Legal
Privacy
policy
Awekia AI Assistant · last updated 4 October 2026
Awekia AI Assistant is a Shopify app that answers your customers' questions from your own products and pages. This explains exactly what it reads, what it stores, who else sees it, and how it is deleted.
It is written against what the app actually does. Every list below is the real set of fields, not a category.
What the app reads from your shop
The app asks Shopify for two permissions and nothing else:
read_products— active products only: title, description, URL handle, and for each variant the price, the item code (SKU) and the stock quantity.read_content— your published pages: title and text, with HTML removed.
It has no permission to read your orders, your customers, your reports, or your payment details, so it cannot see them.
Stock quantity is read but never stored as a number. Only "currently in stock" or "currently out of stock" is kept, because a count read at sync time is wrong the moment someone buys one.
At install the app also records your shop's name, your .myshopify.com domain,
your storefront domain, your Shopify plan, and the shop owner's email address —
the last of these only so it can tell you when your credits are running low.
Nothing is read from your shop until you press Read my catalogue, and it reads again only when you press it again.
What the app stores about your customers
When a customer uses the chat bubble on your storefront, it stores:
- A random id the widget generates in their browser — to tell one visitor's questions from another's, and to keep a conversation together across pages.
- The question they asked, and the answer given — so you can read the conversation, and so questions nobody could answer appear on one list.
- Which of your pages or products the answer used — so you can check an answer against the real page.
- Their name, email or phone, only if they type them in — so you can reply when the assistant could not.
- Their Shopify customer id, only if they are signed in to your store — so a deletion request from Shopify can be matched to them.
What is deliberately not collected
- No IP addresses. None is read, logged or stored anywhere in the app.
- No cookies. The widget keeps one random id in the browser's own local storage. It is not a cookie, it is not sent to any third party, and clearing site data removes it.
- No tracking across sites. The id is per browser and per store, and is used only for the limits described below.
- No payment or card details, ever. All billing goes through Shopify, which we never see.
The random visitor id is not a name and is not a fingerprint. It exists so that one person asking twenty questions can be told apart from twenty people asking one.
Who else the data goes to
To answer a question, the app sends the customer's question and the relevant extracts from your own products and pages to a language model. It does not send names, email addresses, phone numbers, or anything a customer typed into the enquiry form.
- Anthropic — the customer's question and extracts from your products and pages, to write the answer.
- OpenAI — your product and page text, to turn it into a searchable index.
- Cloudflare Turnstile — nothing about the customer from us; their browser completes a check, so that a person can be told from a script.
- Supabase — everything listed above, as the database host.
- Resend — your email address as the shop owner, to send you low-credit warnings.
- Shopify — your purchases and subscription, for billing.
None of it is used to train any AI model, by us or on our behalf. Each provider's own terms govern what they do with what they receive; they are named above so that you can read them.
Nothing is sold, rented, or shared with advertisers. There is no advertising in this app.
Where the data is held
The database is hosted by Supabase on Amazon Web Services in eu-west-1 (Ireland).
Low-credit warning emails are sent through Resend, whose account for this app is in us-east-1 (United States), so your own email address as the shop owner crosses to the US for that purpose. No customer data is sent by email.
How long it is kept, and how it is deleted
Conversations and enquiries are kept for as long as the app is installed. They are not deleted on a timer, because the whole point of the unanswered-questions list is that you can come back to it. If that is not what you want, uninstalling removes them.
- Your products and pages, as indexed — deleted when you uninstall.
- Conversations and the questions asked — deleted when you uninstall.
- Enquiries, including names and emails — deleted when you uninstall, or sooner on request.
- Rate-limit counters — deleted automatically, within a day.
- Records of who completed a robot check — deleted automatically, 12 hours after the check.
- Credits bought and spent — kept, with your shop's identity removed. These are financial records of what was charged.
Shopify requires every app to handle three kinds of deletion request, and this app handles all three:
- A customer asks what you hold about them. The app finds every enquiry matching
their email address or customer id and produces it for you to send on. Email
addresses are matched without regard to capitalisation, so
Name@Example.comfinds a record stored asname@example.com. - A customer asks to be erased. Their enquiries are deleted. Anonymous conversations cannot be matched to a named person and so are not affected — there is no link between the two to erase.
- You uninstall the app. Forty-eight hours later Shopify asks us to erase the shop, and everything above is deleted except the credit records, which are kept with your shop's identity removed.
You can also delete any individual enquiry at any time from the Enquiries screen inside the app.
Telling your customers
The chat bubble is visible on your storefront and collects an email address only when a customer types one in, so there is nothing hidden about it. Depending on where you and your customers are, you may still need to mention it in your own store's privacy policy. If you are in the EU or UK, the usual position is that you are the data controller for your customers' data and we are a processor acting on your instructions.
Security
- All traffic is over HTTPS.
- Requests from your storefront are signed by Shopify and verified before anything is read or written, so one store cannot reach another's data.
- Every table is restricted at the database level by default; the app's own key is the only thing that can read it.
- The app does not keep a copy of your Shopify access token outside Shopify's own session storage.
Changes
Material changes will be dated at the top of this page.
Contact
Questions about anything here, or a request about your data:
hello@awekia.com
Race Course Ridge, P/No. 25 Takoradi, Ghana
Get in touch
For any question about this policy, or a request about your data:
hello@awekia.comRace Course Ridge, P/No. 25
Takoradi, Ghana