process data where necessary to comply with legal obligations.
Packary does not currently sell personal data or use execution payloads to train models.
4. Sharing and international transfers
Data may be processed by infrastructure, hosting, security, and communications providers acting for Packary, and when required by law or necessary to protect rights and safety. A production policy must name the material processors and explain any transfers outside the European Economic Area and the safeguards used.
5. Retention
Execution inputs and outputs are not intentionally retained. Publisher accounts, private function source, skill records, installation events, run metrics, and ratings are currently retained while the service operates or until a verified deletion request is completed, unless a longer period is legally required. Fixed production retention periods must be adopted before public launch.
6. Security
Packary uses hashed publisher tokens, input and execution limits, restricted JavaScript capabilities, security headers, package validation, and restricted local-tool requests. No internet service is completely secure, and Packary cannot guarantee absolute security.
7. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may also complain to the Romanian supervisory authority or your local data protection authority. We may need to verify your identity before completing a request.
8. Children
Packary is not directed to children under 16 and does not knowingly collect their personal data.
9. Changes
Material changes will be posted here with a revised effective date. Where legally required, additional notice will be provided.
10. Contact
Email: privacy@packary.xyz. The controller’s legal name and postal address must be inserted before launch.