Legal

Privacy Policy

Last updated 5 July 2026

This policy explains what data Speedy Bloom Limited ("we", "us") handles, and how. We are the data controller. We are registered in Hong Kong at 19 Bonham Road, Floor 11 Flat A, Hong Kong, and you can reach us about privacy at [email protected]. We have written it to be specific and literal rather than generic. We build more than one tool, and different tools have different data access — so this policy describes each tool separately rather than making one blanket claim. Each tool's access is exactly what its section says: no more.

Attest, our job-application assistant for Chrome, has its own dedicated policy: the Attest Privacy Policy. This page covers our website and our Shopify tools.

1. This website

This website sets no cookies, runs no analytics, and contains no third-party trackers or advertising. Fonts are served from this site itself, not from a third party. Our hosting provider, Cloudflare, processes standard request information (including IP addresses) to deliver and protect the site; it does so as our infrastructure provider under its own privacy terms.

2. Theme Residue Cleaner — what it processes

To produce your report, the tool processes the following:

  • Your theme files — read from your store (or from a theme-export file you upload) so we can find leftover code.
  • Your product descriptions — scanned for widget markup left behind by uninstalled apps.

Our handling of that content is deliberately limited:

  • We discard your theme after processing — the theme content is not retained.
  • We retain the report's findings for 14 days (your re-run window), then delete them.
  • For subscribers, we keep a small fingerprint of your last scan (which residue items, in which files — not the theme) for the length of your subscription, so monitoring can tell new residue from what you've already seen. It is deleted when you cancel or uninstall.
  • To generate the report, extracted snippets of your theme code are sent to our AI processing provider, Anthropic, which classifies them and drafts the findings. These snippets are processed only to produce your report and are not used to train AI models.

3. Accountant Exports — what it processes

Accountant Exports builds the financial exports you ask for — net sales, discounts, refunds, and taxes collected, broken down by period and by product/SKU — reconciled against your store's own numbers. To do that it must read your order records, which Shopify classifies as protected customer data. Its access is exactly this:

  • Order records, read-only (the read_orders and read_all_orders permissions — the latter so a report can cover a full fiscal period, not only the last 60 days): line items, prices, discounts, refunds, tax lines, timestamps, and currency.
  • No customer identity fields. We do not request — and Shopify's field-level permissions therefore do not return to us — customer names, addresses, email addresses, or phone numbers. The report format has no place for them. Tax-jurisdiction breakdowns come from the order's tax lines, not from customer addresses.
  • Product information (read_products) — to label SKUs in your exports.

Our handling of that data is deliberately limited:

  • Order data is processed transiently: the raw order extract exists only while your report is being computed and is deleted as soon as aggregation completes.
  • What we keep is your report definitions and the aggregate export files they produce (totals by period and by SKU). These contain no per-customer rows and no customer identifiers. They are deleted when you uninstall.
  • AI is optional, and it never sees your numbers. Every report can be built with the manual controls alone. If you choose to type a plain-English request (for example, "net sales by SKU for last quarter"), the text of that request — and only that text — is sent to our AI processing provider, Anthropic, to draft a report definition, which is shown to you for confirmation before anything runs (and is not used to train AI models). Your order data is never sent to Anthropic or any other AI provider; every figure in your export is computed by our own deterministic code.

4. What each tool never accesses

Theme Residue Cleaner's access is read-only and limited to theme and product information (the read_themes and read_products permissions). It cannot and does not access your orders or your customer data. We hold no customer personal data from the operation of that tool.

Accountant Exports reads order and product records as described in section 3 — and nothing else. It does not request customer name, address, email, or phone fields (Shopify's field-level permissions do not return them to us), it does not read your theme, and it stores no per-customer records.

Neither tool can write to your live store. All access is read-only, and each tool refuses credentials carrying any permission beyond the ones listed for it. We never sell your data.

5. Service providers

We do not sell your data or share it for advertising. We rely on a small set of service providers, each for a specific purpose:

  • Shopify — the platform your store runs on; provides each tool's read-only API access (theme and product data for Theme Residue Cleaner; order and product data for Accountant Exports), and bills App Store purchases.
  • Anthropic — for Theme Residue Cleaner: processes extracted theme code snippets to generate your report. For Accountant Exports: processes only the text of a typed report request (an optional feature) to draft a report definition. Neither is used for model training, and order data is never sent to Anthropic.
  • Cloudflare — hosts this website and processes request logs to deliver and protect it.
  • Paddle (Paddle.com Market Limited) — where a tool is sold outside the Shopify App Store, processes payment as merchant of record under its own privacy policy.

6. Legal bases

Where the EU/UK GDPR applies: we process the store data each tool reads (theme and product content for Theme Residue Cleaner; order records for Accountant Exports) to perform our contract with you (delivering the report, cleaned theme, monitoring, or export you asked for); we process limited transaction information to comply with legal obligations and for our legitimate interest in operating and accounting for the business; and we process website request data for our legitimate interest in security and reliability.

7. Your rights and requests

Subject to applicable law, you may request access to, correction of, deletion of, or restriction of your personal data, object to certain processing, and request portability. Email [email protected] and we will respond within the time the law requires.

We also honour data-subject requests through Shopify's mandatory privacy webhooks — customers/data_request, customers/redact, and shop/redact — which both tools implement. What each returns reflects what each tool actually stores:

  • Theme Residue Cleaner stores no customer personal data at all, so a customer data request returns that no customer data is held, and there is nothing customer-level to redact.
  • Accountant Exports processes order data transiently and stores no per-customer records: by the time a request arrives, the raw order extract has already been deleted, and the stored exports contain only aggregate figures with no customer identifiers. A customer data request therefore returns that we hold no customer-level data, and a customer redaction has no stored customer-level data to remove. Shopify itself remains the system of record for the underlying orders.
  • For either tool, a shop redaction or an app uninstall deletes everything we store for that store — report findings and monitoring fingerprints (Theme Residue Cleaner), report definitions and export files (Accountant Exports), and the tool's access credentials and subscription records.

If you are in the EU/UK, you also have the right to complain to your local data protection authority.

8. International transfers

We are based in Hong Kong, and our service providers may process data in other countries. Where we transfer personal data internationally, we rely on appropriate safeguards as required by applicable law.

9. Changes

If we change this policy materially, we will update the "last updated" date above. We encourage you to review it when you install or re-purchase a tool.

Privacy questions? Email [email protected].