Privacy Policy
Last updated: July 15, 2026
Introduction
This Privacy Policy explains how ShipFoundry collects, uses, shares, and protects information when you use our website, application, emails, integrations, and related services.
ShipFoundry is operated by ShipFoundry ("ShipFoundry," "we," "us," or "our").
ShipFoundry processes public software updates, matches relevant changes against project context and required read-only GitHub evidence, and creates evidence-backed briefs for research, engineering, workflow, strategy, or bounded agent implementation. Optional MCP and Linear paths strengthen or deliver that workflow without granting automatic implementation authority.
If you have questions about this Privacy Policy or want to exercise privacy rights, contact us at hello@shipfoundry.ai.
Mailing address: ShipFoundry, 13359 N Hwy 183 #406-1201, Austin, TX 78750, United States
1. Scope
This Privacy Policy applies to:
- shipfoundry.ai
- the ShipFoundry web application
- account, onboarding, dashboard, billing, support, newsletter, and product communications
- integrations you choose to connect, such as GitHub, Linear, and MCP clients
- service providers that support billing, email, analytics, observability, AI processing, hosting, authentication, storage, and infrastructure
- any other service that links to this Privacy Policy
This Privacy Policy does not apply to third-party websites, products, or services that we do not control. Those services have their own terms and privacy policies.
2. Information We Collect
We collect information in the following categories.
Account information
When you create an account or use ShipFoundry, we may collect:
- name
- email address
- password/authentication information, handled through our authentication provider
- workspace or account name
- role, team, or account membership information
- login, session, and security information
- communication preferences
Product and project information
ShipFoundry works by understanding the product surface you ask it to watch. Depending on what you enter, upload, connect, or configure, we may collect:
- project names and descriptions
- product goals, constraints, and notes
- stack, framework, package, platform, and tool selections
- tracked stack items and ignored items
- source/watch preferences
- package manifest data, dependency names, versions, and related configuration metadata
- project settings, decision states, feedback, and saved actions
- handoff briefs, copied/exported brief events, and generated implementation context
Repository and integration information
Each project requires read-only access to a repository you select. When you connect that repository, upload project metadata, or enable repo-aware investigation, we may process information needed to provide those features, such as:
- connected account or installation metadata
- repository names and identifiers
- branches, file names, dependency metadata, route/configuration signals, and selected code/context snippets
- repo evidence, candidate findings, confidence notes, and related handoff context
- webhook events or integration status events
- Linear workspace, team, project, label, issue, and mapping metadata if you connect Linear
- explicit Linear export attempts, created issue links and IDs, and duplicate-prevention metadata
- MCP authorization, approved scopes, project access, tool calls, and recorded outcomes
We use this information to generate product-relevant matches, repo-backed evidence, agent-ready handoffs, and integration actions you request.
Billing information
If you purchase a paid plan or start a card-required trial, billing is handled by Stripe or another payment provider we use. We may receive and store billing-related information such as:
- plan name
- subscription status
- trial status
- customer ID
- invoice, checkout, and payment status metadata
- billing email
- last four digits, card brand, and expiration metadata if provided by the payment processor
We do not intentionally store full card numbers on our own servers.
Communications and support information
If you contact us, subscribe to updates, respond to emails, or participate in feedback, we may collect:
- email address
- message content
- support requests
- survey or feedback responses
- newsletter subscription status
- marketing preferences
Usage, analytics, and device information
When you use ShipFoundry, we may collect information about how the service is used, such as:
- pages viewed
- features used
- button clicks and product events
- signup, onboarding, pricing, checkout, project creation, brief generation, copy/export, and integration events
- IP address
- browser type
- device type
- operating system
- referring pages
- approximate location inferred from IP address
- cookie and consent preferences
- logs, diagnostics, and performance data
We use analytics and observability to understand product usage, improve onboarding, debug errors, detect abuse, and monitor launch-critical flows. Non-essential measurement and marketing technologies are controlled through the consent choices described below.
AI and generated-content information
ShipFoundry uses AI systems to summarize public updates, match updates to your project context, generate handoff briefs, and assist with repo-aware investigation where enabled.
