Privacy Policy
Last updated: 5th August 2026
This Privacy Policy explains how ShipGodot ("we", "us") collects, uses, and protects your data when you use the ShipGodot plugin for the Godot Engine and its associated build service (the "Service"), or visit shipgodot.com (the "Website").
1. Who we are (Data Controller)
The data controller responsible for your personal data is:
Michał Myczkowski, operating as ShipGodot
Świętego Mikołaja 8/11/lok. 208, 50-125 Wrocław, Poland
Email: support@shipgodot.com
ShipGodot is currently operated by an individual, not a registered company. This does not change your rights under the GDPR — all rights described in this policy apply in full.
2. Scope
This policy covers two things:
- The Service — the ShipGodot Godot plugin and the cloud build platform behind it.
- The Website — shipgodot.com, which is informational and hosted separately from the Service.
3. Data we collect and why
3.1 License and device data
When you activate the plugin, we collect:
- Your license key — to verify your subscription is valid.
- A device ID — a random UUID generated by the plugin and stored in your operating system's user configuration directory. It identifies your installation so we can enforce activation limits and let you deactivate devices you no longer use.
- A device name you choose (e.g. "Work MacBook") — shown back to you in your device list so you can recognize and manage your activations.
- A seat token — an authentication token we issue to your device after activation. It has no expiry and remains valid until you deactivate the device or it is revoked.
Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR); prevention of license abuse is also our legitimate interest (Art. 6(1)(f)).
3.2 Apple Developer credentials
To build and upload iOS apps on your behalf, the Service requires your Apple Developer credentials:
- Apple Team ID — stored in our database. We keep it there to enforce a one-license-per-team rule.
- App Store Connect API Key ID, Issuer ID, and the contents of your .p8 private key file — these are not stored in our database. They are encrypted with libsodium and stored as encrypted secrets in a private, per-customer GitHub repository that we manage. This repository is isolated per customer and is not accessible to other customers or to the public.
- Code signing certificates and provisioning profiles — generated and managed on your behalf using Fastlane match. They are stored encrypted in our Cloudflare R2 storage (EU region), in a storage prefix isolated per customer. The encryption password is generated on our servers and stored only as an encrypted secret in your per-customer GitHub repository.
We use these credentials solely to build, sign, and upload your app to App Store Connect / TestFlight when you request a build. We never use them for any other purpose. You can rotate these credentials at any time by re-activating with a new API key, which overwrites the stored secrets.
Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
3.3 Your game projects
When you start a build:
- Your zipped Godot project is uploaded via a time-limited, pre-signed upload link directly to our Cloudflare R2 storage (EU region), in your isolated per-customer storage prefix.
- The project is downloaded only by the isolated, ephemeral build virtual machine that runs your build.
- Your project files are deleted as soon as the build process finishes.
- We do not open, inspect, analyze, index, or otherwise process your project files in any way beyond executing the build you requested. We do not use your code or assets for analytics, product improvement, or training of any kind, and we never share them with third parties.
You retain all rights to your projects. See our Terms of Service for the intellectual property terms.
Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
3.4 Build metadata and logs
For each build we store:
- Build metadata — build ID, the bundle identifier you provide (e.g.
com.studio.mygame), the Godot version requested, timestamps, build status, and billable minutes. Stored in our database (Cloudflare D1, EU region) for billing and support. - Build logs — the output of the build process, stored in your per-customer R2 storage prefix so you can download them for troubleshooting. Build logs are automatically deleted after 24 hours. We do not read or process them unless you ask us for support help.
Legal basis: performance of our contract (Art. 6(1)(b) GDPR); retention of billing metadata is also a legal obligation (Art. 6(1)(c)) and our legitimate interest (Art. 6(1)(f)).
3.5 Billing data
All purchases, subscriptions, and payments are handled by our merchant of record, Lemon Squeezy, LLC. When you buy a license or top-up minutes, Lemon Squeezy collects your email address, billing details, and payment card data. We never receive or store your payment card details. We receive from Lemon Squeezy the information needed to operate your license: license status, plan, and order events.
Lemon Squeezy acts as an independent controller for payment processing. See the Lemon Squeezy Privacy Policy.
