Legal

Privacy Policy

Effective September 30, 2026 · Version 1.3 · Markdown

This policy explains what Typeship Inc ("Typeship", "we", "us") collects when you use typeship.dev, the console, the Typeship API, CLI, and MCP server, and the endpoints we host for you (together, the "Service"), and what we do with it.

The short version: we collect what we need to run an account and generate your packages, we don't sell it, we don't use it for advertising, we don't train models on it, and we use cookies for sign-in and interface preferences. Product analytics uses browser storage and can associate activity with your account.

What we collect

Account. When you sign up we get your name, email address, and profile picture, from you or from the sign-in method you choose. Passwords are handled by our sign-in provider and stored hashed; we never see them. We also store your organization's name, members, roles, and plan.

Billing. Paid plans are billed by our merchant of record. It collects your payment details, billing address, and tax information directly. We receive the plan, the billing email, and confirmation that a subscription is active, never your full card number.

Projects and content. Project names and settings, where each Spec comes from (a URL or a GitHub repository and path), spec patches, package names, destinations, the Specs themselves, the packages we generate, and pull request contents. While the CLI's webhooks listen relay is running, the webhook deliveries it forwards pass through our servers. If your Specs or webhooks contain personal information about other people, we process it only on your behalf and your own privacy notice applies to it.

One-shot generation. An API contract you paste into typeship.dev or point us to is sent to our servers, turned into a package, and returned to you. Typeship's CLI, MCP server, and SDKs automatically include an idempotency key on generation requests. We cache those responses, including generated files, for a 24-hour replay window so retries return the same result. Direct API requests with an idempotency key work the same way. For an eligible anonymous URL-based run, we keep the URL, selected product and package settings, generation configuration, API title and operation counts, and an opaque claim token for seven days. That is what lets the claim link turn the run into a project after you sign in. Inline runs, authenticated runs, and runs with source headers create no claim. We may process an IP address to enforce rate limits and keep the request log described below.

Logs and billing measurements. Our infrastructure may log requests to the website, console, API, CLI, and hosted endpoints for security and debugging, including the time, IP address, user agent, status, and errors. We record the current number of configured generated products and API operations for billing. We use cookieless web analytics for page-view measurements. Separate product analytics and error reporting measure usage and failures, as described below.

Product analytics and error reporting. We measure actions such as starting and completing a preview, downloading a package, signing up, creating a project, and running generation. These measurements include the type of input and generated package, elapsed time, and a success or error category. Browser identifiers are stored in local storage. When you sign in, analytics can connect earlier anonymous activity in that browser with your account identifier. Server-side project and generation measurements also use your account identifier.

For Typeship's own MCP server, we measure tool discovery and calls, including the tool name, client category, duration, and result status. Signed-in OAuth activity uses your account identifier; organization-key activity uses an organization identifier. These measurements exclude tool arguments and results, API credentials, Definition URLs and contents, and generated files. Product events exclude names and email addresses. Error reports include diagnostic messages and stack locations, with filtering for credentials, URL parameters, and claim tokens. We do not enable automatic click capture or session recordings.

From GitHub. When you install the Typeship GitHub App, GitHub tells us the installing account and the repositories you selected. We use that access only to read Spec files and write the generated files and pull requests you've configured.

Messages. Anything you send us by email or through docs feedback.

We don't knowingly collect sensitive personal information, precise location, or information from children under 18. Please keep such things out of Specs, payloads, and messages.

How we use it

  • To run the Service: accounts, generations, pull requests, hosted endpoints, the webhook relay, billing, and support.
  • To keep it working: monitoring, debugging, understanding website traffic, and measuring how people use the product.
  • To talk to you about the Service: sign-in codes, billing notices, regeneration results, security alerts, and changes to our terms. Product announcements only if you opt in, and you can unsubscribe any time.
  • To enforce limits and prevent abuse.
  • To comply with the law.

We don't sell personal information, use it for targeted advertising, or use your content or generated code to train machine-learning models.