Depending on your use of the service, information sent to AI providers may include:
- public source update content
- product/project context you provide
- stack and tracked entity information
- selected repo metadata or snippets where enabled
- generated match explanations, handoff drafts, and evidence summaries
- prompt and model metadata, token/cost estimates, latency, and quality/debug logs
We do not intentionally make your private project context or private repository information public. We use this information to provide, improve, secure, and debug ShipFoundry.
Public source information
ShipFoundry also processes public information from software sources, changelogs, release notes, vendor pages, documentation, blogs, feeds, and similar public sources. This information may include public author names, public URLs, and public release metadata.
3. How We Use Information
We use information to:
- provide and operate ShipFoundry
- create and manage accounts
- authenticate users and protect sessions
- onboard projects and track product surfaces
- ingest, normalize, summarize, and rank public software updates
- match stack changes to project context
- generate agent-ready handoffs, repo evidence, acceptance checks, and implementation context
- support copied briefs, MCP task packets and outcomes, and optional explicit Linear issue creation
- enforce plan limits and usage entitlements
- process trials, checkout, subscriptions, invoices, and billing events
- provide customer support
- send product, billing, security, lifecycle, and administrative messages
- send newsletters or marketing messages where permitted
- measure product performance, usage, and launch funnels
- monitor security, prevent abuse, debug incidents, and protect the service
- improve prompts, workflows, ranking quality, source coverage, and product experience
- comply with legal obligations and enforce our Terms of Service
4. Legal Bases for Processing
Where laws such as the GDPR require a legal basis, we process personal information under one or more of the following bases:
- Contract: to provide ShipFoundry, manage your account, process billing, and deliver requested features.
- Legitimate interests: to improve, secure, debug, measure, and operate the service; prevent abuse; understand product usage; and develop better source matching and handoff quality.
- Consent: for certain analytics, marketing communications, cookies, or optional integrations where consent is required.
- Legal obligations: to comply with accounting, tax, legal, regulatory, and security obligations.
You may withdraw consent where processing is based on consent, but that will not affect processing that occurred before withdrawal.
5. How We Share Information
We share information only as needed to operate, secure, improve, and provide ShipFoundry.
Service providers
We may share information with vendors that provide services on our behalf, such as:
- hosting and deployment
- database, authentication, and storage
- payment processing
- email delivery and workspace email
- newsletter and lifecycle messaging
- analytics and product measurement
- error monitoring, logs, tracing, and observability
- AI model and inference providers
- customer support, operations, and security tooling
These providers may process information only as needed to provide their services to us, subject to their agreements and privacy commitments.
Integrations you choose
If you connect third-party integrations, we may share information with those services to complete the actions you request. For example:
- GitHub may receive requests related to connected repositories or installation state.
- Linear may receive issue titles, descriptions, labels, project/team mappings, and handoff content when you explicitly create an issue.
- Authorized MCP clients may retrieve approved project context, updates, briefs, and task packets, and may submit outcomes within the scopes you grant.
- Stripe may receive billing and checkout information.
Your use of third-party integrations is also governed by those third parties' terms and privacy policies.
Legal, safety, and business transfers
We may disclose information if we believe it is reasonably necessary to:
- comply with law, legal process, or government requests
- enforce our Terms of Service
- protect ShipFoundry, our users, or others from harm, fraud, abuse, or security threats
- investigate suspected violations
- complete a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets
If a business transfer occurs, we will take reasonable steps to ensure your information remains protected.
6. Cookies, Analytics, and Tracking
We use cookies and similar technologies to:
- keep you logged in
- secure sessions
- remember preferences
- understand product usage
- measure marketing and launch flows
- debug performance and errors
- improve ShipFoundry
Where legally required, we ask for consent before using non-essential analytics or marketing cookies. You can control cookies through your browser settings and, where available, through our consent controls.
If you disable cookies, some parts of ShipFoundry may not work correctly.
7. Marketing Communications
We may send product updates, newsletters, launch notes, and educational content if you subscribe or where otherwise permitted.
You can unsubscribe from marketing emails by using the unsubscribe link in the email or contacting us at hello@shipfoundry.ai.
We may still send non-marketing messages, such as account, billing, security, legal, and service-related notices.
8. Data Retention
We keep information for as long as reasonably necessary to provide ShipFoundry, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and improve the service.
