Privacy Policy
Last Updated: August 23, 2026
Introduction
JizaiDev (“we”, “us”) provides the Shopify app “AltForge” (the “App”), and we treat the proper protection and handling of the information our users entrust to us as a core responsibility.
The App generates and manages alt text for product images using AI, and it also builds an image sitemap that it submits to Google Search Console and analyses there. This Privacy Policy explains what information we collect and store, what we send to external services, how long we keep it, and what rights you have.
Information We Collect and Store
The App handles the following information to the extent its functions require, and stores it in our database (PostgreSQL on Fly.io).
- Store and authentication data — Your store domain, the Shopify access token and the authenticated session. Where a Shopify online session is used, this includes the name, email address and locale of the staff account signed in to the store.
- Product and image data — Product IDs, product titles, variant names, product types, vendor names, tags, and the ID and current alt text of each image (media item).
- Alt text change history — The alt text before and after a change, together with what triggered it (a manual edit, an automatic run, an applied suggestion and so on). We keep this for audit purposes.
- Search performance data — Dates, page URLs, search queries, impressions, clicks, CTR and average position, retrieved from Google Search Console. Google aggregates and anonymises this data, and it identifies no individual.
- Sitemap and site verification status — The history of sitemap generation, the number of entries, submission status, and the state of site ownership verification. The sitemap XML itself is held in Redis rather than in the database.
- Settings — The AI provider and model in use, your alt text templates, whether automatic generation is enabled, your plan, and the number of AI generations run. If you enter your own AI API key, we store that key as well.
The App requests no API scope relating to customers or orders. It cannot access — and never stores — buyers’ names, email addresses, addresses, order contents or payment details.
Information Sent for AI Alt Text Generation
To generate alt text, produce improvement suggestions and evaluate A/B tests, we send the following information to the AI provider you have selected. This transmission is the core function of the App, and it happens when you run a generation.
- Product images — We send the product image itself. For OpenAI we pass the image URL on the Shopify CDN (resized to 512 px wide), and where that URL cannot be retrieved we send the image data directly. For Anthropic and Google Gemini we always send the image data directly.
- Product text — The product title, variant name, product type, vendor name, up to eight tags, and your alt text template examples.
- Search queries and metrics — Only when you run a suggestion based on search data: the search queries, impressions, clicks, CTR and average position for the page concerned.
- Store-wide metadata — Only when you use the product suggestion feature: a list of the product types, vendors, up to 30 tags and collection names in use in your store.
The recipient is whichever provider you select in the settings screen — OpenAI, Anthropic or Google. Because we never obtain buyers’ personal data, none of it is ever sent to an AI provider.
Information Exchanged with Google Search Console
If you use the features that submit sitemaps, verify site ownership or retrieve search performance, we call Google’s APIs on the basis of your explicit permission, granted by authorising the App with your Google account.
What we send to Google: your storefront URL, the URL of the generated sitemap, and the token used to verify site ownership. What we retrieve from Google: search queries, page URLs, impressions, clicks, CTR and average position, together with the processing status of your sitemaps.
As one way of verifying ownership, the App may write a verification meta tag into your store’s theme. This happens only when you run the verification yourself, and it never alters your products or your page content.
How We Use the Information
- To analyse product images with AI, generate alt text and write it back to Shopify.
- To register alt text in languages other than your primary language as Shopify translations.
- To generate an image sitemap, then submit and monitor it in Google Search Console.
- To produce alt text improvement suggestions, measure their effect and run A/B tests, based on search performance.
- To record the history of alt text changes so that you can review it later.
- To improve the App, analyse and resolve faults, and respond to support enquiries.
How Long We Keep Data, and Deletion
The information listed under “Information We Collect and Store” is not discarded after each operation: it stays in our database for as long as you use the App. The product images used for generation are never stored by us — those remain with Shopify.
If you uninstall the App, or if we receive a store deletion request from Shopify (Shop Redact), we delete the authenticated session, your store settings, the product and image records, the alt text change history, AI usage counts, job history, sitemap-related data, and your Google tokens, which we also revoke on Google’s side.
Search performance history and the records of alt text suggestions, effect measurement and A/B tests are not currently covered by that deletion. This is statistical data tied to your store domain and contains no buyers’ personal data, but it does remain in our database after uninstallation. If you would like it removed, please contact us using the details at the end of this Policy.
