Privacy policy
Eruptian is operated by Agolith, based in the Netherlands. This page describes what the service stores, why, and what you can ask us to do with it. It covers the Eruptian website, the Eruptian Shopify app and the Eruptian browser extension.
For the personal data of your own customers, you are the controller and we are a processor: we handle it only to provide the service to you.
What we store
Your account
Your email address, and either a password hash or a Google account identifier, depending on how you sign in. We never store your password itself. Tokens for verifying your email or resetting your password are stored only as hashes, and expire.
Your connected store
The store domain, the access token that lets us act on your behalf, and settings you choose. Access tokens for stores connected through the website are encrypted at rest. Sessions created by installing the Shopify app are stored by Shopify’s own library in our database without a second layer of encryption; the database itself is not publicly reachable.
What you do with the product
Products you import (source link, resulting product, and the rewritten text), size charts, bundle deals and cart settings, the competitors and products you save while researching, and the notes you write. This is business data about products and shops. It is not your customers’ personal data, and we do not read your orders or your customer list.
Your AI key
Eruptian uses your own key from the AI provider you pick, which we store encrypted and use only to make the calls you ask for. We never use it for anything else and never share it.
Technical logs
Our hosting keeps ordinary server logs (request paths, timestamps, IP addresses) for operating and securing the service.
Cookies
The website sets only the cookies it needs to work, and none that follow you elsewhere: one that keeps you signed in (until you sign out or close your browser), a short-lived one that protects signing in with Google (it expires after ten minutes), and one that remembers the language you chose with the language switch (for a year), and one that remembers whether you collapsed the dashboard’s sidebar (also for a year). There are no advertising or tracking cookies, and no analytics. Your choice of a light or dark look, a few display preferences and some technical notes the pages keep for themselves (such as where you had scrolled to) stay in your own browser’s storage and are never sent to us.
Who else sees it
As few parties as possible, and each of them for one reason:
- Shopify — to read and write the products, themes and discounts you ask us to.
- Anthropic, OpenAI, Groq, Google, xAI, DeepSeek, Mistral, OpenRouter or Moonshot — what you import is sent to the provider whose key you configured, so it can be rewritten or read: the product text, and the product photos, uploaded images or PDF a size chart is read from. Which provider is your choice. Pick Anthropic, OpenAI, Groq, Google, xAI, DeepSeek, Mistral or Moonshot and that one provider is the only one that receives anything. OpenRouter is a broker, so there it is two: OpenRouter itself, and the provider behind the model you name. Where that is matters: Anthropic, OpenAI, Groq, Google, xAI and OpenRouter process in the United States, Mistral in the European Union, and DeepSeek and Moonshot are Chinese providers — DeepSeek’s own privacy policy says what you send is stored in China.
- Railway — hosting and the database, in the European Union.
- MailerSend — account emails such as verification and password resets.
- Stripe — payments for Eruptian Pro: your email address and our reference for your account, and your payment details on Stripe’s own checkout page.
We do not sell data, we do not share it for advertising, and we never use your store’s data to train models. Your AI provider’s own terms decide what they do with what we send them on your behalf: Google’s free Gemini tier, for one, uses it to improve Google’s products, which is why we say so where you paste that key.
The browser extension
The Eruptian Discover extension reads the page you are looking at, and only when you open it and press the button. It reads public Meta Ad Library pages you have opened yourself and public product pages. It does not sign in to Meta, use your Meta session, call undocumented endpoints, or crawl in the background. What it captures goes to your Eruptian account and nowhere else.
How long we keep it
Account and store data lives for as long as your account does. Uninstalling the Shopify app triggers Shopify’s redaction webhooks, and we then delete every record keyed to that store — settings, imports, size charts, bundle deals, cart settings and the stored access token. To have your account itself deleted, email us and we will do it; there is no self-service button yet. Backups are cycled out on their own schedule.
Your rights
Under the GDPR you can ask for a copy of your data, ask for it to be corrected or deleted, object to processing, or ask us to hand it over in a portable form. Write to admin@eruptian.com and we will answer within 30 days. You may also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Security
Access tokens for connected stores and your AI key are encrypted at rest with a key that differs per environment. Everything travels over HTTPS. Links we fetch on your behalf are checked so that they cannot be used to reach our internal network. What we cannot promise is perfection: if a breach affects your data, we will tell you.
Changes
When this policy changes, the date at the top changes with it. If a change materially affects you, we will say so by email rather than leave you to notice.
Contact
Agolith — admin@eruptian.com