ShipNotes — Terms of Service
Provider: QVANS LLC, 3955 Greenfield Ct, Boynton Beach, FL 33436 ("Qvans", "we") · Contact: legal@getshipnotes.app · Governing law: Florida, USA · Effective date: September 15, 2026
These Terms of Service ("Terms") govern use of ShipNotes (getshipnotes.app), a hosted web service that connects to your GitHub or GitLab repositories, uses AI to draft release notes from your merged pull requests, and hosts a public changelog page with an RSS feed and optional Slack notifications. ShipNotes is a business tool; by creating an account you confirm you act for a business or professional purpose and, if you accept for an organization, that you are authorized to bind it ("Customer", "you").
1. The Service
1.1 What ShipNotes does. After you install the ShipNotes GitHub App on repositories you select (or connect a GitLab project with a webhook token), the Service: (a) receives release and tag webhooks; (b) collects merged pull-request titles, bodies, labels, and merge dates for the release range — it does not read diffs or your source tree; (c) generates draft release notes using an AI model; (d) lets you edit and explicitly publish notes to your hosted changelog page and RSS feed, and optionally post to a Slack incoming webhook you configure; and (e) sends related transactional email.
1.2 Web service only. No software is distributed for installation; access is via browser and the GitHub App or GitLab webhook.
1.3 Modifications. We may improve or modify the Service. We will not materially degrade core functionality during a paid period without notice.
2. Your repository data — confidentiality and AI training
2.1 Confidential information. Pull-request titles, bodies, labels, and related repository metadata that the Service accesses ("Repository Data") are your Confidential Information. We will: (a) use Repository Data solely to generate and manage your release notes and operate the Service for you; (b) not disclose it to anyone except the subprocessors listed in the Privacy Policy, each bound by confidentiality and use restrictions; (c) protect it with the measures in Section 8; and (d) delete it as described in Section 9.
2.2 No training by us; providers bound not to train. We do not use Repository Data, your drafts, or your edits to train, fine-tune, or improve any AI or machine-learning model. Repository Data is sent to our AI inference providers transiently, solely to generate your notes, and we only use providers whose API terms prohibit training on customer API inputs. The current providers are named in the Privacy Policy (Section 6). Any future feature that would use aggregated, de-identified content to improve the product would be strictly opt-in and separately documented.
2.3 Least privilege. The GitHub App requests read-only Contents, Metadata, and Pull requests permissions and subscribes only to release, push (tags), and installation events. We will not expand permissions without your acceptance through GitHub's permission-update flow. The GitLab integration receives only the tag-push webhooks you configure and uses the access token you provide.
2.4 Uninstall. Uninstalling the GitHub App revokes our access: the installation is deactivated, its repositories stop syncing, and the installation token can no longer be used. Cached Repository Data is deleted per Section 9.
3. Publishing and your responsibility for published content
3.1 You control publication. Draft notes remain private to your account until a member of your account publishes them. Publication is an explicit, logged action; nothing is published automatically.
3.2 Published content is yours and your responsibility. You are solely responsible for what you publish to your changelog page, RSS feed, and Slack — including anything sensitive that entered a PR title or body (secrets, security details, unannounced features, third-party names). Review drafts before publishing; the publish dialog reminds you. You can edit a published note at any time and the public page is refreshed. To remove a published note or page entirely, contact legal@getshipnotes.app and we will take it down promptly.
3.3 Hosted pages. Your public changelog is served at getshipnotes.app/changelog/<your-slug> with an RSS feed. You must have rights to all content you publish. We may remove content that violates the Acceptable Use Policy or applicable law, with notice where practicable (see the AUP takedown process).
4. AI-generated drafts
Drafts are generated by large language models from your PR data. AI output may be inaccurate, incomplete, may omit or misdescribe changes, or phrase things badly, even when it looks polished. We do not warrant the accuracy of any draft. Drafts are suggestions; your published notes are your content (Section 3). Do not rely on ShipNotes as your only channel for legally required disclosures (e.g., security advisories) without human review.
5. Accounts, plans, billing
5.1 Accounts. Keep credentials secure; you are responsible for activity under your account. Owner and admin roles control billing, membership, and destructive actions. Multi-factor authentication (TOTP) and passkeys are available in Settings → Security.
5.2 Plans and fees. The Free plan allows 1 active repository. Paid plans are Starter ($19/month, up to 3 active repositories), Pro ($49/month, unlimited repositories), and Enterprise ($99/month, unlimited repositories). Prices are in US dollars, billed by Stripe on a monthly recurring basis, and renew automatically until cancelled. Plan limits are metered on active repositories and enforced in-product. Current features per plan are listed on the pricing page.
5.3 Cancellation. Cancel anytime from Billing with effect at the end of the current paid period; access continues until then. Cancellation is at least as easy as sign-up. No refunds for partial periods except where required by law.
5.4 Price changes take effect at your next renewal after at least 30 days' notice. Failed payments trigger a payment-failure email; continued failure may lead to downgrade or suspension.
