Explain where information goes before asking for it

Tell readers which services handle their information, what the skill needs to do its job, what the author can see, and where to find the current policies and controls. Keep each statement tied to the actual product and account configuration. “Your data is private” is too broad to answer those questions.

For an author skill, distinguish the AI app the reader uses, the platform delivering the method, any additional connected services, and the author. A rule governing one participant does not automatically describe the others.

This resource provides a data-flow worksheet and writing template. It does not establish the complete data flow of a particular Skillfully deployment, and no traffic inspection or privacy audit was performed for it.

Begin with the reader’s real concern

Readers may be willing to describe a challenge while hesitating to upload an entire client document. They need to know what the method actually requires and what happens to the information they provide.

An author asking about ChatGPT expressed a recognizable concern:

“I'm writing a book with fairly novel IP, and am concerned about the material being blurted out at some point to other users of ChatGPT.”

That is u/the_embassy_official’s concern, not evidence that a disclosure occurred or a finding about current provider behavior. It illustrates why a broad reassurance is insufficient. Original author discussion.

Answer with documented facts and boundaries. If the platform has not confirmed a detail, name the unresolved question and obtain an answer before asking readers to rely on a promise about it.

Map each participant separately

Use this original worksheet before writing the public explanation. “Verify” means obtain current documentation or appropriate product evidence; it does not mean ask the assistant to guess.

ParticipantInformation to identifyQuestions to resolve
Reader’s AI providerPrompts, attachments, generated responses, account informationWhich plan and settings apply? What are the current storage and training policies?
Skill delivery platformAccount, purchase, access, usage, and any submitted feedback informationWhich fields are collected, why, and who can access them?
Connected servicesInformation sent in requests and returned by toolsWhich services receive it, and which policies govern them?
AuthorInformation actually available through reports, feedback, or supportAre records aggregate or individual? What content is visible?
Support channelMessages and attachments the reader sends for helpWho receives them, how are they handled, and what should be omitted?

The worksheet is deliberately separate from a completed disclosure. It would be misleading to fill the author row with “nothing” or “all conversations” without evidence.

For Skillfully specifically, its published privacy policy lists agent skill usage among automatically collected information and describes sharing usage information with skill authors for improvement. That policy wording does not, by itself, establish exactly which conversation content or fields appear in an author’s current view. Skillfully’s privacy policy.

Do not turn a dashboard label such as “session” into a claim about full transcripts. Equally, do not promise that no usage information reaches the author when the policy says usage sharing can occur. Resolve the exact visibility question with the platform.

Keep storage, training, and visibility distinct

These are different questions: whether information is retained, whether it may be used to improve models, and whether a particular person or service can see it. One answer cannot stand in for all three.

Anthropic’s Google Workspace connector guidance illustrates why detail matters. It distinguishes connector-retrieved information from content copied into consumer chats, with different qualifications around model improvement. Use the provider’s current account-specific guidance rather than shortening it to a universal no-training promise. Claude’s Google Workspace data-handling guidance.

Location claims also need a defined scope. Anthropic’s US-only inference documentation says that setting governs model processing, not third-party service infrastructure or storage location. A statement about one processing step should not become “all your data stays in this country.” Claude’s inference-location explanation.

You do not need to repeat every provider policy on your offer page. Explain the relevant distinctions, link the authoritative policy, and state which account or configuration the explanation concerns.

Ask only for information the task needs

Imagine a fictional author, Harriet, whose skill helps readers prepare a clear internal project update. The method needs the intended audience, current status, decisions required, and unresolved dependencies. It does not inherently need employee home addresses or a complete customer database.

Harriet’s input instructions can ask for a short, non-sensitive description of those four elements. A practice example can use invented project details. If a real document is necessary for a particular use, the reader should first confirm that the services and organization rules permit that use.

This is an illustrative design choice, not a claim that summarizing information guarantees anonymity or makes every upload appropriate. Removing names alone may leave identifying details. The useful starting question is whether the method needs the original material at all.

Designing the skill to request relevant inputs also makes it easier to write a truthful explanation. How to write an agent skill can help define that task and its limits.

Draft the explanation in five parts

Use these prompts as a template, replacing brackets only with verified facts:

  1. What you provide: “To use this method, provide [necessary input]. Do not include [unnecessary or unsupported information].”
  2. Which services handle it: “Your interaction uses [AI provider], [delivery platform], and [other services, if applicable]. Their current policies are linked here.”
  3. What the author receives: “The author can access [verified information] for [purpose].”
  4. Your controls: “Use [verified routes] to manage the relevant information or request help. Disconnecting, deleting a conversation, and canceling payment are separate actions.”
  5. Questions: “Contact [actual support route] before submitting information if this explanation does not resolve your concern.”

Have the responsible platform or privacy owner review the completed wording. Keep a record of the configuration and evidence behind it so you can revisit the explanation when the product changes.

To discuss a skill based on your established method, visit Skillfully and choose Book onboarding. Bring the inputs your method needs and the data questions your readers are likely to ask. Specific answers are more useful than promises you cannot verify.