← ShipSafeScan

Privacy Policy

Effective date: 2026-08-25
Last updated: 2026-08-25

1. Who we are

ShipSafeScan (“we”, “us”) provides a free tool that scans a public GitHub repository and returns a security and quality score, an issue report, and a shareable scorecard. This policy explains what personal data we handle and how. The data controller is Kyungbeom Kim (individual operator, Republic of Korea). You can reach us at privacy@shipsafescan.com.

Privacy Officer: Kyungbeom Kim, reachable at the same address above.

2. What we collect

  • Waitlist email: only if you choose to join our waitlist, we collect the email address you enter.
  • Repository you submit: the public repository URL you choose to scan, and the public repository owner and name derived from it.
  • Basic technical data: standard server logs and request data (such as IP address and timestamps) used to operate the service, prevent abuse, and apply rate limits.

We do not require an account to run a scan, and we do not collect more than we need.

3. Your code and public repositories

When you scan a public repository, we read it in order to analyze it. We store only the resulting score and issue metadata (such as rule identifiers, file paths, and line numbers), not your source code. Any detected secrets are masked before they are shown or stored. This version of the service scans public repositories only and does not access private repositories.

4. How we use your data

  • To run scans and show you the results.
  • To send you the updates you asked for, if you joined the waitlist.
  • To operate, secure, and improve the service, including preventing abuse.

5. Third parties and international transfer

We use service providers to run ShipSafeScan, which may process data outside of the Republic of Korea:

  • Vercel Inc. (United States) hosts and serves the site. Data transferred: request data including IP address, transferred over the network each time you use the site, and retained for the duration of the service.
  • Supabase Inc. (United States) stores scan metadata and waitlist emails. Data transferred: your waitlist email and consent record, and scan metadata, transferred over the network when you submit them, and retained as described in section 7.
  • Anthropic PBC (United States) generates the optional written explanation of results. Data transferred: masked findings only, never your email, sent over the network at the time of a scan. The API is configured so that inputs are not used to train models, and the findings are not retained by us beyond the scan record.

You may refuse this international transfer, but because these providers run the core of the service, refusing means we cannot provide the scan or the waitlist. You can refuse by not using the service and by not submitting your email.

We share personal data with these providers only as needed to run the service, and we do not sell your personal data.

6. Marketing communications

We ask for separate, optional consent before sending marketing or product-update emails. You can withdraw that consent and unsubscribe at any time, and doing so does not affect the rest of the service.

7. Retention

We keep your waitlist email until you unsubscribe or the purpose you gave it for is complete, and in any case no longer than 24 months from the date you gave it, after which it is deleted. Scan metadata is retained for up to 12 months to serve cached results and history. We do not store your repository source code. You can ask us to delete your data at any time.

8. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data, and you may withdraw consent you have given. To exercise these rights, contact us at privacy@shipsafescan.com.

9. Security

We apply reasonable technical and organizational safeguards, keep the data we collect to a minimum, and mask detected secrets. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. Children

ShipSafeScan is intended for developers and is not directed at children under 14. We do not knowingly collect personal data from children under 14.

11. Changes to this policy

We may update this policy as the service evolves. We will change the “Last updated” date above and, where appropriate, provide additional notice.

12. Contact

Questions about this policy or your data? Contact Kyungbeom Kim (individual operator, Republic of Korea) at privacy@shipsafescan.com.