Who we are
Shopruno is operated by Dovecore Software LLC ("Dovecore", "we", "us" or "our"). This policy covers the Shopruno website at shopruno.com, Shopruno accounts and the brand planning tools available through them (together, the "Service").
Questions, requests and complaints about privacy go to support@shopruno.com. Dovecore Software LLC is the controller of the personal information described in this policy.
What the Service does today
Shopruno is in a development preview. Today you can create an account, save brand plans that you write yourself, use AI brand planning, which is included while we launch and described in the next section, and, for a brand whose private store service we have set up for you, connect your Shopify store as described under "Connecting your Shopify store". Managed hosting and purchasing are not available yet.
We will update this policy before we switch on any feature that collects, stores or shares a new kind of information, and the change will be described here before it applies to you.
AI brand planning
When you send a message in brand planning, the conversation and your saved brand plan are sent to Fireworks AI, our AI provider, to generate the reply. That is the only time anything is sent, and only for the brand you are working on. Nothing is sent when you edit, lock or confirm your plan by hand.
What we send and what we do not:
- We send your messages in that brand's conversation, the AI's earlier completed replies, the text of your saved brand plan, your starting point and hosting preferences, and the names and instructions of the planning skills that run.
- We do not send your email address, your name, your password, your account or brand identifiers, your sign-in provider details or anything about payments.
What we store:
- Your messages and the AI's replies, including any plan wording it suggests.
- The run status of each reply (queued, working, completed, cancelled or could not be confirmed), when it started and finished, and which skill versions ran.
- The token counts the provider reports for each reply and an estimated cost we calculate from them.
Fireworks AI processes what we send under its own terms and privacy policy, on our behalf and only to generate the reply. Replies use the model's own knowledge. No web browsing happens, no Shopify action is taken, no store is created or changed, and no payment is made.
AI brand planning is included while we launch. We pay for it, and it runs under an allowance that is capped for each brand and for each day. It may pause when a cap is reached, and it may change or end. It is not a purchase, there is no balance to buy and nothing is charged to you. When a brand's allowance is used up, you can still finish and confirm your plan by hand. Please do not put sensitive personal information into brand planning messages; the Service does not need it.
Retention. Messages, replies, run status and usage are kept with the brand. Removing the brand from your account deletes them, and deleting your account deletes them too. A deletion is refused while a reply is still in progress, so that its cost can be accounted for; wait for it to finish or cancel it, then try again.
In our protected development environment, explicitly authorized fictitious test accounts can run the same AI brand planning under a separate, capped evaluation budget; that data is development data and is deleted the same way.
Connecting your Shopify store
A brand's workspace can be connected to one Shopify store, once we have set up a private store service for that brand on our server. Nothing is connected unless you choose to connect it: from the workspace you enter your store's myshopify.com domain and continue to Shopify, where you authorize the access described below in Shopify's own screen. You can also skip this entirely; every other part of the Service works without a connected store.
What you grant, and what we hold:
- Read access to your store's products, and permission to create products as unpublished drafts. If the private service we set up for your brand includes order access, the authorization also includes read-only access to orders.
- Shopify issues an access token for that grant. We hold it, encrypted, on our own server in the private state of your brand's store service, together with your store's myshopify.com domain and its Shopify shop identifier. The token is used only for that brand's store and only for the reads and the approved draft creations described here. It is never shown to you, to us in the workspace, or to anyone else, and it is never sent to our AI provider.
What we read from your store:
- Products: title, handle, status and last update time, read in the background when you request a refresh, and shown back to you as a saved snapshot.
- Recent orders, once you have granted order access: the order number, when it was created, its payment and fulfillment status and whether it is open, closed or cancelled, for orders created in the last 30 days. We do not request your customers' names, addresses, email addresses, phone numbers or the items they bought.
What we write. Nothing is written to your store without your approval. The only write the Service can make is to create a product as an unpublished draft, after you have prepared its exact title and description and then approved that exact proposal. It publishes nothing, sets no price, attaches no image, and never changes, fulfils, cancels or refunds an order or messages a customer. Every proposal, approval and outcome is recorded with the brand.
Shopify processes your store under your own agreement with Shopify and its privacy policy; when you connect, we access your store through Shopify's API with the permission you granted and nothing more. You can remove that permission at any time by uninstalling the Shopruno app from your Shopify admin.
Retention. The encrypted token, your store's domain and identifier, the saved product and order snapshots and the record of your draft proposals and decisions are kept in your brand's store service until the store is disconnected, the brand is removed from your account or your account is deleted, whichever comes first. From that moment the service can no longer act for the brand, and we delete its stored state from our server within 30 days, as with the rest of your account. A draft product already created in your store stays in your store, where you manage it.
