Privacy Policy
Last updated: 2026-09-02
1. Who we are (data controller)
Ship & Shout (“Ship & Shout,” “we,” “us”) is the data controller for the personal data described in this policy. For any privacy question or to exercise your rights, contact our privacy team at privacy@shipandshout.co. General support is available at hello@shipandshout.co.
2. Data we collect
We collect only what we need to run the service:
Account data
- Your name, email address, and authentication identifiers. You sign in with GitHub OAuth or email and password through Supabase Auth.
- Your plan, delivery schedule, timezone, and theme preference.
Connected source data (read-only)
- Code hosts (GitHub, GitLab, Bitbucket): commit metadata and merged pull requests — counts, titles, timestamps, and authors. We never read your file contents or source code.
- Payment processors (Stripe, Lemon Squeezy): revenue totals and new / churned customer counts. We never move money and never see full card numbers.
- Analytics (Plausible, Vercel Analytics, Fathom):aggregate visitor counts. These are privacy-friendly analytics with no cross-site or advertising tracking.
Content we generate
- The metric summaries behind each week, the drafts produced from them, and the revenue charts rendered as images.
Technical data
- Essential session cookies, and standard server logs (IP address, timestamps) kept briefly for security and abuse prevention. See our Cookie Policy for details.
Access tokens for the sources you connect are encrypted at rest with AES-256-GCM, decrypted only server-side at the moment of use, never written to logs, and never sent to your browser.
3. Purposes & legal bases
Under the GDPR we rely on the following legal bases for each purpose:
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and operate your account | Account data | Contract (Art. 6(1)(b)) |
| Read connected sources to draft your weekly post | Connected source data | Contract (Art. 6(1)(b)) |
| Generate drafts and charts via LLM providers | Metric summaries | Contract (Art. 6(1)(b)) |
| Billing and subscription management | Account data, plan | Contract (Art. 6(1)(b)) |
| Security, fraud and abuse prevention | Technical data, logs | Legitimate interest (Art. 6(1)(f)) |
| Product and service emails | Account data | Legitimate interest / Contract |
| Publishing to LinkedIn or the public timeline | Draft content | Consent (Art. 6(1)(a)) |
Where we rely on consent — such as publishing on your behalf — you can withdraw it at any time without affecting processing that already took place.
4. Subprocessors
We use a small set of vetted providers to run the service. Each processes data only on our instructions and under a data processing agreement.
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, and file (chart) storage | EU / US |
| Vercel | Application hosting and the weekly cron job | US / global edge |
| Lemon Squeezy | Billing and subscriptions (merchant of record) | US |
| Resend | Transactional email delivery | US |
| LLM providers (OpenRouter, Groq, Cerebras) | Draft generation from metric summaries | US |
| OAuth & source providers (GitHub, GitLab, Bitbucket, Stripe, Plausible) | The read-only sources you choose to connect | US / EU |
We send LLM providers only the summarized metrics needed to write a draft — not your raw tokens, source code, or full customer records.
5. Retention
- Account, drafts, charts, and tokens: kept while your account is active. When you delete your account, they are erased immediately (see the GDPR & Your Data page).
- Public timeline entries: taken offline within one hour of deletion.
- Backups: purged within 30 days of deletion.
- Billing records: retained by our merchant of record as required by tax and accounting law.
- Security logs: retained briefly, then rotated.
6. Security
Third-party tokens are encrypted at rest (AES-256-GCM) and decrypted only server-side when used. All data is encrypted in transit over TLS. Every database table enforces Row-Level Security so each user can only reach their own rows. We use read-only OAuth scopes wherever a provider offers them and never request write access to your code. More detail is on our Security page.
7. International transfers
Some subprocessors are located in the United States. Where personal data of individuals in the EEA, UK, or Switzerland is transferred outside those regions, we rely on the European Commission's Standard Contractual Clauses (SCCs) and equivalent safeguards, together with supplementary measures such as encryption in transit and at rest.
8. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, and object to the processing of your personal data, to data portability, and to withdraw consent. You can exercise most of these yourself in Settings → Account, or by emailing privacy@shipandshout.co. We respond within one month. You also have the right to lodge a complaint with your local data protection supervisory authority. Our GDPR & Your Data page walks through how to exercise each right.
9. Children
Ship & Shout is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@shipandshout.co and we will delete it.
10. Automated decision-making
Drafts are generated by large language models from your metric summaries. This processing produces suggestions only — it has no legal or similarly significant effect on you. Every draft is reviewed by a human (you) before anything is published. We do not use your data for automated decisions that produce legal effects, and we do not use it to train third-party models.
11. Changes to this policy
We may update this policy as the product evolves. We will change the “last updated” date above and, for material changes, notify you by email or in the app.
12. Contact
Privacy questions and rights requests: privacy@shipandshout.co. General support: hello@shipandshout.co.