AltSentry AI Image Alt Text
Privacy policy
Updated August 31, 2026
The app processes the minimum Shopify product-image data needed to generate, review, and apply selected alt text.
Data stored
The app stores the shop domain; Shopify product and media identifiers; product title, vendor, product type, Shopify CDN image URL, and current alt text; generated or merchant-edited suggestions, confidence, model, status, bounded errors, and timestamps; shop-scoped operational counts and first-use timestamps for scan, generation, and apply actions; aggregate successful-free-use, temporary reservation, and free-provider-attempt counters; Shopify authentication sessions; and Shopify-managed billing status. It does not store original image bytes.
Free-use and provider limits
To enforce the offer of up to 25 successfully generated free AI drafts and bound provider cost, the app retains aggregate successful-free-use and free-provider-attempt counters when in-app catalog data is deleted. On uninstall, the verified installation’s quota contribution is retained so a rapid reinstall cannot reset used allowance. A required Shopify redaction removes identifying retention for that prior installation.
Separately, the service stores an identity-free UTC-month aggregate with only the month boundary, reserved provider-attempt count, and timestamps. It contains no shop, installation, merchant, product, image, billing, or lifecycle identifier and remains after redaction. An attempt is reserved before the provider call, so the count can remain after a process interruption and is a conservative upper bound rather than an exact count of completed provider requests.
Data leaving Shopify
Scanning reads product media into managed PostgreSQL and makes no AI request. When a merchant selects Generate, the selected Shopify CDN image URL plus product title, vendor, and product type is sent to the OpenAI API using low-detail image input, structured output, and store: false. Existing alt text is not sent.
AI provider controls
OpenAI states that API inputs and outputs are not used for model training by default unless the API organization opts in. Default abuse-monitoring logs can retain customer content for up to 30 days unless legally required longer. See OpenAI API data controls and the current subprocessor list.
Storage, export, and deletion
The production service stores app data in Render PostgreSQL 17 in Frankfurt, Germany. Render documents AES-256 encryption at rest and TLS for external connections. Authenticated merchants can export their shop-scoped app records as JSON or distinctly confirm deletion without changing Shopify. In-app deletion removes catalog records, suggestions, and history while retaining the aggregate counters described above. Uninstall removes app sessions and shop-scoped catalog records while retaining the verified installation’s quota contribution until Shopify-mandated redaction.
Customer data
The app requests no customer or order scopes and stores no customer records. Shopify’s authenticated customers/data_request and customers/redact topics are handled as no-ops.
Merchant control
Scanning, generation, and application are separate actions. Suggestions remain editable. Immediately before applying, the app rechecks Shopify and skips an image whose alt text is no longer empty. Guarded undo restores a prior value only while Shopify still contains the exact text AltSentry applied, preserving later merchant edits. The app does not guarantee accessibility compliance, search placement, traffic, or revenue.
Questions
Email needlylabs@gmail.com. Include the store domain, but do not email tokens, passwords, payment details, customer data, or exports.