A plain list, per app, of the data we hold — and the things we deliberately do not.
The short version: we store the minimum each app needs to function, on our own servers in the European Union, encrypted at rest.
Your shop domain, the domains you scan, and the public DNS records found. No products, no customers, no orders — the app has no access to them.
We do not store names, addresses, phone numbers or payment details. None of it is used for anything except sending that store's own reminders.
Theme file contents and names while a scan or cleanup is in progress, plus the backups you create. Backups are yours and can be deleted at any time.
The full detail is in the privacy policy, and the processing terms are in the DPA that applies automatically when you install.
If anything here was wrong, unclear or out of date, tell us — the article gets fixed the same day.