Privacy Policy
Last updated: August 1, 2026
This Privacy Policy explains how Firefly Sky SEO, Firefly Sky SEO AI Blog, and related Firefly Sky Shopify applications (collectively, “the Apps”, “we”, or “us”) collect, use, store, and protect information when a Shopify merchant installs or uses an App, visits the Firefly Sky Help Center, or contacts support.
Information we process
Merchant and store information
We process the shop domain, Shopify installation and session data, app settings, subscription status, usage and credit records, and the store content needed to provide features selected by the merchant. Depending on the feature, this may include products, product images, collections, blog articles, pages, files, navigation redirects, SEO metadata, structured-data settings, Noindex rules, and performance results.
Credentials and connected services
If a merchant connects an optional service or supplies an API key, we process that credential solely to provide the selected integration. Stored secrets are encrypted at rest.
AI content, brand knowledge, and connected providers
Firefly Sky SEO AI Blog processes prompts, keywords, writing instructions, selected products, existing blog articles, merchant-provided URLs, sitemap pages, brand knowledge, generated text, generated images, revisions, schedules, localization drafts, SEO settings, and model usage metadata to provide content workflows requested by the merchant. The merchant controls review and publishing decisions.
On Free, Starter, and Growth plans, requested AI generation may be processed through AI providers selected and contracted by Firefly Sky. The plan price includes a defined managed-AI allowance and may include a commercial margin; merchants do not need a separate provider account for that allowance. Firefly Sky sends only the inputs needed to provide the requested generation and does not use merchant content to train Firefly Sky models.
Pro also includes a managed-AI allowance and optionally lets a merchant connect its own compatible AI provider. When the merchant activates that option, the Apps send the necessary inputs to the merchant-selected provider, stored API credentials are encrypted at rest, the provider may bill the merchant under its own terms, and the corresponding Firefly article and image generation is not limited by the managed allowance. Disconnecting the custom provider returns the merchant to the Pro managed-AI allowance.
URL and sitemap imports access only URLs supplied or authorized by the merchant and publicly available pages needed to build that merchant’s brand knowledge. Crawled content is isolated by Shopify store.
Google Search Console data
If a merchant connects Google Search Console, the App requests read-only Search Console access. We access authorized properties and the search-performance dimensions and metrics needed for the merchant’s selected keyword, page, country, device, and date filters. This may include query and page values, clicks, impressions, click-through rate, and average position.
We store an encrypted Google refresh token, selected property, synchronization time, filter settings, and synchronized keyword results only to provide and secure Keyword Tracking. We do not use Google user data for advertising or sell it. The App’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements.
Optional Live Visitor Probe
The Live Visitor Probe runs only after a merchant starts it. While active, it can process a visitor’s IP address, country signal, anonymous browser identifier, device type, operating system, browser and user agent, viewport, requested host and URL, referrer, page duration, and outbound link clicks. The anonymous identifier remains in the visitor’s browser local storage until cleared. The most recent 300 events are held in application memory for the active probe session and are not used to build advertising profiles.
Help center, support, and diagnostic data
When you visit the Help Center or contact support, we may process your IP address, browser and device information, pages viewed, cookies required by the website, support messages, and any store details or screenshots you choose to provide. We also process limited request metadata, error details, and operational logs to secure, troubleshoot, and improve the App.
How we use information
- Provide SEO analysis, metadata and image tools, structured data, redirects, access rules, storefront features, and support requested by the merchant.
- Authenticate installations, preserve subscription and usage entitlements, enforce plan limits, and process app charges through Shopify’s Billing API.
- Protect the App from abuse, investigate errors, monitor reliability, and comply with legal obligations.
- Respond to support, billing, security, and privacy requests.
Service providers and international transfers
We use Shopify for platform and billing services, Railway for application and database hosting, and Hostinger/WordPress for this Help Center. Optional integrations may send necessary input to Google, an AI provider selected or configured by the merchant, or other providers needed for the requested feature.
When country-based storefront features need a fallback lookup, the App may use ipwho.is and, for server-side fallback, ipapi.co to resolve a public IP address to a country. Only information needed for that lookup is sent, and server-side results may be cached in application memory for up to six hours.
Providers may process information in countries other than your own under their terms and privacy commitments. We do not sell personal information or use storefront visitor information for targeted advertising.
Retention and deletion
We keep store settings, plan and credit ledgers, and operational records only as long as needed to provide the App, prevent trial or credit abuse, resolve disputes, and meet security, billing, or legal obligations. Shopify mandatory privacy webhooks are authenticated before processing. Customer data access and deletion requests are acknowledged even when an App stores no customer or order data. A shop redaction request deletes store-specific settings, generated assets, drafts, revisions, knowledge sources, schedules, analytics events, usage records, encrypted credentials, support requests, and sessions from the active application database. Uninstalling alone does not immediately erase merchant content because Shopify sends the shop redaction request after its required waiting period. Short-lived backups may retain deleted information until normal rotation completes.
Your choices and rights
Merchants can disable optional storefront features, remove theme app blocks, disconnect AI providers, and stop using the Apps. Existing Shopify articles remain under the merchant’s control. Merchants can request access to or deletion of App-held store data by contacting support. Disconnecting Google Search Console causes the App to attempt to revoke Google access and deletes the stored Google credential and selected property. Merchants may also revoke access from their Google Account.
Depending on location, eligible individuals may request access, correction, deletion, restriction, portability, or objection. Email support@fireflysky.net and include the relevant shop domain. We may request reasonable verification and route storefront-related requests through the applicable Shopify merchant.
Security
We use encrypted transport, access controls, encrypted secret storage, request authentication, tenant-isolation controls, and operational monitoring. No online system is completely secure, but we review and update safeguards as the App changes.
Children
The App and Help Center are intended for business users and are not directed to children.
Changes and contact
We may update this policy as the App, Help Center, providers, or legal requirements change. The current version and effective date remain available on this page. Questions may be sent to support@fireflysky.net.
