
Your data stays yours.
Podley touches your customer emails, order data, and store info. Here’s exactly what that means - and what you can do about it.
Encrypted & secure · Fully transparent · Delete anytime
Our promise
We will never sell your data.
We will never use your data to train AI models - and Anthropic, our AI provider, doesn’t either.
Every third-party service that touches your data is named below.
Your customer data exists for one purpose: helping you respond to support emails.
Data access
What we touch, and what we don’t.
What we access
Gmail - customer service emails
Incoming emails are scanned and classified by AI. Only CS emails are processed. Non-CS emails are filtered and permanently deleted within 30 days.
Shopify - orders, customers, draft orders, discounts
We read orders, customers, and products to build context for each support case. We can issue refunds, cancel orders, swap variants, create draft invoices, and apply compensation discounts - but only when you (or a rule you’ve approved) trigger that action. Products, themes, and storefront code are never touched.
Print-on-demand providers (Printify connected end-to-end; Printful, Gooten, Gelato coming soon)
We read order and fulfillment data for context. When your policies call for it, we can also create replacement orders through Printify. Other actions (claim filing, etc.) are prepared as text for you to submit manually.
AI provider - classification & drafting
Email text is sent to Anthropic (Claude) for classification and response generation. Anthropic does not use your data to train AI models. Standard API requests are retained for up to 30 days for abuse monitoring.
What we never touch
Your personal email content
Non-CS emails are filtered and permanently deleted within 30 days. We never read or store personal email beyond the classification step.
Your costs, margins, or financials
Support cases pull order details only - never your cost basis or margins to make decisions for you. (The optional Books add-on separately shows you your own revenue and COGS numbers, on request.)
Your bank or payment info
All billing goes through Stripe. We never see card numbers or bank details.
Your Shopify products, themes, or storefront code
We never modify products, themes, store settings, or your storefront. Our write access is scoped strictly to support actions: refunds, order cancellations, variant swaps, draft invoices, and compensation discounts.
Your data for AI training
Neither we nor our AI provider (Anthropic) use your data to train models.
Data pipeline
How AI processes your data.
Email arrives
A new email arrives in your Gmail inbox. Podley scans it to determine if it's a customer service message.
Emails are classified by AI. Non-CS emails are filtered out and deleted within 30 days. Podley only applies labels and archives resolved threads - it never deletes emails from your inbox.
AI classifies the email
The email text is sent to Anthropic (Claude) to determine the type: order inquiry, refund request, shipping issue, etc.
Anthropic does not use your data to train AI models. Standard API requests are retained by Anthropic for up to 30 days for abuse monitoring; nothing is shared with other customers.
Context is pulled
Podley fetches the relevant order from Shopify and fulfillment status from your POD provider to ground the reply.
Data is fetched on-demand per case - we don't bulk-sync your entire store. Write access is used only for the support actions you enable.
Draft response is generated
AI generates a reply using your voice settings, the email context, and order data. The draft is stored in your Podley dashboard.
In Training Mode, you review every draft. In Autopilot, approved categories send automatically.
You stay in control
Review, edit, or approve the draft. See exactly what AI generated and what data it used. Override anytime.
Every AI decision, draft, and outbound action is recorded in your activity log.
Infrastructure
Enterprise-grade security.
AES-256-GCM encryption at rest
Sensitive credentials (OAuth tokens, API keys) are encrypted at rest with AES-256-GCM. The underlying database is hosted on Supabase with disk-level encryption.
TLS 1.3 in transit
Every API call and webhook between Podley, your integrations, and AI providers uses TLS 1.3.
Row-level security
The database enforces that each user can only access their own data. No cross-tenant access.
HMAC webhook verification
Every incoming Shopify webhook is checked against its signature before it is read, and one that fails is dropped. The Printify and Stripe receivers hold the same check for when those channels switch on.
Rate limiting
API endpoints are rate-limited per server instance, so a runaway loop or a scripted burst is refused rather than served. Limits shared across instances, and automatic blocking of suspicious traffic, are next.
Audit logging
Every significant action - logins, AI responses, integration syncs - is logged with timestamps.
Your rights
You’re in control.
Full transparency
See every AI decision, every draft, and every outbound action Podley takes on your behalf. The activity log records what you can act on - not low-level system pings.
Export your data
Self-serve export covers your case history, templates, and settings. For a complete export including older records and synced order data, email support and we’ll deliver within 30 days.
Delete everything
Delete your account at any time from Settings. Your data is removed from our live systems immediately, and purged from our encrypted daily backups within 7 days. This does not cancel an active subscription - cancel billing separately, or email billing@podley.app, to stop future charges.
We comply with GDPR (EU), CCPA/CPRA (California), and applicable data protection laws. For full details, see our Privacy Policy.
The safety spine
The model proposes. Code disposes.
Data access is only half of trust. The other half is what the AI is allowed to do. Every action Podley proposes passes a deterministic gate it cannot talk its way around: a fixed allowlist, hard dollar caps, a check that blocks any reply claiming something it did not do, and a draft-only fallback instead of a surprise bill. Every claim there is enforced in code.
See how Podley is kept safeYour customers trust you. You can trust us.
Start your 14-day free trial and see exactly how Podley handles your data.
Questions about privacy? Email privacy@podley.app