Trust & safety
Safety is the product.
A hundred good trades earn trust slowly; one unsafe one spends it at once. These are the rules the app is built around.

How SkillPort is kept safe
Every request an app screen makes names the side it is asking for — educator, learner or guardian — and the server answers only in that scope. Consent to the Terms is recorded with its version and date, never inferred from use. Under-18 learners are in scope through parent or guardian consent, and no date of birth is collected. Sign-in is by passkey or an emailed code, so there is no password to leak. Every marketplace listing is screened for hateful, sexual, harassing, illegal or scam content before it is stored. Money is one trail — invoice, payment, slip, verification — visible to both sides. Personal data is handled under Malaysia's PDPA with a registered data user and a named Data Protection Officer.
Six rules
Built in, not bolted on
- 01
Role-scoped on every request
The scope rides on the call, not on the login. A person who teaches and also learns sees both — each under its own lens, never mixed, never leaking one family's record into another's.
- 02
Consent you can point to
Every account-creating path — an email code or a provider sign-in — records the Terms version accepted and the moment it was accepted. Absent consent is recorded as absent; we never fabricate an affirmation.
- 03
Children, handled honestly
Educator and guardian accounts are adult. A learner account is 18+ or guardian-consented. We do not collect a date of birth: a self-declared one proves nothing and would be more children's data to protect.
- 04
No passwords
Passkeys use your face, fingerprint or device PIN and are bound to skillport.my. The email code needs only a mailbox and is guarded by a guess ceiling. Nothing to reuse across sites.
- 05
One money trail
Only an invoice, credit note, payment or reversal can post to the ledger; nobody types a balance. Duplicate slips and reused reference numbers are checked and shown as flags, not verdicts.
- 06
PDPA, with a name on it
Apply IT Sdn. Bhd. is registered as a data user with Malaysia's Department of Personal Data Protection, has appointed a Data Protection Officer, and notifies breaches within the statutory window.
A parent's rights
You can always reach us about your child
A parent or legal guardian can ask us to give access to, correct or erase their child's personal data, and can withdraw consent for a child's account — whether the child holds an account or an educator created the record. You do not need the educator's permission. Write to our Data Protection Officer from the email address linked to the child's record.
Write to the DPO · dpo@skillport.myQuestions people ask
Can an educator see my other children, or my own classes?
No. An educator sees only the students enrolled with them. A guardian's view is limited to their own linked children, and a person's learner or educator records never appear under the guardian lens.
Where is my data stored?
On secured servers, encrypted in transit. Access is by authenticated session only, and every read is scoped to the role that asked. Details are in the Privacy Policy.
How do I delete my account?
In the app, from Settings, with an identity check. A parent or guardian can request deletion of a child's data by email, and we act on it whether or not the educator agrees.
Is anyone checking what an educator puts in a listing?
Yes, before it is public. Every listing — its title, its description and each translation of it — is screened for hateful, sexual, harassing, illegal or scam content before it is stored, and refused if it carries any. If the check cannot run at all, the listing is refused rather than published unread.
Offer a skill. Or find one.
SkillPort is in early access. Tell us whether you teach, you're learning, or you're paying for someone who is — and we'll get you in.
