Privacy notice

How BuiltShip handles data

This notice describes the current founding product, including company briefs, manual migration reviews, optional analytics, email, and scoped provider work.

Effective July 14, 2026

01

Who is responsible

BuiltShip is responsible for the personal data described in this notice when it decides why and how that data is used. Contact builds@builtship.com for privacy questions or requests.

This is a concise founding notice. A written paid scope may add project-specific processors, access rules, or retention terms. Mandatory data-protection law controls if it requires more.

02

Data we collect

Depending on how you use BuiltShip, we collect:

  • Account data such as name, email, Neon Auth user ID, and session data. Authentication credentials are handled through Neon Auth. BuiltShip's application database does not store your full password.
  • Company-brief data such as the idea, current company URL, target market, desired outcome, generated plan, acceptance checks, request status, and contact preferences.
  • Support and communication data such as chat messages, emails, manual review notes, and any materials you choose to provide for a written scope.
  • Payment and build data when relevant, such as Stripe session and payment status, provider project IDs, private repository and deployment URLs, step status, errors, and acceptance evidence. Stripe handles full card details.
  • Technical data such as request logs, IP address, browser and device data, page URLs, security events, and analytics events when those tools are enabled.

Do not put passwords, payment-card data, health information, government identifiers, or other sensitive personal data in a company brief or chat.

03

Public website scans

A public website scan is used only when relevant to a migration review. It requests public HTML without credentials, account cookies, or access to private networks. It can derive the final public URL, response status, page title, description, platform, and visible technology signals. Submitted paths, query parameters, and fragments are discarded before the request; the scanner reads only the public homepage and safe redirects.

BuiltShip processes raw HTML in memory for the scan and does not retain that raw HTML. We may retain the submitted URL and derived summary with your company brief. The source is the public website you asked us to review. A scan does not log into, import, or change the website.

04

Why we use data

We use personal data to:

  • Create and secure accounts, save briefs, and show the correct plan.
  • Review launch and migration requests, prepare a scope, and communicate.
  • Process accepted payments and provision only the resources in scope.
  • Operate, debug, protect, and improve BuiltShip.
  • Keep records needed for tax, accounting, disputes, and legal duties.

Our legal bases are performance of a contract or steps you request before a contract, legitimate interests in operating and securing the service, legal obligations, and consent where law requires it for non-essential analytics or communications. You can withdraw consent without affecting earlier lawful use.

A human reviews founding launch and migration requests. BuiltShip does not currently make solely automated decisions that produce legal or similarly significant effects about you.

05

Analytics and email

BuiltShip does not currently run product analytics or session replay. Named product-event hooks exist in the application but send no data. We will update this notice and provide an in-product grant, reject, and revoke control before enabling any non-essential analytics.

Brevo may process your name, email, company name, request summary, or message when it delivers account, service, support, abandonment, or owner-notification email. Operational messages are used to provide the service. Marketing email, if introduced, will follow the consent or opt-out rules that apply.

06

Who receives data

We share only what is relevant to the service or accepted scope:

  • Neon for authentication, BuiltShip's database, and a generated database only when that build is accepted.
  • Vercel for BuiltShip hosting, request logs, and a generated deployment only when relevant.
  • Brevo for service email and PostHog for analytics when enabled.
  • Stripe for checkout, payment, and subscription records when you enter a paid path.
  • GitHub for a private generated source repository when included in a paid build.
  • Professional advisers, regulators, courts, or authorities when reasonably necessary to comply with law, protect rights, or resolve a dispute.

These providers may process data in other countries. Where data-protection law applies, transfers must use an applicable adequacy decision, contractual safeguards, or another lawful transfer mechanism. Contact us for the current project-specific provider list or safeguard information.

07

Retention and deletion

We retain account and company-plan data while your account or request is active and for as long as reasonably needed to provide the service, protect it, resolve disputes, and meet legal, tax, and accounting duties. A pending claim token expires after 24 hours. Unclaimed briefs are scheduled for deletion after 48 hours, including their derived public-scan summary.

Raw public-scan HTML is not retained. Derived scan results, paid-scope records, provider IDs, acceptance evidence, emails, logs, and analytics are retained according to their purpose and applicable provider settings. We delete or anonymize data when it is no longer needed, subject to legal holds, security records, backups, and records we must keep.

Founding access does not yet include self-service deletion. Email a request to the address above. We may verify your identity. Deleting BuiltShip data does not automatically delete a customer-controlled or separately contracted Neon, Vercel, GitHub, Stripe, or domain account.

08

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive your personal data, and to object to some processing. You may also withdraw consent and complain to your local data-protection authority.

Send a request to builds@builtship.com. UK users can also contact the Information Commissioner's Office. EEA users can contact the supervisory authority where they live or work.

09

Security, children, and changes

BuiltShip uses access controls, signed claim tokens, tenant checks, private generated repositories, input validation, and encrypted provider connections. No internet service can promise perfect security.

BuiltShip is a business service for adults and is not directed to children. Contact us if you believe a child submitted personal data.

We may update this notice when the product, providers, or legal requirements change. We will change the effective date and provide additional notice when required. See the Terms of Service for service conditions.