Privacy Policy
Last updated: November 7, 2025
Introduction
dpop Studios LLC, doing business as ShipNotes ("we," "our," or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at shipnotes.xyz.
By using ShipNotes, you agree to the collection and use of information in accordance with this policy.
Information We Collect
1. Information from GitHub
When you sign in with GitHub OAuth, we collect:
- Your GitHub username
- Your GitHub user ID
- Your email address associated with your GitHub account
- Your GitHub profile picture URL
- Access to your repositories (read-only)
- Commit history from repositories you select
2. Usage Data
We automatically collect:
- Changelog generation events (timestamps, repository names)
- Export and copy actions
- IP addresses (for rate limiting and security)
- Browser type and version (via user agent)
- Pages visited and time spent on our service
3. Payment Information
If you subscribe to ShipNotes Pro:
- Payment processing is handled entirely by Stripe
- We do not store credit card numbers or payment details
- We receive only your email address and subscription status from Stripe
4. Generated Content
We store:
- Changelogs you generate (both technical and AI-rewritten versions)
- Repository names and commit counts
How We Use Your Information
We use your information to:
- Provide our service: Generate changelogs from your Git commits
- Authenticate you: Verify your identity via GitHub OAuth
- Process payments: Manage your subscription via Stripe
- Improve our service: Analyze usage patterns to enhance features
- Prevent abuse: Enforce rate limits and detect fraudulent activity
- Communicate with you: Send important service updates (if necessary)
- AI Processing: Send commit messages to OpenAI for rewriting (anonymized, no personal identifiers)
Third-Party Services
ShipNotes integrates with the following third-party services:
GitHub
We use GitHub OAuth for authentication and to access your repository data. See GitHub's Privacy Policy.
Supabase (Database)
We use Supabase to store your user profile, generated changelogs, and usage data. Data is encrypted at rest. See Supabase's Privacy Policy.
OpenAI
We send your commit messages to OpenAI's GPT-4 API for AI-powered rewriting. Commit messages are sent without personal identifiers. See OpenAI's Privacy Policy.
Stripe
We use Stripe for payment processing. Stripe handles all payment information securely. See Stripe's Privacy Policy.
Vercel (Hosting)
Our service is hosted on Vercel. They may collect analytics data. See Vercel's Privacy Policy.
Data Storage and Security
We implement industry-standard security measures to protect your data:
- Encryption: Data is encrypted in transit (HTTPS/TLS) and at rest
- Authentication: Secure GitHub OAuth with httpOnly cookies
- Database Security: Row-level security policies on all database tables
- Rate Limiting: Protection against abuse and unauthorized access
- Access Control: Backend uses service role keys with strict permissions
- Secure Logging: Sensitive data is automatically redacted from logs
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Data Retention
We retain your data as follows:
- Account Data: Retained while your account is active
- Generated Changelogs: Stored indefinitely unless you delete them
- Usage Logs: Retained for up to 90 days for analytics
- Payment Records: Retained as required by law (typically 7 years)
Your Rights
You have the following rights regarding your data:
Right to Access
You can view all your data in your account dashboard.
Right to Deletion
You can delete your account and all associated data at any time from your account settings.
Right to Data Portability
You can export your changelogs in Markdown, HTML, or plain text format.
Right to Withdraw Consent
You can revoke GitHub access at any time through GitHub settings or by deleting your account.
Cookies
We use strictly necessary cookies for:
- Authentication: Storing your GitHub access token (httpOnly, secure)
- Session Management: Maintaining your logged-in state
These cookies are essential for the service to function and are exempt from consent requirements under GDPR.
International Data Transfers
Your data may be transferred to and processed in countries other than your own. Our service providers (Supabase, OpenAI, Stripe, Vercel) operate globally and maintain appropriate safeguards to protect your data.
Children's Privacy
ShipNotes is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Updating the "Last updated" date at the top of this policy
- Posting the new policy on this page
- Sending an email notification for material changes (if you've provided your email)
Your continued use of ShipNotes after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or want to exercise your rights, please contact us:
Email: hello@dpopstudios.xyz
Support: Contact Form
GDPR Compliance (EU Users)
If you are in the European Economic Area (EEA), you have additional rights under GDPR:
- Right to rectification of inaccurate data
- Right to restriction of processing
- Right to object to processing
- Right to lodge a complaint with a supervisory authority
Our lawful basis for processing your data is: (1) Contractual necessity to provide our service, and (2) Legitimate interest in improving our service and preventing fraud.
CCPA Compliance (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect and how we use it
- Right to delete your personal information
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your rights
This Privacy Policy is effective as of the date listed above. For questions or concerns, please reach out to us at hello@dpopstudios.xyz.
ShipNotes is a product operated by dpop Studios LLC. This Privacy Policy is issued by dpop Studios LLC.