Legal
Privacy Policy
Last updated: October 9, 2026
This policy explains what Shipfound ("Shipfound", "we", "us") collects when you use shipfound.co, the Shipfound plugin for Claude Code and Codex, the Shipfound MCP server and Shipfound analytics (together, the "Service"), and what we do with it.
Where the work happens
Shipfound works through your own coding agent. Changes to your repository, the pages your agent opens in your browser and any email drafts in your Gmail are made on your machine, by your agent, under your accounts. Our servers do not read your repository, your browser or your mailbox. We receive only what your agent sends to the Shipfound tools: for example the results of your access audit, the work you record (pull request links, page URLs, listing URLs) and the pages it asks us to check.
Information we collect about you
- Account information. Your email address, your name, and your password, which we store only as a bcrypt hash.
- Connection keys. API keys and the sign-in tokens your agent uses to reach the MCP server. We store them as one-way hashes, plus a short prefix so you can tell keys apart.
- Your product and your work. Your product's URL, your access audit, what your agent records as shipped, the questions we ask AI engines about your category, their answers, and the results of our checks.
- App Store connections. If you connect App Store Connect or Apple Ads, we store the keys you provide encrypted (AES-256-GCM) and use them only to act on your app as you ask.
- Payment information. Payments are handled by Dodo Payments. We do not receive or store your full card details; we receive a payment confirmation and limited transaction details.
- Usage data. Which Shipfound tools and pages you use, tied to your account, so we can run and improve the Service. Server logs include IP addresses for security and abuse prevention.
Cookies on shipfound.co
When you sign in, we set two cookies that the Service needs to work: one that keeps you signed in and one that protects your requests against cross-site forgery. We measure shipfound.co with our own analytics in Attribution mode: we ask first, and only if you accept do we keep a first-party visitor id in a cookie and local storage for up to 13 months, so we can see return visits and run A/B tests. If you decline, or your browser sends Do Not Track or Global Privacy Control, the visit is counted in cookieless mode and nothing is stored apart from your choice itself, kept in local storage so we do not ask again. You can change it at any time with "Analytics choice" at the bottom of this page.
Visitors to sites that use Shipfound analytics
When you add the Shipfound script to your site, we process data about your visitors on your behalf. You decide whether to use it and which mode it runs in, and you are responsible for telling your visitors about it.
- Cookieless mode (the default). No cookies, local storage or session storage. A visitor is counted with a hash of their IP address, user agent and your site, mixed with a value that changes every day and is held only in memory, so the same visitor cannot be linked across days. The IP address is used in memory for that hash and for rate limiting, and is never written to storage.
- Attribution mode. Only when you turn it on and the visitor has given consent (through your consent banner, Google Consent Mode or a TCF signal). It sets a first-party identifier in a cookie and local storage for up to 13 months, and removes it if consent is withdrawn. A browser that sends Do Not Track or Global Privacy Control is always measured in cookieless mode. If you identify signed-in users, their user ID is hashed in the browser before it is sent.
- What each event holds. The page host and path, campaign tags (the rest of the query string is dropped), the referring page, country and region, device, browser, operating system, language, screen width, time on page, scroll depth, page speed measurements, and any custom properties you send.
- AI crawlers. When an AI or search bot fetches your pages, we record the bot's name, the path, the response status and time, and the bot's IP address. These are requests from bots, not from people.
- App sites on shipfound.site. If we host your app's site, we count clicks and the referring site.
How we use information
- To run the Service: audits, AI visibility checks, content briefs, verification, analytics and experiments.
- To create and secure your account and to process payments.
- To email you about your account, your results and support requests.
- To prevent abuse, enforce our Terms and meet legal obligations.
- To maintain and improve the Service.
Your public proof page is off by default. If you turn it on, it shows the work you choose to share and never shows drafts or analytics.
Service providers
We share data with these providers only as needed to run the Service:
- Anthropic, for the AI processing that runs on our servers.
- Search and AI-answer data providers, reached through Treg, to fetch search results, search volumes and AI engine answers. These requests contain your category and, where relevant, your product name.
- ScrapingBee, to read the public pages of the site you connect.
- Dodo Payments, for payments.
- Brevo, to send transactional email.
- PostHog, for product usage analytics about the Service.
- Railway, which hosts the Service.
- GitHub and Apple, which we contact only to check the pull requests you record and to act on the App Store connections you set up.
We do not sell personal information. We may disclose information if the law requires it or to protect our rights and users.
How long we keep it
- Account data and your work: for as long as your account is open.
- Analytics events: 395 days on paid plans and 30 days on the Free plan.
- AI crawler records: 395 days. The bot IP address in each record is removed after 90 days.
Your choices
- You can ask us to correct your account information by emailing us.
- You can revoke any API key or chat sign-in in Settings at any time.
- You can ask for a copy of your data, or for your account to be deleted, by emailing team@shipfound.co. Analytics events already collected expire on the schedule above.
- You can turn off non-essential emails with the unsubscribe link or by emailing us.
Security
We hash passwords and keys, encrypt stored Apple keys, and limit who can reach production data. No system is completely secure, so we cannot guarantee absolute security.
Children
The Service is not meant for anyone under 16, and we do not knowingly collect personal information from children.
International users
We and our providers may process and store data in countries other than yours.
Changes to this policy
When we change this policy, we update the date at the top and, where the change matters to you, tell you by email.
Contact
Questions about this policy: team@shipfound.co.