How it works
Your server, in your Hetzner account
ShipTiffin creates the server in your own Hetzner Cloud project and installs Tiffin on it. Hetzner bills you for the server; we charge $19 a month for keeping it managed. Your apps and data never run on anything of ours.
Your Hetzner key
- Make it in a new Hetzner project just for ShipTiffin, so it sees only that project.
- It stays in your browser until you click Create. Then this website seals it to our setup worker’s public key: the website can’t open it; only the worker can, a separate service whose secrets the website never sees. The worker uses it and forgets it when setup ends, whether it worked or not. We keep only a fingerprint (12 characters of its hash) so you can tell which key it was.
- Tick “Keep my key” and we store it, sealed the same way, for one-click resizes. Remove it any time in your account. Without it, a resize asks for a key, uses it and forgets it.
- We only ever touch what we create for your box: each server, volume, firewall and key carries a label with your box’s id, and nothing without it is changed or deleted.
- Every request we make with your key is listed in your account: when, what, and what Hetzner answered.
- We never see your Hetzner password or payment details. Delete the token in Hetzner at any time; the box keeps running.
What we can and can’t do on your server
- Setup logs in with a key made for that one setup, through a firewall opened to our setup worker only. When Tiffin is installed we delete that key from the server and from your Hetzner project, close SSH in the firewall, and check both are gone. After that we have no way to log in.
- We never hold your box’s owner token; it stays on the box. At setup the box makes one sign-in link, which we keep so your first “Open your dashboard” signs you in. Your box enforces it: it works once, and the box refuses it 24 hours after setup. We delete it when you use it (or click Forget). Add a passkey on the box then: after that we have no way to sign in to your box.
- Updates: the box fetches signed Tiffin releases itself, in its maintenance window. We never push anything to it; nothing of ours connects to it except monitoring, which only loads its health page.
- Every six hours the box tells us its Tiffin version and the names of any failing checks. No data, no project names, no visitors. If it stops checking in for 72 hours, we take its shiptiffin.app address off the server’s IP (the server may be gone, and its IP someone else’s); the next check-in brings it back.
- Support never logs in by default, and there’s no button for it yet. If you want us to look at the server itself, write to hello@shiptiffin.com and we arrange it by email: a temporary SSH key you add and open the firewall for, and remove when we’re done.
If you stop paying
Your server and every app on it keep running, untouched. Automatic updates, monitoring emails and support stop. Your name.shiptiffin.app address keeps working for 30 days, with an email when that starts, a week before it goes and when it goes, so you can point a domain of your own at the box. Renew in your account and everything comes back. We never stop, slow or delete anything over billing. Deleting the server happens only when you ask, with a key you paste right then.