Ask Any AIAsk Any AI
Contact
Back to Ask Any AI

Ask Any AI — Privacy Policy

Last Revised: July 31, 2026  ·  Developer: ARUS ENTERPRISES LLC

1. Introduction

This Privacy Policy describes how ARUS ENTERPRISES LLC (“Company,” “we,” “us,” or “our”), a limited liability company organized under the laws of the State of Wyoming, United States, collects, uses, and discloses information in connection with “Ask Any AI” (the “App”), a Shopify application available through the Shopify App Store.

The App has two distinct audiences, and this Policy addresses both:

  • Merchants who install the App on their Shopify store to generate AI-assisted product content and knowledge bases; and
  • Shoppers who interact with the App’s storefront chat widget on a merchant’s store.

By installing the App or interacting with the storefront widget, you acknowledge that you have read and understood this Privacy Policy.

2. Information We Collect From Merchants

2.1 Shopify Account and Session Data

When a merchant installs the App, Shopify’s OAuth process provides us with the store’s shop domain and an access token scoped to the permissions described in Section 3. Where an online session is established, we also receive basic authenticated user information such as name, email address, and locale. This information is stored in our session records to keep the App connected to the merchant’s store.

2.2 Product Catalog Data

Using the access scopes granted at install, the App reads product catalog data from the merchant’s store — including product title, handle, description, vendor, product type, tags, price, and images — in order to build AI-generated knowledge bases about the merchant’s products.

2.3 AI-Generated Content

The App generates and stores content derived from the product data above, including formatted product descriptions, knowledge base sections, predefined questions, and summaries. This generated content is written back to the merchant’s store as product metafields and is also retained in our database.

2.4 App Configuration

We store the merchant’s App configuration and settings, including enabled AI providers, branding and label preferences, prompt templates, and plan or billing state.

3. Shopify Access Scopes

The App requests the following Shopify Admin API access scopes, and no others:

  • read_products — to read product catalog data used to build AI knowledge bases
  • write_products — to write AI-generated content back to the store as product metafields
  • read_themes — to check whether the storefront widget block has been added to the merchant’s theme

The App does not request, and does not have access to, any customer, order, or financial data scopes.

4. Information We Collect From Shoppers

When a shopper interacts with the App’s storefront chat widget (delivered via a Shopify App Proxy), we collect:

  • Chat conversation content — the text of questions asked by the shopper and the responses generated by the AI assistant.
  • Participant identity — either (a) a verified Shopify customer ID, derived from Shopify’s signed logged_in_customer_id when the shopper is logged in to the merchant’s store, or (b) an anonymous device identifier (a UUID stored in the shopper’s browser via localStorage) when the shopper is not logged in.
  • Anonymous-to-customer linkage — where an anonymous device is later seen logged in, we record an association between that device identifier and the resulting customer ID, so that a shopper’s conversation history can be attributed consistently across sessions.
  • Lightweight analytics events — shop identifier, product ID, event type (such as widget impression or click), and which AI provider was used. These events do not contain personally identifiable information.

The App does not require a shopper to be logged in or to create an account to use the chat widget. Anonymous identification is best-effort and relies on browser localStorage rather than a hardened device fingerprint.

5. How We Use Information

We use the information described above to:

  • Operate and maintain the App’s connection to each merchant’s Shopify store
  • Generate AI-assisted product content and knowledge bases for merchants
  • Process and respond to shopper questions submitted through the storefront chat widget
  • Attribute shopper conversations across sessions where an anonymous device is later linked to a logged-in customer
  • Produce aggregate, non-identifying analytics on widget usage (impressions, clicks, provider selection) to help merchants understand engagement
  • Administer billing and plan state through the Shopify Billing API
  • Maintain the security, integrity, and technical operation of the App
  • Comply with legal obligations, including Shopify’s mandatory data protection requirements

We do not use shopper or merchant data for advertising, do not sell personal information, and do not operate any advertising, analytics, or tracking SDKs beyond the App’s own first-party functionality described in this Policy.

