Last updated 2 October 2026
Privacy policy
This policy explains what personal data TrustShip handles and why. TrustShip is run by [LEGAL_NAME], [LEGAL_ADDRESS] (“we”). For anything about your data, write to [LEGAL_EMAIL].
Two roles
- Your account (developers who sign up): we decide how this data is used, so we are its controller.
- Content your app sends (your users’ posts, images, reports): you decide, so you are the controller and we are your processor. The processing terms are in section 7 of the terms of service. If you use an app built with TrustShip, contact that app’s developer first; we will help them answer you.
What we collect
- Account: your email address, a hash of your password (never the password itself), and your Google or GitHub user id if you sign in with them.
- Billing: your plan, your Stripe customer and subscription ids and status, and for crypto payments the invoice and the transaction id you submit. Card details go to Stripe; we never see them.
- Content sent through the API: the text, image URLs, user ids, content ids, reports, blocks, bans and appeals your app sends. Images sent as files are never stored: we keep only a hash of them. Text and image URLs are kept in your project’s audit log so you can review them, except content flagged as sexual content involving minors and content from banned users, which is not kept.
- Technical data: your IP address is used to limit login attempts, and our servers log requests (IP address, time, page) for security; these logs are rotated automatically. TrustShip uses no analytics and no advertising.
Why, and on what legal basis
- To provide TrustShip and your plan: performance of our contract with you.
- To keep the service and its users safe, prevent abuse and detect known child sexual abuse material: our legitimate interests, and legal obligations where they apply.
- To keep accounting and billing records: legal obligation.
Who receives it
We do not sell personal data. These providers process it for us:
- Oracle Corporation (Oracle Cloud Infrastructure), 2300 Oracle Way, Austin, TX 78741, United States hosts TrustShip and its database.
- OpenAI (United States) receives the text and images your app sends, to score them.
- Arachnid Shield (Canadian Centre for Child Protection, Canada) receives images (or their URLs) to check them against known child sexual abuse material.
- Stripe processes card payments and stores your billing details.
- Google and GitHub confirm your identity if you choose to sign in with them.
- Crypto payments are checked against public blockchain data; transactions on a blockchain are public by nature.
Some of these providers are outside the European Union. Transfers rely on the safeguards provided by the GDPR: an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission’s standard contractual clauses. We may also disclose data when the law requires it, for example to report apparent child sexual abuse material.
How long we keep it
- Account data: as long as your account exists. Ask us to delete it at any time.
- Content sent through the API: until you delete the project. Records of known child sexual abuse material matches (identifiers and hashes, never the content) are kept for at least 12 months.
- Billing records: as long as French accounting law requires (10 years).
Cookies
TrustShip sets one cookie, appship_session, when you use the login or sign-up page or the dashboard. It keeps you signed in and protects forms against forgery, so it is strictly necessary and needs no consent. The public pages set no cookie.
Your rights
You can ask to access, correct, delete or export your data, to restrict its use, or object to it, by writing to [LEGAL_EMAIL]. We answer within one month. You can also complain to the French data protection authority, the CNIL (www.cnil.fr), or to the authority where you live.
Changes
If we change this policy in an important way, we will tell you by email or in the dashboard before it applies.
See also the terms of service and legal notice.