LLM Pixels

Security and Data Protection

Last updated 27 August 2026

The technical and organisational measures behind the privacy policy and the data processing agreement.

Data minimisation

The most effective control here is that almost nothing is collected. Storefront events go from the shopper's browser straight to OpenAI without touching our servers. Order data is processed in memory and discarded. No customer personal data is written to disk at any point.

Encryption

Data loss prevention

Separation of environments

Development uses a local database and Shopify test billing. Production credentials and production data are never used in development, and the two databases are entirely separate.

Access control

Incident response

If a security incident is suspected, the following process applies.

Third-party audits

No third-party security audit or certification has been carried out. This statement will be updated if that changes.


Privacy Policy · Data Processing Agreement · Chrome Extension Privacy Policy