Privacy
New ScanPrivacy — Bluethroat Labs
BlueSkills is operated by Bluethroat Labs.
What we collect
- The skill you submit (pasted
SKILL.md, uploaded.zip, or the public GitHub/GitLab archive we fetch). - For the Telegram bot: your Telegram user id, chat id, and the message we need to reply to.
- Documents you send to BluePaper (PDF, Word, or image). Those bytes are uploaded to the BluePaper conversion service and are not stored by BlueSkills.
- Scan reports (findings, scores, stage logs). Runtime logs from a sandbox, when deep analysis runs.
What we do not want
Do not upload secrets, API keys, private keys, .env files with real credentials, or private repository or private package contents. Public GitHub and GitLab URLs only; private repositories are not fetched, and a zip of a private package is not an accepted substitute. Do not send documents to BluePaper that you are not allowed to share with the conversion service.
Subprocessors
- Telegram (bot delivery)
- OpenRouter (optional embedding, judge, and executor models)
- Azure (hosted storage, queues, and ACA sandboxes)
- Cloudflare Turnstile (website scan button, when the operator has enabled it)
- BluePaper conversion API (Azure Container Apps; same operator). BlueMask runs on your device and does not upload the image to BlueSkills.
Retention
- Work artefacts (
input.zipand sandboxruntime/logs): 7 days, then deleted by the store lifecycle policy. - Scan results (
result.json): 30 days, then deleted by the store lifecycle policy. - Azure Container Apps runtime logs (Log Analytics): 30 days.
Deletion is automatic at those deadlines. On the Telegram bot, send /delete (also /delete_data or /privacy_delete) to remove identifiers, session, quota tokens, and bot job records for your Telegram user id after a confirmation step. That also unlinks your Telegram user id from in-retention scan records. Scan result blobs themselves are keyed by the skill bytes, not by Telegram user, so they are not purged by /delete; they expire on the schedule above. Include the scan_id via Report an Issue if you need a specific result removed sooner. The website /delete page describes the same path. Telegram messages follow Telegram's own retention.
Contact
Use /support on the bot, or the Support page on the website.