Legal

Privacy policy

Last updated: 23 August 2026

This is a courtesy translation.

In case of any discrepancy the Turkish version prevails. Türkçe sürüm

Zero tracking

Our marketing site and application contain no Google Analytics, Facebook Pixel or any comparable user-tracking tool.

All fonts and libraries used on our pages are served from our own servers; no third-party CDN connection that would carry your IP address to an external server is used.

Access tokens are held in memory only. Writing sensitive session information to the browser’s localStorage or sessionStorage is forbidden in the codebase and a test enforces it.

Cookies

The application uses one strictly necessary security cookie: notusship_rt, which keeps your session alive securely. It is protected with the HttpOnly, Secure and SameSite=Strict flags, is valid only under the /api/auth path and expires by itself after 30 days.

No advertising, targeting or non-essential analytics cookies are used.

Data ownership and portability

Everything you create in NotusShip — issues, wiki pages, comments, files — belongs to your organisation.

You can export your data as JSON at any time. Accounts of users who leave are anonymised, their personal identifiers are deleted and their access is fully closed.

Security measures

Passwords and session keys are stored hashed: passwords with Identity’s PBKDF2-based hasher and tokens with SHA-256. Raw values are not stored.

Rate limits are applied to the authentication endpoints and an account is locked for fifteen minutes after ten consecutive failed sign-in attempts; this is the protection against brute-force attacks.

System logs are retained for at most seven days and are then disposed of automatically.

Effective date

This policy took effect on 23 August 2026. Changes are published on this page and the effective date is updated; material changes affecting user accounts are additionally announced inside the application.