# Privacy · Easy AI Act Image Labels

> What the app Easy AI Act Image Labels reads in your store, what it stores, where data lives and for how long. No cookies, no tracking.

URL: https://easyaiactlabels.com/en/privacy/

Legal

# Privacy

Last updated: 30 September 2026

Last updated: 2026-09-30 · Controller: lakör GmbH & Co. KG, Am Kreuzgraben 5, 18146 Rostock, Germany, [ai-act-labels@lakoer.de](mailto:ai-act-labels@lakoer.de) (full details in the [Legal Notice](/en/legal-notice/))

This is a courtesy translation. The [German version](/de/datenschutz/) is the legally binding one.

## In short

I am a Shopify app and I read the images of your store to find provenance data. I store no images, no customer data and no orders. The label in your store loads nothing from lakör and sets no cookies. When you uninstall me, your data is deleted. If you use the support chat in the app, I send your message and the technical state of the app to Anthropic (USA), never your store address and never credentials.

## Who this policy applies to

1.  **To you as a merchant** who uses Easy AI Act Image Labels in your Shopify admin, including the support chat in the app (section “Support chat in the app”).
2.  **To visitors of these info pages** (home page, FAQ, support, legal pages).
3.  **Not to the visitors of your store.** The label script runs in your customers’ browsers but does not talk to lakör: no network request to lakör, no cookie, no local storage, no audience measurement. Shopify delivers all files of the label from its own infrastructure. lakör does not learn who visits your store. You therefore do not have to name lakör as a recipient of visitor data in your own privacy policy.

## What I read in your store

During installation Shopify asks you for these permissions:

-   **Read products** (`read_products`): product titles and the assignment of which image belongs to which product. That is how I can tell you where an image is used.
-   **Read files** (`read_files`): your file library, file names, upload date, image dimensions, image URLs and the usage index. For the check I download the original file of each image, but only the first 512 kilobytes, which is where provenance data lives. I read the metadata blocks (C2PA, IPTC, XMP) from it and discard the image data immediately. **I store no images.**
-   **Read themes** (`read_themes`): the settings files of your themes, to see whether the label is turned on and which images sit in theme sections. I never write to your theme.
-   **Read shop locales** (`read_locales`): which languages your store offers, so that the label can appear in your customer’s language when you choose the dynamic language mode.

I request no further permissions. In particular I have no write access to products, files, themes or translations.

## What I do not read

No customers, no orders, no payments, no addresses, no analytics. I have no permission for these areas and do not request it.

## What I write in your store

-   **Two app-owned metafields** (`ai_badge.enabled`, `ai_badge.config`): the on/off switch and the list of images you confirmed as AI-generated or AI-modified. These fields belong to the app and disappear with it.
-   Nothing else. I change no products, no images, no image descriptions, no themes, no menus. A technical block list in the code prevents this; it is checked with every deployment.

## What I store at lakör

What

Why

How long

Your store address (`your-store.myshopify.com`)

All data is assigned to your store

until deletion after uninstall

Access token for the Shopify API (stored encrypted)

So that I may read on your behalf

until uninstall; then deleted immediately

Scan results per image: file name, image URL, dimensions, location, provenance data found (for example “Created with Adobe Firefly”), your decision

The actual purpose of the app

until deletion after uninstall

Settings (locations, corner, size of the label)

Your configuration

until deletion after uninstall

Interface language (your choice in the app’s language menu and the language last seen in the app)

So that the app appears in your language and notices I send without the app being open (for example e-mails about your plan) are written in that language

until deletion after uninstall

Storefront password of your store, only if you enter it for the self-test (password-protected stores)

So that the self-test can load your store pages and count the labels

until you remove it or until deletion after uninstall; never in the log, never in API responses, never passed to third parties

Run history (date, counters per scan)

So that you can see what is new since the last scan

until deletion after uninstall

Automation setting (switch state, time it was turned on, time of the last check run, counters of new, automatically labelled and closed-without-label files)

