Privacy Policy — Blog Smith
Last updated: 12 July 2026
Blog Smith ("the App", "we", "us") builds structured article outlines and, on a paid plan, AI article drafts that you review and publish to your store blog. This policy explains exactly what data the App accesses, why, and how it is protected. Blog Smith is Protected Customer Data Level 0: it does not request, read, store, or process any Shopify protected customer data.
What we access
- Your store's catalog and content (product and collection titles/handles, blog content) via the minimal scopes
read_productsandread_content, used to build internal-link suggestions and to ground generated drafts in your own products. - The topics, keywords and facts you enter, used to generate briefs and drafts.
- Blog posts we create at your request (
write_content) — a new post is written to your store blog only when you click Publish.
What we never access
- Orders, customers, or any customer personal data. We never request
read_ordersorread_customers.
How we use it
- To produce article outlines (deterministic, offline) and — on a paid plan — AI drafts written to the brief and grounded in your catalog, scrubbed for AI-tell phrasing before you see them. Nothing is published automatically; you approve every article.
- We do not sell your data or use it to train third-party models. LLM generation runs under a zero-retention agreement.
Security & retention
- Any Shopify access token is encrypted at rest (AES-256-GCM) and is never returned to the browser or written to logs.
- On uninstall and on a Shopify
shop/redactrequest we delete your stored data — outlines, drafts, token-usage counts, web-vitals samples and the encrypted access token — except the single anti-abuse record described in the next point. - One record is kept on purpose. When a store uses its one free AI-writing allowance we store a salted, irreversible hash of the shop domain and the date the allowance was issued. It survives redaction as an anti-abuse measure (legitimate interest): without it, uninstalling and reinstalling would mint a new free allowance forever. It holds no shop name, no contact details and no customer data, and it cannot be turned back into your domain.
- The GDPR
customers/data_requestandcustomers/redactwebhooks are answered truthfully: we hold no customer personal data.
Contact
Questions about this policy or your data: gheorghe.beschea@overheat.agency.