CoverText scans a Shopify store's product images and Files library for missing alt text, then uses AI to write real alt text back into the store. This page explains exactly what that requires us to see, what it never touches, and where it goes.
- We see your store's product and file media (images, video and 3D-model previews, and any alt text already on them) — never your shoppers' personal data.
- Image content is sent to Anthropic's Claude API to generate alt-text suggestions. It isn't used to train anyone's models.
- We store your shop's install token, usage counts, and cached scan results — tied to your shop, in our own database.
- Uninstalling the app triggers automatic deletion of everything above.
- Billing runs entirely through Shopify's own billing system — we never see or store payment details.
01 Who this covers
This policy applies to CoverText, a Shopify app published by Beratna Labs. It describes what happens to data when a merchant installs CoverText from the Shopify App Store and uses it on their store. It does not cover Shopify's own handling of your data, which is governed by Shopify's Shopify Privacy Policy.
02 What we collect
Installing CoverText grants it two categories of access, both requested through Shopify's standard OAuth install screen:
| Data | Why we need it |
|---|---|
| Store identity & access token ( myshopify.com domain, install/access token, granted scopes) |
Required by Shopify's OAuth flow so the app can make authenticated requests to your store between sessions. |
| Installing staff account (name, email, locale — the person who clicked "Install") |
Shown in the app so you know which staff account is signed in; not used for anything else. |
| Product & Files-library media (image/video/3D-model URLs and any existing alt text) |
The core of the app: read to compute your coverage score, and to generate and write new alt text. |
| App usage (images processed per billing period, automation schedule, last-run results) |
Enforces your plan's monthly limit and powers the dashboard's "last run" summary. |
03 What we don't collect
CoverText never requests Shopify's customer-data permissions
(read_customers or similar). It has no access to
your shoppers' names, emails, addresses, or order history, and
holds none of it in our database — there's simply nothing there
to look up. It also never touches payment card details: all
billing runs through Shopify's own App Pricing system, on
Shopify's infrastructure, not ours.
04 How we use it
- Coverage scoring — comparing which product and file media has alt text against your total catalog, shown as the two coverage percentages on your dashboard.
- AI alt-text generation — sending an image's URL to an AI vision model so it can describe the image, in the tone (descriptive, SEO, or minimal) you choose, then writing the result back to that image's alt-text field.
- Automation ("Autopilot") — on plans that include it, running the two steps above on a schedule you set, without you needing to trigger each run manually.
We don't use your store's content for advertising, don't sell it, and don't use it to train any AI model.
06 Retention & deletion
Store tokens, usage counters, cached scan results, and automation settings are kept in our database for as long as the app stays installed, so your dashboard doesn't need to rescan your entire catalog on every visit.
Uninstalling CoverText clears your access token immediately. Full erasure of every remaining record tied to your shop — usage counters, cached scans, automation settings — happens automatically within the timeframe Shopify's platform requires after uninstall. We don't keep backups of this data beyond that window.
07 Your rights
Because CoverText holds no data about your shoppers, data-subject requests concerning your customers have nothing to retrieve from us — Shopify routes these requests to every installed app automatically, and CoverText responds confirming it holds none.
For data about your own store or staff account — the information in section 2 — you can request a copy or ask us to delete it early (rather than waiting for the post-uninstall window) by contacting us below. Depending on where your business is located, this may also be a right under GDPR, CCPA, or a similar regional law.
08 Security
- All traffic between your store, CoverText, and our server runs over HTTPS/TLS.
- The embedded app authenticates each request with Shopify's session-token mechanism rather than long-lived cookies.
- Access tokens are stored server-side only and are never exposed to the browser.
09 Changes to this policy
If this policy changes in a way that materially affects what we collect or how we use it, we'll update the effective date above and, where required, notify installed merchants in-app.
10 Contact
Questions about this policy, or a request under section 7, can be sent to privacy@beratnalabs.com.