Privacy notice

Live data, deliberately limited storage.

This notice explains how XANON LTD handles account information, connected-service credentials, Amazon data and support information when you use amazonGPT.

Recovery and subscriptions

We store one-way hashes of recovery codes and credential-version records to provide email-free password recovery and invalidate old sessions. Raw recovery codes are shown once and are not retained.

When you subscribe, Stripe receives your account email and billing identifiers to process recurring payments and provide its hosted customer portal. We store Stripe customer/subscription identifiers, payment-access status, billing-period dates and processed webhook IDs. Card numbers and raw webhook payloads are not stored in our application database. Seller, Keepa and advertising responses are not sent to Stripe.

Who is responsible

XANON LTD is the controller of personal information processed to operate amazonGPT. Privacy and security enquiries may be sent to security@amazongpt.app. Account support and product requests should use the authenticated support area.

Data we handle

  • Account identity, including your email address, password hash, role and session records.
  • Encrypted Amazon Selling Partner, Amazon Ads and user-supplied Keepa credentials.
  • Connection metadata such as seller labels, marketplaces, advertiser profile IDs, countries, currencies and connection status.
  • Live Amazon seller, Amazon Ads and Keepa responses needed to answer the request you make.
  • Confirmed write-action details and outcomes, privacy-minimised tool activity metadata, and bug or feature requests you submit.
  • Operational security information such as timestamps, request identifiers, errors and limited server logs.
Live business responses

Orders, listings, stock snapshots, finance history, Ads campaign reads and downloaded Ads reports are processed to answer your request and are not copied into amazonGPT’s application database.

How we use information

We use this information to authenticate users, connect services at the user’s direction, return requested answers, execute explicitly confirmed changes, secure and troubleshoot the service, prevent abuse, provide support, meet contractual requirements and respond to incidents. Our bases under applicable UK data-protection law may include performing our contract, legitimate interests in operating and securing the service, consent where required, and legal obligations.

Where data goes

When you connect amazonGPT to ChatGPT, Claude or another MCP client, requested Amazon or Keepa results are returned to that provider so it can answer you. That provider processes the information under its own terms and privacy notice. Amazon Ads MCP remains disabled unless the applicable Amazon approval covers this customer-directed data flow.

We may use infrastructure and professional service providers acting under appropriate terms, including AWS for backend hosting and database infrastructure and Vercel for the public website. We may disclose information when legally required, to protect rights and security, or during a properly controlled corporate transaction. We do not sell Amazon information or personal information.

Amazon Ads data is not combined with Keepa or another third-party data source unless Amazon has explicitly approved that data flow.

How long we keep it

Encrypted connection credentials and profile metadata remain until the connection or account is removed or the grant is revoked. Amazon Ads write audits are automatically deleted after the configured retention period, currently 90 days. Other security, support and transaction records are kept only as long as reasonably necessary for the stated purpose, dispute handling, security, contractual duties and legal obligations. Live read responses and report downloads are not persisted in the application database.

Disconnecting a service removes the stored credential for that connection. Amazon may also require you to revoke the grant in the relevant Amazon account.

How we protect information

We use encryption in transit, server-side credential encryption at rest, access controls, least-privilege operational access, signed sessions and confirmations, rate limits, private database networking, restricted logs and incident-response procedures. No internet service can guarantee absolute security. Report suspected issues through our security page.

Your rights and controls

You can disconnect linked services from the account dashboard and can contact us to request access, correction, deletion, restriction or another right available under applicable law. We may need to verify your identity and may retain limited information where law, fraud prevention, security or a contractual duty requires it.

amazonGPT is intended for business users who are at least 18 years old. We may update this notice when the product, providers or legal requirements change; the current version and date will remain published here.

Effective and last updated: 3 September 2026