What we store, and why
- Account — name, e-mail and avatar from Google or GitHub when you sign in; your handle; the skills, upvotes, favourites, follows, threads and notifications you create. Legal basis: the service you asked for (contract).
- Brain files — private Markdown you add; encrypted at rest; readable only by you and, over MCP, by your own token.
- Newsletter — the e-mail you subscribe with, after you confirm it (double opt-in). Every mail has an unsubscribe link. Legal basis: consent.
- Install counts — when a skill is fetched (raw URL, CLI, MCP) we count it. No IP addresses or identifiers are stored with the count.
- Server logs — standard web-server logs (IP, URL, time) kept up to 14 days for security and debugging. Legal basis: legitimate interest.
Cookies
| cookie | purpose | lifetime | needs consent |
|---|---|---|---|
emdly_session | keeps you signed in and protects forms | 2 hours of inactivity | no — strictly necessary |
XSRF-TOKEN | protects forms against cross-site requests | 2 hours | no — strictly necessary |
remember_web_* | “stay signed in” after OAuth login | 5 years | no — functional, set only when you sign in |
emdly_consent | remembers your cookie choice | 12 months | no — strictly necessary |
_ga, _ga_* | Google Analytics 4 — which pages and skills are used, in aggregate | up to 2 years | yes — set only after you click Accept |
Analytics runs in Google’s Consent Mode with everything denied by default: until you accept, no Google script loads and no analytics cookie is set. If you decline, we also send no server-side analytics events for your visits. You can change your choice at any time with Cookie settings in the footer.
Who processes data
- Hosting in the EU on our own server.
- Google (Analytics 4) — only after consent; IP anonymisation is on by default in GA4.
- Google and GitHub as sign-in providers — they tell us your name, e-mail and avatar; nothing goes back.
- Mailgun (EU region) for transactional mail and the newsletter.
- The safety-scan model provider receives the skill text you submit for review — never your account data.
Your rights
Access, correction, export and deletion of your data, and withdrawal of consent: write to hello{{ config('emdly.domain') }}. Deleting your account removes your Brain, favourites and notifications; published skills stay in the catalog under your handle unless you ask us to unpublish them, because others may depend on them. You can complain to your national data-protection authority.
Contact
emdly · hello{{ config('emdly.domain') }}. Last updated August 2026.