Privacy policy
What Littleworks processes, why it is needed, and the controls available to you.
Effective September 17, 2026
Who operates Littleworks
Littleworks is operated by Benjamin David Kovacs (“Littleworks,” “we,” or “us”). This policy covers littleworks.app, our Shopify app, hosted works, and agent connections through our plugins, MCP server, and CLI. Contact admin@littleworks.app about privacy or this policy.
Merchants decide what their works do and what information they collect. When a merchant uses Littleworks to process customer information, we process that information to provide the infrastructure they configure. If you are a customer of a store, contact that merchant first about its use of your information; we can help the merchant handle a verified request.
Information we process
- Store and connection information: store name, myshopify.com domain, internal store identifier, approved Shopify scopes, installation status, encrypted Shopify access credentials, and connection records. Connection records include the agent application, approving Shopify user identifier, redirect addresses, authorization status, and timestamps. Agent tokens are stored as hashes where used for verification; temporary authorization material may be encrypted during the connection flow.
- Code and configuration: JavaScript source, work names and titles, descriptions, input schemas, permissions, environments, deployment versions, and pause state.
- Documents and Shopify information: data that works read, create, update, or delete. Depending on the code and granted Shopify scopes, this can include product and order information, customer identifiers, contact details, or other store/customer information the merchant chooses to process.
- Execution information: work and version identifiers, run identifiers, timestamps, status, duration, request origin category, operation counts, error codes, and bounded logs and detailed errors. Inputs and outputs are processed to run the code and return results; they are not automatically saved as complete run payloads. A work may explicitly store or log some of that information.
- Website and security information: network and request information needed to deliver and protect the service, such as IP addresses, request paths, browser information, and rate-limit signals. Our hosting provider processes this information; application rate limits use derived identifiers where applicable.
- Support correspondence: your email address, message, and any information you choose to send when requesting help.
How we use information
We use this information to authenticate store and agent access, run and version works, store merchant-selected data, make permitted Shopify requests, return results, provide diagnostics and support, enforce usage limits, investigate abuse, and comply with applicable obligations. The app does not need your Shopify password. Do not place credentials, payment-card data, government identifiers, health information, or other unnecessary sensitive information in source code, documents, logs, or support messages.
Who receives information
- Your connected AI provider or agent: when you authorize a connection, it can inspect source, versions, run details, and stored documents, and receive results from works it invokes. This may include customer information if your works process or store it. Document reads are not automatically redacted, and log redaction is best-effort. Only connect clients you intend to give this access to; their own privacy settings and policies govern what they retain or use.
- Shopify: permitted requests and their variables are sent to Shopify, which returns the requested store data. Shopify also supplies store authentication and installation information.
- Cloudflare: hosts the website and backend, executes works, stores application data, and provides network protection, operational logs, and recovery services.
- Email providers: Cloudflare Email Routing forwards support email to the operator’s Google-hosted mailbox. Those providers process message content and delivery information so we can respond.
- Authorized recipients and required disclosures: information may be shared with people you authorize or where reasonably required to comply with law, address security incidents, or protect the service and affected users.
We do not sell personal information or provide it to advertising networks. Our app does not send stored data to an AI provider until your chosen client or configured work requests the relevant operation. If you publish an HTTP work, its callers can receive whatever data your code returns; the merchant is responsible for appropriate authorization and output handling.
How long information is kept
| Information | Current retention |
|---|---|
| Run logs and detailed errors | Visible for seven days. An hourly cleanup removes expired log entries and detailed error content; basic run metadata remains. |
| Hosted documents, source, versions, and basic run metadata | Kept to support your deployed works and their history until removed through supported controls or a verified deletion request. Documents can have an optional expiration timestamp: expired documents become unavailable immediately and are removed by bounded hourly cleanup, which may take longer under load. Source, versions, and basic run metadata have no automatic age-based deletion period. Deleting a paused work does not erase its saved versions, run history, or stored documents. |
| Connection records | Kept to operate and audit the connection until a verified deletion request. A connection grant expires after 90 days, and access tokens after one hour; expiry stops authorization but does not delete all associated records. Pending sign-in requests and expired access-token records are removed during subsequent client-registration cleanup. |
| Browser authorization cookie | Expires after ten minutes and is cleared when the authorization flow completes. |
| Cloudflare Workers operational logs | Retained for up to seven days under the current paid hosting plan. |
| Support email | Kept in the support mailbox while needed to resolve and follow up on the issue; there is currently no automatic mailbox deletion schedule. You may request deletion. |
Disconnecting an agent revokes its future access; existing works can continue running. Uninstalling the Shopify app disables store access, clears the stored Shopify credentials, and revokes agent grants. Neither action automatically purges all source, documents, or run history. Contact us if you also want that information deleted.
Deletion from active application storage does not necessarily remove an earlier copy from provider recovery systems immediately. Such copies expire under the provider’s recovery retention. We may retain information when required by law or needed for a specific security or dispute matter and will explain any applicable restriction when handling your request.
Your controls and requests
- Review works, saved source, data, runs, and agent connections in Littleworks inside Shopify.
- Pause works to stop new execution, disconnect agents to stop future agent requests, or uninstall the app to disable its store access.
- Use your connected agent to read, export, correct, or delete documents within your authorized scope. Back up information you need before deleting it.
- Contact admin@littleworks.app to request access, export, correction, deletion, or help with a privacy concern. We verify that the requester is authorized for the store or information before acting. We handle requests in accordance with applicable law and explain any information we must retain.
Security and processing locations
We use encrypted connections, encrypted stored Shopify credentials, store-scoped authorization, sandboxed code execution, and access limits. No system or redaction method eliminates every risk. Never rely on Preview as a Shopify sandbox: its Littleworks documents are separate, but permitted Shopify calls reach the real store.
Cloudflare, Shopify, your selected AI provider, and our email providers may process information outside your country. Littleworks does not currently offer a selectable data-residency region. Each provider’s own terms and privacy policy also apply to its service.
Cookies and changes to this policy
Littleworks uses an essential, short-lived cookie to secure OAuth authorization. Shopify and your chosen AI client manage their own sign-in sessions. The public site does not currently use advertising cookies or a separate marketing analytics tracker.
We will update this page and its effective date when our practices change. If a change requires additional notice or consent, we will provide it as required. Contact us before connecting if anything in this policy is unclear.