1. Overview & Scope
ShipReady is a production readiness platform for applications built with AI coding tools. We analyze deployments and connected repositories for exposed secrets, missing security headers, authentication and database misconfigurations, SEO and AI-visibility gaps, performance problems, and other launch blockers.
This Privacy Policy explains how ShipReady (“we,” “our,” or “us”) collects, uses, stores, shares, and protects information when you use our website, dashboard, APIs, reports, IDE integration, or Model Context Protocol (MCP) server. It applies to all visitors and account holders, and forms part of our Terms of Service.
Where we decide why and how personal data is processed, we act as a controller. Where we process data on your behalf as part of running scans you request — for example content retrieved from a repository you connect — we act as a processor, on the terms of our Data Processing Addendum.
2. Information We Collect
We collect only what is needed to run evidence-backed scans and operate your account:
- Account & contact information: email address, user identifier, authentication metadata, and any profile details you provide at signup.
- Scan target data: the URLs, domains, endpoints, and repository references you submit, together with the HTTP responses, headers, and configuration metadata returned by those targets.
- Integration credentials: access tokens, installation identifiers, webhook endpoints, and API keys you configure to connect ShipReady to GitHub, Supabase, your hosting provider, or your local MCP environment. These are encrypted at rest.
- Billing data: billing email, country, and transaction metadata. Payments are processed by our payment provider acting as merchant of record; full card numbers never reach our servers.
- Technical & telemetry data: IP address, user-agent, request logs, scan execution timings, rate-limit counters, and error diagnostics generated when you use the dashboard or API.
- Product analytics: aggregate page and event data describing how the product is used, so we can find broken flows and improve them.
We do not ask for, and you should not submit, special-category personal data, payment card data, or production credentials beyond the minimum an integration requires.
3. How We Use Your Data
We process data only for the purposes below:
| Purpose | Data used | Legal basis |
|---|---|---|
| Running scans and producing findings, scores, and reports | Scan target data, integration credentials, account identifier | Performance of a contract |
| Generating AI explanations and fix prompts for findings | Finding text and evidence (redacted) | Performance of a contract |
| Account creation, authentication, and support | Account and contact information | Performance of a contract |
| Billing, invoicing, and fraud prevention | Billing data, account identifier | Contract / legal obligation |
| Rate limiting, abuse prevention, and platform security | IP address, request metadata, usage counters | Legitimate interests |
| Diagnosing errors and improving reliability | Error diagnostics, request metadata | Legitimate interests |
| Understanding product usage in aggregate | Analytics events, page paths | Legitimate interests / consent where required |
| Service, security, and billing notices | Account and contact information | Performance of a contract |
We do not use your scan data, source code, or findings to train machine-learning models, and we do not sell, rent, or monetize personal data or scan evidence.
4. Data Sharing & Subprocessors
We share data only with the service providers needed to operate ShipReady, each engaged under contractual data-protection obligations and given the minimum data necessary for its function. The current list — hosting, database and authentication, payments, email, error monitoring, analytics, AI analysis, and repository access — is published on our Subprocessors page and kept current.
Outside those providers, we disclose personal data only:
- where you direct us to, such as when you connect an integration or share a report;
- where required by law, legal process, or a lawful government request, and only to the extent required;
- where necessary to investigate abuse, enforce our Terms, or protect the rights, safety, and integrity of ShipReady, our users, or the public;
- in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy continuing to apply to the transferred data.
5. International Transfers
ShipReady and its providers operate globally, so your data may be processed in countries other than your own, including the United States. Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on an appropriate safeguard — typically the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, or the provider’s certification under an approved framework. The mechanism applied to each provider is listed on our Subprocessors page.
6. Security Practices
Security is the product, so it is also the operating standard:
Evidence redaction
Detected API keys, tokens, and sensitive header values are masked before findings are written to report evidence, so a report never becomes a second copy of the secret it found.
Encryption
All traffic is served over TLS. Integration tokens and credentials are encrypted at rest with AES-256.
Access control
Per-user row-level isolation in the database, least-privilege service credentials, and scoped integration tokens that can be revoked without affecting your account.
Monitoring
Error and anomaly monitoring on the API and scanner, plus rate limiting on scan submission to contain abuse.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and any relevant supervisory authority without undue delay and, where required, within the timeframes set by applicable law.
7. Data Retention
| Data | Retention |
|---|---|
| Account profile | For the life of the account, then deleted on request or on account deletion |
| Scan reports and findings | Stored for the life of the account and never redacted. What your plan lets you READ is separate from what we keep: the Free plan shows your current report only — detail on critical and high-severity findings, a count for medium and low — and does not include scan history, comparison or PDF export. Upgrading restores access to everything already stored, including past scans |
| Integration tokens | Until you disconnect the integration or delete the account |
| Request and error logs | Typically up to 90 days, then rotated |
| Billing records | As long as required by tax and accounting law |
| Aggregated, de-identified usage data | Retained indefinitely; does not identify you |
You can delete individual scan records at any time from the dashboard, or request full deletion of your account and its data. Backups are rotated on a rolling schedule, so deleted data may persist in backups for a short period before being overwritten.
8. Your Rights
Depending on where you live, you may have some or all of the following rights over your personal data:
- access a copy of the data we hold about you;
- correct inaccurate or incomplete data;
- delete your account, integration tokens, and scan history;
- export your data in a portable format;
- restrict or object to certain processing, including processing based on legitimate interests;
- withdraw consent where processing is based on consent, without affecting prior processing;
- opt out of “sale” or “sharing” of personal data — we do neither, so there is nothing to opt out of;
- lodge a complaint with your local data protection authority.
To exercise any of these, contact us at the address below. We will respond within the period required by applicable law, normally within thirty (30) days, and we will not discriminate against you for exercising a right.
9. Cookies & Local Storage
We use strictly necessary cookies and browser storage for authentication, session state, and CSRF protection, plus limited product analytics. We do not use advertising cookies, retargeting pixels, or cross-site behavioral tracking. Full detail, including cookie names and durations, is in our Cookie Policy.
10. Children’s Privacy
ShipReady is built for developers, founders, and technical teams. It is not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
11. Regional Disclosures
11.1 EEA, UK & Switzerland
We process personal data on the legal bases set out in Section 3. You have the rights in Section 8 and may complain to your national supervisory authority. Where processing is based on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms, and you may object at any time.
11.2 California
We do not sell personal information and do not share it for cross-context behavioral advertising. California residents have rights to know, delete, correct, and limit use of sensitive personal information, and the right not to be discriminated against for exercising them. Requests can be made to the contact address below.
11.3 Other jurisdictions
Where local law grants you additional rights over your personal data, we honor them. Contact us and tell us which jurisdiction you are writing from.
12. Changes to This Policy
We may update this Policy to reflect new features, providers, or legal requirements. The current version is always at /privacywith a “Last updated” date. For material changes we will give notice by email or a prominent notice in the Service before they take effect.
13. Contact Us
For questions, data-protection requests, or complaints regarding this Policy, contact us at:
hello@useshipready.dev