Who we share it with

We use companies that process data for us under contracts that limit what they can do with it. They provide:

Service categoryWhat it doesWhere
Hosting and analyticsHosts the website, console, API, and hosted endpoints; measures page views and product usage; processes error reportsUnited States
Data storageStores account, project, and generation dataUnited States
IdentityHandles sign-in, sessions, and organization membershipUnited States
BillingActs as merchant of record for paid plansUnited States
Connected servicesProvides the repository, registry, or sign-in integration you chooseUnited States

Members of your organization can see your name, email, avatar, and what you did in that organization, such as which projects or keys you created. When you configure a destination, the generated files are published to the repository or registry you chose, with whatever visibility that service gives them.

We'll disclose information if the law requires it, to enforce our terms, or to protect the safety or rights of Typeship, our customers, or others. If Typeship is acquired or merges, your information may go with it; we'll tell you if that changes how it's handled.

Cookies and browser storage

Cookies support authentication and interface preferences. Product analytics also uses local storage, which is separate from cookies.

Cookie categoryPurposeLasts
Authentication sessionKeeps you signed in to the console and APISession or up to 1 year
Authentication refreshRefreshes and protects your sign-in sessionShort-lived
Interface preferencesRemembers whether the console sidebar is open7 days

The site uses local storage for analytics identifiers, a sign-up journey record, and interface preferences such as docs search history. The sign-up journey record is used for up to 24 hours and removed when completion is observed. Analytics identifiers can persist until they are reset or browser storage is cleared.

You can clear cookies and local storage through your browser. Blocking authentication cookies prevents you from staying signed in. Clearing local storage removes identifiers from that browser; it does not delete analytics events already received or prevent new identifiers from being created. Contact us to request deletion of information associated with your account. We do not use advertising cookies.

How long we keep it

Account and organization data until you delete your account or organization. Projects, Specs, and generated packages until the project or organization is deleted. Cached one-shot responses stop replaying 24 hours after the first accepted request. We then delete them. Anonymous generation claim recipes are deleted after seven days. Webhook relay events are deleted 24 hours after we receive them, and relay sessions after 48 hours idle. CLI sign-in sessions expire on their own. Request and security logs are kept for a limited period. Billing measurements and records are kept as needed for billing and tax law. We may keep things longer to resolve disputes or comply with the law.

Your rights and choices

You can see and edit your profile, organization, projects, and keys in the console, download your Specs and packages, and delete projects, keys, your organization (as an admin), or your account. You can revoke Typeship's access in your GitHub or Google settings and uninstall the GitHub App at any time; that stops future access but doesn't delete what we already have, so delete the project or organization for that.

Depending on where you live, you may also have the right to ask for access to, correction of, deletion of, or a portable copy of your personal information, to object to or restrict certain processing, to withdraw consent, and to appeal a decision we make about a request. We don't discriminate against anyone for exercising these rights. To make a request, contact us from the email address on your account.

United States. If you live in a state with a comprehensive privacy law (California, Colorado, Connecticut, Virginia, Texas, Oregon, and others), the rights above apply to you to the extent that law covers us. We don't sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising or profiling with significant effects, and haven't in the past 12 months. The categories we collect are identifiers, commercial information, internet activity, and professional information, for the purposes and recipients described above.

Europe (EEA, UK, Switzerland). Typeship Inc is the controller of the information described here, except information inside your content, for which you're the controller and we're a processor. We process your information to perform our contract with you; for our legitimate interests in keeping the Service secure, working, and improving, in ways that don't override your rights; to comply with legal obligations; and, for product announcements, with your consent. We don't make automated decisions with legal or similarly significant effects. You can complain to your local data protection authority (in the UK, the ICO). Your information is processed in the United States; where required we rely on the EU-U.S. Data Privacy Framework for providers certified under it and the European Commission's Standard Contractual Clauses otherwise. Ask us for a copy of the safeguards if you need one. We haven't appointed an Article 27 representative.

Security

Traffic is encrypted in transit, data is encrypted at rest by our hosting providers, API keys and passwords are stored hashed, access is scoped to your organization, and we keep our own access to production to a minimum. No system is perfectly secure, and we can't guarantee the security of information sent to us.

Where it's processed

Typeship is in the United States and so are our providers. If you use the Service from elsewhere, your information is transferred to and processed in the United States.

Changes

We'll update this page when our practices change and update the date at the top. For material changes we'll email you or post a notice in the console first.

Contact

Typeship Inc.