Privacy, in plain language.
Shipshape uses GitHub OAuth to identify you and make authorized, read-only requests about public repositories. It requests read:user; it does not request the broad repo scope.
OAuth access tokens are stored only in encrypted authorization properties. They are never put in URLs, logs, tool output, or rendered pages.
The dashboard keeps an eight-hour session in an HttpOnly cookie. Its GitHub token is encrypted with a key derived from that cookie before it is stored in Cloudflare KV. Rules you choose to save are stored in KV under your GitHub login until you replace them.
Short-lived OAuth state and grants are stored in Cloudflare KV. You can revoke access from GitHub or your MCP client. Shipshape does not sell personal information and does not clone or execute repository code.