What We Collect
sameface stores what it needs to generate media for your store: your shop domain, the models you create or adopt, the descriptions you wrote for them, the scenes you wrote, the prompts the app composed, and a record of every generation with its status and its charge.
It also stores the session Shopify issues when a staff member installs or opens the app. That session carries an access token and, for the person who authorised it, the first and last name, the email address, the locale, and whether they are the account owner or a collaborator. This is the only personal data the app holds, it comes from Shopify rather than from you, and it is deleted when the app is uninstalled.
If you send a suggestion from inside the app, the message and your shop domain are stored so we can reply and so the suggestion is not lost if the notification fails.
Generated images and video clips are uploaded to your own Shopify Files. sameface stores the Shopify file identifier and the delivery URL Shopify returns. It does not keep a copy of the media on its own servers.
sameface does not request, receive, or store customer data. It reads products and writes products and files, and nothing else. It holds no orders, no customers, no addresses, and no payment information.
The models the app makes are generated. The ones that ship with it and any you create from a description are made by an image model; none of them is a real person, no photograph of one is used, and the app grants you no right in a real person’s appearance, because it has none to grant.
You can also upload a photograph of a real person and use it as a model. That photograph is the one thing in this app that is somebody else’s likeness, and it is yours to bring: before it is uploaded you confirm, in those words, that you have the rights to it and that the person in it has agreed their face may be used in shop photographs made by this app. What you confirmed, when, and the exact wording you were shown are stored with that model, so it can be read back later.
An uploaded photograph goes to your own Shopify Files, like every other picture here. If you ask the app to draw portraits from it, the photograph is sent to the media provider as the reference for those portraits, the same way a product photograph is sent for a product shot. Deleting the model deletes the app’s record of it, including that confirmation, and the file stays in your Shopify Files until you remove it there.
How We Use Data
Data is used to authenticate the app with Shopify, to compose the prompt for a generation, to send that prompt and any reference image to the media provider, to upload the result to your Shopify Files, to attach a file to a product when you press publish, and to report your charges back to you.
Third Parties
Generation uses a third-party AI media provider. A prompt, and where you asked for a product shot the public URL of the product image you chose, are sent to that provider so it can produce the result. No customer data is sent, because the app holds none. No staff name, email or access token is sent to any provider.
What the provider keeps of that, and for how long, is governed by its own terms rather than by sameface, and it publishes no retention period for prompts or generated files. So this page states none for them either, rather than promising one we do not control.
Billing runs through Shopify. sameface never sees a card number.
If you send a suggestion and we have email or messaging configured, that suggestion is delivered to us over those channels.
Two measurement tools run on the app’s own screens: Microsoft Clarity, which records how the screens are used, and Google Analytics, which counts them. Clarity is configured to mask the whole page, so what it records is the shape of a session, where a pointer went, what was clicked and where a session ended, and not the words or the pictures on the screen. Google is sent the path of the screen and nothing else: the address of an embedded app carries your shop domain, and that part is removed before it is sent, so Google is told that somebody opened the studio and not whose shop it was.
Neither of them receives a product, a photograph, a prompt, a generated result, an email address or an access token. Neither runs on this page or on any other page outside the app. No other processor receives anything.
Shopify Webhooks
sameface handles the required Shopify privacy webhooks for customer data requests, customer erasure, and shop erasure. Because the app holds no customer data, the two customer webhooks have nothing to return and nothing to delete, and they say so. Shop erasure deletes everything, as described below.
When a shop uninstalls, its app sessions are removed, its access token is cleared, and the cached link to its Shopify subscription is cleared with it, so no work that finishes afterwards can be billed to a merchant who has left.
Retention and Deletion
Your models, scenes, and generation history are retained while the app is installed, so the app can keep a face consistent and show you what you were charged for. Removing a shot in the app removes the app’s record of it. The file stays in your Shopify Files, and anywhere you have published it stays as it is, so removing a shot here never changes your storefront.
Uninstalling deletes the app sessions, including the staff details they carried, and ends the app’s access to your store. The rest of your records are kept for the moment, so that reinstalling brings back your models and your history rather than an empty app.
Shopify then sends a shop erasure request 48 hours after an uninstall. On that request every remaining record for your shop is deleted: models and their portraits, scenes, generations, reservations, the file identifiers, the usage records and any suggestion you sent. Nothing is kept to recognise the shop later. You can also ask us to erase everything at any time by writing to support.
Erasure does not touch your Shopify Files. The photographs and clips sit in your own store and stay there. Deleting our records is not permission to delete your media, and the erasure code has no way to reach it.
One consequence is worth stating plainly. The free photos are granted once, when the app first creates your record. Uninstalling and coming back does not grant new ones. A full erasure removes the record that counted them, so a shop that installs again after an erasure is treated as new. A free photo is spent when the generation starts, so one that fails still spends one; nothing is billed for it.
Contact
For privacy questions or data requests, contact [email protected].