Draft for professional legal review
Privacy
This page explains how ShipRecap uses GitHub data. It is not certified legal advice and should be reviewed by counsel before you rely on it commercially.
What GitHub data we access
When you connect GitHub, ShipRecap requests read:user, user:email, and repo access. That lets us read your profile, email if GitHub provides it, and activity on repositories you can access — including private ones you choose to report on.
Why we access it
We use selected GitHub activity (commit messages, pull request titles, release names, and similar metadata) so you can generate a client-facing report. We do not use GitHub access to publish source code or to monitor employees.
What we store
We store your GitHub user id, username, avatar, email if available, projects you create, reports you generate, and an encrypted GitHub access token so we can fetch activity later. Tokens are encrypted at rest and are never sent to the browser.
What is sent to AI
Report generation sends a bounded list of selected activity titles (and similar short metadata) to a language model. Source code is never sent. We do not send commit hashes, private repository URLs, or file contents to the model.
What is published
Nothing is public until you explicitly publish a report. Published pages include the title, summary, shipped items, optional next steps, dates, and (unless you turn it off) activity counts. Commit hashes, tokens, private repository URLs, and source files are not included.
Disconnect and deletion
You can disconnect GitHub in Settings. That removes the stored token and does not delete your ShipRecap reports or projects. You can delete your account in Settings, which removes your ShipRecap data. If a subscription is active, we cancel it before deleting the account.
Cookies
ShipRecap uses a small number of strictly necessary cookies. We do not use advertising cookies or sell data to ad networks. You can use the site without accepting optional analytics — we do not gate the product behind a cookie banner because we do not set non-essential tracking cookies in your browser.
- shiprecap_session — keeps you signed in after GitHub login. HttpOnly, 30 days, essential.
- shiprecap_oauth_state — short-lived state value during GitHub sign-in to prevent CSRF. HttpOnly, about 10 minutes, essential.
- sr_r_[publicId] — remembers that you unlocked a password-protected report on /r/…. HttpOnly, scoped to that report path, 30 days, essential when you use password-protected links.
Product analytics (for example page views on the marketing site) are sent to our own servers as first-party requests. They do not include source code or commit contents. If we enable optional third-party analytics that store cookies in your browser, we will ask for consent before loading them.
Checkout and billing are handled by Stripe on stripe.com, which may set its own cookies when you pay or manage a subscription.
Contact: privacy@shiprecap.app