Legal

Security & data handling

The current factual security and data-handling posture for public product parsing, short-form research, Agent Memory, and optional generation.

Effective version: 2026-07-29· Service operator: Shopcue

1. What this page is—and is not

This page describes controls implemented in Shopcue. It is not a certification report, penetration-test result, legal opinion, or promise that every procurement requirement can be met. Shopcue does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS service-provider certification, or an independent security attestation.

2. MVP data flow

  1. An authenticated user submits a public HTTPS Shopify product URL.
  2. The server validates the destination, blocks private-network access, follows bounded redirects, enforces content type, size, and timeout limits, and extracts a minimal public product record.
  3. The user confirms product facts, forbidden claims, market, platforms, cadence, and Research Lens before a persistent Agent is created.
  4. A server-only worker claims a leased run and calls configured public-content providers. Each platform can succeed or fail independently.
  5. Shopcue validates and normalizes supported public fields, deduplicates content, calculates deterministic score inputs, and stores evidence relationships without retaining a raw provider payload.
  6. User saves, rejections, creator tracking, competitor seeds, run Delta, generation requests, results, and failures append to Agent Memory.

3. Workspace and database boundaries

  • research Agent tables use Workspace-bound foreign keys and row-level access policies.
  • Workspace members can read authorized research; operator roles can change user-controlled records.
  • Provider ingestion, run claiming, and normalized observation writes are service-role-only.
  • The database enforces the active Agent limit and one open run per Agent.
  • Memory is append-only for normal product operations; failures do not erase previous evidence.

4. Public URL and provider controls

The public product fetcher rejects non-HTTP protocols, credentials in URLs, localhost and private/reserved IP destinations, unsafe redirect targets, unsupported content types, oversized responses, and requests that exceed the timeout. Provider keys remain in server environment variables. The browser receives normalized status and evidence, not secrets or raw provider responses.

5. Video generation boundary

Generation is optional and disabled when no supported server key is configured. Live generation records are Workspace and Agent scoped. Canonical product facts are loaded from the saved Agent on the server, prompts are hashed for lineage, provider operation identifiers remain server-side, and status or file retrieval checks ownership. Generated drafts still require claims, rights, and human QA.

6. Data requested and excluded

The MVP stores public product and public content evidence plus user-confirmed research settings. It does not require Shopify Admin, TikTok Shop orders, ad accounts, customer email, address, phone, bank data, card numbers, private creator contact data, or manual CSV uploads. Users should not place those fields in product URLs, lenses, prompts, or support messages.

7. Failure and cost protection

  • Runs use idempotency, leases, retries, exponential backoff, and terminal review state.
  • A failed refresh preserves older evidence and records the provider or platform failure.
  • Queries and competitor depth are bounded per run; optional generation is separated from research.
  • Provider health pages distinguish ready, unconfigured, disabled, and unavailable states.
  • Paused Workspaces remain readable while new provider-consuming work is blocked.

8. Current subprocessors

  • Supabase— database, authentication, and server-side data services.
  • Vercel— application hosting and request execution.
  • Scrape Creators— public short-form research only when configured; a replacement adapter may be evaluated separately.
  • Google Gemini/Veo— optional original draft generation only when configured and requested.
  • Mailgun— operational and legal email when configured.

9. Retention, deletion, and incident contact

Agent evidence is retained to provide longitudinal Memory and is not automatically deleted on a failed run or provider disconnect. Authorized users may archive Agents and request verified deletion through the data deletion process. Report suspected unauthorized access, leaked links, credential exposure, or security defects through the legal request below without including live credentials or customer data.

Request a security or DPA review

Use a monitored company email and state the concrete requirement. Submission starts a review; it does not imply Shopcue accepts a requested term.