Privacy Policy
Last updated: 28 August 2026
This policy describes what Aethos AI actually does with data, written against our own source code rather than from a template. Where we have a gap, we say so.
[PLACEHOLDER — to be completed before launch] Aethos AI is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COMPANY NUMBER, if applicable]. Until this block is completed, treat the operator as the individual reachable through our aethoshq.com/support form or at hello@aethoshq.com.
The short version
- We collect your email address to sign you in, and the product catalogue of the Shopify store you connect.
- We never request order or customer data from Shopify. We ask for product read/write access only, so we do not receive your shoppers' personal data.
- We send shopping questions and product text to AI providers (OpenAI, Google, Perplexity) because measuring what those engines say requires asking them.
- We do not sell your data, we do not build or train AI models, and we run no advertising trackers.
- Our public Shelf Check reports on stores using only public data, keeps the snapshot for 90 days, and has a takedown route for the store's owner.
- Want your data gone? Use our aethoshq.com/support form or email privacy@aethoshq.com and we will delete it.
1. What we collect
Account data. Your email address, and a display name which defaults to your email address until you change it. We record when you last signed in. Sign-in uses an emailed one-time link ("magic link") — we never ask for or store a password.
Shopify store data. When you connect a store we request the Shopify scopes read_products and write_products — that is the whole list. Under that product read/write access we store your store domain and, for each product: title, description, status, product type, tags, category, SEO title and description, up to 50 metafields, and up to 100 variants (SKU, title, price, options). Writes back to your store happen only when you approve a specific change, and are limited to product description, SEO fields and our own aethos.* metafields. We request no order scope and no customer scope, so we never see your shoppers.
Scan and analysis records. The questions we generate, the answers AI engines returned, the citations in them, visibility scores, suggested optimisations and diagnostic results.
The free brand check. Our public brand check at /scan needs no account. When you use it we store the store domain you typed, the vertical you picked, the questions we asked, the verbatim answers the AI engines gave with any sources they cited, which engine and model answered, and whether your brand was mentioned — so we can serve a cached result and show our own work. We do not store your email address, IP address or browser user-agent as part of a brand check.
The public Shelf Check. Our Shelf Check reports on how ready a Shopify store is for AI shopping agents. It is covered in full in section 9 below, because it is the one place where we hold data about a business that did not ask us to.
The email form. If you submit the email form on our marketing pages we store four things: the email address or store URL you typed; which form it came from (for example "pricing"); the website that linked you to us, if any — the domain only, such as "google.com", never the page you were reading; and the address of the page of ours you first landed on, including any campaign tag in its web address. The last two tell us which of our own efforts brought you here, so we can stop paying for the ones that do not work. Still no IP address, no user-agent, no cookie and no tracking identifier — we cannot recognise you across other websites or across visits. We use all of it to contact you about Aethos and to count where our enquiries come from.
Optional integrations you choose to connect. If you connect Google Analytics 4 we use read-only access (analytics.readonly) to count sessions that arrived from AI referrers. If you connect Klaviyo we use your API key to read response counts from a post-purchase survey. Both are stored as daily aggregate counts only — we do not store individual shopper records from either.
Technical data. We use your IP address to rate-limit our public endpoints so they cannot be abused. That happens in memory only — IP addresses are not written to our database. Our server produces operational logs; where a log line would contain an email address we mask it before writing it.
2. Why we are allowed to process it (UK/EU GDPR)
- Performance of a contract — account data, store data, scans and optimisations. We cannot provide the service without them.
- Legitimate interests — rate limiting and abuse prevention, operational logging, security, running the free brand check so people can evaluate the product, and holding public Shelf Check snapshots (section 9). We balance this against your rights by collecting the minimum, not profiling you, and giving you a route to object that a person actually reads.
- Consent — where you submit your email to hear from us, and for optional integrations you connect. You can withdraw it at any time by emailing us.
- Legal obligation — tax and accounting records relating to payments (held by Paddle as merchant of record, see below).
3. Who we send data to, and exactly what
This is the section templates get wrong. Every processor below is one our code actually calls.
- OpenAI (United States) — we send the shopping questions we generate from your catalogue's categories and attributes, and any custom prompts you write. Separately, to classify how an answer portrays you, we send your brand name, a product title, the question, and an extract of the AI's answer. Why: to measure what ChatGPT says about your products.
