playship
Back to playship.dev

Privacy Policy

Last updated: [DATE]

Placeholder notice: this is a working draft, not a substitute for review by a lawyer licensed in your jurisdiction - especially if you expect users in the EU/UK (GDPR) or California (CCPA), which have specific disclosure and rights requirements this draft only gestures at. Fill in the bracketed fields and have it reviewed before relying on it for a real launch.

This Privacy Policy describes what data playship ("we," "us") collects when you use the CLI, the web dashboard, and related services (together, the "Service"), and what we do with it.

1. What we collect

DataWhy
Email addressAccount identification, login, transactional email (verification, password reset, receipts)
PasswordStored only as a bcrypt hash - we never store or can recover your actual password
Google Play Console service account JSONEncrypted at rest (AES-256-GCM); used only to make Play Developer API calls you request
Firebase service account JSONEncrypted at rest; used only to deploy/manage Hosting sites you request
Your own Anthropic API key, if you provide oneEncrypted at rest; used only for the listing-generation calls you request
App ideas, revision instructions, generated app contentSent to Anthropic's API to generate/revise your app; stored so you can view, download, and revise past versions
Credit ledger (grants, debits, purchases)Tracks your Build credit balance as an append-only history
Payment informationCollected and processed directly by Stripe - we receive only the resulting subscription/customer status, never your card number
IP address (transient)Used only for rate-limiting/abuse prevention; not stored long-term or used for tracking

2. What we don't do

3. Who we share data with

Only the third-party services needed to actually run the Service:

We don't share data with anyone else, except if required by law or to protect against fraud/abuse.

4. Data security

No system is perfectly secure, and we can't guarantee absolute security of your data - but this is what's actually implemented, not aspirational language.

5. Data retention and deletion

We keep your data as long as your account exists. You can permanently delete your account and everything tied to it - credentials, generated projects, credit history - anytime from the dashboard's Account panel. This is immediate and self-service, not a request we process manually. Deleting your account also attempts to tear down any live Firebase Hosting site you published through us and cancel any active subscription; anything that can't be cleaned up automatically is reported back to you so you can finish it yourself.

Some records (e.g., payment history Stripe retains, or what's needed to comply with tax/legal obligations) may persist with our payment processor even after account deletion, per their own retention policies.

6. Your rights

You can access, correct, or delete your personal data through the dashboard at any time. If you're in the EU/UK, California, or another jurisdiction with additional statutory privacy rights (access, portability, restriction, objection, or a "do not sell" request), contact us at the email below and we'll address it - [note: if you expect meaningful EU/UK/California traffic, get a lawyer to review whether this section needs to be built out further, e.g. a formal DPA, a designated representative, or a more detailed legal-basis-for-processing breakdown].

7. Children's privacy

The Service isn't directed at children under 13 (or the relevant minimum age in your jurisdiction), and we don't knowingly collect data from them. Contact us if you believe a child has created an account so we can delete it.

8. International data transfers

The Service's infrastructure runs in [YOUR HOSTING REGION - e.g. "the United States"]. If you're accessing it from elsewhere, your data will be processed there.

9. Changes to this policy

We may update this policy as the Service changes. We'll update the date at the top of this page; for material changes, we'll make a reasonable effort to notify active users by email.

10. Contact

Questions about this policy, or a data access/deletion request beyond what self-service covers: bowwerick@playship.dev