Privacy Policy
Last updated: 7 August 2026
What ShipGate processes
When you run a scan, ShipGate fetches metadata and a small number of files (workflows, manifests, security policy, README) from the GitHub repository you specify, evaluates them in memory, and returns the result to your browser. Repository contents are processed transiently to produce the gate result and are not retained after the scan completes.
What ShipGate stores
- Gate receipts — a short record of a scan (repository name, commit, ruleset, counts, timestamp). Receipts are currently held in server memory only and are lost on redeploy.
- Answers and evidence — your onboarding answers and evidence notes are stored in your own browser (localStorage), not on our servers.
- GitHub tokens — never stored. A token you provide is kept in your browser's session storage and sent only with your scan or fix-PR requests, where it is used for the GitHub API calls of that request and then discarded.
What ShipGate does not do
- No accounts, no tracking cookies, no analytics scripts, no advertising.
- No sale or sharing of any data with third parties.
- No retention of repository source code.
Third parties
Scans call the GitHub API (subject to GitHub's privacy statement). The service is hosted on Railway (subject to Railway's privacy policy), whose infrastructure logs standard request metadata (IP addresses, timestamps) for operations.
Contact
Privacy questions: mulukenermiasdata@gmail.com — ShipGate is operated by Ermaz LLC.