Skip to main content
Shipname

Privacy Policy

Effective date: August 24, 2026

This policy describes the current data flows on ShipName.net. The service does not currently provide accounts, subscriptions, payments, displayed advertising, or cloud-saved name collections.

Name Inputs and Generated Results

When you submit two to five names in the Ship Name Generator, the deterministic engine runs in your browser. Optional concept-name signal words, edits, local name-card downloads, clipboard actions, saved-choice contents, and shared-choice URL fragments are also processed in your browser. The Name Blend Checker compares its two source names and custom candidate locally, and the Blind Name Test keeps its setup and result in browser memory. These interfaces do not send entered names, signal words, generated candidates, actual selected choices, custom drafts, downloaded card text, shared-choice fragments, or blind-test guesses to ShipName.net's server.

Result pages include optional links that search Google, AO3 through Google, Tumblr, or TikTok for the current candidate. Shipname sends no candidate to those services in the background. If you click one of those clearly labeled links, your browser sends the displayed candidate to the selected external service as part of its search URL, and that service's own privacy policy applies.

We do not write submitted names or generated results to an account or application database. Hosting infrastructure may process normal page-request information, such as IP address, request time, user agent, and error data, for delivery, reliability, abuse prevention, and security.

Do not enter secret, sensitive, or unnecessary identifying information. Public name forms or nicknames are usually sufficient.

Browser-Local Saved Choice Hub

When you choose Save, the Saved Choice Hub stores the choice name, its fixed output category, and a local save timestamp in your browser's local storage. It does not store the source names that produced the choice. Saved choices remain on that browser unless you remove them, choose Clear all, or clear site data. They are not synchronized to a Shipname account or application database.

The current local format uses the shipname-saved-picks-v3 key. If the browser still has a valid shipname-shortlist-v2 list, Shipname converts those names locally into the current format, labels them as custom names because the old format did not include an output category, writes the new local list, and removes the old key after a successful write. This migration does not send the old or new saved choices to Shipname's server.

Shared-choice links place a version number, the displayed choice name, and its fixed output category after the # character in the URL. A browser does not include that fragment in its HTTP request to ShipName.net. The receiving page validates and restores the choice in browser memory. It is not added to local storage unless the recipient chooses Save. The application does not copy the fragment or choice text into the first-party product-evidence request.

A fragment-based link is not encrypted or access-controlled. Anyone or any application that receives the complete link can read the shared choice. Do not use it to share secret or sensitive information.

When you open the Name Blend Checker or Blind Name Test from a generated candidate, the candidate and its two source names are transferred once through temporary session storage in the same browser tab. The destination removes that transfer after loading. A standalone check or blind test does not persist its setup or result. If you choose “Copy review summary,” the summary is written to your clipboard for you to control.

Optional Third-Party Analytics

At the effective date of this policy, ShipName.net does not have a production OpenPanel client ID configured. The OpenPanel client therefore does not load and no OpenPanel analytics events are sent.

The codebase contains an optional OpenPanel integration. If it is configured in the future, it may collect screen views, page URL and referrer, browser and device information, approximate location supplied by the provider, and fixed product-event properties. The integration is configured not to track arbitrary element attributes or outgoing-link clicks. We will review and update this policy before enabling materially different third-party analytics, including any handling needed to prevent shared-choice fragments from being exposed.

Review OpenPanel's Privacy Policy and Next.js SDK documentation for the provider's current practices. These links describe the provider, not a claim that the optional integration is currently active on ShipName.net.

Product Evidence Events

To determine whether the generator solves a real task, the site records a limited set of first-party product events when the evidence store is available. A fresh random visit identifier is created in page memory. It is used to deduplicate and connect events from that page visit, including a successful generation, and is not stored in local storage, a cookie, an account, or a cross-site profile. Refreshing or reopening the page creates a new visit identifier.

Visit-level evidence accepts only these fixed event types:

Each visit event also contains only a fixed homepage or guide surface, a fixed entry-point category, a broad referrer category (direct, search, social, internal, or other), a broad browser, crawler, or unknown client classification, and the evidence-protocol version. Entry points are selected from an allowlist such as the homepage, yumeship workflow, named guide categories, or a shared result. Arbitrary paths and raw referrer URLs are rejected from the first-party evidence database.

The current homepage may also record:

The Name Blend Checker may record a draft-check completion under the same privacy-minimized protocol when it was opened from a ranked generated candidate. A checker-open or blind-test-open event is linked to the original generation but contains no source name, candidate, edit, or guess. Custom Blind Name Test answers and keep-or-reject choices are not written to the first-party product-evidence store. Those tools do not send the names or draft text.

The setup value is selected from those two fixed labels. It does not contain a yumesona, F/O, character, fandom, source work, relationship, or other submitted text. The first-party evidence store deliberately does not include an entered name, signal word, generated or saved choice text, the actual selected choice, edited-draft text, shared-choice fragment, share text, email address, raw referrer URL, or IP address. It may record that a selection, save, reuse, share-link creation, or share import happened and the applicable fixed output category, but not the choice value. Each successful generation receives a new random run identifier in addition to the in-memory visit identifier. Neither identifier is an account or cross-site identifier. Obvious crawler events are labeled and excluded from the public readiness totals.

A daily scheduled cleanup deletes visit and generation evidence from D1 after it becomes older than 180 days. These records are used to evaluate product usefulness, identify weak ranking behavior, and decide whether the site is ready for monetization. Actions count only when the service can link them to the applicable visit or generation under the current evidence protocol. Selection counts only after an explicit visitor choice; copying or saving is not treated as selection. Aggregate counts may be published; individual visit and run identifiers are not published.

