Back to home

Privacy Policy

Last updated: 2026-09-06

Controller

The controller responsible for processing personal data on this service is Ian Helmrich, Karolingerallee 9, 69181 Leimen, Germany. Contact: info@aigentably.com. For full legal details see the Impressum.

Data we collect

Account data. When you create an Aigentably account we store your email address, a salted password hash (or OAuth identifier if you sign in with a third party), and basic profile data you choose to provide.

Site configuration. For each website you connect we store the public domain, tool definitions you create, and a public site identifier used in our embed script.

Shopify shop data. When you connect a Shopify store we store the shop domain, the OAuth access token (encrypted at rest with AES-256-GCM), the theme identifier used for the app embed, and metadata about installation status. We request only the scopes listed on the Shopify App Store listing; tokens never leave our servers.

Tool call logs. For each call made by an AI agent to one of your tools we record the tool name, timestamp, originating site, the page path the call was made on (never the query string), the result status, a classified failure reason together with the failure message itself, the calling agent where it identifies itself, and the call arguments. The failure message is scrubbed the same way arguments are, described next, and both are used to diagnose and repair broken tools. Before the arguments are stored they are automatically scrubbed of obvious personal data (email addresses, phone numbers, card, account and IBAN numbers, and fields whose name signals a secret); such values are replaced with a typed placeholder. Non-personal content, such as a search query, is kept. We do not deliberately collect end-user personal data; if your tool definitions cause personal data to flow through Aigentably, you remain responsible for that decision under your own privacy policy.

Generation records. When you use the AI tool-generation feature we store a record of each generation: the structured signals extracted from your publicly crawled pages, the model and prompt version used, and the resulting tool suggestions together with whether you saved, edited, or dismissed them. These records let us operate the feature and improve its quality over time.

Guide download and marketing consent. If you request our WebMCP readiness checklist we store your email address to send it. If you additionally tick the marketing checkbox, we also store the exact consent text, the time, a hashed IP address, and a confirmation status, described further under "Legal basis" below.

Billing data. Payment processing is handled by Stripe. We store the Stripe customer ID, subscription status, and the Shopify billing charge ID; we never see or store full card numbers.

Legal basis (GDPR Art. 6)

  • Performance of a contract (Art. 6(1)(b)) for account, site, Shopify integration, and billing data.
  • Legitimate interests (Art. 6(1)(f)) for security logs, fraud prevention, tool call logs used for debugging and analytics, and the use of aggregated, de-identified data to operate, secure, and improve the service (see "Product improvement" below).
  • Consent (Art. 6(1)(a)) where you opt in to optional features such as marketing emails. Marketing emails use double opt-in: ticking the checkbox does not by itself subscribe you, we send a confirmation email and only start sending once you click the link in it. We record the wording you agreed to, the time, and a hashed IP address as proof of consent, and every marketing email includes an unsubscribe link that takes effect immediately.
  • Legal obligation (Art. 6(1)(c)) for tax-relevant records and Shopify privacy-compliance webhook responses.

Subprocessors

  • Hetzner Online GmbH (Germany): hosting and database storage.
  • Stripe, Inc. (USA, SCCs in place): subscription billing for non-Shopify customers.
  • Shopify Inc. (Canada): OAuth, merchant-managed billing, and Admin API access for shops you connect.
  • Resend (USA, SCCs in place): transactional email delivery.
  • Google Ireland Limited (Ireland, may transfer to Google LLC in the USA under the EU-US Data Privacy Framework and the SCCs): Google Analytics, only for visitors who consent to it, on our public website and inside the signed-in dashboard. Inside the dashboard, page paths have any site, tool or user id stripped out first, so Google never receives which account or record a page belongs to.
  • OpenAI / Anthropic (USA, SCCs in place), used only when you explicitly use the AI tool-generation feature. Prompts and generated outputs pass through these providers; we do not send your tokens or customer data.

Product improvement

We use data generated through the service to operate, secure, and improve it. This includes improving our site crawling and AI tool-generation quality, ranking and suggesting tools, and producing aggregate statistics about how AI agents interact with WebMCP-enabled sites. For these purposes we work with de-identified and aggregated data: the structured signals from publicly crawled pages, the record of which AI suggestions were saved, edited, or dismissed, and tool-call telemetry whose arguments have already been scrubbed of personal data as described above.

When we generate tools for one of your sites, we show the AI model that site's own history: tools of yours that are working, and the changes you made to earlier suggestions. That stays within your own site. We never show one customer's tools, code, or page structure to another customer. Where we learn something across customers, it is a counted pattern reviewed by a person before it is used, never anyone's code, and it excludes pages behind your login.

