How this tool handles data

A technical description of the data flow — what gets sent to the server, where, and how long it's kept. Last updated 2026-09-03.

Legal framework

The legally binding terms of use and personal data processing are in MAIRA's Terms of Service and Privacy Policy. This page adds the technical details specific to ShoppingAttribot (specific subprocessors, retention periods, data deletion) — the general company policies don't name these details today, since they mainly cover the MAIRA website (contact form, newsletter), not this tool.

What gets sent to the server

The XML feed is parsed directly in your browser. What then gets sent to the server: the selected products (title, description, details, highlights) and a lightweight copy of the rest of the catalog (title, category — for cross-sell/substitute matching). If you upload a GA4 popularity export, the CSV file itself stays in the browser — only the popularity ranking derived from it (numbers, not the export's contents) is sent to the server.

Where data goes from there

  • Google Cloud Storage — the job input and results (the `input.json` file, the output feed) in a private bucket (no public access).
  • Google Gemini API — the title/description/details/highlights of selected products, plus candidate titles/categories of the rest, for generating Q&A and cross-sell suggestions.
  • Firebase/Firestore — the account (email via Firebase Auth), job status and metadata, generated-feed history, credit balance, and the ledger.
  • Resend — notification emails (job completion, credit purchase confirmation); for smaller runs, the finished CSV is attached.
  • Stripe — credit payments run through Stripe Checkout (hosted by Stripe); payment details (card number, etc.) never pass through our server. We only hold the Stripe customer ID, the credit balance, and the ledger (no card number).

How long data is kept

The job input (`input.json`) and intermediate results are deleted once the job completes successfully. If a job fails, is abandoned, or never makes it into processing, the input stays until the bucket's retention period expires (30 days). GCS also keeps a 7-day soft-delete window on top of that — a deleted object is recoverable at the storage level during that time, even after being “deleted” in the app.

Generated feed history and the credit ledger stay in Firestore as long as the account exists — they serve as proof of purchase and let you download earlier results.

Where data physically resides

All infrastructure (Cloud Run, GCS, Firestore) runs in an EU region (`europe-west1`) — enforced at the Terraform level, so the app has no way to accidentally create a resource outside the EU.

Gemini — paid tier and data retention

For the Gemini Developer API, Google requires a paid service tier for clients targeting the EEA. Confirmed (2026-08-05): our Gemini project runs on the paid tier and the API key is restricted to only the APIs it needs — verified directly in Google AI Studio/Cloud console.

Google also offers optional zero-data-retention (ZDR) — a stricter mode where Google doesn't retain prompts/responses at all, beyond the standard paid tier. Requesting ZDR only goes directly through Google and is a separate process outside the app. As of 2026-08-05 we've deliberately decided not to pursue this yet — it's a long-term hardening step, not a launch requirement, since the paid tier on its own already covers Google's standard (non-ZDR) retention. If a ZDR request is pursued, this page will be updated.

Contact for data questions / deletion requests

The app doesn't yet have its own account-deletion request form. Until it does, write directly to michael.chamrath@mairateam.com — security questions, data breaches, deletion/export requests, and retention questions are handled directly at this address, independent of the general company contact in the Privacy Policy. Note: these general company policies don't currently name the subprocessors specific to this tool (Google Cloud/Gemini, Stripe, Resend) — treat the sections above as the current description of what the app actually does.

This page describes the technical data flow, not a legal position. The legally binding terms: Terms of Service · Privacy Policy.