AIsleshopping on X, powered by xAI

Privacy & data protection

Last updated: 2026-07-23. AIsle is designed with GDPR storage limitation, purpose limitation, and security-by-design controls (aligned with ISO 27001 practices).

Who we are

AIsle is a brand shopping concierge platform for X campaigns. Control-plane accounts (brands, xAI staff, admins) authenticate via Clerk. Shopper chats are anonymous product-discovery sessions.

Data we process

  • Account data — email, name, role, X handle (from Clerk OAuth). Passwords are never stored by AIsle; Clerk is the identity provider.
  • Shopper chats — message text, pseudonymous visitor id (HMAC at rest), product recommendations, and optional UTM tags. No names or emails are required from shoppers.
  • Merchant integrations — Shopify Admin API tokens are encrypted at rest (AES-256-GCM) and never returned to browsers.
  • Security logs — audit events for connect/disconnect, exports, and retention purges (no secret material).

Lawful bases & purposes

Account data is processed to provide the service (contract / legitimate interest for security). Shopper chat is processed to power the concierge and brand analytics. Brands are controllers of their campaign chat data; AIsle acts as processor for that content.

Retention

Shopper chat sessions are retained for 90 days from last activity, then automatically deleted (including messages). Aggregate brand insights may be kept without raw transcripts. Account data is kept while the account is active.

Processors & sub-processors

  • Clerk — authentication
  • Render (or your host) — application & database hosting
  • Shopify — optional catalogue / Admin API
  • xAI — optional Grok session insights (anonymized aggregates)

Your rights

Control-plane users can export or erase account data from Settings. Shoppers may clear local browser storage to reset their visitor id. Brand admins may request shell-level chat deletion via their AIsle contact.

Security

  • TLS in transit (production HSTS)
  • Encrypted secrets at rest for merchant tokens
  • Pseudonymous shopper identifiers
  • Role-based access control; public chat rate limits
  • Security response headers (CSP, frame options, nosniff)