Privacy Policy

Last updated: September 1, 2026

This policy describes how ShipStable, operated by RADLAB LLC, handles data across its web and native applications. Questions and privacy requests can be sent to privacy@shipstable.io.

Data We Handle

CategoryExamples and purposeStorage
Account and profileEmail, display name, profile image, account ID, authentication session, and workspace membership used to sign you in and operate your account.Supabase and ShipStable application databases while the account is active and as needed to process a verified deletion request.
Workspace and agent configurationWorkspace names, agents, routes, integrations, schedules, endpoints, settings, and provider credentials you configure to run the service.ShipStable application storage. Credentials are operational secrets and are not sent to product-analytics services.
AI requests and responsesPrompts, relevant conversation context, tool input, and model output needed to complete the request you initiate.Transits the ShipStable backend and your selected AI provider. The inspected backend does not currently write prompt or response bodies into its chat-message table. Native apps may keep a protected local cache for up to 24 hours, capped at 1 MiB for snapshots and 1 MiB for chat details.
Chat-session metadataSession title, summary, model, status, timestamps, connector count, and account/workspace ownership used to list and reopen sessions.Stored server-side in the ShipStable application database. This is distinct from prompt and response bodies.
Usage and billingProvider, model, token counts, credit usage, purchase state, subscription entitlement, timestamps, and failure status used for billing, limits, support, and abuse prevention.ShipStable, RevenueCat, the applicable app store, Stripe, and payment infrastructure as applicable to the purchase path.
DiagnosticsCrash details, stack traces, application route, device or runtime information, and performance traces used to diagnose failures.Sentry and ShipStable operational systems. Default PII collection and Sentry session replay are disabled in the inspected configurations.
Optional product analyticsPage or screen views, feature interactions, pseudonymous device/browser identifiers, and account ID when signed in.PostHog, Statsig, and Vercel only under the consent behavior described below. Analytics identity excludes email. Consented Statsig session replay can reconstruct in-product interactions.

Analytics and Consent

  • Web PostHog: capture is off by default. After you opt in, signed-out events use a pseudonymous browser identifier and signed-in events may be linked to your ShipStable account ID. Email and prompt content are not included in the configured identity.
  • Web Statsig: feature flags may evaluate for application functionality. Session replay and auto-captured interaction analytics are loaded only after Statsig analytics consent.
  • Vercel Analytics and Speed Insights: event delivery is blocked until you grant that service consent.
  • iOS and Android: optional product analytics and feature-flag telemetry default off and start only after you enable “Share product analytics” in Settings. The configured identity uses account ID, not email. Crash diagnostics are controlled separately.

On the web, use “Manage cookies” in the footer to change optional consent. In native apps, use the Settings toggle. Withdrawal stops future optional capture and resets the configured analytics identity.

Local Native-App Caches

The native command-center cache can contain workspace summaries and chat content. iOS stores it in a non-backed-up caches directory using complete file-protection writes. Android stores it in a distinct encrypted preference file backed by Android Keystore and excludes it from cloud backup and device transfer. Entries expire after 24 hours, are size-bounded, and are cleared when you sign out or change accounts. Legacy plaintext cache entries are deleted rather than migrated.

Service Providers

Depending on the features you use, data may be processed by:

  • Supabase for authentication, database, and object storage.
  • Vercel and ShipStable backend infrastructure for web delivery and request routing.
  • OpenAI, Anthropic, or another provider you select to perform AI requests.
  • Sentry for error and performance diagnostics.
  • PostHog, Statsig, and Vercel for consent-controlled product analytics.
  • RevenueCat, Apple, Google, Stripe, or related payment services for purchases and entitlements.

ShipStable does not sell personal information. AI-provider handling is also governed by the provider terms and settings applicable to the account or managed service used for the request.

AI-Generated Content

ShipStable uses large language models from providers you select, such as Anthropic (Claude) and OpenAI, to generate some of the text you see in the product. Model providers may embed industry-standard, machine-readable provenance signals (“watermarks”) in generated text to comply with laws such as the EU AI Act. These signals identify text as AI-generated; they contain no information about you and do not affect how the product works. Where ShipStable presents AI-generated content, it is labeled as such or is clear from the context of the feature.

Security

ShipStable uses TLS for network transport, authenticated access controls, resource-level authorization, protected local storage, and the encryption-at-rest capabilities of its hosting and storage providers. No system can guarantee absolute security; report a suspected issue to security@shipstable.io.

Retention

Protected native cache entries expire after 24 hours. Account, workspace, chat-session metadata, and usage records are otherwise retained while needed to provide the service, administer purchases, protect the service, and meet applicable legal obligations. ShipStable does not currently promise a single automatic deletion period for all server records or analytics vendors. Contact us for the current scope applicable to a particular request.

Account and Data Deletion

The current Settings action opens our public deletion-request page; it does not itself execute an automated backend deletion. To request deletion, follow the verified instructions at shipstable.io/delete. We verify ownership and confirm the request scope and expected timing before processing. Some purchase, tax, fraud-prevention, security, or legal records may need to be retained where applicable.

Your Choices and Rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing of personal data, and to withdraw consent. Email privacy@shipstable.io to exercise a request. Identity verification may be required.

Children

ShipStable is a business and developer productivity service and is not directed to children under 13. Contact us if you believe a child has provided personal information.

Changes and Contact

Material changes will be reflected by the date above and communicated where required. Contact privacy@shipstable.io.

Privacy — ShipStable | ShipStable