So that I can check new images daily and after product changes and show you what happened

until deletion after uninstall

Debounce marker after a product change (only your store address, no product data)

So that many changes in quick succession trigger only one check run

15 minutes

Log entries (event, store, truncated IP address, time)

Security and troubleshooting; the IP is truncated by its last octet or its second half

90 days, then removed automatically

Support conversations (your messages, answers by the AI and by lakör, topic, status, language)

So that you see your requests and the answers in the app and lakör can follow the case

90 days after the last message, or earlier if you delete the request in the chat; at the latest on uninstall

Bug reports from the chat (title, description, theme name and version, technical app state)

So that lakör can reproduce and fix the bug

180 days; at the latest on uninstall

Read-access consent (time of consent and its expiry, stored in the request)

Proof of your consent and automatic end of the read access

7 days from consent or until you withdraw it

Collaborator request code (four digits, stored encrypted), only if you enter it in the chat

Access request by lakör in the Shopify Partner Dashboard

until the request is submitted, until you withdraw it or 14 days at the latest; never in the log

Counter of support messages per store and day (a single number)

Usage limit against abuse of the chat

2 days

Review prompt record (the times I asked and the result code from the Shopify dialog, including “Don’t ask again”)

So that I do not ask you repeatedly

until deletion after uninstall

Plan status (your chosen plan Basic, Pro or Unlimited, status and id of your subscription at Shopify, interval, start of the free trial, end of the grace period, cut-off date and times of my notices after your store stops being a development store)

So that I know which plan applies and what it covers (scan, label, image quota, automation, language) and can show you the state on the Plan page

until deletion after uninstall

Inventory list of your image files (file id, upload date, file name without the image)

So that I know which images are inside your quota (the oldest by upload date) and can show you the number of images in your store and a plan recommendation, also without a plan

until deletion after uninstall

Store e-mail address from your Shopify admin

Only for notices about your plan (advance notice and end of free use after your development store becomes a paid store); I send no advertising

until deletion after uninstall

Provenance data in images can contain names, for example the name of a photographer or of the signing tool. I store this data only because it is the evidence for the proposal you see.

I do **not** store: image files, alt texts, customer data, orders.

Shopify informs me by webhook about product changes (`products/update`) and theme publications. I do not read the content of the product notification and store nothing from it; it only triggers a check run that, like every scan, reads files and products through the Shopify API. Customer data is not part of it.

## Support chat in the app

There is a support chat in the app. It is voluntary; you can still reach lakör by e-mail at [ai-act-labels@lakoer.de](mailto:ai-act-labels@lakoer.de). When you ask a question in the chat, this happens:

**Answer by AI.** To answer you right away, I send your message text, the previous history of this one request and a technical summary of the app state to **Anthropic** (Anthropic, PBC, San Francisco, USA; the contracting entity for customers in the EU is Anthropic Ireland Limited, Dublin). The summary contains your settings (locations, corner, size of the label), the counters of the last scan, name and version of your theme, the state of the app embed and of the self-test, and the plan status. It does **not** contain: your store address, access tokens, the storefront password, file names, image URLs or images. Anthropic processes this data as a processor of lakör on the basis of a Data Processing Addendum with EU Standard Contractual Clauses, does not use inputs and outputs to train its models, and stores them under its terms only briefly for abuse detection. Answers by the AI are general information and implementation help, not legal advice; checking your obligations remains your responsibility. **Never enter passwords in the chat.** I never need credentials, and lakör never asks for them.

**Handover to lakör.** If the AI cannot help, if you report a bug or if you ask for a person, I hand the request over to lakör. For this the app posts to a private Slack channel of lakör: your store address, the message text or an excerpt of it and the technical summary from above. Answers from lakör appear in your chat. Bug reports I additionally store as a separate record (title, description, theme, app state) so that lakör can fix the bug.

**Read access, only with your explicit consent.** If you choose “Allow read access” in a request, lakör may, for 7 days and through the app’s existing access token, read products, files and theme settings of your store to follow the case. This is consent; you can withdraw it in the chat at any time, and the read access then ends immediately. No new permissions arise from it, the read permissions listed above remain, and even with read access lakör never writes to your theme.

