Legal / Contact

Privacy Policy

Shipsite.ai processes account data, project data, prompts, generated outputs, connected account tokens, usage data, logs, support messages, and privacy-conscious analytics to operate an AI-assisted site production workflow.

Version 2026-07-27 · Effective 2026-07-27 · Operational compliance baseline (counsel review pending)

Diting and the mythic governance crew listening for truth, reviewing risk, and learning from evidence
  • Account and project data are used to provide the service.
  • Connected account tokens must use scoped OAuth or official access paths.
  • Secrets and BYOK values must not be logged or displayed in full.
  • First-party events store a random browser session ID, path, referrer host, campaign tags, and product actions; they do not store IP addresses, user agents, email addresses, payment data, prompt content, or secret values.
  • Analytics stack is privacy-conscious and may also include Plausible, GA4, Clarity, or Cloudflare analytics only after configuration.
  • Controller: Nextfield Labs LLC, operating Shipsite.ai. Privacy and data-protection contact: hello@shipsite.ai.
  • Purposes and lawful bases: service delivery and requested AI processing (contract); account security, abuse prevention, service reliability, and limited product analytics (legitimate interests); billing and tax records (legal obligation and contract); optional non-essential analytics or marketing where required (consent).
  • Retention: active account/project data is retained while needed to provide the service; operational/security logs are targeted for deletion or aggregation within 90 days; support records within 24 months; billing/tax records for the legally required period. Durable project deletion removes live D1/R2 data; encrypted provider backups expire on the provider's bounded recovery schedule and are not restored except for disaster recovery.
  • Data-subject rights may include access, correction, deletion, portability, restriction, objection, consent withdrawal, and complaint to a competent supervisory authority. Email hello@shipsite.ai; identity and authority may be verified before action.
  • International transfers may occur where Cloudflare, Stripe, GitHub, analytics services, or selected AI providers process data outside your country. Shipsite relies on available contractual transfer safeguards and provider data-processing terms where required.
  • Subprocessor categories include hosting/CDN/storage (Cloudflare), payments/tax (Stripe), source hosting and OAuth integrations (for example GitHub/Google), support/communications, configured analytics, and the AI/model provider selected for a run. The active provider and authorization mode are recorded in run telemetry.
  • Model egress — platform-hosted mode: the selected provider (including supported OpenAI/Codex, Anthropic, Google, OpenRouter, or other configured routes) receives the instructions, relevant project context/code excerpts, and attachments required for that run. OpenRouter may route to the downstream model provider shown for the run.
  • Model egress — BYOK/connected-account mode: the same task-scoped content is sent directly using the customer's selected provider account. Shipsite does not intentionally send connection secrets, payment data, or unrelated workspace content in model prompts. Customers should exclude regulated or highly sensitive data unless a written DPA and suitable provider terms are in place.
  • For a DPA, subprocessor details, privacy request, or security incident report, contact hello@shipsite.ai. Confirmed incidents are assessed, contained, documented, and notified to affected customers or authorities when legally required.
  • Policy status: operational compliance baseline; independent legal counsel review is pending. This status does not reduce mandatory rights under applicable law.

Contact: hello@shipsite.ai. Questions about this policy? We're happy to help.

Browse all