Privacy Policy

Last updated: July 5, 2026

What we access from GitHub

When you sign in with GitHub, we request read access to your profile, email address, public repositories, and organization membership. We read repository, commit, and pull request metadata (titles, messages, changed file names, and line counts) only for the items you select. We do not write to your repositories. If you choose "Include private repos", GitHub grants the broader repo scope so we can list your private repositories — we still only read the items you select, and you can revoke this any time from your GitHub settings.

What we send to AI providers

To generate posts, we send the commit/PR metadata you selected (messages, titles, pull request descriptions, file names, change stats) to OpenAI, along with the context you supply yourself: your product description and voice profile, and any note you add about what a particular piece of work was for. We do not send your source code diffs or GitHub access token.

What we store

We store your GitHub profile basics (name, email, avatar), an encrypted-at-rest GitHub access token to make API calls on your behalf, your generated posts and the context they were generated from, monthly usage counts, and — if you subscribe — your Stripe customer and subscription identifiers. Payment card details are handled entirely by Stripe and never touch our servers.

How to delete your data

Go to Settings → Delete account. This permanently removes your user record, GitHub tokens, generated posts, and usage history from our database. You can also revoke ShipPost's access from your GitHub settings at any time.

Contact

For privacy questions, email warren@walters954.com.

See also our Terms of Service or return home.