AIsleshopping on X, powered by xAI

Privacy & data protection

Last updated: 2026-09-04. AIsle is designed with GDPR storage limitation, purpose limitation, and security-by-design controls (aligned with ISO 27001 practices and the AIsle product proposal).

Who we are

AIsle is a brand shopping concierge platform for X campaigns (WEB shortlink / website card and DM surfaces). Control-plane accounts (brands, xAI staff, admins) authenticate via Clerk. Shopper chats are anonymous product-discovery sessions — AIsle does not build a shopper identity graph.

Data we process

  • Account data — email, name, role, X handle (from Clerk OAuth). Passwords are never stored by AIsle; Clerk is the identity provider.
  • Shopper chats — message text (with common PII patterns redacted where detected), pseudonymous visitor id (HMAC at rest), product recommendations, and optional UTM tags. No names or emails are required from shoppers. Brand-safety blocked content is not stored.
  • DM Brand Safety — when a DM concierge is used, username / bio / profile-image signals may be checked in real time before engaging. Those signals are not retained as shopper records.
  • Merchant integrations — Shopify Admin API tokens are encrypted at rest (AES-256-GCM) and never returned to browsers.
  • Insights — aggregate metrics only (session volume, themes, recommendation mix, Grok summaries). Not individual user journeys.
  • Security logs — audit events for connect/disconnect, exports, and retention purges (no secret material).

Lawful bases & purposes

Account data is processed to provide the service (contract / legitimate interest for security). Shopper chat supports the brand’s legitimate interest in operating a shopping concierge and measuring campaign performance. Where a controller–processor relationship applies, the brand is controller and AIsle is processor for shell config, ephemeral conversation context, and aggregate Insights (including subprocessors such as xAI/Grok under the applicable DPA). Brands remain responsible for their own privacy notices and any X-side data they already hold.

Brand-scoped tenancy

Catalogue, prompts, and Insights stay inside the brand’s concierge shell(s). Conversation data is not shared across brands, sold, or used to train cross-brand profiles.

Retention

Full conversation turns are kept only while the session is active plus a short TTL: 3 days from last activity (product default is 72 hours; configurable via CHAT_RETENTION_HOURS). Raw turns and messages are then automatically deleted. Aggregate brand Insights may be kept without raw transcripts or identity-linked archives. Account data is kept while the account is active.

DM threads may still exist in X Direct Messages under X’s and the brand’s policies — AIsle deletes only its copy and does not control the X-side inbox.

Processors & sub-processors

  • Clerk — authentication
  • Render (or your host) — application & database hosting
  • Shopify — optional catalogue / Admin API
  • xAI — optional Grok session insights (anonymized aggregates only)
  • X — brand OAuth, optional DM delivery (X’s own policies apply)

Your rights

There is no AIsle-side shopper profile to access or port. Control-plane users can export or erase account data from Settings. Shoppers may clear local browser storage to reset their visitor id. Brand admins or ATS may clear individual sessions from the concierge Sessions tab. Residual session content can be purged on the AIsle side on request; Ads/account/platform requests follow X’s and the brand’s existing channels.

Security

  • TLS in transit (production HSTS)
  • Encrypted secrets at rest for merchant tokens
  • Pseudonymous shopper identifiers
  • Role-based access control; public chat rate limits
  • Brand safety filters and DM profile moderation (real-time)
  • Security response headers (CSP, frame options, nosniff)