Skip to content
Shipmoor Shipmoor
  • Pricing
  • Blog
  • Docs
  • FAQ
Start free › Sign in Sign in

Privacy Policy

Last updated: August 28, 2026

Free account. Local execution. No source upload. Shipmoor runs product commands in your environment and contacts its services only for authentication, entitlements, command allowances, billing, security, and product analytics described below, or for a feature you explicitly enable.

This Privacy Policy explains how Shipmoor collects, uses, shares, retains, and protects personal data for the Shipmoor website, account console, CLI, Free and Pro plans, billing, documentation, and related services (the “Services”).

1. Product Privacy Posture

Shipmoor’s Scan, Claim Check, Code Review, Test Evidence, Blast Radius, Agent Harness, and Agent Skills execute on your machine or your own runner. Shipmoor does not operate a hosted model or require your source to pass through Shipmoor.

Every supported CLI installation uses account and device authorization. The CLI contacts Shipmoor to authorize a device, refresh credentials, obtain a signed entitlement lease, consume or display a Free command allowance, and perform narrowly defined security and analytics functions. Those requests are designed to carry identity and operational metadata, not source-shaped project data.

If you explicitly configure a coding-agent or model provider, that provider may receive the inputs you authorize under your separate relationship with it. If a future Shipmoor feature asks you to connect a hosted integration or transmit project content, the feature will identify that behavior and its controls before you enable it.

2. Data We Process

Account and Device Authentication

WorkOS manages browser authentication. Shipmoor may process:

  • email address, name, verification status, provider identity, and login timestamps;
  • opaque user and account identifiers, account type, membership role, and account status;
  • opaque device identifier, device name, authorization state, creation, last-use, revocation, and expiry timestamps;
  • authentication and device-flow event type, outcome, categorized failure reason, provider, and timestamp;
  • necessary IP address, user agent, security logs, and request metadata used to operate and protect hosted endpoints.

The device flow returns a short-lived access token, a rotating device-bound refresh credential, and a signed offline entitlement lease. Access tokens expire after approximately 15 minutes and are not offline entitlement proof. Refresh credentials may remain valid for up to 90 days, rotate on every use, and are stored only as hashes server-side. Reuse of a rotated credential revokes that device credential family.

Entitlements and Signed Leases

Shipmoor processes the minimum data needed to issue, refresh, validate, and revoke signed leases:

  • schema and signing-key version, issuer, audience, and opaque lease ID;
  • opaque user, account, and device identifiers;
  • canonical plan and plan source;
  • capability access and command-allowance keys;
  • allowance quantity, display-only remaining snapshot, and UTC renewal time;
  • issued-at, not-before, expiry, grace, refresh, revocation, and reason fields.

Free leases normally last seven days, with a 72-hour grace period for unlimited Scan, Harness, and Skills. Pro trial and paid Pro leases normally last fourteen days, with a 72-hour grace period. Lease refresh does not shorten the 30-day Pro trial. A Free metered command must reach the allowance service for each invocation.

Command Allowance Metadata

For Free allowance enforcement, Shipmoor accepts only these four command-family keys:

  • claim_check;
  • code_review;
  • test_evidence;
  • blast_radius.

Each admitted invocation sends a fresh random idempotency key and one source label: cli, skill, harness, or ide. A retry of that same invocation reuses its key so it is not counted twice. Stored usage events contain only an opaque account and device identity, the random idempotency key, command key, source label, and timestamp. Counter records also hold the UTC period, included quantity, consumed quantity, and renewal time. Source labels affect analytics labeling only, never price or allowance.

The CLI version and platform may accompany authentication, entitlement, allowance, reliability, and security requests. The usage service does not receive command output or project context. Unknown request fields, including source-shaped fields, are rejected, and request-body logging is disabled for allowance requests.

CI Machine Tokens

Non-interactive CI may use a scoped machine token through the SHIPMOOR_TOKEN environment variable. Shipmoor stores only a hash plus its opaque account identity, name, scope, creation, last-use, optional expiry, and revocation metadata. Free machine tokens are Scan-scoped. Tokens are revocable and are not copied by the CLI to files or logs.

