Privacy & data
Protected customer data
Cite Me is Level 0: it analyzes only your store content to predict and improve AI citability. It never reads orders, customers, or checkouts.
PCD LEVEL 0
What Cite Me accesses
read_products / write_products
Product and collection titles, descriptions and image alt text — read for scoring and to ground generated answers, written back when you run an optimization.
read_content / write_content
Pages, blogs and policies; write-back of generated blog articles and Q&A blocks — reversible, and only when you run the action.
read_online_store_pages / write_online_store_pages
The SEO meta title and description of pages, articles and blogs — read to score them, written when you apply an SEO fix.
read_publications / write_publications
Whether a page is published, so we score what shoppers and AI crawlers actually see — and publishing a product to a sales channel when you ask for it.
read_themes
Read-only check of your live theme, to tell you definitively whether the Cite Me schema app embed is switched on. We never write to your theme.
write_files
Uploading the cover and inline images generated for a blog article into your Shopify Files.
read_customer_events / read_pixels / write_pixels
Only to install and run the optional first-party Web Pixel. Despite the name, these are the pixel and storefront-event scopes — not customer records. The pixel reports purchase value and currency, page path, traffic channel and a hashed dedupe key. Never names, emails, addresses, phone numbers, or orders.
Public storefront
robots.txt, llms.txt, sitemap.xml and rendered page HTML — read like any visitor, no token required.
What Cite Me never accesses
Orders, customers, checkouts, or any personally identifiable customer data. Cite Me does not request read_orders, read_all_orders, read_customers or write_themes — it is structurally unable to read them. The one scope whose name suggests otherwise, read_customer_events, is required by Shopify to run a Web Pixel and is listed above with exactly what that pixel sends.
How your data is handled
- Zero-retention AI: prompts (your catalog text) and AI responses are never logged or retained; only coarse, non-content metadata (token counts, latency) is recorded.
- Encrypted at rest: Shopify access tokens are stored with AES-256-GCM encryption.
- Deleted on uninstall: on app uninstall and on a Shopify shop-redaction request, all of your data is removed.
Honesty
All scores are predicted (heuristic) — never measured AI citations, never rankings, and never a rich-result guarantee. Generated content is written to your store only by an action you started: blog articles are drafts you review and publish, the one-click boosts publish on that click, and a scheduled post publishes on the date you picked — and every write is reversible.