Privacy
Privacy Policy
How information is used when you browse The Skill Leaderboard, appear in a public repository listing, or contact the operator.
Effective 6 October 2026
Who operates the site
The Skill Leaderboard is operated by Milos Milovanovic, an individual based in Belgrade, Serbia. For privacy questions or requests, email milos@skillleaderboard.com.
Information involved
When you browse
The site does not require a visitor account. Hosting and analytics infrastructure may process technical information associated with a request, such as an IP address, device and browser information, requested pages, referring pages, and approximate location.
A theme preference is stored in your browser's local storage. Leaderboard view state and scroll position may be kept in session storage. Search terms used in the main leaderboard search are handled in the browser; individual-skill search requests are sent to the site's own search endpoint. That endpoint matches against the catalog without saving a search record to the database or sending the query to an AI model. Hosting infrastructure still processes the request. You can clear browser storage through your browser settings.
Public GitHub information
The service uses information from public GitHub repositories and profiles, including repository and owner names, links, avatars, descriptions, licenses, stars, activity, skill files, and other public repository signals. The site may add human- or AI-assisted editorial summaries and classifications before publishing them.
Pipeline code also retains historical public GitHub stargazer usernames and star timestamps. Current traction calculations use aggregate repository star observations; the historical records are distinct from website visitor data.
When you contact the operator
If you email the operator, the message, address, and any information you choose to include are used to respond, review a correction or removal request, or discuss advertising. There is currently no on-site contact form, newsletter signup, payment flow, or file upload.
How information is used
- Provide, secure, maintain, and understand use of the site.
- Build and refresh rankings, classifications, and public skill pages.
- Investigate errors, abuse, and correction or removal requests.
- Reply to messages and handle advertising inquiries.
Service providers and external sites
The application uses Vercel for hosting and Supabase for catalog storage and server-side read models. The configured Supabase project's primary region is Ireland (eu-west-1). This identifies the primary database location, not every provider processing location. GitHub supplies public repository information and hosts pipeline workflows and review artifacts. Vercel Analytics is included in the application. The site does not use Google Analytics. The operator reports that the former Google Analytics property and its historical reports have been deleted. Following a link to GitHub or another external site takes you to a service with its own privacy practices.
Scheduled summary and classification jobs are configured to run models locally through LM Studio on a self-hosted computer. Usage-guide generation and verification follow a separate path: public repository documentation excerpts are supplied to OpenAI through Codex. These are catalog-processing jobs, not a visitor chat service. The reviewed website code does not send visitor searches or contact messages to those jobs.
Public mail-routing records point to registrar-servers.com forwarding infrastructure. Email correspondence also passes through the destination mailbox provider, which cannot be identified from those public records.
Retention
The theme preference remains in local storage until you clear it. Leaderboard state in session storage lasts for the browser page session, subject to your browser's restore behavior. You can clear both through browser settings. Catalog snapshots may include historical repository signals; refreshing a listing does not imply deletion of earlier records.
Several pipeline review artifacts are configured to expire on GitHub after 30 days; other artifacts inherit repository settings. This does not set a deletion period for database records, workflow logs, or copies on the self-hosted computer. No general time-based deletion schedule for catalog and historical GitHub records was found in the reviewed code.
Retention for hosting and analytics data, database backups, OpenAI processing, local pipeline files, and email depends on the purpose for which the information is held, provider settings, operational needs, and applicable legal requirements. Vercel documents a 24-hour lifetime for its Web Analytics visitor-session identifier, not a 24-hour deletion period for all analytics data. No broader automatic deletion schedule is promised here.
Your choices and rights
Depending on the circumstances and applicable law, you may have rights to request access, correction, erasure, restriction, or portability; object to certain processing; and withdraw consent where processing relies on consent. These rights may be subject to legal conditions and exceptions. You can also ask for a public listing to be corrected or reviewed for removal by emailing the operator with the repository URL and relevant details.
Requests will be handled within the period required by applicable law. Only information necessary to understand the request and, where needed, verify identity should be provided.
You may also lodge a complaint with Serbia's Commissioner for Information of Public Importance and Personal Data Protection. See the Commissioner's guidance on exercising data-protection rights.
Changes to this policy
If this policy changes, the date at the top will be updated. Material changes will be explained clearly on this page.