# Trust and security · Easy AI Act Image Labels

> Which Shopify permissions the app uses, what I read and store, where the data lives and for how long, and how you report a security vulnerability to me.

URL: https://easyaiactlabels.com/en/trust/

Trust and security

# What I read, where it lives, for how long.

I need your images to find evidence. Nothing more. Here is exactly what happens.

I read

Image files of your products, collections, blogs, and theme sectionsInside them: C2PA manifests, IPTC DigitalSourceType, and XMPWhere an image is usedThe languages of your store

I do not read

Customer dataOrders and paymentsAddresses and analytics: I have no permission for them

I do not change

Image files and alt textsProductsTheme code

## Data at a glance

lakör runs me on Cloudflare. The database (Workers KV) stores data in data centers in the EU and the US and briefly holds copies at Cloudflare locations worldwide. Cloudflare does not offer a restriction to EU locations for Workers KV (accessed September 14, 2026), so I do not claim one. Transfers to the US are based on the EU-US Data Privacy Framework and EU Standard Contractual Clauses.

**Image metadata** Finding evidence and showing it to you: provenance data found per image

Where

Cloudflare Workers KV, EU and USA

How long

until deletion after uninstall

**Findings per image** Results summary, proposals, automation: file name, URL, dimensions, location

Where

Cloudflare Workers KV, EU and USA

How long

until deletion after uninstall

**Your decisions** Which images carry a label

Where

Cloudflare Workers KV, EU and USA; confirmed images also in an app metafield in your store

How long

until deletion after uninstall; the metafield disappears with the app

**Settings** Corner, size, page types, language

Where

Cloudflare Workers KV, EU and USA

How long

until deletion after uninstall

**Image files** Only for reading during the scan, the first 512 kilobytes per file

Where

in memory only, never stored

How long

discarded immediately

**Access token** So that I may read on your behalf, AES-GCM encrypted

Where

Cloudflare Workers KV, EU and USA

How long

until uninstall, then deleted immediately

**Log** Event, store, truncated IP address, timestamp

Where

at Cloudflare

How long

90 days

**Support conversations** Only if you use the chat in the app

Where

at Cloudflare; sent to Anthropic (USA) for the reply, without your store domain

How long

90 days after the last message

### Permissions in Shopify

During installation, Shopify shows you every permission before you agree. I request four read-only permissions and no write access; I write only two app-owned metafields, the on/off switch and the list of images you have confirmed.

read\_products

Product titles and which image belongs to which product

read\_files

File inventory and originals, the first 512 kilobytes per file for C2PA, IPTC, and XMP

read\_themes

whether the label is active and which images sit in theme sections

read\_locales

the languages of your store, for the label in your customer’s language

### After uninstall

The label disappears from your store immediately, and I delete the access token at the same moment. I delete stored findings as soon as Shopify sends the deletion request `shop/redact` 48 hours after uninstall, no later than after 30 days; a daily cleanup job checks this. Log entries expire after 90 days.

### Found a security vulnerability?

Write to [ai-act-labels@lakoer.de](mailto:ai-act-labels@lakoer.de), also machine-readable at [/.well-known/security.txt](/.well-known/security.txt). I confirm receipt within 48 hours with a first assessment. Everything legal is in the [privacy policy](/en/privacy/).
