This policy describes what data Shipproof collects, how we use and store it, and what rights you have — including the rights GDPR grants to users in the European Union.
Shipproof is an automated security audit service. [PLACEHOLDER: the operating legal entity and address will be listed here once incorporated.]
When you connect a repository or upload an archive, the code is cloned or extracted into an isolated, one-time (ephemeral) container: with no network access at all for a ZIP archive, or with access limited to github.com when cloning a repository.
The code is analyzed statically — as text and file structure. We never execute your code.
Secrets (API keys, passwords, and similar) found in the code are masked before anything leaves the isolated container. Neither the masked nor, obviously, the real secret values are ever sent to external LLM services or shown unmasked in the report.
Once a scan finishes, the source code, the repository clone, and any uploaded archive are deleted immediately. We do not retain your source code after a scan completes — in any form, for any length of time. If you upload an archive and never run a scan, it's automatically deleted after a technical timeout (currently 24 hours).
The database and the report only ever store the finding metadata listed in section 2 — never the code itself.
Account and project data is processed to provide you the service (performance of a contract). Technical and log data is processed for security and abuse prevention (legitimate interest).
Where we use an LLM to explain findings, we rely on a legitimate interest in providing clear, actionable guidance; only the finding's own text fields (category, severity, title, description) are sent to the model — never evidence, secrets, or your source code.
We do not sell your data to third parties.
Account data and finding metadata are kept for as long as your account exists.
Source code is never retained at all — see section 3.
Technical logs containing IP addresses are kept for a limited period for security purposes. [PLACEHOLDER: confirm the exact log retention period.]
Honestly, about where we are today: self-serve account deletion through the interface isn't built yet — it's in progress. To request deletion of your data right now, email us at the contact address below and we'll handle it manually.
If you're located in the EU/EEA, your data may be processed outside the EEA by the sub-processors listed in section 5. [PLACEHOLDER: confirm and name the specific safeguards in place for each sub-processor — e.g. Standard Contractual Clauses.]
The service is not directed at anyone under 16. We do not knowingly collect data from children.
We'll notify you ahead of any material change to this policy — by email or an in-app notice.
Questions about data processing: [PLACEHOLDER: contact email / data protection contact].