- Google (Generative Language / Gemini API, United States) — we send the same shopping questions. Gemini runs its own web searches to answer them. Why: to measure what Gemini says.
- Perplexity (United States) — we send the same shopping questions. Why: to measure what Perplexity says.
- Our text-generation provider (Manus Forge by default; the endpoint is configurable and may be OpenAI) — when you ask us to generate a rewritten description we send that product's title, its current description text, its metafields, its variant options, and the brand-voice note you saved for the store if you set one. Why: that is the input the rewrite is generated from.
- Shopify — we read your product catalogue and write back approved changes, under the two scopes named above. Why: it is your store.
- Shopify's Global Catalog — a separate, public, credential-free Shopify service that returns the AI-side view of a store: the description and product attributes Shopify's own models generated. We send the store domain and a link to our public agent profile; we send no merchant data and no personal data. Why: it is what an AI shopping agent actually sees, so it is what we have to measure — for your store, and for a store someone runs a public Shelf Check on (section 9).
- Resend (email delivery) — we send your email address and a sign-in link. Why: to deliver magic-link sign-in. This is the only email we send from the product.
- Paddle — our payments provider and merchant of record. When you subscribe, Paddle collects your billing details directly and we never see or store your card number. Paid subscriptions are not switched on yet, so today we hold no billing data at all. Why: to take payment and handle sales tax and VAT.
- Google Fonts — our pages load fonts from Google's servers, so Google receives your IP address, browser user-agent and the page you requested. Why: web fonts. We are aware this is a transfer and are moving to self-hosted fonts.
- Hetzner Online GmbH — our hosting provider, a German company. Our server and database run on a single machine in its Helsinki, Finland region, so your data is stored inside the EU. Why: hosting.
Website analytics. We carry no third-party analytics tag — no Umami, no Google Analytics, no page-view tracker of any kind on our marketing pages. An unconfigured Umami tag used to ship here and load nothing; we removed it rather than switch it on. The practical consequence is that we do not know how many people read this page, and we would rather say that than run a tracker we did not tell you about. If we ever add one we will name it here and update the date at the top.
What we do not do. We do not sell your data or share it with data brokers. We do not build or train AI models, and we do not use your data to train any model of our own. We send data to the providers above in order to get an answer back; each provider's own terms then govern what they do with it, and you should read theirs if that matters to you. We run no advertising, no behavioural tracking and no cross-site tracking on this site, and we serve no advertising cookies.
Crawler checks. To tell you whether AI crawlers can reach your storefront, our server fetches a handful of your own public pages using the user-agent strings those crawlers use. This visits only the store domain you connected, and reads only public pages.
Storefront fetches. Separately, to work out how a store presents itself to AI agents, our server fetches a few files that any visitor can request — /.well-known/ucp, /agents.md, /llms.txt and robots.txt. For your own store this happens because you connected it. It also happens to a third-party store when someone runs a public Shelf Check on it, which is covered in section 9. Either way we read only public files, we request them one store at a time and only when a person asks, and our user-agent names Aethos and carries a contact address.
4. International transfers
We host in Finland, inside the EU. The AI providers, Resend, Shopify and Paddle listed above are wholly or partly based in the United States, so using Aethos involves transferring data outside the EEA and UK. We rely on the transfer safeguards those providers offer — standard contractual clauses and, where the provider participates, the EU–US Data Privacy Framework. If you want the specific mechanism for a named provider, ask us and we will tell you what we have.
5. How long we keep it
- Sign-in links — valid for 15 minutes, usable once, and stored only as a hash. Used and expired links are purged.
- Sessions — your session cookie lasts 30 days. We can revoke every outstanding session for your account at once, which takes effect on the next request; ask us and we will do it. There is no button for this in the interface yet.
