Privacy Policy
Last updated: September 21, 2026
Kai ("the app") is an app for Shopify, Wix and WooCommerce stores that adds an AI-powered product
search chat to a merchant's storefront. This policy explains what data the app collects, why, and how it's
handled, for both the merchants who install it and their customers who use the chat widget.
Information collected from merchants
When a merchant installs the app, we receive and store:
- Shopify: A store identifier: the
myshopify.com domain of the store
- Shopify: An access token issued by Shopify (via OAuth), used to read the store's product catalog
- Wix: A store identifier: the app instance ID Wix assigns to the site
- Wix: No long-lived token is stored — short-lived access tokens are requested from Wix when needed
- WooCommerce: A store identifier: the hostname of the store's website (for example
shop.example.com)
- WooCommerce: A WooCommerce REST API key (consumer key and secret) that the merchant explicitly approves on their own store's authorization screen, used to read the store's product catalog and to register product-change webhooks
- The store's contact email address, read from the store's basic settings, used only to
notify the merchant about the app (for example, an uninstall confirmation or usage alerts)
- The public address of the store's website, used to make sure only that store's own pages
can use its chat widget
- Product data: titles, descriptions, prices, images, vendors, tags, variants, and stock
levels — read from the store's catalog and kept in sync automatically
Shopify: The app requests only the read_products permission. It never requests, reads, or stores order history, customer records, or payment information.
Wix: The app requests read access to store products, plus the ability to add its chat widget to the merchant's site and read basic site settings (such as currency and contact email). It never requests, reads, or stores order history, customer records, or payment information.
WooCommerce: The WooCommerce authorization screen shows the app requesting read/write access, because WooCommerce only lets a key register webhooks with write permission. The app uses it only to read products, categories and basic store settings (currency and contact email), and to create and remove its own product webhooks. It never reads or stores orders, customer records, or payment information.
Information collected from shoppers
When a customer uses the chat widget on a storefront, we process:
- The text of the messages they send, in order to search the store's catalog and generate a
reply
- A randomly generated session identifier, stored in the shopper's browser (not a real
identity), so a conversation can continue across messages on the same visit
The app does not ask for or knowingly collect a shopper's name, email address, phone number,
physical address, payment details, or account information. Chat messages and session identifiers
are not linked to any real-world identity.
How this data is used
- Product data is indexed so the chat assistant can search and recommend items from the
merchant's own catalog
- Shopper messages are sent to OpenAI's API to generate search results and natural-language
replies
- Session identifiers let a shopper's conversation stay coherent across multiple messages
We do not sell any data, and we do not use shopper messages or store data for advertising.
Third-party service providers
The app relies on the following processors to operate:
- OpenAI — processes chat messages and product text to power search and
generate replies
- Supabase — hosts the database that stores synced product data, store
credentials (Shopify access tokens, no long-lived Wix credentials and the WooCommerce API key), and conversation history
- Railway — hosts the application server
Each provider processes data only as needed to provide their respective service to the app.
Data retention and deletion
- Shopify: If a merchant uninstalls the app, its access is immediately deactivated, and the merchant is emailed a notice of this.
- Shopify: The store's data (product catalog, stored credentials, and conversation history) is kept for 48 hours after uninstall — if the app is reinstalled within that window, everything is still there and nothing needs to be set up again.
- Shopify: After 48 hours, that data is permanently deleted, following Shopify's mandatory compliance process (its
shop/redact request).
- Wix: If a merchant uninstalls the app, its access is immediately deactivated, and the merchant is emailed a notice of this.
- Wix: The store's data (product catalog, stored credentials, and conversation history) is kept for 48 hours after uninstall — if the app is reinstalled within that window, everything is still there and nothing needs to be set up again.
- Wix: After 48 hours, that data is permanently deleted; the app removes it automatically once the 48 hours have passed.
- WooCommerce: WooCommerce does not notify apps when a merchant removes them. A merchant can revoke the app's key at any time in WooCommerce → Settings → Advanced → REST API, which immediately stops all access, and should also remove the chat widget snippet from their site.
- WooCommerce: To have the store's data (product catalog, stored credentials, and conversation history) deleted, the merchant can email us at the address below; we delete it within 7 days of the request.
- Shopify: Because the app never stores customer names, emails, or order data, Shopify's
customers/redact and customers/data_request requests have nothing to act on beyond acknowledgment.
- Wix: Because the app never stores customer names, emails, or order data, Wix's data-deletion and data-access requests have nothing to act on beyond acknowledgment.
- WooCommerce: Because the app never stores customer names, emails, or order data, there is no customer data to export or erase beyond the anonymous chat sessions described above.
Cookies and local storage
The chat widget stores a single random session identifier in the shopper's browser
(localStorage) so their conversation persists across messages. This value is not a
tracking cookie, is not shared with third parties for advertising, and can be cleared at any
time by clearing the browser's site data.
Children's privacy
This app is intended for use by Shopify, Wix and WooCommerce merchants and their storefront visitors generally, and
is not directed at children. We do not knowingly collect personal information from children.
Changes to this policy
If this policy changes, the updated version will be posted at this same URL with a new "last
updated" date.
Contact
Questions about this policy or how data is handled can be sent to
rasoul.jalali.k@gmail.com.