shipfound

Legal

Privacy Policy

Last updated: October 9, 2026

This policy explains what Shipfound ("Shipfound", "we", "us") collects when you use shipfound.co, the Shipfound plugin for Claude Code and Codex, the Shipfound MCP server and Shipfound analytics (together, the "Service"), and what we do with it.

Where the work happens

Shipfound works through your own coding agent. Changes to your repository, the pages your agent opens in your browser and any email drafts in your Gmail are made on your machine, by your agent, under your accounts. Our servers do not read your repository, your browser or your mailbox. We receive only what your agent sends to the Shipfound tools: for example the results of your access audit, the work you record (pull request links, page URLs, listing URLs) and the pages it asks us to check.

Information we collect about you

Cookies on shipfound.co

When you sign in, we set two cookies that the Service needs to work: one that keeps you signed in and one that protects your requests against cross-site forgery. We measure shipfound.co with our own analytics in Attribution mode: we ask first, and only if you accept do we keep a first-party visitor id in a cookie and local storage for up to 13 months, so we can see return visits and run A/B tests. If you decline, or your browser sends Do Not Track or Global Privacy Control, the visit is counted in cookieless mode and nothing is stored apart from your choice itself, kept in local storage so we do not ask again. You can change it at any time with "Analytics choice" at the bottom of this page.

Visitors to sites that use Shipfound analytics

When you add the Shipfound script to your site, we process data about your visitors on your behalf. You decide whether to use it and which mode it runs in, and you are responsible for telling your visitors about it.

How we use information

Your public proof page is off by default. If you turn it on, it shows the work you choose to share and never shows drafts or analytics.

Service providers

We share data with these providers only as needed to run the Service:

We do not sell personal information. We may disclose information if the law requires it or to protect our rights and users.

How long we keep it

Your choices

Security

We hash passwords and keys, encrypt stored Apple keys, and limit who can reach production data. No system is completely secure, so we cannot guarantee absolute security.

Children

The Service is not meant for anyone under 16, and we do not knowingly collect personal information from children.

International users

We and our providers may process and store data in countries other than yours.

Changes to this policy

When we change this policy, we update the date at the top and, where the change matters to you, tell you by email.

Contact

Questions about this policy: team@shipfound.co.