Privacy
We hold almost nothing.
This is the short version and it is also the whole version. Version 2026-08-03.
The part that matters
We never store data from inside an application we check. Not a row, not a field, not a file, not a response body — not in a log, not in a cache, not in our database.
Where a check needs to know whether a table is readable, we ask the database for a count instead of rows, so the response body is empty by construction. Where we find a credential, we record its type and last four characters and destroy the rest before it reaches storage. If ShipSafe were breached tomorrow, there would be nothing of your users’ in it.
What we collect
- Your email address
- To sign you in and to send alerts. That is all.
- Hostnames you ask us to monitor
- To know what to check.
- Findings metadata
- The check that fired, the severity, and pre-redacted evidence — for example, a table name or a header that was missing.
- Scan timestamps and a hash of your bundle
- To tell you when something changed.
- Your IP address
- Rate limiting and the audit record. Not used for analytics or advertising.
- The audit record
- For every scan: the time, the exact URLs requested with methods and status codes, and the authorisation it relied on. Kept 24 months.
What we never collect
- Data belonging to your users, your customers, or anyone else.
- Full credential values. We keep the type and last four characters, nothing more.
- Response bodies from any request we make, in any form.
- Your source code. Where we detect a published source map, we record that fact and the file paths, never the code.
- Behavioural analytics, session recordings, cross-site trackers, or advertising identifiers.
We set no non-essential cookies. The only cookie we use is the one that keeps you signed in, which is why there is no consent banner on this site.
Who we share it with
Four processors, named, and nobody else. We do not sell or rent anything to anyone.
- Vercel
- Hosting and serverless functions.
- Neon
- Postgres database.
- Resend
- Transactional email.
- Lemon Squeezy
- Payments, as merchant of record. They hold your billing details; we do not.
We do not process payment card details at any point. We never see them.
Your rights
You can access, correct, export, or delete everything we hold about you. Deletion is a button in your account settings rather than a request form, because a right you have to ask for is a worse right.
Deleting your account removes your email address, your apps, and your scan history immediately. Audit records are retained for their 24-month period with the account link removed, because their purpose is to account for requests we made to third-party sites.
If you are in the EU or UK, our lawful basis is performance of a contract for the service itself, and legitimate interests for security, rate limiting, and the audit record. If you are in India, the same applies under the Digital Personal Data Protection Act 2023.
Retention
- Account and apps
- Until you delete them.
- Findings and scan history
- Life of the account, or your plan’s history window.
- Free-tier scan reports
- 24 hours, then deleted.
- Audit records
- 24 months.
- Response bodies
- Never stored at any point.
Aggregate statistics
We publish aggregate percentages about what our checks find — for example, what share of apps ship a live credential. These never include a hostname, a URL, an owner, or anything that could identify an application, and we do not publish them at all below a sample of 100 distinct apps.
We do not publish, share, or name individual findings. Not in marketing, not in a blog post, not in a “hall of shame”.
Alerts and scan digests are service messages tied to apps you asked us to monitor, and each one has a one-click unsubscribe. Marketing email is a separate opt-in and a separate list. We never merge the two.
Contact and grievances
privacy@shipsafe.world reaches the person responsible for data protection at ShipSafe, who is also its founder. Expect a reply within 72 hours.
If you have found requests from our scanner in your logs, the scanner policy explains exactly what they were, and the opt-out on that page takes effect immediately.