Policy
Privacy policy
Effective 13 August 2026. This policy covers Okiela at app.okiela.io, its Shopify app, and its MCP tools for AI assistants.
Who controls the data
Okiela operates this service. Questions and privacy requests can be sent to daint@okiela.io or through Contact.
Data we process and why
- Calculator and MCP inputs: product price, cost, shipping, fees, discounts, traffic/order counts, ROAS, and a public product-page URL when requested. We use them only to return the requested calculation, page reading, or action plan. MCP tool arguments are not inserted into Okiela's product database.
- Account and authentication: email, account identifier, OAuth grants, and authentication/security events. We use them to sign users in, authorize MCP calls, prevent abuse, and revoke access.
- Optional Shopify connection: variant prices and cost per item plus order totals from the previous 30 days, under read-only scopes. We use them to fill the seller's calculation. We do not request customer names, customer emails, shipping addresses, or payout data.
- Optional weekly ledger: email, product link/name, the numbers entered, selected actions, send status, and an unsubscribe token. We use them only to send the requested ledger.
- Optional shared cost structure: category, price, product cost, shipping, fee percentage, and discount percentage after an explicit Share press. It has no account, email, session, device, or IP field.
- Service measurement and support: an allowlisted page path, optional random per-tab session id, coarse device class, hosting-layer country code, bot classification, and information deliberately sent through the contact form. We use these to understand whether key pages work and to answer requests.
Recipients and transfers
Data is processed by service providers that host or deliver Okiela: Lovable Cloud/Supabase for the application, authentication and database; Cloudflare infrastructure used by the hosting and DNS safety checks; Resend for emails the user requests; Shopify for the optional Shopify connection; and the AI-assistant provider the user chooses for MCP calls. Each provider processes data under its own terms and infrastructure.
We do not sell personal data. A public product-page scan sends a normal unauthenticated web request to the supplied public store URL; it sends no Okiela account data or Shopify credential.
Retention
- MCP calculation inputs are processed for the response and are not stored in Okiela's product database.
- Authentication records and OAuth grants remain while the account or grant is active and are removed or revoked when the account/grant is deleted, subject to provider security logs.
- Shopify installation access is removed when the app is uninstalled or Shopify sends an erasure request.
- Weekly-ledger records remain while the subscription is active. Unsubscribing stops delivery; a deletion request removes the identifiable row.
- Anonymous shared cost structures, page-measurement records, and contact messages currently remain until manually deleted. Okiela is implementing automatic deletion windows; we do not claim one before that control is live.
- Infrastructure and authentication logs follow each hosting provider's retention settings and legal obligations. Contact Okiela for the current provider-specific window; we do not publish a fixed duration unless it has been configured and verified.
Your controls
You can use the calculators without an account or Shopify connection; decline the optional Share and weekly-ledger actions; unsubscribe from every ledger email; disconnect Okiela in the AI assistant; uninstall the Shopify app; or ask us to access, correct, or delete identifiable information. We may need enough information to verify and locate a request.
A shared cost structure contains no identifier. We will try to remove one if the supplied details and approximate time distinguish it, but cannot promise to identify a particular anonymous row.
Security, children, and changes
Okiela limits access and permissions to what the service needs, but no internet service can promise absolute security. Do not send card details, passwords, API keys, health records, government identifiers, or other restricted data through an Okiela tool or form.
Okiela is for people operating online stores and is not directed to children under 13. Material policy changes will be posted here with a new effective date.