Declara — Privacy Policy

Last updated: September 23, 2026

This app lets a merchant mark which of their product images were generated with AI, and shows a small badge on those images in their storefront. It exists because the EU AI Act asks for that disclosure to be clear and in a consistent place. This policy explains exactly what the app reads, what it stores, what it puts on the storefront, and what it does not touch.

What the app reads

When a merchant opens the app, it queries the Shopify Admin API for what it needs to show them a list of their own images:

It does not read orders, customers, names, email addresses, phone numbers, addresses, or payment details. It does not request permission to read any of them.

What the app stores

The marks themselves are stored in the merchant’s own store, as Shopify metafields, not in this app’s database. Two reasons: the storefront badge can then be drawn without calling this app at all, and a merchant who uninstalls keeps the disclosure the law asked them to make.

What the app puts on the storefront

This app adds a theme app extension to the merchant’s storefront. It is the product, so it is worth being exact about what that code does:

Retention and deletion

When a merchant uninstalls the app, Shopify sends an app/uninstalled webhook and the app deletes that store’s session and its entire record of marks made and removed. Nothing else is stored here, so uninstalling removes all of it.

The marks left on products belong to the merchant and stay in their store, as their own metafields, where they can edit or remove them without this app.

A merchant can also request deletion at any time by emailing hjuhyun35@gmail.com.

Security

If something goes wrong

If the developer finds, or is told about, a breach or a suspected one:

To report a vulnerability or a suspected breach, email hjuhyun35@gmail.com. Reports are read by the developer directly.

Service providers

The app runs on Cloudflare, which provides both the server that answers requests and the database behind it. Shopify is the source of all merchant and store data. No other third party receives data from this app: there is no analytics service, no error-reporting service, and no advertising or marketing tooling.

What the app does not do

Changes to this policy

If the app ever changes what it reads, stores, or puts on the storefront, this page will be updated before that change ships, and the date at the top will change with it.

Contact

Questions about this policy or about data handling: hjuhyun35@gmail.com