Skip to content
Dashboard
Menu Legal · Privacy Policy

Legal

Privacy Policy

What ship.page (Bitgate, Inc.) stores, why, and for how long. The short version: we run an ephemeral hosting service, not an ad network — we collect the minimum needed to operate and bill.

What we store

  • Drop content and metadata. The files you deploy, plus the drop's slug, timestamps, file count, owner (if authed), and expiry. Anonymous deploys are not tied to any identity.
  • Account data (only if you sign in): your sign-in identity (Google, Apple, or GitHub) via Firebase — a Firebase user ID, your email address, and an internal account ID.
  • Password protection. Protected drops store a salted password hash, not the password. Unlocking sets an essential, host-only browser session cookie valid for 12 hours; it is not used for analytics or cross-drop tracking. Passwords are not included in API responses or telemetry.
  • API keys. Stored only as a SHA-256 hash plus a short display prefix. We cannot recover a lost key.
  • Email preferences. Per-category opt-in/out flags for your account.
  • Billing state. Payments are processed by Stripe; we never see or store card numbers. We store only your plan status, keyed by account ID.
  • Drop visit telemetry. When someone views a drop, we record server-side: the slug, the path, the referring site's hostname, and the visitor's country. No IP addresses, tracking cookies, user accounts, or third-party analytics scripts are recorded or added for this telemetry. Retained 90 days, then deleted.
  • MCP/API telemetry. Which API/MCP methods were called, client name and version, and whether the call was authenticated. No payloads, keys, or IPs. Retained 90 days.
  • Marketing-site analytics. The ship.page website itself uses Google Analytics and Simple Analytics. This applies to ship.page only — drops never load our analytics or any third-party script from us.

What we never do

We do not sell data, run ads, fingerprint visitors, or track people across drops. We do not inject anything into your content. Drop URLs may be checked against automated threat lists (such as Google Safe Browsing) to detect abuse like phishing and malware; drop content is never used for advertising or profiling.

Who processes the data

  • Cloudflare — edge hosting and file storage (drops are served from Cloudflare's network, which keeps its own standard edge logs);
  • OVH — database hosting, located in the EU;
  • Stripe — payment processing;
  • Google (Firebase) — sign-in for accounts;
  • Google Analytics and Simple Analytics — marketing-site analytics only.

Retention

Anonymous-drop rows and files are deleted after expiry plus the 30-day private recovery window. Owned expired files are retained for 90 days. Visit and API telemetry are deleted after 90 days. Account data is kept until you ask us to delete it. Removed (451) drops stay removed.

Your rights

You can request access to, correction of, export of, or deletion of your personal data at any time — email bart@bitgate.com from the address on your account. Deleting your account removes your API keys and paid drops. You can also revoke API keys yourself from the dashboard at any time.

Security

All traffic is TLS-encrypted, API keys are stored hashed, and drops are isolated from each other on separate subdomains. Report security issues to abuse@bitgate.com.

Changes

We may update this policy as the service evolves; the "last updated" date below tracks that. Material changes will be called out on this page.

Last updated Aug 20, 2026