Privacy Policy
Last Updated: February 18, 2026

Introduction

We value your trust and are committed to protecting your privacy. This Privacy Policy describes how ShipifyAI collects, uses, shares, and safeguards information when you access or use our automated software delivery platform — including the web dashboard, the ShipifyAI CLI, and any related APIs and services. By using ShipifyAI, you acknowledge and agree to the practices described in this policy.

Information We Collect

When you register or use our platform, we collect basic account data such as your first name, last name, email address, hashed password, and company name, along with authentication-related data including 2FA secrets, single-use backup codes, and session tokens. As you set up your work, we also store project and integration data — the metadata of your projects (names, repository links, board configuration) and the encrypted credentials for the third-party services you connect, including GitHub Personal Access Tokens, Jira API tokens with the associated email and site URL, and Slack Bot Tokens. To run your CLI workers safely, we collect session-related data such as device identifiers, operating system, IP address, and activity logs covering heartbeats, task IDs, and action timestamps needed to authenticate and monitor those workers. We additionally gather technical data like browser type, device identifiers, cookies, and similar telemetry collected through the dashboard, and we retain support communications — any messages or interactions with our support team — for quality, security, and audit purposes.

What we do not collect or store is equally important: ShipifyAI never stores, mirrors, or analyzes the source code generated, modified, or read by your AI agent — that code is committed directly to your repository and remains entirely under your control. We also do not store the content of your tasks, comments, or messages in Jira, Slack, or GitHub beyond the minimum metadata required to coordinate the workflow.

How We Use Your Information

We use your information to provide, operate, and maintain the ShipifyAI platform and CLI workers, to authenticate users and devices, and to secure access to your account. Your data also enables us to coordinate task execution between your repositories, task boards, and communication channels, manage billing and worker provisioning when applicable, and detect abuse or fraud that could affect the integrity of the service. Beyond core operations, we use aggregated usage data to improve platform performance, refine the user experience, and communicate service updates, security alerts, and account-related notifications. We do not use your data, code, or integration content to train any AI model — ours or otherwise.

Third-Party AI Tools and Configuration

ShipifyAI is an orchestration platform: you decide which AI providers and agents your workers use (for example, Claude Code by Anthropic). When you connect such a tool, your data flows directly to that provider under their own terms and privacy policy. You are responsible for configuring your AI agents, choosing which providers to connect, and defining the scopes of access you grant them. ShipifyAI does not assume liability for the data handling practices, security controls, or behavior of third-party tools you choose to integrate.

Sharing of Data

We do not sell or rent your personal data. We may, however, share information with carefully selected partners and processors strictly as needed to operate the service. This includes cloud and hosting providers used for infrastructure and sandboxed worker execution, email delivery providers such as SendGrid for transactional and account messages, and error monitoring or observability tools used to maintain platform reliability. When paid plans are active, we share the minimum required data with payment processors. Where you connect third-party AI providers, the data your workers send through them flows under those providers' agreements. We may also disclose information to authorities or regulators when legally required.

Data Retention

We retain your data only as long as necessary to operate the service, maintain your account, comply with legal, tax, and accounting obligations, and resolve disputes or enforce our agreements. Encrypted integration tokens are deleted from our database when you remove a connection or delete the associated project. Account data is removed — or anonymized for aggregate analytics — within a reasonable period after account closure, except where retention is required by law.

Security Measures

We apply industry-standard security controls to protect your data. All third-party integration tokens (GitHub, Jira, Slack) are encrypted at rest using AES-256, with encryption keys managed through environment variables or secrets vaults rather than stored in the database. Access to integrations follows a scoped, least-privilege model: AI agents never receive direct access to your full Jira or Slack workspaces — dedicated backend scripts feed only the scoped context required for the specific task at hand. CLI workers run in sandboxed, isolated environments rather than on our servers, and CLI sessions are bound to specific devices using a combination of IP address, operating system, and device identifier. We also enforce multi-factor authentication, refresh-token rotation, continuous monitoring, and TLS encryption for all data in transit. While we apply strong protections, no system is fully invulnerable, and you remain responsible for safeguarding your login credentials, CLI tokens, and the security configuration of your repositories and connected tools.

Cookies & Tracking

Our dashboard uses cookies and similar technologies to maintain sessions, remember preferences, and analyze usage patterns. You can disable cookies in your browser settings, but some platform features may not function correctly as a result.

Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data, to restrict or object to certain processing activities, to receive a copy of your data in a portable format, and to withdraw consent or opt out of marketing communications. To exercise any of these rights, please contact us through the channels listed below. We will respond within the timeframes required by applicable law.

Children’s Privacy

ShipifyAI is intended for users aged 18 or older. We do not knowingly collect personal data from minors, and if we become aware that we have received data from a person under 18, we will delete it promptly.

International Data Transfers

ShipifyAI may process and store data in jurisdictions outside your country of residence. Where required by law, we put in place appropriate safeguards — such as Standard Contractual Clauses — to ensure your data continues to be protected.

Policy Updates

We may revise this Privacy Policy from time to time to reflect changes in laws, technology, or our business practices. Updated versions will be posted on this page with a revised "Last updated" date, and continued use of our services after such updates constitutes acceptance of the revised policy.

Contact Us

If you have questions about this Privacy Policy or how we handle your data, please reach out via the contact form on our website.