What we keep, and what we throw away on purpose.
A security scanner that hoards your data is a liability, not a product. Here is exactly what happens to it.
Last updated 25 July 2026
The short version
ShipShape scans web apps and tells you what is wrong with them. To do that it has to look at your site, and sometimes it has to look at data your site is exposing. This page says exactly what we keep from that, and what we deliberately throw away.
We do not sell your data. We do not sell anyone else's data that we find while scanning yours.
What we store when you run a scan
A scan record contains:
- The address you asked us to scan, and when.
- The findings: what class of problem, where, how severe, and the evidence needed to prove it.
- Which checks ran and which did not, so the report can say honestly what was covered.
- Your email address, if you created an account or subscribed to monitoring.
What we deliberately do NOT store
If we find that your database is readable by strangers, we have to make the request that returns a row in order to prove it. We record the COLUMN NAMES and the number of rows returned. We do not record, log, or display a single cell of the data itself.
This is enforced in the code and covered by an automated test that plants a fake person's name, email, phone number and card number in a test database and fails the build if any of them appear anywhere in a finding or a report. The reason is simple: our report gets emailed and forwarded, and a report containing your customers' data would be a second copy of the breach we are telling you about.
The same applies to a configuration file we find published on your site. We report that it is reachable. We do not reprint what is in it.
Secret values
If we find an API key or password exposed in your site's code, what we show depends on whether you have proved you control the site.
On a free scan, where nobody has proved anything, the value is masked. You can see that a key is exposed and where it is, but not the working key itself. Otherwise the free tier would be a way for a stranger to harvest other people's credentials.
Once you have verified you control the site, you see the value in full, because you need it to find and rotate the key.
How long we keep things
Full scan reports are kept for 90 days and then deleted. A short summary row — the date, the verdict, the number of confirmed findings — is kept for up to 400 days so that monthly monitoring can show you a trend. That summary contains no evidence and no data from your site.
If you stop monitoring, we delete the monitoring record outright rather than marking it inactive.
Who else sees it
Plain-English explanations in your report can be written by an AI model (Anthropic). This only happens for the bundled demo target that we own. For any real site you scan, the wording is produced locally from templates and no finding evidence leaves our systems. When AI has been used, the report says so on its face.
We use Vercel for hosting, Upstash for storage, and Resend for email. They process data on our behalf in order to run the service.
We do not use your scan data to train any AI model.
Analytics and telemetry
If you consent, we record the ORIGIN of a scanned site — the domain only, with the path and query stripped — together with counts of findings by severity. We do not record the findings themselves in that telemetry. You can decline and the scan works identically.
Your report is yours
You can download your report and the machine-readable findings file at any time, with no account and no email address required. Ask us to delete your data and we will.
Contact
Email hello@shipshapelabs.com for anything on this page, including deletion requests.
These pages describe how ShipShape actually behaves and were written to be accurate rather than to be comprehensive legal cover. They have not been reviewed by a solicitor. Get that review before taking payment.