Legal
Privacy Policy
This policy explains what Shipshot collects, why, who may process it to help run the service, how long key records are kept, and how deletion works. Download important exports and keep your own copy.
Last updated August 13, 2026
1. What we collect
- Account details: your name, email address, and — if you use them — the profile information Google or GitHub shares during sign-in.
- Encrypted store keys: if you save an App Store Connect API key or Google Play service-account JSON, Shipshot stores the private material encrypted and never returns it after save.
- Projects: the designs, screenshots, images, fonts and text you create or upload.
- Exports: the files the renderer produces from your projects.
- Support conversations: messages you send through the support messenger, including product questions from unsigned visitors. File attachments require a signed-in account.
- Billing records: plan, payment status and invoices from Stripe.
- Security logs: sign-in events, session data and rate-limit records that protect accounts.
- Edge request logs: the public gateway records the network address, timestamp, request method and path without the query, response status and size, and browser user-agent so Shipshot can operate, secure, and diagnose the service. Critical gateway errors may include the request line. These necessary technical logs are recorded whether or not optional analytics is enabled.
- Paid public AI abuse controls: Shipshot derives a keyed one-way HMAC from the requester network address for durable hourly and in-flight limits on anonymous image and caption tools. The raw network address is not stored in that admission record.
- Support AI admission: signed-in support chat derives a keyed one-way HMAC from the account identifier; unsigned visitor questions derive a keyed one-way HMAC from the requester network address. This enforces hourly and in-flight assistant limits. The raw account identifier and network address are not stored in that HMAC field.
- Support attachment admission: Shipshot derives a keyed one-way HMAC from the signed-in account identifier or, for leftover anonymous conversations, the requester network address. This enforces hourly object and byte limits for each requester plus hourly and retained-byte limits for the service as a whole. Once a supported, size-valid upload is admitted, unsafe-file rejections and later scanning, storage, or save failures still count toward the hourly admission limits; unsupported or oversized files rejected before admission do not. The raw account identifier and network address are not stored in the attachment admission record.
- Optional analytics: only after you allow it, Shipshot creates a random identifier for the browser tab and periodically reports the current Shipshot route and product stage while visible. On the pricing page, it also reports one layout-stability number. Reports exclude your account identity, query, hash, referrer, analytics cookies and browsing outside Shipshot.
2. Why we collect it
We use this information to run the product: signing you in, saving and rendering your work, delivering exports, answering support, preventing abuse, and billing the right plan. We may also use information where needed to meet legal obligations or protect the service and its users.
3. Cookies
Shipshot uses cookies and similar technologies needed to provide the service, such as keeping you signed in and supporting sign-in flows. Optional analytics stays off unless you allow it below. Declining analytics does not affect the product. Your analytics choice is kept in this browser for up to 180 days, then Shipshot asks again.
4. Service providers and integrations
We may use service providers to help operate Shipshot. They may process information as needed for the services they provide and subject to their applicable terms and policies:
- Stripe processes payments and subscriptions for paid plans.
- When Shipshot AI support or image tools are enabled, Alibaba Cloud Model Studio (Qwen) processes the text prompts, support messages, or image-generation inputs needed to return the requested result. If those tools are unavailable, that content is not sent to Qwen.
- Cloudflare Turnstile verifies unsigned visitors before paid support AI answers. Challenge tokens are sent to Cloudflare for verification; signed-in accounts skip that check.
- Storage and hosting providers may hold uploaded assets, project data and rendered exports.
- Email delivery providers send verification, password-reset and service messages.
- Google and GitHub support optional sign-in.
- Apple and Google process store keys and screenshot files only when you push a saved ZIP into a listing version.
Google Analytics 4 processes the approved measurement events only after you allow optional analytics. Shipshot disables Google signals, advertising personalization, and automatic page-view collection, and sends only the controlled event fields described above.
5. Retention and deletion
Active and archived projects and their uploaded assets are retained while your account exists. Moving a project to Trash archives it; it stays recoverable there indefinitely until you restore it or delete your account. Deleting an individual uploaded image or font from an active project removes its project record immediately and queues its exact stored files for deletion; storage failures are retried. To delete an asset from an archived project, restore the project first and delete that asset, or delete the account. If an upload is interrupted after its bytes reach storage but before its project record is saved, those unlinked files become eligible for automatic cleanup within 24 hours. Deleting your account removes account-linked database records and immediately queues account-owned stored objects for deletion; a storage outage causes that object cleanup to retry rather than silently abandon the request.
Export archives use plan-specific age and count limits, and the first limit reached applies. Basic exports are retained for up to 30 days or the newest 10 archives per project. Pro exports are retained for up to 180 days or the newest 100 archives per project. Scale exports are retained for up to 365 days or the newest 500 archives per project. An archive attached to a store submission is protected from routine retention cleanup. Download anything you need to keep longer.
Opaque visitor analytics records expire after 30 days. Revoking analytics immediately stops new client reporting and removes the local visitor identifier from this browser tab.
Edge access and critical-error logs rotate daily and are kept for up to 15 days on the production host, including the current log, before automatic removal.
AI request and result records are kept for 30 days after a job completes, fails, or is rejected, then the hourly retention sweep deletes them. A generated image asset keeps its prompt as provenance while that asset or its archived project remains in the account. Deleting the individual generated asset or deleting the account removes that provenance under the corresponding deletion process; moving its project to Trash does not. To delete a generated asset from Trash, restore the project first. Security audit metadata records the provider, project, asset, and job identifiers but does not duplicate the prompt. A running job is first failed by the provider-timeout safeguard and is never deleted by the retention sweep while it is still marked running.
Empty open support conversations that never receive a message are deleted after 24 hours without support activity. Anonymous support conversations that contain messages or attachments but have no human support reply are deleted after seven days without support activity, including their stored attachments; requesting a human or receiving an automated answer does not extend that period. A conversation linked to an account or answered by human support remains available until it is closed. Deleting an account closes its linked support conversations before removing the account link. Closed support conversations, including their messages and attachments, are kept for 24 months after the last support activity, then deleted by the hourly retention sweep. Security audit events are kept for 12 months. Shipshot billing transaction records are kept for seven years; Stripe may keep its own payment records under Stripe’s policy and legal obligations.
You can delete your account in Account or request deletion through support@getshipshot.com from the address on your account. Self-service deletion requires entering your account password, that any active paid subscription has ended or expired, and that ownership of any team workspace with other members has been transferred or deleted. OAuth-only accounts must set a password before self-service deletion, or request deletion via email. A legal obligation, active dispute, fraud investigation, or preservation order may require a narrowly scoped record to be held longer; when that exception ends, the ordinary deletion schedule resumes.
6. Security
We use reasonable measures designed to protect the service and your information. Uploads are scanned as part of the service, but no security measure can guarantee that all harmful content or unauthorized access will be prevented.
7. Your rights
You can request access to, correction of, export of or deletion of your information through support. Where privacy law gives you additional rights, the same support address handles those requests.
8. Contact
Shipshot is the service name used by the independent operator of getshipshot.com.
Privacy questions: write to support@getshipshot.com.
Analytics choice
You have not made an analytics choice yet.
If allowed, Shipshot uses a random browser-tab ID to count controlled page categories, product stages, and one Pricing layout-stability number. We also load Google Analytics 4 to count sign-ups, checkout starts, first exports, and confirmed purchases. When allowed, we may also load the X (Twitter) ads pixel for the same consent-gated conversion events. We never send your email, name, project content, prompts, or full URLs, and analytics is not used for ad personalization.