Privacy
Last updated 12 August 2026
This page describes exactly what we hold and why, in plain terms rather than boilerplate.
Who operates ShipHerald
ShipHerald is a product of NexAI Tech, a sole proprietorship registered in India, which is the data controller for everything described here. Reach us at [email protected].
Using the free brand check without an account
The check on our home page reads a website address you type in. We keep the address and the critique for one day so that a second visitor asking about the same site gets the answer without us reading it again, and then we drop both. We do not ask for your email, we do not set a tracking cookie, and nothing about that visit is joined to an account later.
What we collect once you sign up
- Your email, from the account you sign in with. It identifies your workspace and lets us contact you about it, and nothing else.
- Your workspace content - the brands you add, the website evidence ShipHerald crawls from URLs you explicitly provide, files you upload, and the drafts generated from them.
- Social account credentials, only for channels you connect yourself. These are encrypted at rest and are never shown back to you or to us in plain text.
- Messages your connected accounts receive - comments, direct messages and WhatsApp messages, along with whoever sent them. WhatsApp has no endpoint we can read a conversation back from, so a message we did not store when it arrived is gone; those are kept in your workspace, most recent first, and older ones fall off. Everything else is read from the platform when you open the screen.
- Operational logs - request paths, status codes, and timings, kept to diagnose failures. Access tokens are stripped before anything is written.
What we deliberately do not store
- Lead form answers. When someone fills in a lead form on your Facebook Page, Meta's notification carries an identifier and no answers. We keep only a count and timestamp so the screen knows to refresh. LinkedIn forms are read when you open their list. In both cases, contact details come from the platform over an authenticated call and are never written down here.
- We do not sell or rent your data.
- We do not use your brand content to train models for anyone else.
- We do not post anything to your social accounts unless you connect the channel and explicitly turn live posting on. ShipHerald ships with publishing disabled.
Processors
Content generation runs on Microsoft's hosted OpenAI service. Authentication is handled by WorkOS. Uploaded brand assets are stored in Cloudflare R2. Payments are taken by Razorpay, which receives your billing details directly - we never see or store a card. Each receives only the data needed to do its job.
Retention and deletion
Deleting a brand in the app removes its evidence, drafts, media, campaigns, and attribution events. Disconnecting a channel deletes its stored credentials and the account details the platform gave us. Delete your data explains every route out, including the one you can start from Facebook rather than from us, and lets you check what a deletion actually removed.
Contact
Privacy questions and deletion requests: [email protected].