Billing

Stripe processes Pro checkout, subscriptions, payment collection, invoices, taxes, and the billing portal. Shipmoor may receive customer and subscription identifiers, selected price and billing period, subscription state, current period end, cancellation state, payment-failure grace state, billing contact details, and webhook event metadata needed for idempotency and reconciliation. Shipmoor does not store full payment-card numbers.

A newly created personal account’s 30-day Pro access does not create a Stripe customer, Checkout Session, subscription, invitation, or card record. Stripe data is processed only when you choose a paid subscription or have an existing Stripe-managed entitlement.

Website and Support

If you contact Shipmoor, request support, or submit a form, we process the information you provide, such as your name, email address, company, message, attachments, and communications metadata. Do not include source or secrets unless a support flow explicitly requests them and you choose to provide them.

3. Data Excluded From Normal Product Requests

Authentication, entitlement, allowance, and default analytics requests must not upload, accept, log, persist, or derive any of the following:

  • source code, file contents, repository contents, or patches;
  • diffs, changed lines, source-derived fingerprints, or self-digests;
  • prompts, tickets, tasks, agent transcripts, or acceptance criteria;
  • findings, recommendations, verdicts, scores, or rule results;
  • evidence, attestations, reports, SARIF, VSA files, or other command output;
  • file or directory paths, repository names or URLs, branch names, commit messages, or project configuration;
  • test names, test source, test output, build output, runner output, or model output;
  • secrets, provider credentials, environment values, or local artifact contents.

Raw local artifacts, configuration, Harness and Skills setup, reports, and attestations remain in your environment unless you choose to send them to another service. Authentication and allowance metadata never enters Shipmoor’s evidence, output schemas, or self-digests.

4. Analytics Allowlist

Default product analytics is limited to these event names:

  • account_created;
  • device_authorized;
  • command_usage_consumed;
  • allowance_exhausted;
  • subscription_started.

These events may carry the opaque account/device identity and operational fields already described, including CLI version/platform, command-family key, invocation source, random idempotency key, and timestamp where relevant. They do not carry command output, verdict class, findings, evidence, project identity, or any field listed in Section 3. Vercel provides website/application hosting and the analytics transport used for this allowlisted measurement.

5. How We Use Data

We use the data described above to:

  • create and administer accounts and authorize, name, and revoke devices;
  • authenticate sessions and rotate credentials;
  • issue, refresh, validate, and revoke signed entitlement leases;
  • atomically enforce the four independent Free command allowances and prevent duplicate consumption;
  • create, scope, display, and revoke CI machine tokens;
  • provide Pro checkout, billing, renewal, cancellation, and tax support;
  • measure the allowlisted activation and usage events;
  • diagnose reliability problems, prevent abuse and fraud, and investigate security incidents;
  • answer support, privacy, legal, and security requests; and
  • comply with law and enforce our agreements.

6. Processors

Shipmoor uses these processors for the current Services:

ProcessorRoleProcessing location
WorkOSAuthentication, OAuth, identity, and session workflowsUnited States and global infrastructure as needed
StripePro checkout, subscription billing, invoices, taxes, customer portal, and paymentsUnited States and other Stripe processing locations
SupabaseHosted database for account, device, entitlement, usage, token, billing, and audit metadataUnited States or configured cloud region
VercelWebsite and application hosting, edge delivery, deployment, and allowlisted analyticsUnited States and global edge network

Processors may change as the Services evolve. We will update this policy or provide appropriate notice before a material change.

7. Cookies and Local Credential Controls

Hosted account surfaces use necessary cookies for authenticated sessions, CSRF/state validation, and post-sign-in redirects. We do not use those cookies for cross-context behavioral advertising.

