Last updated: 2026-09-01

This is the short version of how Boresha treats your store. The privacy policy and DPA are the formal documents.

01

Proposals, not silent publishes

Everything the AI writes is a proposal. For each listing you choose publish live, save as draft, or discard. Optimizing an existing product is update or leave it alone. Nothing is written to Shopify until that step.

02

What we process

Catalog content, your brand profile, media you upload or we generate, staff identity from the Shopify session, and billing identifiers. Support tickets if you write in.

03

What we never send to models

Customers, orders, and payment cards.

04

Where it runs

Application hosting is Railway in Amsterdam (EU). Generated images and video wait in staging storage (Cloudflare R2). When you accept them they go to Shopify Files, and we delete our staging copy. Analytics events are kept for 180 days.

05

Uninstall and redact

Uninstall stops the app. Shopify’s GDPR shop/redact webhook is how we hard-delete or anonymize that shop’s rows. You can also email support@boresha.app.

Ready to use Boresha? Add Boresha to Shopify