Security & trust

You stay in control. Always.

No fear-mongering, no "bank-grade" theater. Just clear, honest answers about what Shiplore does with your code — and what it never does.

You approve every post

Drafting and strategy are automated; publishing never is. Full-auto is opt-in per platform, and approval is always the default. Nothing goes out in your name without your yes.

Read-only access, revoke anytime

We request read-only GitHub scope on the repos you choose. We cannot write to your code, and you can disconnect in one click — which stops all processing immediately.

Diffs summarized, never posted raw

Your changes are summarized in-flight into a short description of what shipped. That summary powers the draft. Code is never published verbatim or leaked into a post.

Never trained on, never sold

We do not store your source code long-term, do not use it to train any model, and do not sell your data. Trust is the only moat that matters to us.

Specific & truthful

What we do — and don't — with your code

What we do

✓ Read commit messages and diffs from repos you connect

✓ Summarize each diff in-flight to understand what you shipped

✓ Retain that short summary to power and improve your drafts

✓ Store encrypted access tokens scoped to the minimum needed

What we never do

✕ Store your raw source code long-term

✕ Use your code or repos to train machine-learning models

✕ Publish code verbatim or leak repo contents into a post

✕ Post anything without your explicit approval

We won't over-claim "we never see your code" — that would be false, and developers would catch it. We summarize diffs to draft posts. Concrete and honest beats loud and vague.

Under the hood

How we keep it safe

Encryption everywhere

Data is encrypted in transit (TLS) and at rest. Tokens are stored encrypted and access-scoped.

Least privilege

We request the minimum GitHub and X scopes required — read-only on repos, post-on-approval on X.

Export & delete

Download all your data anytime. Delete your account and everything tied to it — processed within 30 days.

Vetted subprocessors

We share data only with the infrastructure needed to run Shiplore — hosting, AI inference, payments — each under strict terms.

Human-in-the-loop

The architecture makes a human approval step structural, not optional. We will never ship an unsupervised auto-poster.

Responsible disclosure

Found something? Email security@shiplore.com. We respond fast and credit researchers who report in good faith.

Read-only. Revocable. Approved by you.

That's the whole deal. Connect a repo, see your first drafts, and disconnect any time you like.

Start free