Privacy

How GradeMY uses scan data.

This policy explains the information used to run a public storefront scan, identify the request, and make its report available.

Last updated October 1, 2026

Public evidence

A scan may fetch public storefront HTML, product and collection pages, metadata, structured data, sitemap and robots signals, policy links, visible product content, and other public trust signals.

Email and report records

The work email entered after the store URL is used to identify and save the report request. The current scan opens results in the browser and does not send email. Records may include the submitted URL, email, optional shopping request, report data, timestamps, and operational metadata.

Connected GradeMY accounts and ChatGPT

When you connect an account, Auth0 handles sign-in, including an enabled Google sign-in option. GradeMY verifies the access token and uses an opaque account identifier to associate scan ownership, monthly usage, and existing subscription entitlements. GradeMY does not receive your sign-in password.

The ChatGPT plugin receives the storefront URL and optional shopping request passed to its tools. It returns scan IDs, public page evidence, findings, suggested corrections, and coverage limits to ChatGPT. The plugin does not need your full conversation history. Avoid entering private customer information or credentials in a shopping request.

Website billing uses Stripe. GradeMY records Stripe customer/subscription identifiers, entitlement status, webhook event identifiers, and usage records. Stripe handles payment details; the ChatGPT plugin does not create purchases or checkout sessions.

Retention and data requests

Account usage records, scan ownership records, and saved reports currently have no automatic expiry. They remain stored until explicitly deleted. Disconnecting the ChatGPT plugin does not by itself delete GradeMY records or cancel a website subscription.

To request access to or deletion of your GradeMY account and scan records, contact matthewjmcbridejr+grademy-support@gmail.com. Requests are handled manually and require verification of the account. Records that must be retained for billing or legal obligations, and records held independently by providers, may require separate handling. There is currently no self-service deletion tool in the ChatGPT plugin.

What GradeMY does not access

Default scans do not access checkout sessions, carts, customer accounts, payment information, private orders, passwords, analytics, private admin screens, or write-enabled store credentials.

Optional help requests

If you ask for help after viewing a report, GradeMY stores the name, role, optional message, and existing scan context shown in that flow. It does not require you to re-enter the store and report details already attached to the scan.

Sharing

GradeMY does not sell customer data to advertisers. Google Cloud processes account usage and scan records, Vercel hosts the website, Auth0 handles account authentication, and Stripe handles website billing. OpenAI processes tool inputs and results when you use GradeMY in ChatGPT under its own service terms. These providers receive the data needed for their respective functions.

Contact

Questions: matthewjmcbridejr+grademy-support@gmail.com.