Trust Center
Trust, written down.
What we read, what we write, where your data goes, and what we refuse to do.
Data we read
We request a single Shopify scope to read: read_products. That covers your product titles, descriptions, variants, images and metafields. It is the raw material we audit and improve, and nothing more.
For the free public audit, we read only your public storefront pages, the same pages a shopper or an AI agent can already load. We never request access to orders or customers, on any plan.
Our Shopify listing also declares two optional read scopes. Shopify cannot offer them to you yet under our current install flow, so today nobody has granted them and nothing reads them. When they can be granted, saying no will cost you nothing:
read_legal_policiesTo read your refund and shipping policies so the AEO agent can check whether an AI assistant could answer a shopper asking about returns or delivery. If you do not grant it: Nothing. The policy checks report that we could not look, and your score moves in neither direction.read_online_store_pagesTo read your Online Store pages so the AEO agent can check whether real support content exists for shoppers and agents to be pointed at. If you do not grant it: Nothing. The support content check reports that we could not look, and your score moves in neither direction.
Data we write
We request a single scope to write: write_products. We use it only to apply fixes you approve: cleaner descriptions, structured product data, GTINs and feed-ready attributes, written back as product fields and metafields.
Structured data (schema.org JSON-LD) is written to a product metafield using the same write_products scope. We never request write access to your theme. Publishing that markup to your storefront is done by an app embed you switch on yourself in your theme editor, and switch off the same way. Every write is recorded in your Fixes history with the before and after, and every write is reversible.
How we use AI
When you ask for a copy fix, we send our AI model the product text we are rewriting, and only that: the title, the description, the attributes we extracted from it, and, for an SEO fix, the current SEO title and meta description. The AI writes the draft and you approve it before anything is published. This data is not used to train AI models. We never send customer personal data, because we never read it, and we never send your name, your email address or your store domain.
Your copy settings are not sent. Brand tone, words to avoid and facts to include are stored and shown back to you on the settings screen, and nothing else in the product reads them today. That is a defect in the feature rather than a privacy practice, and it is written down here and in the Privacy Policy rather than quietly corrected.
Security
Your data is encrypted in transit and at rest. Authentication is handled by Shopify OAuth, so we never see or store a password. We follow the principle of least privilege: we request only the two product scopes above, and nothing else.
Infrastructure and subprocessors
We keep this list honest and current. It is generated from the same definition our code uses, and a test fails our build if the app can reach a company this list does not name.
- Hosting and delivery of the app and the website, plus aggregate visit counts.Vercel, United States, with edge delivery worldwide.
- Database and authentication.Supabase, European Union region.
- The app platform, the source of the product data we audit, and the script that makes the embedded app work in your admin.Shopify, Canada and the United States.
- Writing product copy with Claude, on the fixes you ask us to generate.Anthropic, United States. Data is not used to train models.. We evaluate AI vendors on cost and quality. If we switch, this entry updates the day the new vendor starts processing your data.
- Sending the emails the product sends: welcome, scan complete, fixes ready, billing.Resend, United States.
- Payment processing for the small number of stores that did not install through Shopify. If you installed from the Shopify App Store, Stripe receives nothing about you.Stripe, United States and Ireland.
- Measuring which of our own adverts produced a customer. We upload a file of click identifiers and the value of the plan bought.Google (recipient, not a subprocessor), United States.
Paid plans are charged through Shopify Billing: the price is approved in your Shopify admin and the charge lands on your Shopify invoice. Stripe appears above because it still bills the small number of stores that did not install through Shopify. If you installed from the Shopify App Store, Stripe receives nothing about you.
The full detail, including what each company receives and when it started, is on our Subprocessors page.
Honesty commitments
These are the things we refuse to do, written down so you can hold us to them.
- We do not promise guaranteed AI rankings, because nobody can keep that promise.
- We do not sell a measurement we do not take. If a number is not on this site, it is because nothing in the product produces it yet.
- We never cloak content, showing agents something different from what shoppers see.
- We never invent reviews or testimonials.
- Under GDPR you have the right to erasure. Uninstall and your store data is deleted within 30 days, and you can request immediate deletion at any time.
Changes to this page
When this page changes, the change is logged here, dated.
Entries below are development history rather than customer-facing incident notes, since this page predates a public launch.
- Genericized the "How we use AI" section: "How we use Claude" is now "How we use AI", and that section no longer names the vendor or links to its terms. The vendor is still named in the Infrastructure and subprocessors list below, where full disclosure is required regardless.
- Stated the two optional read scopes our Shopify listing declares, that Shopify cannot grant them yet under our current install flow, and that declining them costs nothing. Every scope name on this page is now rendered from the same definition the install flow uses, rather than typed here.
- Corrected two false statements. The billing rail is Shopify Billing, not Stripe (Stripe survives for stores that did not install through Shopify). The subprocessor ledger listed four companies where the real list is seven, and it is now generated from the same definition the code uses rather than typed here. Also corrected the Claude section: your copy settings are not sent to Anthropic and never have been.
- Reviewed against Increments 4-6 shipped code. Updated JSON-LD delivery description to reflect current metafield approach.
- First public version of the Trust Center.