The “log retention period” attached to each plan governs how far back the admin screen shows your change history. It does not automatically delete records once that period has passed.
API Scopes
The App requests the following Shopify API scopes.
- read_products / write_products Reading products and images (media), and creating products and adding media during a bulk upload.
- read_files / write_files Updating the alt text of images.
- read_locales / read_translations / write_translations Retrieving the languages your store supports, and registering alt text in languages other than your primary one as translations.
- read_content Reading blog articles so that the images they contain can be included in the sitemap.
- read_themes / write_themes Reading and writing your theme in order to insert Google’s site verification tag.
From Google we request only two scopes: Search Console (webmasters) and site verification (siteverification). We request no access to any other Google service, such as Gmail, Drive or Contacts.
External Services We Use
The App relies on the following external services.
- Shopify — Reading and writing products, images, translations and themes through the Admin API and webhooks.
- Fly.io — The hosting platform for the App and its database. The application runs in the Tokyo region.
- OpenAI / Anthropic / Google — Alt text generation. What we send is set out under “Information Sent for AI Alt Text Generation”, and it goes only to the provider you select in the settings screen.
- Google Search Console / Site Verification — Submitting sitemaps, verifying ownership and retrieving search performance, as described above.
- JizaiDev support platform (desk-api.jizai.dev) — Storing what you send from the feature request and bug report forms inside the App, together with any screenshots you attach. Nothing is sent unless you submit a form.
We use no advertising or analytics services. Note that the generated image sitemap is served at a URL that requires no authentication, so that search engine crawlers can fetch it. It contains the URLs and alt text of your published product images.
Disclosure to Third Parties
We do not provide your information to third parties, except in the following cases.
- Where disclosure is required by law.
- Where it is necessary to protect a person’s life, body or property.
- Where you have given your prior consent.
- Where information goes to the external services listed under “External Services We Use”, within the limits set out there, because those services are essential to providing the App’s functions.
We never use your information for advertising, and we never sell or share it with third-party marketing services or data brokers.
Your Rights
You hold the following rights over the information we keep.
The App is registered for Shopify’s privacy webhooks. Because it is designed never to obtain or store buyers’ personal data, when a customer data or deletion request arrives (Customer Data Request / Customer Redact) we hold no customer data to disclose or erase. When a store deletion request arrives (Shop Redact), we delete data to the extent described above.
Compliance with the Google API Services User Data Policy
The App’s use of information received from Google APIs, and any transfer of that information to other apps, adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice, this means the following.
• We use data obtained from Google APIs only to submit image sitemaps to Google Search Console, to verify site ownership, and to display and analyse search performance in the App’s admin screen.
• We never sell data obtained from Google APIs, and we never share it with third parties.
• We never use that data for advertising or marketing purposes.
• No human being reads that data, except with your explicit consent, for security purposes, to comply with applicable law, or in aggregated and anonymised form.
• Search performance data, including search queries, is sent to an AI provider only when you run an alt text improvement suggestion, and only in order to generate that suggestion, as described above.
• You may revoke the App’s access at any time from your Google account settings (myaccount.google.com). If you uninstall the App, we revoke the Google tokens we hold on Google’s side.
International Data Transfers
The App runs in Fly.io’s Tokyo region, but the AI providers’ APIs and Google’s APIs may process requests on servers outside Japan. The information described under “Information Sent for AI Alt Text Generation” and “Information Exchanged with Google Search Console” is transferred abroad for that processing. In every case, traffic is encrypted with SSL/TLS.
Security
We work to prevent unauthorised access, data loss and data breaches by encrypting traffic with SSL/TLS, hardening our servers against vulnerabilities, and limiting access rights within our development team.
Google authentication tokens are encrypted with AES-256-GCM before they are stored in our database.
Changes to This Policy, and Contact
We may update this Policy as we add features or as applicable law changes. Where a change is material, we will revise the last-updated date on this page and let you know through the App’s admin screen or a comparable channel. For questions about this Policy or about how we handle data, and for access or deletion requests, please get in touch.
JizaiDev (developer and operator of the App)
Use the feature request or bug report form in the App’s admin screen, or the support link available from the app list in your Shopify admin.