Your answers, verified.
Privacy policy
This policy explains what data the AnswerProof AI Visibility Audit app, the AnswerProof browser extension, and the answerproof.ai website collect, how it is used, and how to have it deleted.
Effective date: July 19, 2026
Summary
The short version: the answerproof.ai website collects very little — a waitlist email if you give us one, standard server logs, and Google Analytics usage data. The Shopify app reads your store's public content to grade it, keeps only your recent scan results, and deletes them when you uninstall.
Nothing is sold or shared for advertising, and you can ask us to correct or delete your data at any time — see “Your rights” below.
Who we are and how to contact us
AnswerProof is operated by Joe Caridi LLC, the Shopify Partner behind the AnswerProof apps. For any question about this policy or about your data, email [email protected].
What this policy covers
This policy covers three things: the AnswerProof AI Visibility Audit app for Shopify (the "app"), the AnswerProof AI readiness check browser extension (the "extension"), and the public answerproof.ai website (the "website"). Your relationship with Shopify itself — your store, your Shopify account, your customers' data — is governed by Shopify's own privacy policy, not this one.
Data we collect and store (the app)
You install the app from the Shopify App Store and approve its access through Shopify OAuth. The app is strictly read-only: it cannot change your store, your theme, or your content. It reads your store in two ways:
- Your public storefront. The app fetches roughly 20 public pages the way an AI crawler would — robots.txt, sitemap.xml, your homepage, up to 8 product pages, 2 collection pages, 2 blog articles, and Shopify's agentic endpoints such as agents.md and llms.txt. It identifies itself as AnswerProofAuditBot and fetches politely, with rate limits.
- The Shopify Admin API, using only the read-only scopes read_products and read_content. Through them it reads product titles, descriptions, SEO fields, image alt text, product type, vendor and category, collection information, and blog articles, up to your 500 most recently updated products.
For each shop, we store:
- your .myshopify.com shop domain and your primary domain;
- install and uninstall timestamps;
- the API access token Shopify issues so the app can operate;
- your scan results — scores, per-check findings with their evidence (short excerpts drawn from your store's public content and catalog), the generated report summary, and scan statistics.
We keep your 25 most recent scans.
Data we never collect
We never request, see, or store customer (shopper) data of any kind — no names, no email addresses, no physical addresses, no orders, no payment details. The app has no Shopify permissions that would expose customer data to it.
Shopify sends every app its customers/data_request and customers/redact privacy webhooks. We acknowledge them, and because we hold no customer data, there is never anything to return or delete under them.
How we use your data
We use the data above for exactly one purpose: producing your own audit report and its history. We do not sell your data, we do not use it for advertising, and we do not share one merchant's data with another.
AI-generated summaries
Your report's executive summary may be generated with Anthropic's Claude API. What we send to Anthropic: the scan's findings (check results, scores, and evidence excerpts from your store's public content) and your shop name. What we never send: customer data, your storefront password, or your API access token. Summaries are cached so identical findings are not sent again.
Subprocessors and infrastructure
We rely on a small set of providers to run AnswerProof:
- Shopify — the platform through which all store data is accessed.
- Anthropic — generates the report's executive summary, as described above.
- Railway — hosts the app and its PostgreSQL database.
- Cloudflare — serves the answerproof.ai website and routes our email.
- Google — provides the Google Analytics service that measures traffic on the answerproof.ai website.
Data retention and deletion
We keep your 25 most recent scans per shop. If you uninstall the app, Shopify notifies us through its standard privacy webhooks, and your stored data is deleted as part of Shopify's standard redaction process: when the shop/redact webhook arrives (about 48 hours after uninstall), your shop record and all of its scans and cached summaries are permanently deleted.
You can also request deletion at any time by emailing [email protected].
Storefront password handling
If your store is behind a storefront password (for example, before launch), you can choose to enter it so the app can scan your storefront. Your password is used once, in memory, for that single scan: it is never written to our database, never logged, and never included in your scan results. Each new scan asks for it again.
The browser extension
The AnswerProof AI readiness check extension collects nothing and sends nothing. Every check runs entirely on your device.
When you click the extension's icon, it reads the page in your current tab — headings, paragraphs, metadata, and structured data — and computes its report locally, in your browser. In detail:
- It makes no network requests to us or to anyone else. The one outbound request it triggers is for the current site's own public robots.txt file, made by your browser directly to that site, to report whether AI crawlers are allowed there.
- It stores nothing — no browsing history, no page content, no settings. Nothing persists after the popup closes.
- It has no account, no cookies, and no analytics or tracking of any kind.
- It only runs when you click its icon. It never reads pages in the background.
The extension's link to this website carries campaign tags (utm_ parameters) that tell us the visit came from the extension; they identify the extension, not you. Once you are on answerproof.ai, the website terms below apply.
Website visitors
The public answerproof.ai website uses Google Analytics to understand which pages people visit and how they found us. Fonts are served from our own server, not a third party.
- Google Analytics sets cookies and collects usage data: pages viewed, approximate location derived from your IP address, browser and device details, and the site that referred you. Google LLC processes this data on our behalf. You can block these cookies in your browser settings or with Google's opt-out browser add-on.
- If you join the AnswerProof for Shopify beta waitlist, we store the email address you enter, the time you signed up, your browser's user-agent string, and any campaign tags (utm_ parameters) in the link that brought you here. We use this only to contact you about the beta.
- To limit abuse of that form, we count recent signup attempts per IP address in server memory; these counts are never written to disk.
- Like most websites, our server keeps standard technical logs (IP address, requested page, time) used only for security and troubleshooting.
- The website is served through Cloudflare, which processes visitor traffic (including IP addresses) as our network and security provider.
- If you create an account and sign in to the AnswerProof Web product, the site sets a session cookie strictly necessary to keep you signed in. There are no advertising cookies anywhere on the site.
Your rights
You can ask us at any time to access, correct, or delete the data we hold about you or your shop by emailing [email protected]. Depending on where you live, laws such as the EU/UK GDPR or the California CCPA may give you formal versions of these rights, including the right to complain to a data protection authority. We honor access, correction, and deletion requests from everyone, regardless of location.
Changes to this policy
If we make material changes to this policy, we will update this page and the effective date at the top. The current version always lives at this address. This policy took effect on July 15, 2026.
Contact
Email [email protected]. Mail to any answerproof.ai address is forwarded (via Cloudflare Email Routing) to the operator's inbox and is used only to answer your inquiry.