Privacy Policy
This policy explains what information AeonicX collects, how we use it, and the choices you have.
Last updated: 16 August 2026
Overview
AeonicX (“AeonicX”, “we”, “us”) provides an AI chatbot that businesses embed on their websites. This policy covers two groups of people: the business owners who create an account with us, and the website visitors who chat with a business's assistant.
Information we collect
From business owners who sign up:
- Account details — your email address and a securely hashed password.
- Business content you add — company information, FAQs, services, policies, and appointment settings.
- Support messages you send us through the contact form or by email.
From website visitors who use a business's chatbot:
- The messages exchanged during a conversation with the assistant.
- Details a visitor chooses to provide — such as name, email, phone, or answers to lead questions.
- Appointment requests, including the requested date and time.
We do not knowingly collect sensitive personal information, and we ask businesses not to configure their assistant to request it.
How we use information
- To provide the service — powering the chatbot, storing conversations, and delivering leads and appointment requests to the business.
- To generate AI replies and short internal summaries of a conversation for the business owner.
- To send transactional emails, such as email verification codes and appointment confirmations.
- To respond to support requests and improve the product.
We do not sell personal information, and we do not use conversations to train third-party AI models.
Service providers
We rely on a small number of trusted providers to run AeonicX. These are the only third parties that process data on our behalf. Tools a business connects themselves are covered separately, under Integrations you connect, below.
- Google (Gemini API) — generates the assistant's replies from the knowledge base content and conversation sent with each request. Data sent to the Gemini API on a paid plan is not used to train Google's models.
- Neon — the managed PostgreSQL database holding account details, knowledge base content, conversations, leads and appointment requests.
- Render — hosts our application server, which processes every request described in this policy.
- Cloudflare — hosts and delivers our website and dashboard, and provides network security.
- Resend — delivers our transactional email: verification codes, password links, and appointment confirmations.
- Razorpay — processes subscription payments for customers who sign up on aeonicx.com. Card details are entered with Razorpay and never reach us.
- Shopify — for merchants who install our Shopify app: the product catalogue source, and the biller for their subscription.
- Sentry — receives a technical report when something goes wrong on our servers, so we can find and fix it. Our reports are sent to Sentry's European region, and it is deliberately configured not to receive request contents, cookies or IP addresses, so conversations and knowledge base content are not sent to it.
- Google Analytics — measures traffic on our public website only. It is not present in the chat widget, so a visitor chatting with a business's assistant is not measured by it.
These providers process data only to perform services on our behalf and are bound by their own security and privacy obligations. We will update this list before adding a new one.
Integrations you connect
Some businesses connect their own marketing tools to AeonicX. When they do, the details and context from leads their assistant captures are sent to that tool — an account that belongs to them, not to us.
- Klaviyo — when a business connects their Klaviyo account, each lead their assistant captures is sent there as a contact record: the name and the email or phone number the visitor gave, what they were asking about, and the product they were interested in. A visitor is asked separately, by a checkbox they tick themselves, before any marketing consent is recorded — and if they do not tick it, no consent is recorded.
We send this only at the business’s instruction and only while the connection is active. Disconnecting stops it immediately. Anything already sent lives in that business’s own account, under their agreement with that provider.
If you connect a Shopify store
A business can connect its Shopify store so the assistant can answer questions about its products. This section describes exactly what that connection involves.
What we access. The AeonicX app asks for two permissions: to read products, and to read orders. We read the store's catalogue — product titles, descriptions, images, prices, categories and product page links. We do not request or receive access to customer records, checkouts, or financial information, and we never ask for access to orders older than the 60 days Shopify includes by default.
Why Shopify's permission screen mentions device and location data. When a merchant installs or updates the app, Shopify lists every category of information the orders permission is capable of exposing — including geolocation, IP address, browser and operating system. That is a description of the permission, not of AeonicX. We request only the order status, the shipping and tracking details, and the contact detail used to confirm the shopper placed the order. We never ask Shopify for a shopper's IP address, location, browser or device, so we never receive them.
How the catalogue is used. Catalogue entries are stored against the merchant's AeonicX account and included, alongside the rest of their knowledge base, in the context sent to our AI provider when a website visitor asks a question. Shopify notifies us when a product changes so the catalogue stays current.
How orders are used, and why nothing is kept. Order access is used for one feature: answering a shopper who asks where their order is. When a merchant has switched that feature on and a shopper enters an order number together with the email or phone number used on that order, we ask Shopify for that single order, check the details match, and write its status into the chat. We do not copy the order into our systems — no order contents, no shopper name, no address, no email — and no order data is sent to our AI provider. The reply is assembled from the store's own values, not generated. Nothing about the order is retained once the message is written; the conversation history records only that a status check took place.
Shopify's privacy webhooks. Shopify requires every app to answer three requests: for a shopper's data, for a shopper's data to be erased, and for a store's data to be erased after uninstalling. We verify and answer all three. Because we store no shopper or customer data — order lookups are read-through and retained nowhere — we hold nothing to return or erase in response to the first two.
Uninstalling. When the app is removed we delete the access credentials for that store and stop syncing it immediately. The merchant's AeonicX account — knowledge base, catalogue and conversation history — is kept, so that reinstalling restores their setup instead of starting over. To remove it entirely, delete the account from the AeonicX dashboard or email us.
Billing. Merchants who install from the Shopify App Store are billed by Shopify on their existing Shopify invoice. We never see or store card or payment details; Shopify tells us only which plan is active and until when.
Cookies
When you log in to the dashboard, we set a single secure, HTTP-only cookie to keep you signed in. It is essential for the service to function and is not used for advertising or cross-site tracking.
On our public website we use Google Analytics, which sets its own cookies to measure how many people visit and which pages they read. It is not present in the chat widget.
The chat widget sets no cookies at all. It keeps the current conversation in your browser's local storage — on the website you are visiting, not ours — so that reloading the page does not lose the thread. It is discarded after two hours without a message, or as soon as the visitor restarts the chat. The widget's colour and position are cached in the same place so it does not flicker on load.
Our app inside the Shopify admin stores nothing in the browser; each request is authenticated by a short-lived token that Shopify issues.
Data retention
Account and business content is kept for as long as your account is active.
- Chat transcripts — removed automatically 60 days after the last message in that conversation. This includes the messages themselves and everything recorded about them.
- Unanswered questions — removed automatically 60 days after the question was last asked, if the business has not answered or dismissed it.
- Records of leads sent to a business's own marketing tool — the copy of the lead is discarded as soon as it has been delivered, and the record that it was sent is removed after 60 days.
- Leads and appointment requests — kept while the account is active. These are the business's own record of someone contacting them, and removing them on a timer would destroy the business's records rather than protect anyone.
If you close your account or ask us to delete your data, we will remove it from our active systems within a reasonable period, except where we are required to keep it for legal reasons. Closing an account deletes everything belonging to it, including all of the above.
Security
Passwords are hashed, dashboard sessions use secure cookies, and each business's data is isolated from every other business. No online service can promise perfect security, but we take reasonable technical and organisational measures to protect the information in our care.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, or to object to certain processing. Business owners can edit or remove most of their data directly in the dashboard. For anything else, contact us and we will help.
Website visitors who have chatted with a business's assistant should contact that business first, as it controls its own customer data; we will support the business in fulfilling any request.
Children
AeonicX is a business tool and is not directed at children under 13, and we do not knowingly collect their personal information.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “last updated” date above and, for significant changes, take reasonable steps to notify account holders.
Contact us
Questions about this policy? Email deep@aeonicx.com or use our contact page.