Skip to content

Privacy policy

We audit code, and code is the most sensitive thing you can hand a stranger. So the short version is this: your code is deleted as soon as the scan finishes, the findings follow it 15 days later, and the only personal thing we ever ask for is an email address — to send you your report link when you buy one, or to follow up if you asked for the free repair prompts.

Last updated

Who we are

ShipDoctor is operated by Bowtie.co. This policy covers this website and the audits you run through it. Questions, or a request about your data, go to privacy@bowtie.co.

What we hold, why, and for how long

Everything below is the complete list. If something is not here, we do not have it.

The code you submit — an uploaded archive, or a public repository we clone for you.
It is the thing being audited. It is analysed in a sandbox with restricted network access and is never used to train anything.
The working copy is deleted as soon as the scan finishes. An uploaded archive is kept, encrypted at rest and readable by nobody else, for up to 24 hours — the deeper analysis you get when you buy the report has to read your code again, and that is the only reason it survives the scan. It is deleted the moment that analysis finishes, or when the 24 hours are up, whichever comes first. A repository we cloned is not kept at all: if you buy, we clone it again at the exact commit we graded. What survives either way is the findings, not the code.
The findings: grades, scores, severities, the file and line each finding points at, effort estimates and repair prompts.
They are the report you came for, and what a return link reopens.
Deleted automatically 15 days after the audit runs. There is no archive behind that.
An anonymous audit identifier of the form audit-{uuid}.
It is the whole identity of an audit on our side. Repository names, file paths outside the findings, and tool names are kept out of the payloads this site can see at all.
Deleted with the findings it names, after 15 days.
Your email address — only if you buy a report, or if you give it to open the repair prompts for the findings your free report shows.
If you buy, Stripe sends the receipt and we send one message: the link that reopens your report. If you give it for the repair prompts, the prompts appear on the page and nothing is sent in reply. Either way we also add the address to our mailing list, held with Resend, and may send you occasional messages about ShipDoctor — product news and offers. Every one of those carries an unsubscribe link, and unsubscribing stops them for good; it does not affect a report you have bought.
A purchase address is held by Stripe under their retention rules and by our mail provider as a delivery log. An address given for the repair prompts is also kept in a file on our server, with the anonymous audit identifier and nothing else. The mailing-list copy at Resend is held until you unsubscribe or ask us to delete it — write to us and we will remove it from everywhere we hold it. What we send Resend is the address alone: it is never joined to a repository, to an audit identifier, or to your findings.
Your IP address and request metadata.
Rate limiting, abuse prevention and a daily capacity budget — a scan spends real compute on untrusted code.
Held transiently in rate-limit counters and in server logs, which are kept only as long as we need them to investigate abuse.
A GitHub access token, if you choose "Connect GitHub".
To list the repositories you can see, so you can pick one. The scope we request grants no write access anywhere, and the token is never forwarded to the audit engine — we send it the repository URL, which it clones like any other public repository.
Kept in a cookie your browser holds and our server reads; disconnecting removes it. We never copy it into storage of ours.

How your code and your identity stay apart

An audit is known to our systems as audit-{uuid} and nothing else. The audit engine is never told who submitted a repository, and it never sees an email address: the address lives on the website side, with payment and with the message we send you, and is never written next to the findings or the code they came from.

It works in the other direction too. The report screens receive grades, findings and the file and line each finding points at — not repository names, not the names of the tools we run, and nothing about other people’s audits. Your code is analysed in a sandbox with restricted network access, and it is never used to train a model, ours or anyone else’s.

Who else sees any of it

Four companies, each doing one job. We do not sell data, and there is nobody on this list whose product is advertising.

StripePayments
Your email address and payment details. Card details are entered on Stripe’s own hosted checkout page and never reach our servers.
Cloudflare (Turnstile)Bot check on the submit button
The signals its challenge collects. Turnstile sets no cookie and builds no advertising profile, which is why the site can use it without asking you for consent.
Amazon SESTransactional email
Your email address and the one message we send: your return link after a purchase. Nothing is sent for the free repair prompts.
ResendMailing list
Your email address, and whether you have unsubscribed. Nothing else — not your name, not your audit identifier, and nothing about your code or your findings.
GitHubRepository access, only on the paths that use it
The read-only authorisation you grant, if you connect an account, or nothing at all if you upload an archive.

These providers operate in the United States, so running an audit means your data is processed there.

Cookies and analytics

Most cookies this site sets are necessary for it to work. Analytics and advertising cookies from Google Tag Manager are set only after you Allow on the banner.

sd_audit
Holds the key to your audit. It is httpOnly, so script on the page cannot read it, and it is what lets the report screens prove the audit is yours.
15 days, matching the life of the audit itself.
sd_prompts
Set only if you ask for the repair prompts for the findings shown in your free report: it records that you asked, so the prompts stay on the page instead of asking you again. It holds no email address and no part of your report.
15 days, matching the life of the audit itself.
sd_gh_token, sd_gh_state
Only set if you connect a GitHub account: the read-only token and the one-time value that protects the authorisation round trip.
Until you disconnect, or the browser session ends.

This site can load Google Tag Manager so we can measure how the product is used. The container may start before you answer the banner; until you Allow, Consent Mode keeps advertising and analytics storage denied so tags run in a limited form. Allowing lets those tags use cookies. Saying no keeps storage denied. Nothing about your code or your findings is sent to analytics. Configure tags in the container to mask per-audit paths.

Our bot check, Cloudflare Turnstile, runs on the page where you start an audit. It sets no cookie and builds no advertising profile.

Your choices

  • Wait, and it is gone. Deletion is the default and it is automatic — there is no archive to ask us to empty.
  • Delete sooner. Email privacy@bowtie.co with your audit id and we will remove the findings before the window closes.
  • Disconnect GitHub.If you connected an account, the disconnect control on the intake screen drops the token immediately. You can also revoke our access from GitHub’s own settings.
  • Ask what we hold. Write to us and we will tell you, and correct or erase it where the law gives you that right. Because there are no accounts, we may need the audit id or the email you paid with to find anything at all.

Security

The key to your audit lives in a cookie your browser holds and our server reads; scripts on the page cannot read it. Payment happens on Stripe’s own checkout page, so card details never reach us. Your report is unlocked only by a payment Stripe has confirmed to our servers directly — never by anything your browser tells us.

No system is perfect, and ours audits untrusted code for a living. If you find a security problem here, please write to privacy@bowtie.co before disclosing it publicly.

Children

ShipDoctor is a tool for people who ship software, and it is not directed at children. We do not knowingly collect anything from anyone under 16.

Changes to this policy

If what we do changes, this page changes first, and the date at the top moves with it. A change that materially reduces the protections described here will not be applied retroactively to an audit already run.

The terms that govern buying a report are on the terms of service page.