Last updated: July 5, 2026
When you sign in with GitHub, we request read access to your profile, email address, public repositories, and organization membership. We read repository, commit, and pull request metadata (titles, messages, changed file names, and line counts) only for the items you select. We do not write to your repositories. If you choose "Include private repos", GitHub grants the broader repo scope so we can list your private repositories — we still only read the items you select, and you can revoke this any time from your GitHub settings.
To generate posts, we send the commit/PR metadata you selected (messages, titles, file names, change stats) to OpenAI. We do not send your source code diffs or GitHub access token.
We store your GitHub profile basics (name, email, avatar), an encrypted-at-rest GitHub access token to make API calls on your behalf, your generated posts, monthly usage counts, and — if you subscribe — your Stripe customer and subscription identifiers. Payment card details are handled entirely by Stripe and never touch our servers.
Go to Settings → Delete account. This permanently removes your user record, GitHub tokens, generated posts, and usage history from our database. You can also revoke ShipPost's access from your GitHub settings at any time.
For privacy questions, contact us via the GitHub repository or the email listed on our website.
See also our Terms of Service or return home.