Remedy — privacy policy
Last updated 11 August 2026.
Remedy is a Shopify app published by iTechVista. This policy covers the Remedy app only. It describes what the app can access, what it stores, who else sees it, and how to get rid of it.
The short version
- Remedy cannot read customer names, addresses, email addresses or orders. It does not request those permissions on any plan.
- It reads your themes, products and content, and it loads your public storefront pages the way any visitor would.
- On paid plans it sends product images that have no description to an AI provider so a description can be written. Nothing else is sent.
- Everything Remedy holds about your store is erased 48 hours after you uninstall.
What Remedy accesses
Remedy requests these Shopify access scopes and no others:
-
read_themes— to identify which theme your store runs. -
read_products— to find images that have no description, without crawling your storefront. -
read_content— pages, blogs and articles, for the same reason. -
write_themes— the only write permission. It is used for exactly two things: storing the verified stylesheet that delivers corrections, and writing descriptions onto images. Remedy does not write theme files.
None of these can reach customer or order data. This keeps Remedy outside Shopify's protected customer data programme.
Why the install screen says “View staff and contributor data”
Shopify’s install screen groups permissions into categories rather than listing them one by one,
and it puts read_content under a heading that reads
“View staff and contributor data — Store owner, blog contributors”. That is a
fair description of the category and a misleading description of Remedy, so it is worth saying
plainly what it means here.
Blog articles in Shopify carry an author, and the author is a member of your staff. Because Remedy reads your blog articles — to test them for accessibility problems, like every other page — the permission that lets it do so is the same permission that exposes the author’s name. Remedy does not read it, store it, or send it anywhere. It has no interest in who wrote a post; it is looking at whether the post’s headings are in order and its images are described.
Remedy cannot see staff email addresses, permissions, or logins, and it cannot see customers or orders at all. If you would rather verify that than take our word for it, the full list of what an app was granted is in your admin under Settings → Apps and sales channels → Remedy → App permissions.
What Remedy stores
- Your shop domain, the theme you run, and your plan.
- Scan results: which checks failed, on which page templates, on which elements, with the page URL and the element's markup snippet.
- Corrections generated, whether each passed verification, and whether it was applied.
- Descriptions written for images, and a hash of each image so the same picture is never described twice.
- A dated log of everything above. This log is append-only — it cannot be edited or deleted by us or by you, because a record you can quietly rewrite is not a record.
Data is held in Supabase (PostgreSQL), with the application hosted on Vercel.
AI providers
Remedy's AI features are provided by Anthropic, a company based in the United States, with Google, also based in the United States, as the only configured alternative. No other AI provider is used.
The only thing Remedy sends to an AI provider is an image that has no description, and only on a paid plan. Product titles, prices, customer information and order data are never sent — Remedy does not request access to them at all. Under Anthropic's and Google's commercial API terms, images sent through their APIs are not used to train their models.
Both are United States companies. Remedy does not make a claim about the physical location of the servers that process an image, because that is a commitment we would have to contract for and verify before stating it.
Subprocessors
| Company | Purpose | Based in |
|---|---|---|
| Shopify | The platform the app runs on | Canada |
| Vercel | Application hosting | United States |
| Supabase | Database | United States |
| Anthropic | Writing image descriptions | United States |
| Configured alternative for image descriptions | United States |
Your storefront visitors
Remedy sets no cookies on your storefront, runs no tracking, and collects nothing about your shoppers. Corrections are rendered into the page Shopify already sends, so a shopper's browser never contacts Remedy at all.
Deleting your data
Uninstalling the app stops everything immediately. Shopify then notifies us, and 48 hours later every record Remedy holds about your store is erased, including the append-only log. You can also ask us to erase it sooner at support@itechvista.com.
Image descriptions Remedy wrote are yours and stay on your products. They were written into your Shopify data, not held by us.
Requests about a specific person
Shopify's three mandatory privacy webhooks are implemented. Remedy's honest answer to two of them is that it holds nothing: it cannot read customer data and never has. The third — erasing a shop's data — is wired to the erasure described above.
Contact
iTechVista — support@itechvista.com