Back to home
Legal & Transparency

Privacy Policy

LAST UPDATED: JULY 31, 2026

1. Overview & Scope

ShipReady is an automated security scanning and launch-readiness platform tailored for AI-generated and “vibe-coded” web applications. We analyze target deployments for exposed secrets, missing security headers, authentication risks, Supabase/database leaks, and production readiness blockers before software launches.

This Privacy Policy explains how ShipReady (“we,” “our,” or “us”) collects, uses, stores, and protects information when you interact with our website, dashboard, APIs, reports, or Model Context Protocol (MCP) server integrations.

2. Information We Collect

To provide passive, evidence-backed security scans and launch readiness scores, we collect limited categories of information:

  • Account & Contact Information: Email address, user identifiers, and profile credentials created during signup or login.
  • Scan Target Data: Live application URLs, public repository parameters, header metadata, and configuration parameters submitted for security analysis.
  • Integration Credentials: Access tokens, webhook endpoints, or API keys configured to connect ShipReady with GitHub, Vercel, Supabase, or your local MCP server environment.
  • Payment & Billing Data: Billing contact info and transaction metadata. Credit card details are processed directly by our external payment processor; we do not store full payment card numbers on our servers.
  • Technical & Telemetry Data: IP addresses, user-agent strings, request logs, scan execution durations, and error diagnostics collected when accessing our web dashboard or API endpoints.

3. How We Use Your Data

We process data solely to deliver, improve, and secure our automated scan services:

  • Performing passive HTTP inspection and rule-based security evaluations on authorized target URLs.
  • Generating Launch Readiness scores, risk classifications, and downloadable audit reports.
  • Synthesizing actionable, context-aware AI fix prompts for your code editor (such as Cursor).
  • Monitoring system health, preventing abusive scan activity, and maintaining service performance.
  • Sending critical account notices, security alerts, or updates regarding our private beta.

4. Data Sharing & Subprocessors

We respect your privacy and never sell, rent, or monetize your personal details or scan evidence. We share data only with verified third-party subprocessors necessary for operation:

  • Hosting & Cloud Providers: Secure infrastructure platforms (e.g. Vercel, Supabase) used to store database records and host platform binaries.
  • Payment Processors: Merchant services processing subscription fees and invoicing.
  • Legal & Safety Compliance: When required by applicable law, subpoena, or to protect the safety, security, and integrity of our platform and users.

5. Data Retention & Security Practices

Security is core to our mission. We safeguard your data through robust technical measures:

Evidence Redaction

Detected API keys, secret tokens, and sensitive headers are automatically masked or redacted prior to recording findings into report evidence logs.

Encryption Standards

All network traffic is enforced via TLS 1.3 encryption. Credentials and integration tokens are encrypted at rest using AES-256 standards.

We retain scan reports for as long as your account remains active. You may request manual purge or deletion of individual scan records at any time.

6. User Rights & Data Control

You retain full control over your data. Depending on your jurisdiction, you have the right to:

  • Access, review, or export your account profile and historical scan reports.
  • Request correction of inaccurate account information.
  • Request complete deletion of your user account, integration tokens, and scan history.

To exercise any of these rights, contact us at our support email below.

7. Cookies & Local Storage

ShipReady uses strictly necessary cookies and local storage tokens required for authentication, maintaining session state across dashboard requests, and protecting against cross-site request forgery. We do not use intrusive third-party tracking pixels or ad-targeting cookies.

8. Children’s Privacy

ShipReady is designed exclusively for software developers, founders, and technical teams. Our service is not intended for individuals under 18 years of age, and we do not knowingly collect personal data from children.

9. Changes to This Policy

We may periodically update this Privacy Policy to reflect new security checks, feature additions, or regulatory updates. Any changes will be posted on this page with an updated “Last Updated” date. Material changes will be communicated through our website or direct email notice.

10. Contact Us

If you have questions, feedback, or data privacy requests regarding ShipReady, please contact our team at:

useshipready@gmail.com