We do not sell personal data. Any insights we publish or share externally, such as benchmarks or trend reports, are aggregated and do not identify you, your end users, or your business. You can object to processing based on legitimate interests at any time by contacting us.

Retention

Account data is kept while your account is active and for up to 30 days after deletion to handle reversal requests and abuse investigations. Tool call logs and generation records are retained for as long as we operate the service, since we use them on an ongoing basis for analytics and to improve crawling and AI generation quality. This is proportionate because the personal-data footprint is minimized before storage: arguments are scrubbed of personal data as described above, and IP addresses are stored only as a one-way hash, never in plain form.

Shopify-specific retention. When a merchant uninstalls Aigentably from their store, or when Shopify sends a shop/redact webhook, all shop data (access tokens, theme metadata, install state) is deleted within 48 hours. customers/redact and customers/data_request webhooks are handled per Shopify's privacy-compliance requirements; since Aigentably does not persist Shopify customer records, these requests are completed by confirming no such data exists in our systems.

Your rights (GDPR Art. 15–22)

You have the right to access, rectify, erase, restrict processing of, port, and object to processing of your personal data. To exercise any of these rights email info@aigentably.com. We respond within 30 days.

You may also lodge a complaint with a supervisory authority. The competent authority for the controller is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg.

Cookies and tracking

We use a small number of strictly necessary cookies for authentication and CSRF protection. We do not use advertising or cross-site tracking cookies. Beyond the necessary ones there are two purposes we ask about separately, and you can answer them separately: campaign attribution and Google Analytics. Both are off until you say yes.

We count visits to our public pages ourselves, without cookies and without any third-party analytics service. For each visit we store the page path, the host of the site that linked to you, and a code derived from your IP address and browser by way of a one-way hash that changes every night. The hash cannot be turned back into your address and cannot be matched across two days, so it tells us roughly how many people visited and nothing about who they are. Your IP address itself is never stored. This needs no consent because nothing is placed on your device, and it happens whether or not you accept the cookie below.

One cookie is not strictly necessary, and we ask before setting it. If you accept the banner shown on your first visit, we store which campaign brought you to the site: the utm_source, utm_medium, utm_campaign, utm_term, utm_content and gclid values from the address bar, the host of the page that linked to us, and the page you landed on. It expires after 90 days. If you later create an account, those values are attached to it so we can tell which advertising is worth paying for.

The cookie contains no identifier for you and no full referring URL, only the host, so a search term you typed elsewhere never reaches us. Nothing is stored before you answer, and declining removes anything already stored. Declining changes nothing about how the site works. Your answer is remembered for a year in a cookie holding a single word.

The second purpose is Google Analytics 4, which we use to see which pages people actually use and where they give up. It runs only if you accept it: until then no script from Google is loaded and no connection to Google is made from this site at all. If you accept, Google Analytics sets cookies on your device (_ga and _ga_<id>, usually for two years) containing a randomly generated ID that recognises your browser on later visits, and it processes your IP address, the pages you view, approximate location derived from the IP, and details about your device and browser.

The recipient is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which processes the data on our behalf under Art. 28 GDPR and may pass it to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework, and transfers are additionally covered by the EU standard contractual clauses. We switch on IP anonymisation, and we keep Google Signals and advertising personalisation switched off, so the data is not used to build advertising audiences. Our reporting data is deleted after 14 months.

Despite these safeguards, US authorities may in principle be able to access data held by a US provider, and you cannot exercise the same rights against them as against a controller in the EU. We think you should know that before you decide. The legal basis for Google Analytics, and for the campaign cookie, is your consent under Art. 6(1)(a) GDPR and § 25(1) TTDSG.

You can change either answer here at any time, and withdrawing is exactly as easy as giving it: one click. Withdrawing deletes the cookies of that purpose immediately, including Google's. It does not affect the lawfulness of anything we processed while your consent was in place. Independently of us, Google offers a browser add-on that blocks Google Analytics on every site, and describes its own processing in its privacy policy.

Campaign attribution

One cookie of ours holding campaign names, so we can tell which of our ads are worth paying for. No identifier, never shared.

Google Analytics

Cookies from Google with a pseudonymous ID, so we can see which pages people actually use. Your IP address reaches Google LLC, including servers in the USA. Advertising features stay off. Turning this off deletes those cookies immediately.

International transfers

Where subprocessors are located outside the EU/EEA, transfers are governed by the EU Standard Contractual Clauses (Commission Decision 2021/914) and supplementary measures where required.

Security

All Shopify access tokens are encrypted at rest with AES-256-GCM. All traffic to the service is TLS-encrypted. Webhook signatures are verified with HMAC-SHA256 before processing.

Changes

We may update this policy from time to time. Material changes will be announced by email to active account holders at least 14 days before they take effect.