1. Who we are
Kobold is operated by SAUDADE MEDIA OÜ (registry code 17537135), Sepapaja tn 6, 15551 Tallinn, Estonia. We are the controller for account data and a processor for the store data we handle on behalf of the merchant or agency that connects a store.
2. Data we get from Shopify
When you install the Kobold app we ask Shopify for two permissions only: read_themes and write_themes. With them we receive: • Your shop's name, myshopify domain and primary domain. • Your theme files (Liquid, JSON templates, settings, CSS, JavaScript and theme assets) for the live theme and the copies Kobold creates. • An offline access token. It is encrypted at rest (AES-256-GCM) and only decrypted inside the job that talks to Shopify.
3. Data we never collect
Kobold does not request access to orders, customers, checkout, payments, products or analytics. We do not receive or store your shoppers' names, emails, addresses or payment details.
4. Data you give us
• Account details: name, email and sign-in data (via Clerk). • Workspace content: task requests, agent threads, plans, approvals and client approval links. • Store memory notes and agent rules you write. • A storefront password, if your store is password-protected. Stored encrypted, used only to open previews. • Screenshots and page captures Moss takes of your preview themes while testing. • Billing details, handled by Stripe. We never see or store full card numbers.
5. How we use it
We use store data only to do the work you ask for: plan, build and test theme changes on a copy, show you before and after, and publish when you approve. Theme files and task messages are sent to our AI provider (Anthropic) to generate plans and code. [Confirm: Anthropic does not train models on API data under its commercial terms.] We do not sell data or use it for advertising.
6. Shopify privacy webhooks
We subscribe to Shopify's mandatory compliance webhooks. • customers/data_request and customers/redact: Kobold holds no customer data, so we confirm and log the request. • shop/redact (sent 48 hours after uninstall): we delete that store's memory, theme index, snapshots and screenshots within 30 days.
7. How long we keep it
• While the app is installed: as long as your workspace exists. • After uninstall: access token deleted immediately; store data purged within 30 days. • Theme copies Kobold made stay in your Shopify theme library. You can delete them any time. • Invoices and credit history: kept for [7 years] for tax purposes.
8. Subprocessors
We use these companies to run Kobold. Each is bound by a data processing agreement.
9. Your rights
Under the GDPR and similar laws you can ask to see, correct, export or delete your personal data, and object to how we use it. Merchants can delete a store's data by uninstalling the app or removing the store in Kobold. Requests about a shopper's data should go to the merchant; Kobold does not hold it.
10. Contact
Email privacy@usekobold.com or write to SAUDADE MEDIA OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia. You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or to the data protection authority where you live.
11. Changes to this policy
If we change what we collect or who we share it with, we'll email workspace owners at least 30 days before the change takes effect.