ShipNotes
How it worksPricingDocsFAQ
Sign inGet started free

ShipNotes — Privacy Policy

Service: ShipNotes (web application at getshipnotes.app) · Controller: QVANS LLC, 3955 Greenfield Ct, Boynton Beach, FL 33436 · Contact: legal@getshipnotes.app · Governing law: Florida, USA · Effective date: September 16, 2026

This Privacy Policy explains how QVANS LLC ("Qvans", "we") processes personal data when you use ShipNotes, an AI changelog generator that connects to GitHub and GitLab repositories, drafts release notes from merged pull requests, and hosts public changelog pages. ShipNotes is a web application for business use (no mobile app).


1. Plain-language summary

  • From GitHub or GitLab we read only merged PR titles, bodies, labels, and merge dates for your release ranges — never diffs or your source tree.
  • Repository data is used solely to generate your release notes. We never use it to train AI models, and we only use AI providers whose API terms prohibit training on customer inputs.
  • Nothing goes public until someone on your account clicks publish.
  • We use a small, named set of subprocessors (Section 6). We do not sell or share personal information, and we run no third-party analytics or advertising trackers — product analytics are stored first-party in our own database.

2. Roles

  • For account, billing, support, and product-usage data, we are the controller.
  • For repository-derived personal data (e.g., PR author names and handles, or names and emails appearing in PR text), we act as your processor: we process it on your documented instructions (your use of the Service). A Data Processing Addendum is available on request at legal@getshipnotes.app. Your organization is the controller of that data.
  • For published changelog pages, the publishing customer controls the content; we host it.

3. Data we process and why

Category Examples Purpose Legal basis (GDPR)
Account data Name, email, hashed password, MFA and passkey credentials, session data (Better Auth) Authentication, account management Contract (Art. 6(1)(b))
Repository data (as processor) PR number, title, body, labels, merged-at; repository name; release tags Generate and manage your release notes Your instructions (Art. 28); customer's own basis
Integration data GitHub installation IDs and encrypted installation tokens; encrypted GitLab access tokens Operate the repository connection Contract
Billing data Plan, subscription status, Stripe customer and subscription IDs (card data stays with Stripe) Billing and plan limits Contract; legal obligation (tax)
Transactional email data Recipient address and message content (via Cloudflare Email Service) Signup confirmation, password reset, team invitations, release-published, payment-failed, and license-renewal notices Contract / legitimate interests
Slack configuration Your Slack incoming-webhook URL (stored encrypted) Post release notifications you configure Contract
Product events (first-party) Named events (e.g., release generated, user signed up) tied to account IDs, stored in our own database Understand and improve the product; plan-limit enforcement Legitimate interests
Error and observability data Error events and traces via Sentry; LLM token usage and cost metrics Reliability, abuse and spend monitoring Legitimate interests
Public changelog visitor data Standard server and CDN logs (Cloudflare) Serve and protect public pages Legitimate interests

We do not process special-category data by design and do not direct the Service at children.

4. AI processing

Draft release notes are generated by large language models through third-party inference APIs. In production we use DeepInfra (DeepSeek V4 Flash), Groq (OpenAI GPT-OSS 120B), and xAI (Grok 4.3), with automatic failover between them; the specific models may change as providers retire or release them. What is sent: the PR titles, bodies, and labels for the selected release range, plus your voice and format settings. What is not sent: diffs, file contents, tokens, or credentials.

These calls are routed through Cloudflare AI Gateway in our own Cloudflare account. The gateway records each request and response — the same PR metadata described above and the generated draft, together with the model used, token counts, and latency — so that we can troubleshoot failures and monitor cost. We keep sending our own provider API keys through the gateway; Cloudflare does not add, resell, or bill for inference. Gateway logs are retained on a rolling basis in a capped store (oldest entries are deleted first) and are deleted on request.

We do not use your repository data, drafts, or edits to train, fine-tune, or improve any AI/ML model, and we only use inference providers whose API terms prohibit training on customer API inputs. Prompts are processed transiently to produce your draft. We track token usage and cost per account for billing and abuse control; these metrics contain no PR content. We will update Section 6 before adding or replacing a provider.

No decisions producing legal or similarly significant effects are automated; a human on your account reviews and publishes notes.

