Privacy Policy

Last updated: August 15, 2026

ShipZen ("the App") is a macOS application for managing App Store Connect. It is developed and operated by Sardorbek Rakhimov, an independent software developer ("we", "us"). This policy describes how the App and this website (shipzen.app) handle your data. We built ShipZen local-first on purpose: the less of your data we ever touch, the less can go wrong.

Summary

Data Stored on Your Mac

The App keeps its data on your device:

You can delete all of this at any time by removing the App, its data container (via macOS storage management or ~/Library/Containers), and its Keychain items.

Network Connections the App Makes

The App connects only to the following services. Most connections happen only when you use a feature that requires them; crash and error reporting — and usage analytics, if you have turned them on — connect starting at launch, as described below:

The optional MCP server listens on localhost only and is protected by a per-install token. If you connect an external tool (for example an AI client on your Mac) to it, that tool processes your App Store Connect data under its own configuration and policies — review what you connect.

Purchases

ShipZen Pro is sold through the Mac App Store. Payment is handled entirely by Apple against your Apple ID: we never receive your name, email address, Apple ID, payment card, or billing details.

To unlock Pro features and prevent fraud, the App uses RevenueCat, a subscription infrastructure service, as our processor. RevenueCat receives a randomly generated identifier, App Store purchase receipt and transaction data, and basic app and device information (such as app version and platform). We do not attach your identity to this identifier, and nothing we send RevenueCat identifies you. RevenueCat processes this data to validate purchases and give us aggregate sales statistics, under the RevenueCat Privacy Policy.

Diagnostics and Usage Events

The App reports two separate things: crash, hang, and error reports, which are always sent, and usage analytics, which are off unless you turn them on. Neither ever carries the content of your work. The App tells you about both on first launch, and tells you again before it starts collecting something materially different.

Crash, Hang, and Error Reports (always on)

To help diagnose and fix crashes, freezes, and significant internal errors rather than silently endure them, the App reports them to Sentry, a crash-reporting service acting as our processor, in the European Union. These reports are sent whether or not usage analytics are enabled.

A report can include: the stack trace and error type of the crash, hang, or handled error, the App version and build, your macOS version, Mac model, and basic hardware details such as memory, the names of the App's own recent internal operations (a fixed, published list of labels such as "fetch.fullMetadata" — never their arguments or results), and app-session health, which is a count of sessions that ended normally versus in a crash. A handled-error report describes the error with fixed labels only — the area of the App, a normalized category, an HTTP status code, and the error's type name — never its message text.

A report never includes your identity, and we never attach one: no name, email, Apple ID, App Store Connect account, or device serial. The app-session health signal is counted per installation rather than per report, so it is keyed to a random identifier that the crash-reporting library generates and stores on your Mac. It is the same kind of identifier as the usage-analytics install ID described below: random, derived from nothing about you, your Apple ID, or your hardware, not linkable to a person, and gone when you remove the App's data.

Sentry's project setting to discard IP addresses is enabled, so your IP address is not stored. Before a report is sent, the App keeps only a short list of technical details it needs in order to diagnose the crash — the App and macOS versions, your Mac model, and basic hardware — and discards everything else the crash-reporting library would otherwise attach, including your Mac's language, region, and time-zone settings. Any free text the crash handler collects is scrubbed as well: credentials are redacted, web addresses are reduced to their host name, and long digit sequences are masked. Because crash reports are detailed by nature, we describe them as content-free and not linked to you rather than fully anonymized: they contain no content and nothing that identifies you, but they are technical records of a moment in the App.

Usage Analytics (opt-in)

Usage analytics are off unless you turn them on — at the first-launch notice or later in the App's settings — and nothing is sent, or even stored, before that notice appears. If you opt in, the App reports a small set of events to PostHog, an analytics service acting as our processor, in the European Union, to understand whether the App's core features get used. These events are deliberately content-free and limited to:

Events also carry the App version, build number, distribution channel, and how analytics were enabled. They are tied to a random install identifier that is not derived from you, your device serial, or your Apple ID, and they are not stitched together into a session trace.

Crash reports and usage events never include:

You can turn usage analytics off again at any time in the App's settings; that withdraws your consent going forward. Disabling stops all analytics reporting, discards anything queued, and resets the install identifier — opting in again creates a new random one. Neither analytics nor crash reporting is ever required for any feature to work. Builds without these capabilities send nothing.

The optional local diagnostic log described above is separate from both, and is never uploaded.

This Website

shipzen.app is a static site hosted on Cloudflare Pages. Cloudflare, as our hosting provider, processes visitor IP addresses transiently as part of operating and securing its network. The site sets no tracking cookies and uses no advertising or social trackers. If analytics are enabled, we use Cloudflare Web Analytics, which is cookieless and does not fingerprint or identify visitors.

If you join the launch waitlist, we store your email address, the signup time, and which page section you signed up from, solely to tell you when ShipZen is available. Your IP address is stored separately for up to one hour to rate-limit abuse and is never joined to your email. When you sign up, a notification containing your email address is delivered to us through Resend, our email delivery processor. We keep waitlist emails until you ask us to remove you or until we stop sending launch announcements, and we do not use them for anything else or share them with anyone beyond the processors that deliver these emails.

What We Never Do

Legal Bases, Transfers, and Retention

Where the GDPR or similar laws apply, we rely on: performance of a contract (providing the App and processing purchases), legitimate interests (fraud prevention, security, stability, and crash and error diagnostics under random identifiers), and consent (usage analytics and the waitlist). Our processors — RevenueCat, Sentry (Functional Software, Inc., with crash data stored in the European Union), PostHog (usage analytics stored in the European Union), Cloudflare, and Resend — may process data in the United States and other countries. Each does so under the European Commission's Standard Contractual Clauses or an equivalent approved safeguard, set out in the data processing terms it publishes on its own site.

How long we keep things: crash, hang, and error reports are retained by Sentry for up to 30 days. Usage analytics events are retained by PostHog for up to 12 months. Purchase records are kept by RevenueCat while we use its service — when that ends, we can ask RevenueCat to delete or return them under its data-processing terms. Waitlist emails are kept until you ask us to remove you or until we stop sending launch announcements. Everything else stays on your Mac, where you control it.

Your Rights

Most data the App handles is under your direct control on your own device, and you can delete it yourself. For the little we are responsible for — a waitlist email, or purchase and diagnostic records held under random identifiers — you can contact us at [email protected] to ask for access, correction, deletion, a copy in portable form, or restriction of processing, or to object to the processing we base on our legitimate interests, which includes crash and error diagnostics. We will respond within the time the law allows. For usage analytics, you can withdraw your consent at any time with the toggle in the App's settings; for the waitlist, email us — neither affects anything done before you withdrew. Note that purchase and diagnostic records are held under random identifiers we cannot link to you, so in some cases we cannot locate data about you precisely because we never had your identity. You may also lodge a complaint with your local data protection authority.

Children's Privacy

ShipZen is a professional developer tool that requires an Apple Developer account. It is not directed at children, and we do not knowingly collect information from children.

Changes to This Policy

If we change this policy, we will publish the revised version here with a new date, and note material changes in the App's release notes. Continued use of the App or website after an update constitutes acceptance of the revised policy.

Contact

Data controller: Sardorbek Rakhimov (ShipZen) — [email protected].