Privacy
mainship turns your GitHub activity into draft social content. This page explains what personal data we collect, why, and how you can ask us to delete it. We write it for people in the UK and EU under UK GDPR / GDPR.
What we collect
- Email address — when you sign up or join a waitlist, so we can create your account and reach you about the product.
- GitHub username — when you connect GitHub, so we can label your week and attribute commits correctly.
- Repo metadata — names, last-push times, languages, and commit/PR summaries for the week you generate from. We do not store your source code.
- Account content — brand kit settings and generated content packs you create in Studio.
- Billing entitlements — plan status from Stripe when you subscribe. We never store full card numbers.
What we use it for
To run your account, pull the GitHub week you choose, generate draft content with AI, show usage limits, and (if you pay) manage your subscription. We do not sell your data. We do not use your GitHub activity to train our own models.
Who processes it
- Supabase — authentication and database (processor).
- Anthropic — content generation subprocessors when you hit Generate or Refine; we send week summaries and prompts, not your full repo.
- Stripe — payments, if you subscribe.
- Resend — transactional or waitlist email when enabled.
- Vercel — hosts the app; may process request logs.
Legal bases
Contract (providing the service you signed up for), and legitimate interests (securing the product, understanding aggregate usage). Where consent is required (for example some marketing email), we ask separately.
Retention
We keep account and generation data while your account is open. After deletion we remove application data we control within a reasonable period. Stripe and other processors may keep records they need for tax or fraud rules.
Your rights
You can ask for access, correction, export, or deletion of your personal data, and you can object to or restrict some processing. To request deletion, email hello@mainship.co from the address on your account (or tell us enough to find it). We will confirm and delete what we control. You can also disconnect GitHub in Studio → Account, which removes the stored token and cached week data while keeping past generations until you ask us to delete the account.
If you are in the UK or EEA and unhappy with our response, you can complain to the ICO (UK) or your local supervisory authority.
Cookies and analytics
We use cookieless analytics (Vercel Analytics) that does not require a consent banner. Essential cookies may be set for sign-in sessions via Supabase Auth.
Contact
Privacy questions and deletion requests: hello@mainship.co.