How we improve the Service
To learn which planning steps help and which do not, we keep usage records about how the planning tools are used: which planning skill ran and which version of it, whether it finished, was cancelled or could not be confirmed, whether it asked you a question, how long it took and what it cost us, whether you applied suggested wording to your plan and how many fields, when you confirmed a plan, and any feedback label you choose under an AI reply, such as "Useful direction" or "Too generic". Choosing a feedback label is optional.
These records hold counts, timestamps and fixed labels only. They never contain your messages, your brand plan text, your name or your email address, and they refer to your brand only through a coded reference that changes every month and cannot be reversed outside our database. We read them as totals to improve the planning tools and the Service. We do not share them, we do not use them for advertising, and we do not use them to train generalized artificial intelligence models.
Usage records are kept for 13 months and then deleted, or sooner when you delete your account.
Information we collect
Account information. When you create an account we collect:
- Your email address.
- Your password, which we never store in readable form. We keep only a one-way bcrypt hash.
- Whether and when you verified your email address, and when your account was created and updated.
Sign-in with Google or GitHub. If you choose to sign in with a Google or GitHub account, we receive only the information needed to identify you. The section "Google user data" below explains exactly what we receive from Google. From GitHub we keep your numeric GitHub user ID and your primary, verified email address.
Brand plans. When you use the planning tools we store what you enter, which can include:
- A brand name.
- Written answers about your brand, such as its description, audience, problem, positioning, voice, business model, products, constraints, goals and assumptions.
- Confirmed versions of your plan ("blueprints"), which are saved as fixed revisions so you can refer back to exactly what you confirmed.
Please do not put sensitive personal information, such as health, financial account or government identification details, into your brand plans. The Service does not need it.
Technical information. Like most websites, our servers record basic request information for security and to keep the Service running. This includes your IP address, the page requested, the time and a request identifier. We configure our logs to leave out passwords, email addresses, one-time codes and the text of your brand plans. IP addresses are also used, in memory only, to limit repeated sign-in and signup attempts.
Messages you send us. If you email support@shopruno.com, we keep the message and our reply so we can help you.
How we use information
We use the information above only to:
- Create your account, sign you in and keep your account secure.
- Save, show and export your brand plans.
- Generate AI brand planning replies when you ask for them, as described under "AI brand planning", and account for what they cost us.
- Read the products and recent orders of a Shopify store you connected, and create the draft products you approve, as described under "Connecting your Shopify store".
- Send service email you need, such as email verification, password recovery and important notices about your account or these policies.
- Answer your questions and support requests.
- Detect, prevent and investigate abuse, fraud and security incidents.
- Operate, maintain and fix the Service.
- Improve the planning tools, using only the usage records described under "How we improve the Service" and the examples you choose to share under "Examples you choose to share".
- Comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use it to show you ads.
Saved onboarding and customer dashboard
We retain your selected starting point, hosting preferences, brand planning progress and user-reported installation progress to let you resume your journey. Before sign-in, a temporary record stores only a starting selection, linked through your encrypted session. Unclaimed records expire after 30 days and are removed by our daily retention sweep. After sign-in, these choices belong to your account and remain until account deletion.
Your account may also hold software access grants, exact release identities and download request history. An optional installation address is provided by you; saving it does not connect us to your server or give us credentials or access to it. These records are removed with your account. A download request is not proof of installation. Software purchasing and managed hosting remain unavailable; recording these preferences does not buy or activate them.
Google user data
This section describes how Shopruno accesses, uses, stores and shares information it receives when you choose "Continue with Google".
What we access. We request only the openid and email scopes. From Google we receive your Google account identifier, your email address and whether Google has verified that address. We do not request or receive your name, profile photo, contacts, Gmail, Google Drive, Google Calendar or any other Google data.
How we use it. We use your Google account identifier and verified email address only to create your Shopruno account, sign you in, and connect Google sign-in to an existing Shopruno account when you ask us to.
How we store it. We store your Google account identifier and email address in our account database, alongside your Shopruno account. Google issues an access token during sign-in; we use it once to read the identifier and email address, and then discard it. We never store Google access or refresh tokens.
How we share it. We do not sell Google user data or transfer it to anyone for advertising, credit checks, data brokering or any other purpose. It is stored with our hosting provider (listed below), who processes it only on our behalf, and we disclose it only where required by law or to protect the security of the Service and its users. Our staff do not read it except with your permission, for security investigations, or where required by law.
AI and machine learning. We do not use Google user data to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models.