In general:
- account information is retained while your account is active
- project and handoff information is retained while your workspace or project remains active
- billing records are retained as required for accounting, tax, fraud prevention, and legal purposes
- analytics and log data may be retained for a shorter operational period unless needed for security, debugging, abuse prevention, or legal reasons
- backups may retain deleted information for a limited time before they are overwritten or deleted
Eligible single-owner personal accounts can request deletion from account settings after subscription cancellation is completed or scheduled. For blocked cases, team accounts, admin accounts, or other privacy requests, contact hello@shipfoundry.ai. We may retain limited information where required by law, for legitimate business records, to prevent abuse, or to complete pending transactions.
9. Security
We use reasonable technical, organizational, and administrative measures designed to protect information. These may include access controls, encryption in transit, provider security controls, logging, monitoring, and least-privilege practices.
No system is perfectly secure. You are responsible for maintaining the confidentiality of your account credentials, protecting connected accounts, and reviewing any generated handoff or implementation output before using it.
If you believe your account or data may have been compromised, contact us at hello@shipfoundry.ai.
10. Your Choices and Rights
Depending on where you live, you may have rights to:
- access personal information we hold about you
- correct inaccurate information
- delete certain information
- export or receive a copy of certain information
- object to or restrict certain processing
- withdraw consent where processing is based on consent
- opt out of certain marketing communications
- appeal a privacy request decision where required by law
To make a request, contact hello@shipfoundry.ai.
We may need to verify your identity before responding. We will not discriminate against you for exercising privacy rights required by law.
11. California Privacy Notice
This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies.
Categories of personal information we may collect
In the past 12 months, we may have collected the following categories of personal information:
| Category | Examples |
|---|---|
| Identifiers | Name, email address, IP address, account IDs, customer IDs |
| Customer records | Billing contact information and subscription metadata |
| Commercial information | Plan, subscription, trial, invoice, checkout, and transaction metadata |
| Internet or network activity | Pages viewed, product events, device/browser data, logs, cookie data |
| Geolocation data | Approximate location inferred from IP address |
| Professional or project-related information | Company/workspace name, project name, role, stack, tools, repo metadata, product context |
| Inferences | Product usage patterns, source coverage needs, matching/ranking signals, preferences |
| Sensitive personal information | Account login credentials and connected integration tokens or secrets, where applicable |
We do not use sensitive personal information to infer characteristics about you.
Sources of personal information
We collect personal information from:
- you
- your account administrators or workspace members
- your use of ShipFoundry
- integrations you connect
- payment processors
- analytics, hosting, authentication, observability, and infrastructure providers
- public sources where relevant to ShipFoundry's update intelligence
Business or commercial purposes
We collect and use personal information for the purposes described in this Privacy Policy, including providing the service, billing, support, security, analytics, product improvement, and legal compliance.
Disclosure of personal information
We may disclose the categories above to service providers and integrations as described in this Privacy Policy.
Sale or sharing
We do not sell personal information.
We do not knowingly share personal information for cross-context behavioral advertising as those terms are defined by California privacy law. If our practices change, we will update this Privacy Policy and provide any required opt-out mechanism.
California rights
California residents may request to:
- know what personal information we collect, use, disclose, or share
- access personal information
- delete personal information
- correct inaccurate personal information
- opt out of sale or sharing, if applicable
- limit certain uses of sensitive personal information, if applicable
- not be discriminated against for exercising privacy rights
To submit a request, contact hello@shipfoundry.ai.
12. International Users and Transfers
ShipFoundry may process information in the United States and other countries where we or our service providers operate.
If you use ShipFoundry from outside the United States, your information may be transferred to, stored in, and processed in countries that may have different data protection laws than your country. Where required, we use appropriate safeguards for international transfers.
13. Children
ShipFoundry is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact hello@shipfoundry.ai and we will take reasonable steps to delete it.
14. Third-Party Links and Services
ShipFoundry may link to third-party websites, documentation, changelogs, tools, vendors, repositories, and integrations. We are not responsible for the privacy practices of third parties.
Your use of third-party services is governed by their own terms and privacy policies.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you, such as by posting the updated policy, updating the "Last updated" date, or sending a notice where appropriate.
Your continued use of ShipFoundry after an updated Privacy Policy becomes effective means you acknowledge the updated policy.
16. Contact
For privacy questions, requests, or concerns, contact: hello@shipfoundry.ai
ShipFoundry, 13359 N Hwy 183 #406-1201, Austin, TX 78750, United States