- Store, catalogue and scan data — kept while your store is connected. When you disconnect a store, or when Shopify tells us you uninstalled the app, we delete all of it:
- AI-generated description suggestions and their self-check receipts
- Per-product diagnostic results (which readiness rules passed)
- Product kind classifications and their provenance
- AI-engine scan results (which prompts mentioned your products)
- Product variant records (SKUs, prices, stock)
- AI-referral traffic and revenue attribution figures
- Snapshots of how AI shopping agents describe your products
- Agentic-readiness scans of your storefront
- "How did you hear about us?" survey aggregates from Klaviyo
- War Room alerts, both open and resolved
- Drift-monitoring cycle history
- Competitors you added to the War Room
- AI-crawler accessibility checks of your storefront
- Custom prompts you wrote for scanning
- Scan job history and readiness snapshots
- Shopify metafield definitions we created for structured facts
- Weekly digest send history
- One-click unsubscribe tokens issued in digest emails
- Your subscription history with us — when each plan change, charge and cancellation happened
- Your imported product catalog
- The custom Shopify app credentials issued for your store
- Any request you filed to connect this store before it was set up, and the email address on it
- In-app alerts — 90 days after an alert is resolved, it is deleted by the same daily job. Resolved means a later check measured that the condition was over — not that time passed. Two kinds never age out at all: an alert that is still open, however old, because a problem nobody has fixed is still true; and an alert recording something that happened and cannot un-happen, such as a description being rewritten. Those go when you disconnect the store, with the rest of its data.
- Shopify app uninstall — we act on Shopify's
shop/redacterasure webhook and purge the same store data. We keep the store record itself so that a reinstall does not lose your subscription or make you set everything up again. That row holds your store domain and:- which plan you are on
- the billing-provider customer reference behind your invoices
- the subscription reference, so a reinstall resumes it
- whether that subscription is active, paused or cancelled
- the monthly price you signed up at, which we hold for you
- which published price list that price came from
- the catalogue vertical you picked, so a reinstall does not ask again
- your founding-brand number, if you are one of the first brands we onboarded
- whether you finished setup, so a reinstall does not restart the wizard
- how many Shopify pushes you have used this billing month
- when that push counter next resets
- the fact that you unsubscribed from our digest email, if you did — kept so we never email you again
customers/redactandcustomers/data_request; we acknowledge both and record that there was nothing to erase or export, because we never hold your shoppers' data in the first place. - Public Shelf Check snapshots — 90 days, then deleted. This one is enforced by code rather than by this sentence: every snapshot is written with an expiry timestamp, and a sweep runs daily and again on each new scan to delete the rows that have passed it.
- Free brand-check records — 90 days from the scan, then deleted. The same period as a Shelf Check snapshot, because it is the same kind of thing: a report about a store, captured on demand.
- Payment-provider event records — 90 days. When our payment provider tells us something about your subscription we record the event's id and type so the same message cannot be replayed against your account. It holds no card details — we never see those — and the same daily job deletes it.
- Email-form entries — 24 months from when you gave us the address or from the last time you contacted us, whichever is later. Writing to us again restarts the clock; if you never do, the record is deleted automatically. You do not have to wait for that — ask us at aethoshq.com/support or email privacy@aethoshq.com and we will delete it now.
- Your account record — kept while you use Aethos, and deleted after 24 months without a sign-in if by then it holds nothing: no connected store, and no outstanding request to connect one. That record is your email address, the display name shown with it, and when you last signed in. If you still have a store connected we keep the account, because deleting it would take your store's settings and subscription with it. You never have to wait for that clock either — ask us at aethoshq.com/support or email privacy@aethoshq.com and we will delete the account now.
An earlier version of this policy admitted that the last two had no automatic expiry at all. That was true when we wrote it, and we fixed the software rather than leave the sentence standing: both are now deleted by a daily job, and the periods above are the ones that job actually uses.
6. Your rights, and how to actually use them
If you are in the UK or EEA you have the right to access your data, to correct it, to have it erased, to receive it in a portable form, to object to or restrict our processing, and to withdraw consent. We extend the same handling to everyone regardless of where you live.
Be aware of one gap: there is no self-service "delete my account" button in the product today. What you can do yourself is disconnect your store from Settings, which deletes the store data listed above. For everything else — your account record, an email address you gave us on one of our forms, a brand-check record — use our aethoshq.com/support form or email privacy@aethoshq.com and a human will do it. We aim to complete requests within 30 days and will confirm when it is done. Building a self-service account-deletion path is on our roadmap.
If you think we have handled your data badly, please tell us first — but you also have the right to complain to your national data protection authority.
7. Security
Shopify access tokens, Google refresh tokens and stored API credentials are encrypted at rest with AES-256-GCM. Traffic is encrypted in transit with TLS. Sign-in tokens are stored only as hashes. Session cookies are HTTP-only, so page scripts cannot read them. We request the minimum Shopify scopes the product needs. No service is perfectly secure, and we will tell you promptly if a breach affects your data.
