Legal

Privacy Policy

Effective date: July 22nd, 2026

1. Overview and Products Covered

This Privacy Policy describes how visualAI retail solutions, inc. ("visualAI," "we," "us") collects, uses, and protects data across our full product suite: shopperGPT, cleanerGPT, studioGPT, catalogGPT, and discoverGPT (our REST API and Model Context Protocol server). It applies whether you reach visualAI through a merchant's Shopify storefront, through our developer platform at developer.vairetail.com, or through an AI agent such as Claude, ChatGPT, or Cursor connected to our MCP server.

2. Data We Collect

  • Merchant catalog data: product titles, descriptions, images, prices, and inventory attributes, connected via Shopify, BigCommerce, WooCommerce, Magento, a custom PIM, or CSV upload.
  • Shopper interaction data: search queries, uploaded images and color selections used for visual search, click and conversion events, and A/B test assignment - collected to operate shopperGPT and cleanerGPT on a merchant's storefront.
  • Try-on images (studioGPT): photos a shopper uploads or captures to preview a product on themselves, and the avatar or composition images generated from them. See "Virtual Try-On Images" below.
  • Developer and account data: name, email, company, authentication identifiers (via our authentication provider, Clerk), and API/OAuth credentials for anyone who registers for discoverGPT or a merchant Shopify app.
  • API and MCP request data: the requests, tool calls, and responses exchanged with the discoverGPT REST API and MCP server, including which tools an AI agent (Claude, ChatGPT, Cursor, or another MCP-aware host) invokes on a developer's behalf.
  • Billing data: processed by Stripe on our behalf; visualAI does not store full payment card numbers.
  • Standard usage data: device and browser information, IP address, and aggregate site analytics collected via Vercel Analytics.

3. Virtual Try-On Images (studioGPT)

Photos used for virtual try-on are processed to generate the on-model preview a shopper requests, using an image-composition pipeline built on Google Cloud's Vertex AI. These images are not used to train third-party foundation models, are not used for facial recognition or biometric identification, and are not sold or shared for advertising. The same processing, retention, and deletion practices apply when a virtual try-on image is submitted programmatically through the discoverGPT API or MCP server - for example, by a developer's or agency's AI agent - rather than uploaded directly by a shopper; the developer or agency submitting the image is responsible for having the necessary rights to do so. We retain try-on images only as long as needed to deliver the feature and as described under "Data Retention" below, and a shopper, merchant, or developer may request deletion at any time by contacting privacy@vairetail.com.

4. How We Use Data

We use the data above to operate, maintain, and improve shopperGPT, cleanerGPT, studioGPT, catalogGPT, and discoverGPT; to provide support and respond to requests; to detect abuse, fraud, and misuse of the API or MCP server; to enforce rate limits and plan entitlements; and to communicate service updates. visualAI will never sell your data or repurpose it beyond supporting your instance of the platform.

5. AI Processing and Service Providers

visualAI uses a small set of service providers to operate the platform, each processing data solely on our behalf and under contract: Google Cloud Platform for hosting and for AI processing via Vertex AI (Gemini models power search embeddings, catalog enrichment, and studioGPT image composition), Clerk for authentication and account management, Stripe for billing, and Vercel for hosting and analytics. None of these providers is permitted to use your data for their own purposes.

6. Third-Party AI Discovery Feeds (catalogGPT)

catalogGPT makes a participating merchant's catalog discoverable to third-party AI systems - ChatGPT, Gemini, Perplexity, and similar agents - through structured feeds (Schema.org/JSON-LD, llms.txt, UCP, and ACP). This is an intentional, merchant-controlled feature rather than incidental sharing: a merchant chooses to enable catalogGPT and controls what is published. Only catalog and product information is included in these feeds; shopper personal data is never published this way.

7. discoverGPT: API and MCP Platform

Developers authenticate to discoverGPT through Clerk and OAuth 2.0 (client credentials), and every API and MCP request is authorized against that credential. When you connect an MCP-aware host - Claude, ChatGPT, Cursor, or a custom agent - to the discoverGPT MCP server, only the specific tool call and its response pass through our gateway; we do not receive or store the surrounding conversation a shopper or developer has with their AI assistant, only the discrete request made to our tools and the catalog data needed to answer it. API and MCP request logs are kept for security, debugging, and abuse-prevention purposes, per the retention practices below.

8. Data Segregation and Multi-Tenant Isolation

Each merchant's and each developer's data is logically isolated within our multi-tenant platform. Your data is not aggregated with data from any other customer, and analytics or insights derived from your deployment remain confidential and are not disclosed to third parties without your explicit authorization.

9. Data Retention

We retain data for as long as your account is active and as reasonably needed to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your data, including try-on images and API credentials, by contacting privacy@vairetail.com.

10. Your Choices and Rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal data, or to object to certain processing. To exercise any of these rights, contact privacy@vairetail.com and we will respond consistent with applicable law.

11. Cookies, Analytics, and International Transfers

We use Vercel Analytics and similar tools to understand aggregate site usage; your theme preference (light/dark) is stored locally in your browser and never leaves your device. visualAI is based in the United States and may process data in the United States and other countries where our service providers operate, as described under "AI Processing and Service Providers" above.

12. Security

visualAI employs encryption in transit and at rest, OAuth 2.0/JWT-based access control for the API and MCP server, and restricted internal access to production data, to protect the integrity and confidentiality of your information.

13. Changes to This Policy

We may update this Privacy Policy as our products evolve. Material changes will be posted on this page with an updated effective date above.

Questions?

📩 privacy@vairetail.com