The short version
Shipwrite has no accounts and does not ask for your name or email. It stores the app you upload, a random identifier in your browser so you can manage your previews, and anonymous counts of visits. It does not sell data or use advertising trackers.
What Shipwrite stores
- Your uploaded project. The source archive is stored privately and encrypted, and is deleted 14 days after the preview is created (it stops running after seven), or sooner if you delete the preview.
- App data. If your app uses a SQLite database of up to 25 MB, Shipwrite saves a copy when the app sleeps so it can restore it on wake. It is deleted with the preview.
- Preview details. The name you gave the project, its type, status, and timestamps.
- An owner cookie.
__Host-shipwrite_owneris a random value kept for 30 days that lets this browser manage the previews it created. Shipwrite stores only a hash of it. - A visitor cookie.
shipwrite_visitoris a random value kept for up to one year, used only to count unique browsers on Shipwrite and on previews. Shipwrite stores a hash of it for at most 400 days. It is not set when your browser sends Do Not Track or Global Privacy Control. - Your network address. It is used to apply rate limits. A keyed hash of it is kept on each preview you create, so that an abusive network can be blocked; the address itself is not stored by Shipwrite. Shipwrite's cloud provider also processes addresses in its firewall and load balancer.
- App output. The last output of a running app is kept for seven days so the owner and Shipwrite operators can diagnose failures. Shipwrite's own service logs are kept for 14 days.
- A browser check. Before an upload from the website, Shipwrite's firewall (AWS WAF) runs a silent check that the request comes from a real browser and stores a short-lived token cookie,
aws-waf-token. It is not used for tracking. - Agent access. If you approve a coding agent or create an API key, Shipwrite stores a hash of the credential until it expires or you revoke it.
Apps made by other people
A preview link opens an app that someone else built. Shipwrite adds a small “Deployed with Shipwrite” control to the page but does not control what the app itself collects. Treat a preview like any other website you do not know.
Where data is kept and who can see it
Data is stored with Amazon Web Services in the United States. Shipwrite operators can view preview details and app output, and can open stored projects when investigating abuse or a failure. Shipwrite discloses data when the law requires it.
Deleting your data
Delete a preview from the browser that created it and its source and saved data are removed. Everything else expires on the schedule above. If you no longer have that browser, email the preview link to shipwriteai1009@gmail.com and Shipwrite will remove it.
Contact
Privacy questions and requests: shipwriteai1009@gmail.com.