Legal
Privacy Policy
Last updated September 25, 2026
Information we collect
- Account information. When you create an account, we collect your email address and, if you choose to provide it, your name. Passwords are handled by our authentication provider and are never stored in plain text.
- Project and account data. We store the projects, source code, settings, and other information you submit to shell.build so the service can provide it back to you and keep your account working.
- Usage and device metadata. We may receive browser and app version information, device or network details, and technical logs needed to keep shell.build reliable, secure, and usable.
- Billing information. shell.build does not currently sell paid subscriptions. If paid plans are introduced in the future, payments will be handled by a payment provider and shell.build will not store your full card details.
How we use your information
- To provide, maintain, and improve shell.build.
- To send transactional messages, such as account confirmation, sign-in, and security notices. We do not send marketing email without your explicit opt-in.
- To detect and prevent abuse, fraud, and security incidents.
- To comply with legal obligations.
Data storage and security
- Project and account data is stored using infrastructure designed to protect it. Data in transit is protected by TLS, and access to production systems is limited to people who need it to operate and support shell.build.
- We retain account information while your account is active. When you delete your account, we delete or anonymise associated data in accordance with our retention and legal obligations.
Third parties
- Cloudflare We use Cloudflare for infrastructure, hosting, DNS, and protection against abuse and distributed denial-of-service attacks.
- Authentication providers If you sign in with Google, GitHub, Microsoft, or another supported provider, that provider may share account information with us as part of authentication.
- Email providers We use email providers to deliver account and security messages. Their handling of message data is governed by their own privacy policies.
- We do not sell your personal data to third parties.
Your rights
- You may request a copy of the personal data we hold about you, ask us to correct inaccuracies, or ask us to delete your account and associated data. To exercise these rights, email oscar@otbeaumont.me.
- If you are in the EEA, UK, or Switzerland, you may have additional rights under GDPR and equivalent legislation, including the right to lodge a complaint with your local supervisory authority.
Cookies
- shell.build uses a session cookie to keep you signed in. We do not use third-party tracking cookies or advertising cookies. Any essential storage required to provide the service is used for that purpose only.
Changes to this policy
- We will post changes to this page and update the date at the top. For material changes, we will provide notice by email before they take effect where appropriate.
Contact
- Questions or privacy requests: oscar@otbeaumont.me. We aim to respond within five business days.