Privacy Policy

Last updated: November 7, 2025

Introduction

dpop Studios LLC, doing business as ShipNotes ("we," "our," or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at shipnotes.xyz.

By using ShipNotes, you agree to the collection and use of information in accordance with this policy.

Information We Collect

1. Information from GitHub

When you sign in with GitHub OAuth, we collect:

  • Your GitHub username
  • Your GitHub user ID
  • Your email address associated with your GitHub account
  • Your GitHub profile picture URL
  • Access to your repositories (read-only)
  • Commit history from repositories you select

2. Usage Data

We automatically collect:

  • Changelog generation events (timestamps, repository names)
  • Export and copy actions
  • IP addresses (for rate limiting and security)
  • Browser type and version (via user agent)
  • Pages visited and time spent on our service

3. Payment Information

If you subscribe to ShipNotes Pro:

  • Payment processing is handled entirely by Stripe
  • We do not store credit card numbers or payment details
  • We receive only your email address and subscription status from Stripe

4. Generated Content

We store:

  • Changelogs you generate (both technical and AI-rewritten versions)
  • Repository names and commit counts

How We Use Your Information

We use your information to:

  • Provide our service: Generate changelogs from your Git commits
  • Authenticate you: Verify your identity via GitHub OAuth
  • Process payments: Manage your subscription via Stripe
  • Improve our service: Analyze usage patterns to enhance features
  • Prevent abuse: Enforce rate limits and detect fraudulent activity
  • Communicate with you: Send important service updates (if necessary)
  • AI Processing: Send commit messages to OpenAI for rewriting (anonymized, no personal identifiers)

Third-Party Services

ShipNotes integrates with the following third-party services:

GitHub

We use GitHub OAuth for authentication and to access your repository data. See GitHub's Privacy Policy.

Supabase (Database)

We use Supabase to store your user profile, generated changelogs, and usage data. Data is encrypted at rest. See Supabase's Privacy Policy.

OpenAI

We send your commit messages to OpenAI's GPT-4 API for AI-powered rewriting. Commit messages are sent without personal identifiers. See OpenAI's Privacy Policy.

Stripe

We use Stripe for payment processing. Stripe handles all payment information securely. See Stripe's Privacy Policy.

Vercel (Hosting)

Our service is hosted on Vercel. They may collect analytics data. See Vercel's Privacy Policy.

Data Storage and Security

We implement industry-standard security measures to protect your data:

  • Encryption: Data is encrypted in transit (HTTPS/TLS) and at rest
  • Authentication: Secure GitHub OAuth with httpOnly cookies
  • Database Security: Row-level security policies on all database tables
  • Rate Limiting: Protection against abuse and unauthorized access
  • Access Control: Backend uses service role keys with strict permissions
  • Secure Logging: Sensitive data is automatically redacted from logs

However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

Data Retention

We retain your data as follows:

  • Account Data: Retained while your account is active
  • Generated Changelogs: Stored indefinitely unless you delete them
  • Usage Logs: Retained for up to 90 days for analytics
  • Payment Records: Retained as required by law (typically 7 years)

Your Rights

You have the following rights regarding your data:

Right to Access

You can view all your data in your account dashboard.

Right to Deletion

You can delete your account and all associated data at any time from your account settings.

Right to Data Portability

You can export your changelogs in Markdown, HTML, or plain text format.

Right to Withdraw Consent

You can revoke GitHub access at any time through GitHub settings or by deleting your account.

Cookies

We use strictly necessary cookies for:

  • Authentication: Storing your GitHub access token (httpOnly, secure)
  • Session Management: Maintaining your logged-in state

These cookies are essential for the service to function and are exempt from consent requirements under GDPR.

International Data Transfers

Your data may be transferred to and processed in countries other than your own. Our service providers (Supabase, OpenAI, Stripe, Vercel) operate globally and maintain appropriate safeguards to protect your data.

Children's Privacy

ShipNotes is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Updating the "Last updated" date at the top of this policy
  • Posting the new policy on this page
  • Sending an email notification for material changes (if you've provided your email)

Your continued use of ShipNotes after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or want to exercise your rights, please contact us:

GDPR Compliance (EU Users)

If you are in the European Economic Area (EEA), you have additional rights under GDPR:

  • Right to rectification of inaccurate data
  • Right to restriction of processing
  • Right to object to processing
  • Right to lodge a complaint with a supervisory authority

Our lawful basis for processing your data is: (1) Contractual necessity to provide our service, and (2) Legitimate interest in improving our service and preventing fraud.

CCPA Compliance (California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information we collect and how we use it
  • Right to delete your personal information
  • Right to opt-out of the sale of personal information (we do not sell your data)
  • Right to non-discrimination for exercising your rights

This Privacy Policy is effective as of the date listed above. For questions or concerns, please reach out to us at hello@dpopstudios.xyz.

ShipNotes is a product operated by dpop Studios LLC. This Privacy Policy is issued by dpop Studios LLC.