Bulk FAQ Generator
Privacy Policy
Last updated: 4 August 2026
This policy explains what data the Bulk FAQ Generator app for Shopify accesses, what it stores, who else processes it, and how long it is kept. It applies to the app and to this website.
1. Who is responsible
Bulk FAQ Generator is operated by Juulr B.V., established in the Netherlands, the data controller for the processing described here. For any question about this policy or about your data, write to hessel@juulr.com.
2. We do not access customer personal data
The app requests only these Shopify access scopes: read_legal_policies, read_themes, write_metaobject_definitions, write_metaobjects and write_products.
None of these grant access to customers, orders, checkouts or payment data. The app cannot read your customers’ names, addresses, email addresses or order history, and it never receives them.
3. What the app reads from your store
- Product information: title, description, product type, vendor, tags, options, variant titles and prices, and text-based product metafields. Used as the factual basis for generated questions and answers.
- Store policies: the text of your shipping and refund policies. Used so answers about delivery and returns match your own terms.
- Theme files: the file names of your live theme and the contents of your product templates. Used for one purpose only: checking whether the FAQ block has been added, so the app can warn you if nothing renders on your storefront.
- App subscription status: the name and status of your active subscription, to determine which plan limits apply.
4. What the app writes to your store
- App-owned metaobjects containing the published questions and answers.
- A product metafield per product, referencing those metaobjects.
- Two shop metafields holding your plan level and your structured-data preference, so your theme can read them.
5. What we store, and where
Application data is stored in a PostgreSQL database hosted by Supabase in the eu-central-1 region (Frankfurt, Germany). The application itself runs on a virtual private server at Hostinger, also in Frankfurt, Germany. Data is transmitted over TLS, and the database provider encrypts data at rest.
- Session: your shop domain and the Shopify access token that authorises the app.
- Store settings: shop domain, output language, interface language, maximum number of FAQs, auto-publish preference, structured-data preference, plan level and monthly usage counters.
- Knowledge base: the text you enter yourself as extra context, plus your answers to open questions.
- Product mirror: product ID, title, product type, status and image URL, so the product list can be filtered and sorted without repeatedly querying Shopify.
- Generated FAQs: questions, answers, their sources and their order.
- Generation jobs: status, error messages, and the number of tokens and the cost per generation, used for monitoring and for enforcing plan limits.
- Cached store policies, refreshed periodically.
6. AI processing by third parties
To generate FAQs, the app sends the product context described in section 3, together with your store policies and your knowledge base, to an AI provider. It is sent for that request only, and is not part of any public dataset we create.
Requests go to OpenRouter (OpenRouter, Inc., United States), which forwards them to the model provider we select. That provider is currently Google, using the Gemini model family. No customer personal data is included in these requests, because the app has no access to it.
We do not train any AI model on your data. Whether a model provider retains request data, and for how long, is governed by that provider’s own terms; see the OpenRouter privacy policy and the Google Gemini API terms.
7. Processors we use
| Processor | Purpose | Location |
|---|---|---|
| Shopify | The platform the app runs on | Canada, global infrastructure |
| Supabase | Application database | Germany (eu-central-1) |
| Hostinger | Server hosting the app and its worker | Germany (Frankfurt) |
| OpenRouter, Inc. | Routing AI requests | United States |
| The AI model that writes the answers | United States |
Transfers to processors outside the European Economic Area rely on the European Commission’s Standard Contractual Clauses as included in those providers’ data processing terms.
8. How long we keep data
- While the app is installed, the data in section 5 is kept so the app can function.
- When you uninstall, your session and access token are deleted immediately. The app can no longer reach your store from that moment.
- 48 hours after uninstalling, Shopify sends a shop redaction request and all remaining data for your store is deleted: settings, knowledge base, product mirror, generated FAQs and job history. The short delay exists so that reinstalling straight away does not cost you your work.
- Metaobjects and metafields already published in your own store stay with you. They are your data, in your store, and remain after uninstalling. You can remove them yourself, or unpublish them in the app before uninstalling.
9. Your rights
Under the GDPR you may request access to your data, correction, deletion, a portable copy, or restriction of processing, and you may object to processing. Write to hessel@juulr.com and we will respond within 30 days. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
If a shopper asks you to handle a request about their personal data, note that this app holds none. Shopify’s mandatory customer data request and customer redaction webhooks are implemented and reach our systems, and they find no customer records to return or erase.
10. Cookies and tracking
The app uses the session cookies that Shopify requires to authenticate you inside the Shopify admin. There are no analytics, advertising or tracking cookies, on this website or in the app, and no third-party trackers are loaded.
11. Changes to this policy
If the app starts processing data differently, this page is updated and the date at the top changes with it. Material changes will be communicated inside the app.