Legal basis: performance of our contract (Art. 6(1)(b) GDPR) and compliance with legal (tax/accounting) obligations (Art. 6(1)(c)).
3.6 Support
If you email support@shipgodot.com, we process your email address and the contents of your message to help you.
Legal basis: our legitimate interest in providing support (Art. 6(1)(f)), or contract performance where the request concerns your subscription.
3.7 Website
The Website at shipgodot.com is hosted by Ghost Foundation (Ghost(Pro)). Ghost may collect standard technical data from visitors (such as IP address, browser information, and cookies) as described in the Ghost Privacy Policy. The Website is separate from the Service and no Service data is shared with it.
4. Links to third-party sites
The Service and the Website may contain links to websites we do not operate, such as documentation, the Godot Engine project, our payment provider's checkout, or Apple's developer portal. If you follow such a link, the site you reach is governed by its own terms and privacy policy, and we have no control over its content or data practices. We encourage you to review the privacy policy of any third-party site you visit. This section does not apply to the service providers listed in Section 6, whose processing of your data on our behalf remains our responsibility.
5. What we do NOT do
- We do not sell your personal data.
- We do not use your data for advertising.
- We do not access, analyze, or train anything on your game projects, source code, or assets.
- We do not use your Apple credentials for anything other than the builds and uploads you request.
6. Our service providers (subprocessors)
We use the following providers to operate the Service:
| Provider | Purpose | Location of data |
|---|---|---|
| Cloudflare (Workers, D1, R2) | API backend, database, file storage | EU (R2 and D1 configured in EU region) |
| GitHub, Inc. | Per-customer private repositories storing encrypted secrets; build workflow orchestration | United States |
| Scaleway SAS | Mac build servers that run your builds in isolated virtual machines | Paris, France (EU) |
| Lemon Squeezy, LLC | Merchant of record: payments, subscriptions, licensing | United States |
| Ghost Foundation | Website hosting (shipgodot.com only) | See Ghost's privacy policy |
7. International data transfers
We keep your project files, certificates, build logs, and database records in the EU. However:
- GitHub (United States) stores your encrypted Apple API credentials as repository secrets and orchestrates build workflows. Transfers to GitHub are protected by the EU–US Data Privacy Framework and/or Standard Contractual Clauses.
- Lemon Squeezy (United States) processes billing data as merchant of record under its own safeguards.
8. How long we keep your data
| Data | Retention |
|---|---|
| Your zipped game project | Deleted immediately when the build finishes |
| Build logs | Deleted automatically after 24 hours |
| Build metadata (status, minutes, bundle ID) | Kept while your account is active, then up to 3 months for billing/support history |
| Apple API credentials (encrypted secrets) | Kept while your license is active; deleted on account deletion request; overwritten when you rotate keys |
| Signing certificates and profiles | Kept while your license is active; deleted on account deletion request |
| Apple Team ID | Kept while your license is active, to enforce the one-license-per-team rule |
| License, device, and activation records | Kept while your license is active; deactivated device records kept for abuse prevention up to 3 months |
| Billing records | As required by tax and accounting law |
To request deletion of your account and associated data, email support@shipgodot.com.
9. Security
Security measures we apply include:
- Apple API credentials encrypted with libsodium and stored as secrets in isolated, private, per-customer repositories.
- Signing certificates encrypted at rest with a per-customer password that is generated server-side and never exposed to other customers.
- Per-customer isolation of all stored files (dedicated storage prefixes).
- Builds executed inside isolated, ephemeral virtual machines that are discarded after each run.
- Time-limited, pre-signed URLs for all project uploads and log downloads.
- Encrypted connections (TLS) for all data in transit.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the supervisory authority as required by GDPR.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted ("right to be forgotten");
- restrict or object to processing;
- receive your data in a portable format;
- withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email support@shipgodot.com. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Polish supervisory authority: Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw, Poland — https://uodo.gov.pl.
11. Children
The Service is intended for developers who hold an Apple Developer account and is not directed at children under 16. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page with a new "Last updated" date, and for material changes we will notify active customers by email.
13. Contact
Questions about this policy or your data: support@shipgodot.com