Privacy policy
Version 3 · Effective 3 September 2026
AskIdris is built and operated by Idris Labs Ltd, a company registered in the United Kingdom. This policy explains what data we collect, why we collect it, and the choices you have. Questions and requests reach a person at support@askidris.com.
The two kinds of data we handle
We handle data in two distinct roles, and different rules apply to each:
- Your account data — the email address and sign-in details you use for AskIdris, and anything you submit on our beta application form. For this data we are the data controller.
- Your store’s data — the commerce and storefront data we analyse to provide the service. We process this on your instruction, as the merchant’s processor: it is your store’s data, used only to provide AskIdris to you.
What we collect from your store
- Order and catalogue data from Shopify — order amounts, dates, products, discounts, refunds and country codes, plus your product catalogue, costs you supply and inventory levels. We deliberately minimise personal data here: your customers’ names, email addresses, phone numbers and street addresses are stripped before storage and are never persisted by AskIdris. Orders are linked by pseudonymous identifiers so figures like new-versus-returning can be computed without contact details.
- Storefront behaviour — a web pixel on your storefront records shopping events (page and product views, searches, cart and checkout steps) so we can analyse your funnel. The pixel honours Shopify’s customer-privacy consent: it does not send analytics events for visitors who have not given analytics consent. It never records payment details, and it never records what visitors type into forms.
- Storefront checks — we periodically load public pages of your own storefront (identified as “IdrisMonitor”) to check that it is working, and keep captures of those public pages. When a specific finding calls for it, an automated check may also walk public shopping steps on your storefront — viewing a product, adding it to the cart, reaching the checkout page — to verify the path works. These checks never enter payment details and never place an order.
- Figures you supply — product costs, recurring operating costs and daily advertising spend you choose to enter or upload. These are store-level business figures you state yourself; they contain no personal data and are used only in the analysis we show you.
- Sources you connect — if you choose to connect Google Search Console, Google Merchant Center, Klaviyo or Judge.me, we read reporting data from them (search queries and clicks for your site, price benchmarks, campaign performance, product reviews). Reviewer contact details are not read from review sources.
- Tools you connect in Sources — you can also connect a support desk (Gorgias, Zendesk), an engineering or status feed (Sentry, Statuspage, Datadog, GitHub or Vercel deploys), a Google Sheet, an inbound webhook, your own API or an MCP server. Idris reads only what the connection you configure returns, and keeps short mechanical excerpts of it as evidence on the cases and briefs that consulted it. A support-desk excerpt can include what a customer wrote in a ticket, so connect a desk only if that is acceptable to you as the controller of that data; those excerpts fall under the same retention, export and deletion as the rest of your workspace.
- Destinations you choose — if you connect a Slack channel as a destination, case titles, case summaries and briefing headlines are sent to that channel for the events you opt into. Nothing is sent to a destination you have not configured.
How we use it
One purpose: to provide AskIdris to you — detecting problems and opportunities in your store, building the evidence for them, and reporting what changed. We do not sell data, share it with data brokers, or use it for advertising. Emails from AskIdris (weekly reviews, case alerts, the daily briefing) are controlled by you in Settings.
Parts of the analysis are produced with AI models from Anthropic. Excerpts of your store’s figures, and short excerpts from the sources and tools you connect, are sent to Anthropic’s API to write that analysis; our providers act as processors for us and are not permitted to use your data for their own purposes, including training their models.
Google user data
If you connect Google Search Console or Google Merchant Center, we access their reporting data for your own site and product listings, and use it only to show you those insights inside AskIdris and to build the analysis the product exists to provide. AskIdris’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Disconnecting a source in Settings stops further reads at once.
Who processes data for us
AskIdris runs on a small set of infrastructure providers, each processing data only to run the service: Supabase (database), Vercel (application hosting), Anthropic (AI analysis), Resend (email delivery), and the platforms you connect (Shopify, the optional sources and tools you connect, and any destination such as Slack that you configure). Some providers process data outside the UK under their standard data-protection terms.
Retention and deletion
- Your conversations with the analyst, and the requests we send to Anthropic to answer them, are kept for the life of your workspace so the analyst can remember what you told it; they are erased with the workspace. Beta application details are kept until you ask us to remove them.
- Granular storefront events are retained for around 90 days; the daily aggregates derived from them are kept for the life of your workspace so long-run comparisons stay possible.
- You can export your workspace’s data, and you can delete your workspace — deletion erases the store’s data across every table we hold.
- We honour Shopify’s privacy webhooks: a customer data request or redaction from your Shopify admin is processed against our records, and uninstalling with a store redaction erases the store’s data entirely.
API access you create
A workspace owner can create API tokens that let external tools they choose (for example, an AI assistant on their own computer) read the workspace’s figures — the same analysis the app itself shows. This access is read-only, created and revoked only by the workspace owner in Settings, and we store only a cryptographic hash of each token, never the token itself. No data is shared with any external tool unless you create a token and give it to that tool yourself.
Cookies
This marketing site sets no cookies. The app sets only the cookies it needs: a sign-in session cookie, a cookie that remembers which workspace you were using (one year), and short-lived state cookies while you connect a source. Idris staff additionally carry an admin session cookie and an audited impersonation cookie. There are no advertising or cross-site tracking cookies.
Your rights
Under UK data protection law you can ask us for access to, correction of, or erasure of your personal data, ask for a copy in a portable form, or object to processing — email support@askidris.com and we will respond. If you are unhappy with how we handle your data you can complain to the UK Information Commissioner’s Office (ico.org.uk). If you are a customer of a store that uses AskIdris, the store is the controller of your data — contact the store, and we will act on its instruction.
Changes
When this policy changes we will post the new version here and update the date at the top.