Who we are
ShipDoctor is operated by Bowtie.co. This policy covers this website and the audits you run through it. Questions, or a request about your data, go to privacy@bowtie.co.
What we hold, why, and for how long
Everything below is the complete list. If something is not here, we do not have it.
- The code you submit — an uploaded archive, or a public repository we clone for you.
- It is the thing being audited. It is analysed in a sandbox with restricted network access and is never used to train anything.
- Deleted as soon as the audit finishes, along with its working directory. What survives is the findings, not the code.
- The findings: grades, scores, severities, the file and line each finding points at, effort estimates and repair prompts.
- They are the report you came for, and what a return link reopens.
- Deleted automatically 15 days after the audit runs. There is no archive behind that.
- An anonymous audit identifier of the form audit-{uuid}.
- It is the whole identity of an audit on our side. Repository names, file paths outside the findings, and tool names are kept out of the payloads this site can see at all.
- Deleted with the findings it names, after 15 days.
- Your email address — only if you buy a report, or if you give it to open the repair prompts for the findings your free report shows.
- If you buy, Stripe sends the receipt and we send one message: the link that reopens your report. If you give it for the repair prompts, we keep it so we can follow up about that audit — the prompts themselves appear on the page, and no email is sent. There is no list and no marketing.
- A purchase address is held by Stripe under their retention rules and by our mail provider as a delivery log. An address given for the repair prompts is kept in a file on our server, with the anonymous audit identifier and nothing else, until we delete it — write to us and we will remove it sooner. Either way it is never joined to a repository or stored beside the findings.
- Your IP address and request metadata.
- Rate limiting, abuse prevention and a daily capacity budget — a scan spends real compute on untrusted code.
- Held transiently in rate-limit counters and in server logs, which are kept only as long as we need them to investigate abuse.
- A GitHub access token, if you choose "Connect GitHub".
- To list the repositories you can see, so you can pick one. The scope we request grants no write access anywhere, and the token is never forwarded to the audit engine — we send it the repository URL, which it clones like any other public repository.
- Kept in a cookie your browser holds and our server reads; disconnecting removes it. We never copy it into storage of ours.
How your code and your identity stay apart
An audit is known to our systems as audit-{uuid} and nothing else. The audit engine is never told who submitted a repository, and it never sees an email address: the address lives on the website side, with payment and with the message we send you, and is never written next to the findings or the code they came from.
It works in the other direction too. The report screens receive grades, findings and the file and line each finding points at — not repository names, not the names of the tools we run, and nothing about other people’s audits. Your code is analysed in a sandbox with restricted network access, and it is never used to train a model, ours or anyone else’s.
Who else sees any of it
Four companies, each doing one job. We do not sell data, and there is nobody on this list whose product is advertising.
- Stripe — Payments
- Your email address and payment details. Card details are entered on Stripe’s own hosted checkout page and never reach our servers.
- Cloudflare (Turnstile) — Bot check on the submit button
- The signals its challenge collects. Turnstile sets no cookie and builds no advertising profile, which is why the site can use it without asking you for consent.
- Resend — Transactional email
- Your email address and the one message we send: your return link after a purchase. Nothing is sent for the free repair prompts.
- GitHub — Repository access, only on the paths that use it
- The read-only authorisation you grant, if you connect an account, or nothing at all if you upload an archive.
These providers operate in the United States, so running an audit means your data is processed there.
Your choices
- Wait, and it is gone. Deletion is the default and it is automatic — there is no archive to ask us to empty.
- Delete sooner. Email privacy@bowtie.co with your audit id and we will remove the findings before the window closes.
- Disconnect GitHub.If you connected an account, the disconnect control on the intake screen drops the token immediately. You can also revoke our access from GitHub’s own settings.
- Ask what we hold. Write to us and we will tell you, and correct or erase it where the law gives you that right. Because there are no accounts, we may need the audit id or the email you paid with to find anything at all.
Security
The key to your audit lives in a cookie your browser holds and our server reads; scripts on the page cannot read it. Payment happens on Stripe’s own checkout page, so card details never reach us. Your report is unlocked only by a payment Stripe has confirmed to our servers directly — never by anything your browser tells us.
No system is perfect, and ours audits untrusted code for a living. If you find a security problem here, please write to privacy@bowtie.co before disclosing it publicly.
Children
ShipDoctor is a tool for people who ship software, and it is not directed at children. We do not knowingly collect anything from anyone under 16.
Changes to this policy
If what we do changes, this page changes first, and the date at the top moves with it. A change that materially reduces the protections described here will not be applied retroactively to an audit already run.
The terms that govern buying a report are on the terms of service page.