Account identity
When you sign in, AIPM uses your GitHub identity to connect publishing actions to your account.
Privacy
AIPM supports public registry packages and private org packages. This page explains what data is used for accounts, publisher profiles, package metadata, tokens, and project files.
When you sign in, AIPM uses your GitHub identity to connect publishing actions to your account.
Your display name and profile image help users see who owns an org or package.
Org names, package names, metadata, versions, visibility settings, and package files are stored by the registry.
Publish tokens are used by the CLI, expire quickly, and should not be saved in project files.
CLI login stores a local session on your machine so private package reads do not require pasting a token into every command.
The registry may process request metadata to run the service, fix abuse, and keep it available.
The website can save your theme choice in your browser. This is not needed for publishing.
Public package names, descriptions, targets, versions, manifests, and included skill files are public registry content. Check them before you publish.
AIPM does not need private source code, secrets, customer records, internal documents, or unrelated project files. A good package includes only the manifest, main skill file, examples, and tool files the skill needs.
AIPM should add account deletion, package owner transfer, stronger audit logs, verified publisher labels, package access exports, and a privacy contact channel.