You choose repository access
ShipCheck works with repositories made available through the ShipCheck GitHub App installation.
This policy explains what ShipCheck can access, what happens when you connect GitHub, how repository content is processed, when AI-assisted analysis may be used, what information may be retained, and the controls available to you.
ShipCheck works with repositories made available through the ShipCheck GitHub App installation.
Normal repository access uses GitHub App installation authentication rather than requiring you to paste a personal access token.
Where supported, AI-assisted review can be configured per repository while deterministic ShipCheck checks continue independently.
Scanning does not itself rewrite your repository. Repository-changing actions require an explicit ShipCheck action.
This Privacy Policy explains how ShipCheck collects, processes, uses, retains, and protects information when you use the service.
ShipCheck is designed to review software changes and repository behavior. Source code may contain confidential or proprietary information, so ShipCheck aims to limit access and processing to what is reasonably necessary to provide its functionality.
When you create an account or authenticate through GitHub or another supported provider, ShipCheck may receive information such as your username, display name, profile image, email address where available, and authentication identifiers required to operate your account.
When you connect a repository, ShipCheck may process repository names and identifiers, owners, installation information, branch names, commit identifiers, pull-request metadata, changed files, patches, tests, and selected repository context.
ShipCheck may retain scan status, scores, verdicts, findings, evidence, file locations, generated fixes, regression tests, behavior descriptions, Behavior Guards, Behavior Contract versions and governance settings, verification plans, investigation traces, evidence-policy decisions, behavior history, scan timestamps, intent decisions, feedback, and related repository identifiers.
We may process technical information needed to operate, troubleshoot, secure, and improve ShipCheck, including application errors, request metadata, browser information, security events, and limited diagnostic logs.
GitHub App permissions and your repository selection determine the repositories available to ShipCheck.
ShipCheck uses GitHub App authentication to interact with connected repositories and may create short-lived installation access tokens when repository access is required.
Removing a repository from the GitHub App installation or uninstalling the ShipCheck GitHub App prevents future repository access through that installation, subject to any data already retained as described below.
ShipCheck retrieves repository content when needed to perform a scan, understand a code change, trace behavior, generate a requested output, or perform another feature you initiate.
Processing may include changed code, pull-request patches, related implementation files, tests, callers, validation logic, authorization logic, configuration, and other context relevant to evaluating repository behavior.
ShipCheck is not designed to create a permanent mirror of your entire repository. Portions of code or patches may nevertheless appear in retained scan information when necessary to preserve findings, evidence, fixes, generated tests, behavior history, or other product functionality.
ShipCheck aims to send only information reasonably relevant to the analysis rather than automatically sending an entire repository.
When AI-assisted features are enabled, ShipCheck may send selected information to third-party AI service providers, including OpenAI, in order to perform analysis or generate requested outputs.
Information provided for AI-assisted analysis may include repository metadata, pull-request titles or descriptions, changed files, relevant code changes, selected supporting repository context, deterministic findings, protected behaviors, or generated prompts necessary for the requested feature.
Third-party AI providers process information according to their own terms, privacy policies, data controls, and retention practices. Those policies may change over time.
Where ShipCheck provides repository-level AI controls, disabling AI-assisted review prevents that repository's scans from using the corresponding AI-review feature. Other deterministic functionality may continue to operate.
When you protect a behavior or use features that track repository behavior over time, ShipCheck may store the behavior description, supporting evidence, related files, origin information, historical outcomes, intent decisions, and contract lifecycle, criticality, enforcement, ownership, approval, structured claims, required evidence, verification history, and other metadata necessary to provide behavioral-governance functionality.
This information may remain associated with your repository until it is removed, the repository is deleted from ShipCheck, your account is deleted, or retention is otherwise ended according to ShipCheck's data practices.
Repository-changing features require an explicit action, such as choosing to apply a generated fix or regression test.
When you request a repository-changing action, ShipCheck may use the permissions available through the GitHub App installation to make the requested change.
ShipCheck uses information to authenticate users, connect repositories, perform scans, generate reports, identify behavior changes, maintain Behavior Contracts and history, verify contract evidence, produce risk-aware ship verdicts, generate requested fixes and tests, enforce plan limits, provide support, protect the service, diagnose problems, prevent abuse, and improve product reliability.
We may also use aggregated or de-identified information to understand product performance and usage patterns where doing so does not reasonably identify a particular user or repository.
ShipCheck may use third-party providers to operate the service. Depending on the feature, these may include GitHub, hosting and database providers, authentication services, payment processors, monitoring infrastructure, email providers, and AI service providers.
These providers may process information on ShipCheck's behalf as necessary to provide their services and are also subject to their own applicable terms and policies.
If you purchase a paid ShipCheck plan, payment information may be processed by ShipCheck's payment processor.
ShipCheck may retain subscription identifiers, plan information, billing status, subscription dates, usage records, and related metadata needed to manage your account. ShipCheck does not need to store full payment-card details when those details are handled directly by the payment processor.
Account records, scan history, protected behaviors, billing records, and temporary processing data may have different retention periods.
ShipCheck retains information for as long as reasonably necessary to operate the service, provide requested features, preserve scan and behavior history, meet security needs, comply with legal obligations, resolve disputes, and enforce agreements.
Some temporary repository context used during processing may be discarded sooner than retained scan results or behavior data.
Backup systems, security logs, billing records, or legally required records may remain for a limited period after other data is deleted.
Security controls reduce risk but cannot make any internet service completely secure.
ShipCheck uses technical and organizational measures intended to protect account, repository, and scan information. These may include access controls, GitHub App authentication, encryption provided by infrastructure services, authorization checks, logging, and restricted repository operations.
No method of transmission, storage, or software operation is completely secure, and ShipCheck cannot guarantee absolute security.
More information may be available on the ShipCheck Security page.
Repository access can be changed through your GitHub App installation settings.
You may disconnect repositories or uninstall the GitHub App through GitHub. Where account or repository deletion controls are available in ShipCheck, you may use those controls to request removal of associated product data.
Certain records may remain where reasonably necessary for backups, fraud prevention, security, billing, legal compliance, dispute resolution, or enforcement of agreements.
You may also contact karunsarvajith@gmail.com regarding data-access or deletion questions.
ShipCheck may use cookies, browser storage, or similar technologies that are necessary to maintain sessions, authentication, security, preferences, and core product functionality.
Additional technologies may be used for diagnostics or product analytics where implemented and permitted.
ShipCheck and its service providers may process information in countries other than the country where you live.
Data-protection laws may differ between jurisdictions. Where required, appropriate safeguards may be used for applicable cross-border transfers.
ShipCheck is a developer service and is not directed to children under the minimum age required to consent to online services in their jurisdiction.
If you believe personal information from a child has been provided to ShipCheck improperly, contact us so the matter can be reviewed.
We may update this Privacy Policy as ShipCheck, its infrastructure, or applicable requirements change.
The current version will display an updated date. Material changes may be communicated through the service or another reasonable method where appropriate.
Questions about this Privacy Policy or ShipCheck's data practices can be sent to karunsarvajith@gmail.com.