Declara — Privacy Policy
Last updated: September 23, 2026
This app lets a merchant mark which of their product images were generated with AI, and shows a small badge on those images in their storefront. It exists because the EU AI Act asks for that disclosure to be clear and in a consistent place. This policy explains exactly what the app reads, what it stores, what it puts on the storefront, and what it does not touch.
What the app reads
When a merchant opens the app, it queries the Shopify Admin API for what it needs to show them a list of their own images:
- Product titles and IDs
- The images attached to those products: the image ID, the file name, and the thumbnail URL
- The app’s own marks, so a product that is already marked shows as marked
It does not read orders, customers, names, email addresses, phone numbers, addresses, or payment details. It does not request permission to read any of them.
What the app stores
- The Shopify session for each installed store: the store domain, the API access token, and the granted permission scopes. This is what lets the app talk to Shopify on the merchant’s behalf.
- A record of each time the merchant marked an image as AI-generated or removed that mark: the product ID, the image ID, which of the two it was, and when. This exists so a merchant asked to show when a disclosure was in place can show it. It holds nothing about any shopper.
The marks themselves are stored in the merchant’s own store, as Shopify metafields, not in this app’s database. Two reasons: the storefront badge can then be drawn without calling this app at all, and a merchant who uninstalls keeps the disclosure the law asked them to make.
What the app puts on the storefront
This app adds a theme app extension to the merchant’s storefront. It is the product, so it is worth being exact about what that code does:
- It reads the list of marked image file names that the theme has already rendered into the page, finds those images, and draws a small badge in a corner of each one.
- It sends nothing to this app’s servers, and nothing to any third party. The list of marked images is already in the page. The only files the browser fetches because of this app are the badge’s own script and, if the merchant chose the official EU icon, that icon — both served from the store’s own Shopify CDN, like the rest of the theme.
- It sets no cookies and writes nothing to the browser’s storage.
- It does not read, collect, or transmit anything about the shopper: no identifiers, no behaviour, no page views, no cart contents.
Retention and deletion
When a merchant uninstalls the app, Shopify sends an app/uninstalled webhook and the app deletes that store’s session and its entire record of marks made and removed. Nothing else is stored here, so uninstalling removes all of it.
The marks left on products belong to the merchant and stay in their store, as their own metafields, where they can edit or remove them without this app.
A merchant can also request deletion at any time by emailing hjuhyun35@gmail.com.
Security
- All traffic runs over HTTPS, and the server refuses plain HTTP.
- The database is Cloudflare D1, encrypted at rest with AES-256 by the host, with the keys held by the host and not by this app. It has no public address: the app reaches it over a binding available only to this app’s own code, and nothing on the internet can address the database directly.
- Access tokens are stored server-side and are never exposed to the browser. Credentials are held in the host’s secret store, not in the source code.
- One person — the developer — can reach the server and the database, using accounts protected by unique passwords held in a password manager. Nobody else has access.
- Development and testing never use real store data. The badge is tested against Shopify’s own public theme demo stores.
If something goes wrong
If the developer finds, or is told about, a breach or a suspected one:
- The app is taken offline or its access tokens are rotated immediately, whichever stops the exposure faster.
- The cause is established from the server logs, and the entry point is closed before the app is turned back on.
- Affected merchants and Shopify are told within 72 hours of the breach being confirmed, in plain language: what happened, what data was involved, when, and what has been done about it. If the picture is still incomplete at 72 hours, they are told that instead of being told nothing.
To report a vulnerability or a suspected breach, email hjuhyun35@gmail.com. Reports are read by the developer directly.
Service providers
The app runs on Cloudflare, which provides both the server that answers requests and the database behind it. Shopify is the source of all merchant and store data. No other third party receives data from this app: there is no analytics service, no error-reporting service, and no advertising or marketing tooling.
What the app does not do
- It does not track shoppers or visitors.
- It does not sell, rent, or share data with anyone.
- It does not use merchant data to train machine learning models.
- It does not send email to merchants or their customers.
- It does not decide for the merchant which images need a disclosure, and it is not legal advice. The merchant chooses what to mark; the app records and displays that choice.
Changes to this policy
If the app ever changes what it reads, stores, or puts on the storefront, this page will be updated before that change ships, and the date at the top will change with it.
Contact
Questions about this policy or about data handling: hjuhyun35@gmail.com