Skip to content

Company policy

Privacy policy

What ShipReady collects when you run a Launch Risk Check or buy a product, how long it is kept, and how to have it deleted.

Last updated September 14, 2026

Who we are

ShipReady is operated by TechTide AI LLC, Columbus, Ohio, United States. We provide launch assurance services for applications built with AI development tools. Questions about this policy, or about the data we hold on you, go to Alex@techtideai.io and we answer within five business days.

What the free check collects

The Launch Risk Check reads the public pages and JavaScript bundles of a URL that the submitter has confirmed they own or are authorized to test. We do not sign in to your application, we do not use credentials, and we do not read anything that a member of the public visiting your site could not also request.

When you run a check we store:

  • The URL you submitted and the final URL after redirects.
  • The six answers you declared about how the app was built and what it handles.
  • Your confirmation that you own the app or are authorized to test it.
  • The findings we observed, and the list of items we could not verify.
  • A one-way hash of your IP address, the referring page, any utm values in the link you arrived through, and your browser user agent string. The raw IP address is never written to our database.
  • Your email address, only if you chose to enter one to receive the results.

Findings that look like credentials

One of our observed checks looks for server-side keys that have been published into a browser bundle by mistake. When we find a value that matches a known key pattern, it is masked at the moment of capture. We record the pattern type, the file path, and a short masked prefix. The full value is never stored, never displayed on a results page, and never sent by email. If you believe a live key has been exposed, rotate it with the provider that issued it.

How long we keep things

  • Check records, including findings and declared answers, are kept for 90 days and then deleted.
  • Account records, purchase entitlements, intake submissions, and delivered work are kept while your account exists, because you need them to access what you bought.
  • Payment records are held by Stripe under their own retention rules. We do not store card numbers or bank details at any point.

Accounts and email

Buying a product creates an account tied to your email address. Sign-in uses a one-time code sent to that address, so there is no password for us to store. We use your email to send receipts, the confirmations and delivery notices tied to your purchase, and replies to messages you send us. We do not sell your data and we do not share it for advertising.

Service providers

We use a small set of processors to run the service: Lovable Cloud for hosting, the database, and authentication, Stripe for payments and the card details we never see, PostHog for product analytics, and Resend for email delivery. Each receives only what it needs to perform its function.

PostHog records page views and a short list of named product events, such as a check being created or a purchase completing. Text on the page is masked before it is sent, nothing is captured automatically from clicks or keystrokes, and the script only loads after your first interaction with the page.

Cookies and browser storage

We use three categories, and none of them are advertising cookies:

  • Necessary. The sign-in session set by Lovable Cloud, and the payment provider cookies Stripe sets on its own checkout.
  • Preferences. Short lived entries in your browser that remember the address you last checked, that you hid the bar offering the check, and where you arrived from.
  • Analytics. The PostHog identifier described above, used to count visits and the named product events.

Your choices

You can ask us for a copy of the data tied to your email address, ask us to correct it, or ask us to delete it. Write to Alex@techtideai.io from the address on the account. We action deletion requests within 30 days, except where we are required to retain transaction records for tax and accounting purposes. If you are in a jurisdiction with statutory data rights, such as the EU, the UK, or California, those rights apply to you and this is the address to use.

Children

ShipReady is a business service and is not directed at anyone under 16. We do not knowingly collect data from children.

Changes

If this policy changes in a way that affects what we collect or how long we keep it, we update the date at the top of this page and, for account holders, send a note by email.

Check your app

Run all sixteen groups on your published address and see the evidence behind every result.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026