Privacy Policy
Last updated: July 9, 2026
1. What we collect
Your account details (name, email), the prompts you write, the code Shipd generates for you, and usage metrics (token counts, feature events) needed to run and bill the service.
2. What we don't do
We don't sell your data, we don't train models on your private code or repositories, and we never store the values of your environment variables — those go directly to your deployment provider.
3. Connected services
Tokens for GitHub, Vercel, and your own API keys are stored encrypted at rest and used only to perform the actions you invoke. Disconnecting a service deletes its token immediately.
4. Where data lives
Application data is stored with Supabase (Postgres, row-level security per organisation), backend processing runs on Railway, and the frontend is served by Vercel. AI generation is processed by Anthropic; prompts sent for generation are subject to Anthropic's API data policies and are not used for model training.
5. Multi-tenant isolation
Every record is scoped to your organisation and enforced at the database layer with row-level security, plus API-level checks on every endpoint.
6. Retention & deletion
Projects, versions, and chats persist until you delete them. Deleting your account removes your personal data and encrypted tokens; deployed apps on your own connected accounts are untouched.
7. Cookies
We use only the cookies required for sign-in sessions and CSRF protection during OAuth flows. No third-party advertising trackers.
8. Contact
Privacy questions or deletion requests: the.arkitek.ai@gmail.com.