Privacy Policy
1. Who this covers
This policy describes how Rudy AI ("the app", "we") handles information when a Shopify merchant installs it on their store. It concerns merchants, not their shoppers. See §3.
2. What the app accesses
When you install Rudy AI, Shopify grants it these permissions, and it requests no others:
| Permission | Why the app needs it |
|---|---|
Read and write productsread_products, write_products | To review product content for SEO and write improvements you approve |
Read and write themes, write theme coderead_themes, write_themes, write_theme_code | To create new themes and preview them |
Read and write content (pages)read_content, write_content | To create and edit pages |
Read and write filesread_files, write_files | To upload a generated theme's images to your store's Files, so the theme itself stays small enough for Shopify to install |
Read metaobjects and their definitionsread_metaobjects, read_metaobject_definitions | To understand how your store structures content |
The app does not request access to customers, orders, or payment information, and does not read them.
3. Shopper data
The app does not collect, store, or process personal information about your customers. It works
with your store's design, product content and pages. Per Shopify's App Store requirements, the app
still implements Shopify's mandatory compliance webhooks
(customers/data_request, customers/redact, shop/redact) to
respond to any data-subject requests Shopify forwards.
4. What is stored
| Data | Why |
|---|---|
| Your store domain and Shopify access token | To act on your store when you ask it to |
| Your account details as Shopify provides them: store name, email address, phone number, country and currency | To identify your store, contact you about the app, and apply the right currency to usage and billing |
| Product titles, descriptions and related content | To review and improve them |
| Pages and themes generated or edited through the app | So you can preview, revise and reinstall them |
| Content retrieved from any reference URL you provide | To build the design you asked for |
| Keyword and search-performance data, where you connect it | To report on how your store is found |
| Your AI provider credential | To make the requests you ask for, on your account |
| Credentials for any search-data service you connect (Google Search Console, Bing, SerpAPI, DataForSEO) | To fetch your own search data on your account rather than ours |
| Usage records — how much processing each task consumed | For your plan's limits and billing |
Reference URLs you provide
When you give the app a URL, it retrieves that page to build a design from it. Retrieved content is stored with the resulting theme so you can preview and edit it. Use a site you own or have the right to use. The app takes design and structure; it does not copy products, prices, photographs or descriptions into your catalogue.
5. Your AI provider connection
Rudy AI does not include AI processing. You connect your own account with an AI provider.
- Your credential is encrypted before it is stored and never displayed back to you in full.
- Content is sent to that provider to be processed.
- We do not use your content to train or fine-tune our own models. Your data is processed only in response to the requests you make.
- That provider's own terms and privacy policy apply to what they receive.
- Their usage is billed to you by them, separately from any subscription to this app.
6. Who else receives data
| Recipient | What they receive | Why |
|---|---|---|
| Shopify | Requests made on your behalf | The app runs on your store |
| The AI provider you connect | Content submitted for processing | The app's core function |
| Our hosting provider | Everything stored, at rest | The app must run somewhere |
| Search-data providers (DataForSEO, SerpAPI, Bing, Google Search Console) | The queries needed to fetch your search data. We do this on your behalf using our own accounts with these providers, so you do not need one. If you prefer, connect your own in Settings and we use that instead | Keyword reporting |
| AI providers (OpenAI, Anthropic, Google) | Content submitted for processing | AI features you enable |
Your information is not sold, and is not shared for advertising.
6.1 Where data is stored
Data is stored with our hosting provider in the United States (Ashburn, Virginia). Our infrastructure provider is Tencent Cloud, a company based in China. We disclose both facts because both may matter to you.
6.2 Generated design structure
Generated page and theme structures may be offered to other merchants as reusable design patterns. We share structure only — never your copy, product text, or personal content. Your wording and design instructions are removed when your store is deleted.
You can decline. Turn off "Share design patterns" in Settings and nothing your store generates from then on is added to the shared library. Turning it off does not withdraw structures already contributed; write to support@getrudy.ai and we will remove them. Declining does not reduce what the app can do for your store — you still benefit from the shared library, you just stop adding to it.
6.3 Website analytics
This privacy policy concerns the Rudy AI Shopify app, which does not collect or process your customers' data (see §3). This section covers visitors to our marketing website, getrudy.ai.
Our website uses Google Analytics to understand how visitors use the site. Google Analytics sets cookies and collects aggregate, non-personally-identifiable information such as pages visited, time on site, device and browser type, and general geographic region. This data is transmitted to and processed by Google under Google's own Terms of Service and Privacy Policy. We do not use it to identify individual visitors, and it is not used for advertising or shared for advertising.
Visitors can opt out of Google Analytics by using the Google Analytics opt-out browser add-on or their browser's cookie controls.
7. Retention and deletion
- Data is kept while the app is installed.
- When you uninstall, we receive Shopify's uninstall notification and delete your store's data
within 30 days. Consistent with Shopify's requirements,
shop/redactfires 48 hours after uninstall and redaction is completed within 30 days (unless legally required to retain). - You may request deletion at any time by writing to support@getrudy.ai, and we will confirm when it is done.
- Themes already installed on your store belong to your store and are unaffected by deletion here. The same is true of images the app uploaded to your store's Files: they stay, because an installed theme may still be displaying them. You can remove them yourself from Shopify admin under Content → Files.
8. Security
- Your AI provider credential is encrypted at rest using authenticated encryption.
- Access to stored data is limited to what is needed to operate the service.
- Data in transit is protected with TLS. No system is perfectly secure, and we do not claim otherwise. If you believe an account has been compromised, write to support@getrudy.ai and rotate the affected key at your provider.
9. Your rights
Depending on where you are, you may have the right to access, correct, export or delete your
information, and to object to certain processing. Write to
support@getrudy.ai and we will respond within 30 days. For
requests Shopify forwards on a merchant's behalf, we respond through Shopify's required channels
(the customers/data_request, customers/redact, and
shop/redact webhooks).
California residents: You may have additional rights under the California Consumer Privacy Act (CCPA), such as the right to know what personal information is collected and to request deletion. We do not sell personal information. Write to support@getrudy.ai to exercise any of these rights.
10. Changes
If this policy changes materially, we will update the date above and notify merchants with the app installed before the change takes effect.
11. Contact
Tunabear Inc., d/b/a Rudy AI
11711 Hillcrest Rd, Dallas, TX 75230
support@getrudy.ai