ShipSafe

Privacy Policy

Last updated: 2026-08-23

Draft in place. Operator legal name and contact email must be filled in, and this policy reviewed, before the service publicly collects data.

1. Who we are

ShipSafe (“we”, “us”) provides a free tool that scans a public GitHub repository and returns a security and quality score, an issue report, and a shareable scorecard. This policy explains what personal data we handle and how. The data controller is [OPERATOR]. You can reach us at [CONTACT EMAIL].

2. What we collect

  • Waitlist email: only if you choose to join our waitlist, we collect the email address you enter.
  • Repository you submit: the public repository URL you choose to scan, and the public repository owner and name derived from it.
  • Basic technical data: standard server logs and request data (such as IP address and timestamps) used to operate the service, prevent abuse, and apply rate limits.

We do not require an account to run a scan, and we do not collect more than we need.

3. Your code and public repositories

When you scan a public repository, we read it in order to analyze it. We store only the resulting score and issue metadata (such as rule identifiers, file paths, and line numbers), not your source code. Any detected secrets are masked before they are shown or stored. This version of the service scans public repositories only and does not access private repositories.

4. How we use your data

  • To run scans and show you the results.
  • To send you the updates you asked for, if you joined the waitlist.
  • To operate, secure, and improve the service, including preventing abuse.

5. Third parties and international transfer

We use service providers to run ShipSafe, which may process data outside of the Republic of Korea:

  • Hosting and infrastructure (for example, a cloud hosting provider) to serve the site and store scan metadata.
  • AI analysis provider: where an optional written explanation of results is generated, masked findings may be sent to a third-party AI API configured so that inputs are not used to train models. This may involve transfer to servers located outside Korea.

We share personal data with these providers only as needed to run the service, and we do not sell your personal data.

6. Marketing communications

We ask for separate, optional consent before sending marketing or product-update emails. You can withdraw that consent and unsubscribe at any time, and doing so does not affect the rest of the service.

7. Retention

We keep your waitlist email until you unsubscribe or the purpose you gave it for is complete, after which it is deleted. Scan metadata may be retained to serve cached results and history. You can ask us to delete your data at any time.

8. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data, and you may withdraw consent you have given. To exercise these rights, contact us at [CONTACT EMAIL].

9. Security

We apply reasonable technical and organizational safeguards, keep the data we collect to a minimum, and mask detected secrets. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. Children

ShipSafe is intended for developers and is not directed at children under 14. We do not knowingly collect personal data from children under 14.

11. Changes to this policy

We may update this policy as the service evolves. We will change the “Last updated” date above and, where appropriate, provide additional notice.

12. Contact

Questions about this policy or your data? Contact [OPERATOR] at [CONTACT EMAIL].