Privacy
Last updated:
Short version: we read metadata about your commits, never your code. Visitors aren't tracked with cookies, and we don't store IP addresses. If you delist, your activity data is deleted within 30 days.
Who we are
shipboard.lol is run by Daniel Bragg. Contact: email hello@shipboard.lol or DM @shipboard_lol on X.
If you just visit
- No cookies are set while you browse, and we don't store your IP address or browser details.
- When you follow a project's link, we record the project, the time, the website you came from (its domain only), and your country. That's used for click counts, which are shown to owners and never scored.
- The "here now" counter uses a live connection with a random ID. Nothing about it is stored.
- Page-view statistics use Plausible, which sets no cookies and stores no personal data.
If you sign in or list a project
- Your GitHub account: signing in with GitHub gives us your GitHub user ID, username, display name, avatar, and email address. Signing in sets a session cookie so you stay signed in.
- Your repos: through the GitHub App, with read-only access to contents and metadata. We store commit IDs, timestamps, author usernames, line counts, and file paths (only to filter out lockfiles and generated code). We never store or show file contents or commit messages.
- What you write: your project name, pitch, link, category, tags, and epitaph, which are public.
- Payments: handled by Stripe. We never see your card number; we keep your subscription status and Stripe customer ID.
- Emails: we send a few emails about your listing (for example, a reminder before it renews, or when it goes quiet or is revived), using your GitHub email address.
Unclaimed entries
Some projects are added from public GitHub data before anyone claims them. For those we store the same kind of commit metadata from public repos, plus the repo's public description. Maintainers can have them removed at any time; see the entry's Remove page or contact us.
Where it's stored, and who processes it
Our data is stored in the United States: our database runs on Supabase (us-east-1) and the site is hosted by Vercel in the US. These services process data for us:
- Supabase: database and sign-in
- Vercel: hosting (processes requests to serve the site)
- Stripe: payments
- Resend: email delivery
- Inngest: background jobs
- GitHub: sign-in and the repo data we read
- Plausible: cookieless page-view statistics
How long we keep it
- Raw commit metadata is kept for 90 days. Daily totals and score history stay while the project is listed.
- If you delist a project, its commits and activity are deleted within 30 days.
- A removed unclaimed entry is hidden at once and its data deleted within 30 days.
- A Graveyard tombstone is removed on request.
Your rights
Wherever you live, you can ask to see the data we hold about you, correct it, or delete it. Email hello@shipboard.lol and we'll answer within 30 days. You can also delist a project yourself at any time.