Fixed Organic Acquisition Measurement

Shipname has prepared privacy-minimized measurement for one disclosed organic Pinterest experiment. The experiment is not an account system and has not started merely because the measurement path exists. It accepts only campaign pinterest-organic-2026-08 and these six creative identifiers: pin02-yume-a, pin06-yume-b, pin01-group-a, pin03-format-a, pin04-concept-b, and pin05-handle-a. Publication links use the dedicated acq_campaign and acq_creative parameters. Unknown or partial campaign/creative values do not receive acquisition attribution. Other URL query text, including arbitrary UTM values, is not copied into the first-party evidence request or database, and extra evidence-request fields are rejected.

When a browser opens a valid allowlisted campaign link, Shipname creates a fresh random UUID journey for that session. The client attempts to consume and remove the journey after one continuation through session storage in the same browser tab, and accepts it for no more than 30 minutes, so that a guide visit can be associated with a later homepage generation. After that deadline, the next time Shipname's acquisition code reads the value it ignores and deletes it; closing the tab or clearing site data may remove it sooner. It is not placed in the published Pin URL, written to local storage or a cookie, or used as an account or cross-site identifier. Shipname does not synchronize it between tabs. Some browsers may initialize a newly opened tab with a one-time copy of the opener tab's session storage; after that copy, each tab's storage is separate and the same acceptance deadline applies. Reloading within the limited session may reuse the journey for deduplication; a new independent landing creates a new journey. A journey represents an anonymous session, not a person or unique user.

Accepted acquisition evidence adds only the fixed campaign, fixed creative, random journey UUID, fixed entry point and surface, broad referrer category, broad client classification, protocol version, timestamps, and the fixed product events described above. It does not store an entered or generated name, arbitrary UTM value, raw page URL, raw referrer, URL fragment, email address, or IP address in D1. Ordinary hosting and security infrastructure may still process the requested URL, IP address, user agent, and referrer as described under Name Inputs and Generated Results; those infrastructure request records are separate from the first-party product-evidence database.

Owner and release quality-assurance visits use the fixed internal_test=1 marker and are excluded from qualified acquisition aggregates. D1 acquisition rows follow the same 180-day daily deletion rule. During an authorized 14-day experiment, Shipname may also preserve daily aggregate endpoint snapshots and Pinterest's native click totals for comparison. Those reports contain aggregate counts, not submitted names or a claim that a journey is a unique person.

Fixed-Sample Human Review Study

The Human Review Study asks visitors to assess candidates from a fixed set. It does not accept entered names or free-text responses. When the review store is available, a submission records:

The application database does not store an entered name, candidate free text, email address, raw referrer URL, or IP address for this study. Normal hosting and security infrastructure may still process ordinary request information as described above.

Completed fixed-case identifiers are stored in the visitor's browser local storage to reduce accidental repeat submissions. That local list is not synchronized to an account. Obvious crawler responses are excluded from public aggregates, individual review identifiers are not published, and the same daily scheduled cleanup deletes study records after they become older than 180 days.

Public results are descriptive observations from received responses. They are not presented as a representative opinion poll, demographic study, or linguistic validation.

Email

If you email us, we receive the address, message, and attachments you choose to send. We use that information to respond, investigate corrections or product problems, protect the service, and maintain necessary correspondence.

Do not email unrelated private information. Engine reports usually need only the public name forms, selected context, returned candidate, and engine version.

Cookies

Shipname does not currently set an account, payment, advertising, or analytics cookie in its application code. Saved Choice Hub entries are kept in local storage. Ordinary visit and per-generation evidence identifiers remain in page memory and are not persisted in local storage or cookies. For the fixed organic acquisition measurement described above, one random journey UUID may be held in same-tab session storage. The client attempts to consume and remove it after one continuation and accepts it only during the first 30 minutes. After expiry, Shipname ignores and deletes it the next time the acquisition code reads it; closing the tab or clearing site data may remove it sooner. It is not stored in local storage or a cookie. Shipname does not synchronize it between tabs, although some browsers may give a newly opened tab a one-time initial copy of the opener's session storage; the copies are separate afterward. Infrastructure providers may use strictly necessary security or delivery mechanisms. External sites linked from our pages follow their own policies.

Advertising

ShipName.net does not currently display ads. A standard Google AdSense loader is present for site verification while the site is reviewed. Loading that script may cause the visitor's browser to contact Google and send ordinary technical request information such as IP address, user agent, page URL, and referrer. No on-page ad units are currently configured by Shipname.

Google and other third-party vendors may place and read cookies in a visitor's browser, or use web beacons, IP addresses, and other identifiers to collect information as a result of ad serving on this site. Google may use this information to serve, measure, and personalize ads, prevent fraud and abuse, and improve its advertising services.

Read How Google uses information from sites or apps that use its services for details about Google's processing. Visitors can review or control personalized advertising through Google's Ads Settings and can learn about other industry opt-out choices at YourAdChoices.

Where applicable, including for visitors in the European Economic Area and the United Kingdom, required consent controls will be shown before advertising cookies or personalized advertising are enabled. A visitor's available choices may include consenting to personalized advertising, receiving non-personalized advertising, or managing and withdrawing consent.

Advertising providers and consent requirements may change. Material changes will be reflected on this page before the affected advertising or data processing is enabled.

Data Sharing

Information may be processed by providers needed to host, secure, measure, or operate the site, and when required to comply with lawful requests or protect users and the service. We do not intentionally sell submitted names or email contact information.

Retention and Control

Children

The service is a general creative tool and is not directed specifically to children. Do not submit sensitive information about a child. A parent or guardian can contact us about a privacy concern.

Changes

Material changes will update the effective date on this page. New accounts, payment, displayed advertising, persistent cloud storage, or materially different analytics require this policy to be revised before those features are activated.

Contact

Privacy questions: externalanswer@gmail.com