5. Retention and deletion

Data Retention
Cached PR metadata and generated drafts While the account exists; deleted immediately with the account, or on request for specific repositories
Repository connections Deactivated immediately on GitHub App uninstall or GitLab integration removal; the GitHub installation token is revoked at GitHub
Slack webhook URLs Encrypted; deleted when you remove the integration or your account
Published changelog content Until you edit it (the page is refreshed) or your account is deleted; removal of a specific published entry on request
Account and billing records Deleted immediately on account deletion; Stripe retains billing records for its statutory obligations
Product events Life of the account; de-identified on account deletion (the account reference is removed)
Error and observability data Sentry retains error events for up to 90 days
LLM gateway logs Rolling, capped store at Cloudflare (oldest entries deleted first); deleted on request
Database recovery window 6 hours of point-in-time history, after which deleted data is unrecoverable

6. Subprocessors and international transfers

Subprocessor Role Data touched Location / transfer mechanism
Neon, Inc. Postgres database hosting All stored data above United States (AWS us-east-1) — Standard Contractual Clauses
Cloudflare, Inc. Application hosting (Workers), Hyperdrive, CDN for public pages, transactional email, AI Gateway (LLM request/response logs) Traffic, cached pages, connection metadata, email content; LLM prompts (PR titles, bodies, labels) and generated drafts Global network — EU-US Data Privacy Framework / SCCs
GitHub, Inc. Source platform (via the GitHub App you install) Repository data at source Per your GitHub agreement
GitLab Inc. Source platform (via the webhook you configure) Repository data at source Per your GitLab agreement
Groq, Inc. LLM inference for note drafting PR titles, bodies, and labels, transiently United States — SCCs
Deep Infra, Inc. LLM inference for note drafting PR titles, bodies, and labels, transiently United States — SCCs
xAI Corp. LLM inference for note drafting PR titles, bodies, and labels, transiently United States — SCCs
Stripe, Inc. Payments and subscriptions Billing data; card data (held by Stripe) EU-US Data Privacy Framework / SCCs
Functional Software, Inc. (Sentry) Error monitoring Error events (authentication tokens redacted; request bodies not sent) EU-US Data Privacy Framework / SCCs
Slack Technologies, LLC Notification delivery (only if you configure a webhook) The release note summary you choose to post Per your Slack agreement

We will provide notice (and, for DPA customers, an objection mechanism) before adding subprocessors. Transfers outside the EEA and UK rely on adequacy decisions, the EU-US Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses.

7. Security

TLS in transit; encryption at rest; application-layer encryption of GitHub installation tokens, GitLab tokens, and Slack webhook URLs; GitHub webhook HMAC signature verification and GitLab secret-token verification; per-account authorization isolation; automated CI checks that prevent tokens from being logged; error monitoring configured to redact authentication tokens; spend and abuse alerting; multi-factor authentication (TOTP) and passkeys; all sessions revoked on password reset; SOC 2-audited infrastructure providers (Neon, Cloudflare). Report security issues to legal@getshipnotes.app.

8. Cookies

The dashboard uses strictly necessary session cookies (Better Auth). We run no third-party analytics or advertising cookies. Public changelog pages set no tracking cookies.

9. Your rights

EEA/UK (GDPR): access, rectification, erasure, restriction, portability, objection, and the right to complain to the supervisory authority in your country of residence or work. For repository-derived personal data where we act as processor (e.g., you are a developer whose handle appears in a customer's PRs), we will route or support the request with the relevant customer, as Article 28 requires. You can export your account data at any time from Settings and delete your account from Settings → Danger zone.

California (CCPA/CPRA): rights to know and access, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as defined by the CPRA and do not use sensitive personal information beyond providing the Service. We do not discriminate for exercising rights. Requests: legal@getshipnotes.app; we verify via your account; authorized agents are accepted with written permission. We respond within 45 days (extendable once as the law allows).

10. Published changelogs — third-party content

Content on hosted changelog pages is published by the respective customer, who is responsible for it. To request removal of content about you (including personal data a customer published), or to report abuse, contact legal@getshipnotes.app; we will act under the Acceptable Use Policy takedown process and applicable law.

11. Changes and contact

Material changes will be notified by email or in-product before taking effect. We have not appointed a Data Protection Officer or an EU/UK representative; direct all privacy enquiries to QVANS LLC, 3955 Greenfield Ct, Boynton Beach, FL 33436, legal@getshipnotes.app.

ShipNotes© 2026 MK Cloud Technologies
PricingDocsFAQGuidesGlossaryGitHub App
TermsPrivacyDisclaimersAcceptable Use