Privacy Policy
Effective October 8, 2026
Ship Release Kit (the command-line tool ship, "the tool") is an internal release tool operated by its developer, Neo Chen, for publishing the developer's own apps. This policy explains what the tool does with data, in particular data it gets from YouTube.
YouTube API Services
The tool uses YouTube API Services. By using its YouTube features you agree to be bound by the YouTube Terms of Service. YouTube is a Google service, and Google's handling of your data is described in the Google Privacy Policy.
What the tool accesses
When you connect a YouTube channel through Google sign-in, the tool asks for two permissions:
youtube.upload: to upload your app's promo video to your channel as an unlisted video.youtube.readonly: to read your channel's ID and title, the list of your own uploads, and each of your uploaded videos' privacy status, processing status and original file name.
It uses this only to upload the promo video, to check whether a video already linked from your Google Play store listing is the same file as the one on your computer (so it is not uploaded twice), and to make sure a video is public or unlisted before linking it. It does not access any other YouTube data, other channels' data, comments, analytics, or your Google account profile.
What the tool stores, and where
There is no server. Everything stays on the computer where the tool runs:
- The OAuth refresh token, the granted scopes, and the connected channel's ID and title, in a local file readable only by your user account (
~/.config/<project>/youtube-token.json). The channel ID and title are refreshed every time the tool connects to YouTube. - The ID of each video the tool uploads, in a local log of each upload run.
The video's link is written to your Google Play store listing, which is the purpose of the feature. The tool does not share, sell or send YouTube data to anyone else, does not use it for advertising, and does not use cookies or similar technologies.
Revoking access and deleting data
- Disconnect in the tool (the 「断开」 (Disconnect) button on the upload page, or
ship store youtube logout). This revokes the token with Google and deletes the local token file. - You can also revoke access at any time on the Google security settings page: https://security.google.com/settings/security/permissions.
- To delete the local upload logs, delete the
.runsfolder in the project's store directory. Videos you uploaded stay on your YouTube channel, where you can delete them in YouTube Studio.
Contact
Questions about this policy: saviourdog@gmail.com.
If this policy changes, the new version will be posted on this page with a new effective date.