The CLI stores refresh credentials in macOS Keychain, Windows Credential Manager, or Linux Secret Service when available. A restrictive 0600 local-file fallback may be used with a warning. A signed lease may be stored in a restrictive local file. SHIPMOOR_TOKEN is read from the environment and is not copied to disk or logs by the CLI. You can view and revoke devices and machine tokens through the controls Shipmoor provides.

8. Sharing

We may share personal data and operational metadata with:

  • the processors listed above as needed to provide the Services;
  • professional advisors such as lawyers, auditors, accountants, insurers, and banks;
  • authorities or third parties when required by law, legal process, security, fraud prevention, or enforcement of rights; and
  • transaction parties in a merger, acquisition, financing, reorganization, or asset sale.

We do not sell personal data or share it for cross-context behavioral advertising.

9. Retention

We retain data only as long as reasonably needed for the purpose collected, subject to legal, accounting, security, fraud-prevention, backup, and dispute requirements:

  • account and device records remain while needed to operate the account and are deleted or de-identified after a verified deletion request, subject to the exceptions above;
  • active credential hashes, leases, grants, machine-token records, and revocation state remain while valid and as needed afterward to prevent replay and abuse;
  • command counters and idempotency events remain long enough to enforce the applicable UTC period, resolve retries and disputes, prevent duplicate charging, analyze abuse, and meet accounting or legal needs, then are deleted or de-identified;
  • authentication and security audit events are ordinarily retained for 12 months unless an incident, fraud inquiry, or legal obligation requires longer retention;
  • Stripe and billing records remain as required for subscription support, tax, accounting, audit, and legal obligations;
  • allowlisted analytics is retained only as long as needed for product measurement and security, then deleted or aggregated; and
  • local project data remains under your control because Shipmoor does not receive it through normal product requests.

Backups may retain deleted records for a limited rotation period before automatic expiry. Data under a legal hold is retained until the hold ends.

10. Deletion and Other Controls

You may revoke a device or CI token using product controls, sign out locally, cancel Pro through the billing portal, or request account-data deletion by emailing privacy@shipmoor.dev. Logout, downgrade, revocation, and account-plan changes do not delete your local configuration, Harness or Skills setup, reports, or evidence.

We verify deletion requests and delete or de-identify account-controlled personal data where required and technically feasible. We may retain limited records needed for tax, accounting, security, fraud prevention, legal compliance, dispute resolution, and proof that a request was fulfilled. If an organization controls your account, we may direct an organization-data request to that organization.

Depending on your location, you may also have rights to access, correct, restrict, object to, or request portability of personal data, withdraw consent where applicable, or appeal a privacy-rights decision.

11. Security

We use technical and organizational safeguards designed to protect hosted data, including scoped access controls, encryption in transit, encryption at rest where appropriate, hashed server-side credentials, credential rotation and replay revocation, signed leases, logging controls, monitoring, and vendor review.

No system is perfectly secure. You are responsible for securing your repositories, endpoints, CI systems, credentials, tokens, local lease files, runners, networks, logs, backups, coding-agent providers, and third-party integrations. Report security issues to security@shipmoor.dev.

12. International Transfers

We and our processors may process personal data outside your country. Where required, we use appropriate safeguards such as data-processing terms, contractual commitments, and standard contractual clauses.

13. Children

The Services are not directed to children under 16, and we do not knowingly collect personal data from children under 16.

14. Changes

We may update this policy. For material changes, we will provide reasonable notice through the website, product, email, console, CLI, or another appropriate channel. The date at the top identifies the effective version.

15. Contact

Privacy questions and requests may be sent to privacy@shipmoor.dev.

Language agnostic verification

Shipmoor works with any language through your existing build and test toolchain. Native deterministic Scan rules currently cover:

  • Python
  • TypeScript
  • JavaScript
  • Go

Supported editors & agents

  • VS Code
  • Codex
  • Claude Code
  • Cursor
  • Aider
Shipmoor Shipmoor

© 2026 Shipmoor. Legal: legal@shipmoor.dev

  • Pricing
  • Terms
  • Privacy
  • Blog
  • Console