Skipper

Privacy Policy

Last updated August 27, 2026

Skipper is a product of Slipway, Inc. (“Skipper,” “we,” “us,” or “our”). This policy explains what information we collect, why we collect it, how it is handled, and what you can ask us to do about it.

It covers this website, the Skipper service at app.skipper.dev, and Skipper for Mac. Where a section applies to only one of them, it says so.

What we collect and why

Our guiding principle is to collect only what we need. Here is what that means in practice.

Identity and access

You sign in to Skipper with GitHub. When you do, GitHub gives us your account’s numeric identifier, username, display name, email addresses, and avatar image URL. We use these to create your account, show you to your teammates, and contact you about the service. We also store an access token issued by GitHub on our servers, for as long as the connection remains in place, so we can act on your behalf and read the organizations and repositories you choose to grant us. You can revoke that token at any time from your GitHub account settings, which ends our access immediately.

Workspace and team information

When you create a workspace we store its name and the GitHub organization it belongs to, and a record of its members. If you invite someone, we store the name, email address, and GitHub username you provide so we can send the invitation and show it as pending. If you connect Slack, we store the tokens and workspace identifiers needed to post there on your behalf.

Billing information

If you sign up for a paid plan, we ask for payment and billing details. Card numbers are submitted directly to our third-party payment processor and never reach Skipper’s servers. We keep a record of the transaction, including the last four digits of the card, so we can maintain your account history, issue invoices, support billing questions, calculate any tax due, and detect fraudulent charges.

Skipper for Mac

The Mac app runs on your machine and works against your local checkouts. It does not upload your source code, your local repositories, your terminal output, or your conversations with coding agents to Skipper’s servers, and the crash logs it writes for itself stay on your Mac. It makes two kinds of outbound request. It checks releases.skipper.dev for a newer version, which reaches our content delivery provider as an ordinary web request carrying your IP address and your current app and macOS versions. And it sends the diagnostics described next.

Diagnostics from the Mac app

Skipper for Mac sends diagnostic data to a third-party error and performance monitoring provider in the United States. We want to be specific about this, because it is more than crash reporting.

  • It sends crash reports and application errors, and also performance traces and profiling samples of the app’s own execution.
  • It is enabled by default, and while it is on it runs on every session rather than on a sample of them.
  • Reports carry identifying information, including your IP address and identifiers for your Mac and user account, along with your operating system and app version.
  • You can turn it off. In Skipper for Mac, open Settings, then General, then Privacy, and switch off Share diagnostics. The reporter stops as soon as you switch it off rather than at the next launch, and the choice persists across updates. Reports already queued at that moment may still be delivered; nothing is collected after it.

This data is not designed to capture your source code or your conversations with coding agents, and we do not use it for that. But an error report describes the state the app was in when something went wrong, so it can include file and directory paths and fragments of whatever the app was handling at that moment. We use it to find crashes, hangs, and performance problems, and for nothing else.

Website and service logs

Our web servers keep standard request logs, which include IP addresses, request times, pages requested, and browser and operating system versions. We use them to operate the service, to investigate errors, and to detect and prevent abuse. We log account sign-ins by IP address for the same reasons.

Cookies

We use a single first-party cookie to keep you signed in to app.skipper.dev. We do not run advertising, and we do not use analytics or tracking cookies on this website or in the service. There is no third-party analytics script on any Skipper page.

Voluntary correspondence

When you email us with a question or for help, we keep that correspondence, including your email address, so we have a history to refer to if you contact us again. We also keep anything else you volunteer, such as written answers to a survey.

Your code and the coding agents you run

Skipper for Mac drives AI coding agents from other companies, for example Claude Code, Codex, or Gemini, using the accounts, subscriptions, and API keys you supply. When you run one of those agents, it sends your prompts and the parts of your code it needs to that company’s service, under your own agreement with them and their privacy policy, not this one.

That traffic does not pass through Skipper’s servers and we do not receive a copy of it. We encourage you to read the privacy policy of any agent provider you configure, because what they do with your code is governed by them and not by us.

When we access or disclose your information

Service providers

We rely on third parties to run Skipper. They provide cloud infrastructure and database hosting, content delivery and network security, source code hosting and identity, error and performance monitoring, and payment processing. They process information only to provide those services to us. We name our current providers if you ask.

At your direction

When you connect another service to Skipper, information moves between them because you asked for it. Connecting GitHub lets us read the organizations and repositories you grant. Connecting Slack lets us post messages to the channels you choose. You can disconnect either at any time.

Our own access to your content

We access the contents of your account only to resolve a support request you have raised, to fix a fault that requires manual intervention, or to investigate suspected abuse of the service. We keep that access to the minimum the task requires.

Aggregated and de-identified information

We may aggregate or de-identify information so that it no longer identifies you, and use the result for any purpose, including improving and promoting Skipper.

When required by law

Slipway, Inc. is a United States company. We do not hand over customer information in response to government requests unless we are compelled by valid legal process. Where we are permitted to tell you that we received such a request, we tell you.

If the company changes hands

If Slipway, Inc. is acquired by or merges with another company, we notify you before any personal information is transferred or becomes subject to a different privacy policy.

Your rights

We extend these rights to every Skipper user, wherever you are.

  • Access. You can ask what personal information we hold about you.
  • Correction. You can ask us to correct information that is wrong. Most of it comes from your GitHub profile, so correcting it there updates it here.
  • Deletion. You can ask us to delete your account and the personal information we hold about you. Some deletions leave you unable to use Skipper.
  • Portability. You can ask for a copy of the information you have given us.
  • Objection. You can object to how we use your information, and we tell you what we can do about it.

Email humans@skipper.dev to exercise any of these. We may need to verify your identity before we act, usually by confirming control of the email address or GitHub account on the record. We may also need to keep some information to meet legal obligations, resolve disputes, or enforce our agreements, and we say so if that applies.

Security, retention, and where your data lives

How we secure your data

Traffic between you and Skipper is encrypted in transit with TLS. Data at rest in our databases and backups is encrypted by our hosting providers. Access to production systems is limited to the people who need it.

Data retention

We keep information for as long as we need it for the purposes described in this policy, after which we delete or de-identify it. How long that is depends on the kind of information and why we hold it. We also keep information where we need to in order to meet a legal obligation, resolve a dispute, or enforce our agreements. When you ask us to delete your account, we remove your personal information from our active systems, and copies held in routine backups age out on our normal backup cycle.

Location

Skipper is operated in the United States, and the information we hold is stored there. If you are outside the United States, be aware that any information you give us is transferred to and stored in the United States. By using Skipper you consent to that transfer.

Changes and questions

We may update this policy to reflect new practices or to comply with regulations. When we make a significant change we update the date at the top of this page and take other reasonable steps to let you know.

For questions, comments, or concerns about this policy, your information, or your rights, email humans@skipper.dev . We are glad to answer.