Security & Privacy
Your Data Is Yours. We Just Help You Read It.
Copac AI is built for trust from the first connection — read-only, encrypted, and entirely under your control.
Security & privacy
Your data is yours. We just help you read it.
Built for trust from the first connection — read-only, encrypted, and entirely under your control.
Read-only integrations
We read your data to analyze it — and make no automatic changes to your store or ad accounts.
Platform tokens never stored
Connections run through Windsor.ai. We store only a connection identifier — never your platform access keys.
Encrypted in transit & at rest
Your data is encrypted end to end, and all syncing and analysis happen server-side.
Hardened by default
Strict content-security and frame policies, HSTS, and same-origin CSRF protection on every request.
GDPR data rights
Export or permanently delete your organization's data at any time. We never sell customer data.
You stay in control
Recommendations only. Every action is yours to take — or ignore.
Read-only by design
Copac reads your data to analyze it and never writes back. There are no automatic changes to your store or ad accounts — every recommendation is yours to act on or ignore.
Your platform tokens are never stored
Integrations are brokered through Windsor.ai. We persist only a connection identifier, not your platform access tokens, and all data syncs happen server-side so your keys never reach the browser.
Encrypted and hardened
Your data is encrypted in transit and at rest. Every response sets a strict content-security policy, denies framing (X-Frame-Options: DENY, frame-ancestors 'none'), sets nosniff and a strict referrer policy, and enforces HSTS. State-changing requests carry a same-origin CSRF check.
- Content-Security-Policy locked to known first- and third-party origins
- Encryption in transit (TLS) and at rest
- Same-origin CSRF protection on writes
- Authenticated app routes protected at the edge
GDPR data rights
You can export your organization's data on demand and permanently delete your organization and all associated data at any time. Account actions are recorded in an audit log, and we never share or sell customer data.
Security FAQ
- Do you store my Shopify or ad platform passwords?
- No. Connections run through Windsor.ai and we store only a connection identifier — never your platform access tokens. All syncing happens server-side, and your keys are never exposed to the browser.
- Can Copac change my campaigns or store?
- No. Every integration is read-only and Copac is recommendation-only. We make no automatic changes to your advertising accounts or store.
- How is my data protected?
- Data is encrypted in transit and at rest. Every response carries strict security headers — a content-security policy, frame and MIME protections, and HSTS — and state-changing requests are protected with same-origin CSRF checks.
- Can I export or delete my data?
- Yes. You can export your organization's data at any time, and request permanent deletion of your organization and all associated data. We never sell customer data.
Analytics you can trust with your data
Connect securely in minutes — read-only, always under your control.
Get Started