**Collaborator request code, only with your explicit consent.** For a fix in your theme lakör needs collaborator access to your store, which you approve yourself in Shopify; the app itself never writes to the theme. If you enter the four-digit collaborator request code from your Shopify admin in the chat for this purpose, I store it encrypted, transmit it to lakör through the private Slack channel, and lakör uses it exclusively for the access request in the Shopify Partner Dashboard. The code is deleted as soon as the request is submitted, when you withdraw it in the chat or after 14 days at the latest. Withdrawing in the chat only deletes the code; access already granted you revoke in your Shopify admin under Users. For this too I need no password.

**Review.** After a solved request or on the Overview page of the app I may ask whether you would like to review the app in the App Store; with “Don’t ask again” I store only that decision. There is no reward for a review. The dialog is Shopify’s own review dialog. lakör only learns whether you clicked and whether Shopify showed the dialog; the review itself is processed by the Shopify entity under its privacy policy.

**Usage limit and deletion.** So that the chat is not abused, I count the messages per store and day; once the limit is reached, you can continue by e-mail. You can delete individual requests in the chat yourself. I delete conversations 90 days after the last message, bug reports after 180 days, the daily counters after 2 days. With the uninstall all of this is deleted immediately (deletion command `shop/redact`).

Without the Anthropic connection (for example during an outage) the chat works as a form: your message then goes directly to lakör via Slack, without an AI answer.

## Where your data is located

lakör runs Easy AI Act Image Labels on the platform of **Cloudflare, Inc.** (San Francisco, USA). Cloudflare is a processor of lakör under a contract pursuant to Art. 28 GDPR. The database (Cloudflare Workers KV) stores in data centers in the EU and the USA and keeps short-lived copies in Cloudflare locations worldwide. The transfer to the USA relies on Cloudflare’s certification under the EU-US Data Privacy Framework and, in addition, on the EU Standard Contractual Clauses.

For the AI answers in the support chat lakör uses **Anthropic** (Anthropic, PBC, 548 Market St, San Francisco, CA 94104, USA; for customers in the EU Anthropic Ireland Limited, Dublin). Anthropic is a processor of lakör under a Data Processing Addendum pursuant to Art. 28 GDPR. Processing takes place in the USA; the transfer relies on the EU Standard Contractual Clauses (Art. 46 GDPR), which are part of the addendum. Anthropic does not use the transmitted inputs and outputs to train its models. Only message text, conversation history and technical app state are transmitted, without store address and without credentials (section “Support chat in the app”).

**Payment.** Payment data (payment method, invoices) is processed exclusively by the Shopify entity under its privacy policy; lakör sees no payment data and receives from Shopify only the status of your subscription (for example active, cancelled) and its id.

**E-mail to you.** Notices about your plan (the advance notice and the message about the end of free use after your development store becomes a paid store) I send to the store e-mail address stored in your Shopify admin via **Resend** (Resend, Inc., 2261 Market Street, San Francisco, CA 94114, USA). Resend is a processor of lakör under a contract pursuant to Art. 28 GDPR; the transfer to the USA relies on the EU Standard Contractual Clauses (Art. 46 GDPR). Transmitted are your e-mail address, subject and text of the message; Resend stores delivery logs.

For internal operational alerts (for example “scan aborted”, “theme changed”) and for support lakör uses **Slack** (Slack Technologies, LLC, USA, certified under the Data Privacy Framework). An operational alert contains your store address and a short event text, no images, no tokens. A support handover additionally contains your message text or an excerpt of it, the technical app state and, only if you explicitly entered it, the collaborator request code. The support channel is private and visible only to lakör staff.

Shopify itself is the source of your data and your own processor; the relationship between you and Shopify is governed by Shopify’s data processing agreement, not by this policy.