6. AI Processing and Sub-Processors

To generate product content and chat responses, the App sends relevant data to the following third-party service providers acting as our sub-processors:

  • OpenRouter (openrouter.ai): Product content and shopper chat messages are routed through OpenRouter, which in turn relays requests to underlying large language model providers (which may include OpenAI, Google, and Anthropic, depending on configuration) in order to generate AI content and chat responses.
  • External AI provider links: Where the App surfaces direct links to third-party AI assistants (such as ChatGPT, Claude, Perplexity, or Grok), the question text, an anonymous visitor identifier, and the selected provider are transmitted to that provider. Use of these external assistants is subject to that provider’s own privacy policy and terms.

We do not control, and are not responsible for, how these third-party AI providers process data once it is transmitted to them. Merchants and shoppers should review the privacy policies of OpenRouter and any linked AI provider for further detail.

7. Hosting and Infrastructure Sub-Processors

We rely on the following infrastructure providers to operate the App:

  • Railway: hosts the App’s application server and its primary Postgres database.
  • Postgres (hosted on Railway): stores merchant session data, product and AI-generated content, App configuration, chat conversations, and shopper identifiers described above.
  • Redis: operates a background job queue used to process content indexing and AI generation tasks. Redis is used for transient job processing and is not a persistent store of user data.
  • Shopify Billing API: processes App subscription and plan charges directly through Shopify. We do not use a separate payment processor, and we do not receive or store payment card data.

We do not use any other third-party analytics, advertising, or customer-relationship tracking services in connection with the App.

8. Data Retention

We retain merchant session data, product data, and AI-generated content for as long as the App remains installed on the merchant’s store, and for a limited period thereafter to allow for reinstallation, in accordance with the data deletion practices described in Section 9. Shopper chat data and identifiers are retained to support conversation continuity and merchant analytics, subject to the same deletion practices.

9. Your Rights and Shopify-Mandated Data Requests

The App implements Shopify’s mandatory GDPR compliance webhooks:

  • customers/data_request: When a merchant receives a data request on behalf of one of their customers, we locate any chat conversations and identifiers in our database associated with that customer’s Shopify customer ID and make that data available to the merchant to fulfill the request.
  • customers/redact: When instructed to redact a specific customer’s data, we delete or anonymize chat conversations and identifiers in our database associated with that customer’s Shopify customer ID.
  • shop/redact: When a merchant uninstalls the App and the shop data redaction period has elapsed, we delete the merchant’s session data, product data, AI-generated content, App configuration, and associated shopper data from our systems, in accordance with Shopify’s required timelines.

Merchants or shoppers who wish to make a data access, correction, or deletion request outside of these automated Shopify processes may contact us using the details in Section 13.

10. Cookies and Local Storage

The App does not use advertising cookies or third-party tracking pixels. The storefront chat widget stores a randomly generated anonymous device identifier in the shopper’s browser localStorage solely to maintain continuity of a chat conversation across page views. This identifier does not by itself identify a specific individual unless and until it becomes associated with a logged-in Shopify customer ID as described in Section 4.

11. Data Security

We apply industry-standard technical safeguards to protect information processed by the App, including encrypted transport (HTTPS/TLS), access controls on our database and hosting infrastructure, and Shopify’s standard OAuth token handling. No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security against all possible threats.

12. Children’s Privacy

The App is intended for use by Shopify merchants and their storefront shoppers in a general commercial context. We do not knowingly direct the App at children, and we do not knowingly collect information from individuals under the age of 13 through the App.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the App’s functionality or applicable legal requirements. Material changes will be reflected by an updated “Last Revised” date at the top of this page.

14. Contact

For questions regarding this Privacy Policy or the App’s data practices, please contact:

ARUS ENTERPRISES LLC
30 N Gould St Ste N
Sheridan, WY 82801
[email protected]