6. Intellectual property
6.1 Your content. As between the parties, you own your Repository Data, the generated release notes (drafts and published), your edits, and your published changelog. We assign to you all right, title, and interest we may have in generated notes and claim no rights in your source data.
6.2 Our IP. We own the Service, software, and templates. You receive a non-exclusive, non-transferable right to use the Service during your subscription.
6.3 License to operate. You grant us the limited rights needed to host, cache, process, and display your content solely to provide the Service (including serving your public changelog to visitors).
6.4 Feedback may be used without obligation.
7. Acceptable use
The Acceptable Use Policy is part of these Terms and governs both dashboard use and content published to hosted changelog pages.
8. Security
We implement: encryption in transit (TLS) and at rest; application-layer encryption of GitHub installation tokens, GitLab tokens, and Slack webhook URLs; webhook signature verification (GitHub HMAC) and secret-token verification (GitLab); per-account authorization isolation; automated checks in CI that prevent tokens from being logged; error monitoring configured to redact authentication tokens and to exclude request bodies; multi-factor authentication and passkeys; and infrastructure from SOC 2-audited providers (Neon, Cloudflare). We do not currently hold our own SOC 2 report. Report vulnerabilities to legal@getshipnotes.app.
9. Data retention and deletion
On uninstall of the GitHub App (or removal of a GitLab integration): the installation is deactivated immediately and its repositories stop syncing; the installation token is revoked at GitHub and can no longer be used. On account deletion (Settings → Danger zone, owner only): the account and everything under it — members, repositories, releases, cached Repository Data, drafts, published notes, changelog pages, and subscription records — are deleted immediately, the Stripe subscription is cancelled, and GitHub App installations used only by that account are revoked. Product analytics events are retained in de-identified form (the account reference is removed). Minimal billing records are kept by Stripe as required for tax and accounting. Our database provider keeps a point-in-time recovery window of 6 hours, after which deleted data is unrecoverable. You may also request deletion of cached Repository Data for specific repositories at legal@getshipnotes.app.
10. Warranties and disclaimers
EXCEPT AS EXPRESSLY STATED, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. WE DO NOT WARRANT UNINTERRUPTED OPERATION, THAT AI DRAFTS WILL BE ACCURATE OR COMPLETE, OR THAT THIRD-PARTY SERVICES (GITHUB, GITLAB, SLACK, STRIPE, GROQ, DEEPINFRA, XAI, NEON, CLOUDFLARE) WILL BE AVAILABLE. MANDATORY RIGHTS UNDER APPLICABLE LAW ARE UNAFFECTED.
11. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW: (a) NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOST PROFITS, REVENUE, OR DATA; (b) WE ARE NOT LIABLE FOR LOSSES ARISING FROM CONTENT YOU PUBLISH OR FROM MISSED OR INACCURATE RELEASE COMMUNICATIONS WHERE THE REVIEW-AND-PUBLISH CONTROLS OPERATED AS DESIGNED; AND (c) EACH PARTY'S AGGREGATE LIABILITY IS CAPPED AT THE FEES PAID OR PAYABLE BY YOU IN THE 12 MONTHS PRECEDING THE EVENT. THE CAP IN (c) DOES NOT APPLY TO A BREACH OF SECTION 2 (CONFIDENTIALITY AND AI TRAINING), WILFUL MISCONDUCT, GROSS NEGLIGENCE, OR LIABILITY THAT CANNOT BE LIMITED UNDER APPLICABLE LAW.
12. Indemnity
You will indemnify us against third-party claims arising from content you publish, your breach of the AUP, or your violation of law. We will indemnify you against third-party claims that the Service (excluding your content) infringes their intellectual-property rights.
13. Data protection
The Privacy Policy describes our processing of personal data. For repository-derived personal data (e.g., PR author handles), we act as your processor. A Data Processing Addendum incorporating the EU Standard Contractual Clauses is available on request at legal@getshipnotes.app and, where executed, prevails over the Privacy Policy for that data.
14. Suspension and termination
We may suspend or terminate for material breach (including AUP violations and non-payment) with notice where practicable, or immediately for security or legal risk. You may terminate at any time (Section 5.3 and Section 9). Sections 2 (surviving confidentiality), 3.2, 6, 9–12, and 15 survive termination.
15. General
Governing law and venue. These Terms are governed by the laws of the State of Florida, USA, without regard to conflict-of-laws rules. Disputes will be brought exclusively in the state or federal courts located in Florida, and each party consents to their jurisdiction. Changes. Material changes to these Terms are notified by email or in-product at least 30 days before taking effect; continued use after that date is acceptance. Assignment only with consent, except that either party may assign to an affiliate or in a merger, acquisition, or sale of substantially all assets. Entire agreement: these Terms, the Acceptable Use Policy, the Privacy Policy, and (where executed) the DPA and any order form; an order form prevails on conflict. Notices: to us at legal@getshipnotes.app; to you at your account email. GitHub is a trademark of GitHub, Inc.; GitLab of GitLab Inc.; Slack of Slack Technologies, LLC; Stripe of Stripe, Inc. ShipNotes is not affiliated with or endorsed by any of them.
Related documents: Privacy Policy · Acceptable Use Policy · Disclaimers