## Legal bases

-   Use of the app, scan, storage of your decisions: performance of the usage agreement with you, Art. 6 (1) (b) GDPR.
-   Support chat, AI answer and handover to lakör: performance of the usage agreement with you (support), Art. 6 (1) (b) GDPR.
-   Plan status, billing through the Shopify entity and notices about your plan by e-mail: performance of the usage agreement with you, Art. 6 (1) (b) GDPR.
-   Read access to your store and storage of the collaborator request code: your consent, Art. 6 (1) (a) GDPR, withdrawable in the chat at any time; the withdrawal takes effect for the future.
-   Log entries, operational alerts, security checks, usage limit of the chat: legitimate interest in secure and traceable operation, Art. 6 (1) (f) GDPR.
-   Where you are a sole trader and your store address or e-mail refers to you personally, the same applies.

Two roles, kept apart: for the data lakör needs to perform the agreement with you (store address, access token, log, settings), lakör is itself the controller. For image metadata and product data that lakör evaluates on your behalf, lakör is your processor. The agreement for this is part of the [Terms of Use](/en/terms/), annex “Data processing”, and is concluded with the installation.

What you do in the App Store (search, installation, reviews) is processed by the Shopify entity under its own privacy policy; lakör only receives the installation itself.

## How long I store data

-   As long as Easy AI Act Image Labels is installed: everything in the table above.
-   After uninstall: Shopify invalidates the access token immediately, and I delete it at lakör at the same moment. 48 hours later Shopify sends lakör the deletion command (`shop/redact`); then all data of your store is deleted. At the latest 30 days after uninstall all data is gone, even if the deletion command should not arrive; a daily clean-up run checks this.
-   Exception: log entries expire after 90 days, even if you uninstall earlier.
-   Support conversations expire 90 days after the last message, bug reports after 180 days, the collaborator request code after 14 days, the daily counters after 2 days, in each case also without uninstall; with the uninstall immediately.

## Your rights

-   **Access, rectification, erasure, restriction, data portability** (Art. 15 to 20 GDPR): e-mail to [ai-act-labels@lakoer.de](mailto:ai-act-labels@lakoer.de), answer within 14 days, by law at the latest within one month.
-   **Trigger deletion yourself**: uninstall the app (Shopify admin, Apps, Easy AI Act Image Labels, Uninstall). Individual support requests you delete directly in the chat.
-   **Withdraw consent** (Art. 7 (3) GDPR): read access and collaborator request code you withdraw in the chat, without giving reasons.
-   **Object** to processing based on legitimate interest (Art. 21 GDPR): same address.
-   **Complain** to a data protection supervisory authority. Competent for lakör: Landesbeauftragter für Datenschutz und Informationsfreiheit Mecklenburg-Vorpommern (State Commissioner for Data Protection and Freedom of Information of Mecklenburg-Western Pomerania), Schwerin, Germany.

lakör has not appointed a data protection officer because the statutory requirements are not met.

## Visitors of these info pages

When you open these pages, Cloudflare as hosting provider processes technically necessary connection data (IP address, time, page requested, browser identifier) for delivery and to fend off attacks. lakör does not evaluate this data and uses no cookies, no analytics tools and no external fonts on these pages.

## Changes

If what I read, write, store or pass on changes, this policy is updated in the same step and the change is announced in the app. You will always find the current version at [/en/privacy/](/en/privacy/); the legally binding German version is at [/de/datenschutz/](/de/datenschutz/).

## This website

This website is served as a static site via Cloudflare (Workers, Static Assets). It sets no cookies, loads no fonts or scripts from third parties (fonts are served from the same server) and uses no analytics that could recognise you. Cloudflare processes the connection data needed to deliver the page and to fend off attacks (IP address, time, requested page); the legal basis is Art. 6(1)(f) GDPR. If you write to me ([ai-act-labels@lakoer.de](mailto:ai-act-labels@lakoer.de)), I process your details to answer your request (Art. 6(1)(b) or (f) GDPR).

_This is a courtesy translation. The German version is the binding one: [Deutsche Fassung](/de/datenschutz/)._
