Effective September 1, 2026

Privacy policy

This policy separates the public skills-only plugin available today from planned hosted services that are not yet enabled.

Public plugin

Lukecho Media Studio contains workflow instructions and no Lukecho account connection, analytics, telemetry, remote MCP server, or background service. The repository does not collect personal data. If a user chooses a third-party media tool in their host, that separate tool's privacy terms apply.

Planned hosted services

The remaining sections describe data that a future GitHub or hosted service may process only after production access is explicitly launched.

Data we process

GitHub may send account ID, login, account type, installation ID, plan details, repository ID, repository name, issue number, requester ID, requester login, command text, and event timestamps.

Data we avoid

The channel hub is designed not to persist raw webhook bodies, GitHub OAuth tokens, xAI credentials, private signing keys, or source media. Protected credentials stay in their designated service boundary.

Why we process data

Retention

Production retention periods will be minimized and documented before launch. Account data associated with a completed cancellation request will be deleted within 30 days unless law requires a longer period.

Sharing

Data is shared only with infrastructure providers needed to operate the service and with platforms the user intentionally connects. We do not sell personal information.

Security

Controls include signed webhook verification, bounded payloads, short-lived entitlements, separate service tokens, redacted errors, and publisher-reviewed release gates.

Your choices

You may request access, correction, or deletion through the process on the data deletion page.

Contact

Use the support page for privacy questions. Do not place credentials or private identifiers in a public issue.