Limited Use. Shopruno's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Your control. You can remove Shopruno's access at any time at https://myaccount.google.com/connections. To delete the Google information we hold, ask us to delete your account as described under "Your rights and choices".
Service providers
We use a small number of service providers who process information on our behalf, under contracts that require them to protect it and use it only to provide their services to us:
- Hetzner Online GmbH hosts the Service and its backups on servers in Nuremberg, Germany.
- Google (Google Workspace) delivers the email we send you and hosts our support mailbox.
- Fireworks AI, Inc. generates the AI brand planning replies from the conversation and saved plan we send it, as described under "AI brand planning". It does not receive your email address or account details.
- Google and GitHub authenticate you when you choose to sign in with them. Their own privacy policies govern the accounts you hold with them.
- Cloudflare provides domain name services for shopruno.com. It does not receive your visits to the Service.
When purchasing opens, payments will be processed by a payment provider such as Stripe, and we will update this policy first. We will never receive or store your full card number.
We may also disclose information if we are required to by law, to protect the rights, safety and security of our users, Dovecore or others, or as part of a merger, acquisition or sale of assets, in which case this policy will continue to apply to the information transferred.
Where information is stored
Our servers and backups are located in Germany. Dovecore Software LLC is based in the United States, and our email provider may process information in the United States and other countries. Where the law requires it, we rely on appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses offered by our providers.
How long we keep information
- Account information and brand plans are kept while your account exists.
- When you ask us to delete your account, we delete your account, sign-in connections and brand plans from our live systems within 30 days, unless we must keep something to meet a legal obligation or resolve a dispute.
- Backup copies are replaced on a rolling schedule and deleted information disappears from them as they expire. Until then, backups stay protected and are used only to restore the Service.
- One-time sign-in, verification and recovery codes expire within 30 minutes and are deleted once they expire or are used. Sign-in attempt records are deleted within a day. Expired sign-in sessions are deleted too.
- Usage records about the planning tools (see "How we improve the Service") are deleted after 13 months, or when you delete your account.
- Examples you chose to share (see "Examples you choose to share") are kept until you withdraw them, remove the brand or delete your account.
- AI brand planning messages, replies, run status and usage (see "AI brand planning") are kept with the brand until you remove the brand or delete your account.
- A connected Shopify store's encrypted access token, its domain and identifier, the saved product and order snapshots and your draft proposals and decisions (see "Connecting your Shopify store") are kept until the store is disconnected, the brand is removed or your account is deleted, and deleted from our server within 30 days of that.
- Server logs are kept for a limited period for security and troubleshooting, then deleted.
- Support email is kept as long as needed to help you and keep a record of our response.
How we protect information
We use HTTPS for every connection, store passwords only as bcrypt hashes, store one-time codes only as hashes, encrypt the session cookie, keep secrets out of our source code and restrict server access to authorized administrators. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal information, we will notify you as required by law.
Your rights and choices
You can delete your account yourself, at any time, in your account settings. It removes your account, your sign-in connections and your brand plans from our live systems straight away, so download anything you want to keep first.
You can also ask us to access, correct, export or delete your personal information, or to stop processing it, by emailing support@shopruno.com from the email address on your account. You can download your confirmed brand blueprints yourself from your brand plans. We may need to confirm your identity before acting, and we will respond within 30 days, or sooner where the law requires.
Residents of the European Economic Area, the United Kingdom and Switzerland. We process your information to provide the Service you requested (contract), to keep the Service secure and working (our legitimate interests), to meet legal obligations, and with your consent where we ask for it. You have the right to access, rectify, erase, restrict, object to and port your information, to withdraw consent at any time, and to complain to your local data protection authority.
California residents. In the last 12 months we have collected identifiers (such as your email address, IP address and sign-in provider account ID), internet activity limited to server request records and the planning-tool usage records described above, the content of your brand plans and your AI brand planning messages and replies, any de-identified plan or conversation examples you chose to share, and the product and order records read from a Shopify store you connected, from you and your browser, for the purposes described above. Your password is account login information that we use only to let you sign in. We have not sold or shared personal information as those terms are defined by California law. You have the right to know, access, correct and delete your personal information, to use an authorized agent, and not to be discriminated against for exercising these rights.
Children
The Service is for adults aged 18 or older using it for business purposes. It is not directed to children, and we do not knowingly collect information from anyone under 18. If you believe a child has given us information, contact us and we will delete it.
Changes to this policy
We will post any change on this page and update the effective date above. If a change materially affects how we handle your information, we will tell you by email or in the Service before it takes effect.
Contact us
Dovecore Software LLC, operator of Shopruno. Email: support@shopruno.com.