SEARCH AI
Privacy Policy
Last updated 6 August 2026
Search AI is a shopping assistant that merchants add to their Shopify storefront. This policy explains what the app collects, why, and who it is shared with. It covers both the merchants who install Search AI and the shoppers who use it on their stores.
The short version
Search AI does not collect any information that identifies a shopper. No name, no email address, no phone number, no postal address, and no IP address is ever stored. Conversations are held against a random token generated in the shopper's browser, which is not linked to any account or person.
What the app stores
| Data | Why | Kept for |
|---|---|---|
| Store catalog — product, collection, page and blog article titles, descriptions, prices, tags and images | So the assistant can find and recommend real products. This is information the store already publishes. | Until the app is uninstalled or the catalog item is deleted |
| Chat transcripts — what a shopper typed and what the assistant replied | So the conversation makes sense across several messages, and so the merchant can review what their assistant is telling people | A period the merchant chooses, 90 days by default |
| Usage events — the searches the assistant ran, how many results they returned, and which products were opened | To show the merchant what shoppers ask for and what their catalog fails to answer | The same period as transcripts |
| Order references — a Shopify order ID, order number, total and currency, linked to the chat session that preceded it | So the merchant can see whether the assistant influenced sales. Only collected when the merchant enables revenue attribution. | Retained after the transcript is deleted, with the link to the session removed |
| Store settings — colours, copy, plan and configuration | To run the app | Until the app is uninstalled |
What the app does not store
- Shopper names, email addresses, phone numbers or postal addresses
- IP addresses
- Shopify customer IDs or customer accounts
- Payment details of any kind
Search AI does not request access to Shopify's customer records. It reads products, collections, content, publication status, and orders. Of the order, it reads only the identifier, number, total, currency, date, and the tag it placed on the cart itself — no customer fields.
Cookies and browser storage
Search AI sets no cookies. It stores two things in the browser: a random token, so that a returning shopper's conversation and any resulting order can be connected, and a copy of the conversation itself, so the panel still shows it after the shopper changes page or reloads. A matching tag is added to the shopping cart. The stored conversation expires 48 hours after the last message, is readable only by the store it was created on, and is never transmitted anywhere — the copy on the browser exists so the shopper can see their own history, not so anyone else can.
The token and the cart tag are treated as tracking, and both wait for consent. Where a store uses a cookie or consent banner, Search AI reads the shopper's choice through Shopify's Customer Privacy API. If the shopper has declined, no token is kept, no cart tag is added, and no click is recorded. The conversation is then held in per-tab storage instead, which the browser discards when that tab closes — so the panel still survives a reload, and the assistant still works for that visit, but it does not follow the shopper beyond it.
Who the data is shared with
Search AI uses the following processors. Each receives only what it needs to perform its function.
| Processor | What it receives | Purpose |
|---|---|---|
| Anthropic (Claude) | The shopper's messages and excerpts of the store's catalog | Generating the assistant's replies |
| Voyage AI | Catalog text and shopper search phrasing | Converting text into the numeric form used for semantic search |
| Neon | All stored data described above | Database hosting |
| Vercel | Requests in transit | Application hosting |
Data is never sold, and never shared for advertising or for anyone else's marketing.
Deletion
- Uninstalling stops the assistant immediately. Shopify then notifies the app 48 hours later, at which point the store's catalog index, every transcript, all usage events and all order references are permanently deleted.
- Retention deletes transcripts and usage events automatically once they pass the merchant's chosen window. Order references are kept so historical revenue reporting stays accurate, but the link connecting them to a chat session is removed at the same time.
- Customer deletion requests made through Shopify remove the order references for that customer's orders. The remaining transcripts are not connected to them.
Where data is held
Data is stored in the United States. All traffic uses TLS, and the database is encrypted at rest.
Merchants
Merchants who install Search AI can review everything held for their store in the app's Chat logs and Analytics pages, change the retention period or turn off revenue attribution in Settings, and remove all of it by uninstalling. For a data processing agreement, see the Data Processing Addendum.
Changes
Material changes to this policy will be reflected in the date at the top and notified to merchants through the app.
Questions about this document: michael@wip.fyi