Privacy policy
What we read from your provider, what we never touch, what becomes public, and how to delete all of it. Written to match what the software actually does.
What this covers
This policy explains what outship collects when you use outship.lol or connect a hosting provider, why we collect it, and how to get rid of it.
It is written to describe what the software actually does, not to describe the widest thing we might one day do.
What we collect
From your provider connection: your username, display name, email address, and account creation date; your project names and their production URLs; and one record per deployment containing its identifier, commit hash, deployment target, build status and timestamp.
Derived from the above: your ship score and its four components, your rank, and your rank movement.
From your use of the site: your email address if you join the waitlist, a salted one-way hash of your IP address used solely to rate-limit that form, and standard server and analytics logs.
Your email address is used only for messages you would expect: confirming your first score, confirming deletion of your account, and telling you when something significant ships. Every one of them carries an unsubscribe link. We do not sell it and we do not send marketing on anyone else's behalf.
We never ask for a password. Authentication happens entirely through your provider.
What we never access
We do not read your source code. We do not read environment variables or secrets. We do not read build or runtime logs. We do not read your customers' data.
Our API client is restricted by an explicit allowlist to the user, projects and deployments endpoints. Any call outside that list fails in code. The access token your provider issues may grant broader permissions than we use; the allowlist is what makes the restriction real rather than a promise.
We do make ordinary public HTTP requests to your production URLs to check they respond. This is how uptime is measured and how a project is confirmed live. It is the same request any visitor makes.
Why we collect it
To compute and publish your ship score and rank — the core function of the service, which you request by connecting.
To keep the ranking honest, by detecting duplicate and manufactured deployments.
To operate the site securely, including rate-limiting abuse of public forms.
Where a legal basis is required, ours is your consent for the public ranking and the waitlist, and our legitimate interest in operating and securing the service.
What is public
Once you connect, your username, ship score, rank, rank movement, deployment count, streak, number of live projects and uptime figure are visible to anyone. Your project names may appear on your profile.
Your email address is never public and is never shown to other users. Your access token is never public and is never sent to the browser. Individual deployment records, commit hashes and rejection reasons are not published.
Who else sees it
We do not sell your data and we do not share it for advertising.
We use service providers to run outship: a hosting provider, a managed Postgres database, and an email provider used only to send the messages you asked for. They process data on our instructions.
We may disclose information where we are legally required to.
How long we keep it
Deployment records and scores are kept while your account is connected.
When you disconnect, or revoke access from your provider dashboard, your account and everything linked to it — provider tokens, projects, deployments, scores and sessions — is permanently deleted. This is a hard delete, not a hidden flag, and it happens automatically when we receive the revocation.
Waitlist email addresses are kept until you unsubscribe, which every email links to.
How it is protected
Provider access tokens are encrypted at rest with AES-256-GCM and are never logged or returned to the browser. Sessions are stored server-side so that revoking access invalidates them immediately.
Traffic is served over HTTPS. Incoming provider webhooks are verified by signature before being processed.
No system is perfectly secure. If a breach affects you, we will tell you.
Your choices
You can disconnect at any time, which deletes your record. You can unsubscribe from any email we send. Where private mode is available, you can be scored without appearing publicly.
outship is operated from India and the Digital Personal Data Protection Act, 2023 applies. Under it you may ask us to confirm what we hold about you, correct or complete it, or erase it, and you may nominate someone to exercise those rights if you cannot.
If you are in the UK, EU or elsewhere with equivalent protections, you may also have rights to access, correct, export, or object to the processing of your data. Write to us and we will action it, wherever you are.
If you appear on outship and do not want to, tell us and we will remove you.
Cookies and contact
We set one essential cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
Questions, data requests and grievances all go to hello@outship.lol, which reaches the person who runs outship directly. We aim to acknowledge within 48 hours and resolve within 30 days.
If this policy changes materially, the last-updated date at the top of this page changes with it.