8. Cookies and browser storage
We use no advertising or cross-site tracking cookies. What we do set:
app_session_id— a strictly necessary, HTTP-only cookie holding your signed-in session. Lasts 30 days.sidebar_state— remembers whether you collapsed the dashboard sidebar. Lasts 7 days.- Browser local storage:
aethos-theme(light or dark),sidebar-width,aethos:onboarding-step:<your-store>andaethos:onboarding-job:<your-store>(so a refresh does not lose your place in setup — note these keys include your store domain), andmanus-runtime-user-info, which caches your name, email and role so the signed-in interface can render without a round trip. - Browser session storage:
manus-cookie, a fallback copy of your session used when a browser blocks our cookie.
You can clear all of the above from your browser settings at any time; clearing the session entries signs you out. None of these are analytics or advertising cookies, and we set no analytics cookie — as section 3 says, we carry no third-party analytics tag at all.
9. The public Shelf Check
Our Shelf Check produces a public report on how ready a Shopify store is for AI shopping agents. It is the one part of Aethos that holds information about a business which never asked us to, so it gets its own section and its own rules.
What it reads. Only public information, from two places. First, Shopify's own public Global Catalog, which we query with no credentials at all — the only thing identifying us is a URL pointing at our public agent profile, which Shopify fetches. Second, the store's own publicly served files: /.well-known/ucp, /agents.md, /llms.txt and robots.txt. We do not sign in, we never use a merchant's credentials, and we see no order or customer data. Our requests identify themselves with a user-agent that names Aethos and carries a contact address, so a store owner reading their own logs can tell who we are and reach us.
Where we refuse to look. Because a stranger types the hostname, we resolve it before fetching anything and refuse the whole host if it points anywhere private or internal, pinning the one public address we resolved for every request in that scan. That is there to stop our server being used to reach somewhere it should not — it also means we cannot be pointed at a private network by a crafted domain.
We only scan on request. A store is scanned when a person asks for it, one store at a time. We do not crawl Shopify in the background and we do not offer a searchable index of other people's catalogues.
What we store. The store domain, the report we generated from that public data, how many requests the scan used, whether we read the catalogue at one depth or two, and — only if the live-answer feature is switched on for that scan — the verbatim answer an AI engine gave and which model gave it.
How we score it, and what that is worth. We publish the method on the report itself. It grades each product on the product metadata Shopify's catalogue carries — top features and technical specifications — and bands the store from that. Selling points are reported but are deliberately not part of the grade, because Shopify generates them for everyone and they separate nothing. The thresholds are our own opinion, not Shopify's, and a score is not a statement of fact about the store or its business.
How long. 90 days from the scan, after which the snapshot is deleted automatically (section 5). If you connect that store to Aethos and claim the scan, it stops being an anonymous public snapshot and becomes your own store data, kept while your store is connected and deleted when you disconnect.
If it is your store and you want the report gone. Use the takedown control on the report, our aethoshq.com/support form, or email legal@aethoshq.com. A person — not a script — reads every request and answers within 7 days. We deliberately do not let the form suppress a store on its own, because a control that lets anyone erase anyone's report is a tool for harassing competitors; an operator works the queue from a tool that orders it by the deadline we promised you. Honouring a request does two things: we delete every stored snapshot for that domain, and we stop scanning it here at all.
If you gave us your email on that page. The page tells you before you type it what the address is for, that we never sell it, and how to have it erased. It also carries a control that deletes it on the spot — you do not need an account to use it, and it works for any address we captured through one of our forms. It answers the same way whether or not the address was on file, so it cannot be used to find out who has signed up. If that control fails, tell us at aethoshq.com/support or email privacy@aethoshq.com and we will do it by hand. The address is kept on the schedule in section 5 like any other; the consent line on that page is about how to get it deleted rather than how long it lasts.
Our legal basis for holding a Shelf Check snapshot is legitimate interests: reporting on public commercial data so merchants can evaluate their own readiness. We balance it by using public sources only, deleting after 90 days, publishing the method we scored by, and honouring takedowns.
10. Children
Aethos is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
11. Changes
If we change this policy we will update the "Last updated" date at the top. If a change materially affects how we handle your data, we will email account holders before it takes effect.
12. Contact
Data protection and privacy requests: privacy@aethoshq.com. Shelf Check takedowns and other legal notices: legal@aethoshq.com. Anything else: hello@aethoshq.com. For all of these, our aethoshq.com/support form reaches the same people and does not depend on email delivery.