What we hold, where it lives, and who can reach it.
Feedmind reads your product catalog. That is commercially sensitive even though it is published on your storefront, and the handling of it should be legible without a sales call. This page states what we do. The DPA states it in contractual language.
The essentials
Encryption
TLS 1.2 or higher in transit. AES-256 at rest for the database, object storage and backups. Secrets are held in a managed secret store, never in source.
EU residency
Application data, catalog content, scores and backups are stored in European Union regions. Feedmind itself is a Luxembourg company.
Access
Access to production is limited to the people who operate the service, protected by multi-factor authentication, and every administrative action against a customer account is written to an audit log.
Approval gated writes
No write to your store happens without an approval you made in the interface. There is no automatic publishing mode and no scheduled write.
No card data
Payments run on Stripe. Card details are entered on Stripe and never reach our servers. We hold an invoice record and a payment method reference, nothing more.
No model training
Your catalog content is sent to model providers only to produce the draft you asked for, under terms that prohibit training on it. We train no models on customer data.
You can see what we hold, at any time.
Store settings list the scopes granted, the scopes pending and the scopes we never request. Revoking write access takes one action and does not affect your score.
Export and erasure, without a support ticket.
Both live in Settings, Security. Export delivers everything we hold about your account and catalog in a machine readable form, usually the same day. Deletion is permanent, removes catalog data, scores and drafts, and cancels any active subscription. Invoices are kept where Luxembourg accounting law requires it, and nothing else is.
Uninstalling from Shopify triggers the same deletion path through the mandatory data webhooks, within thirty days.
| What | How long |
|---|---|
| Catalog and scores | While the store is connected |
| After disconnect | Deleted within 30 days |
| Drafted content | Deleted with the account |
| Support messages | 12 months |
| Audit log | 24 months |
| Invoices | 10 years, statutory |
Seven subprocessors, all named.
Supabase for the application database, Google Cloud and Scaleway for compute and storage, Stripe for payments, and the language model providers used for drafting. Each is listed with its role, its processing region and the data it sees on the subprocessor page, which also carries our commitment to announce a change thirty days before it takes effect.
Tell us before you tell anyone else.
Write to security@getfeedmind.com with enough detail to reproduce the issue. We acknowledge inside two business days and keep you updated until it is closed. We will not pursue anyone who reports in good faith, stays within their own account and does not exfiltrate or destroy data.
What we do not claim.
Feedmind is not certified under ISO 27001 or SOC 2, and we will not imply otherwise. It is an early company operating a small, well understood surface. Everything on this page is a practice we follow today, not an aspiration, and the moment a certification exists it will be named here with its date.