Kobold Help

Security and data retention

How Kobold protects your store, and what it keeps.

Your store

  • Kobold never edits your live theme. Its Shopify client refuses writes to the published theme and to themes that don't belong to the task.
  • Checkout files are never writable, and Kobold never reads orders, payments or customer data.
  • Publishing always needs an approval from a member with the right role, and every publish, rollback and "publish anyway" is recorded in the audit log.

Secrets

Shopify access tokens and storefront passwords are encrypted with AES-256-GCM under rotating keys. They are never logged, never shown in the browser and never sent to the AI models.

The agents

Theme files, memory, client comments and emails are passed to the agents as data, not instructions, so text inside a theme file can't make them act outside the task. The agents' tools are limited to the task's store and copy; Moss's test scripts can't run arbitrary code.

Client links use 32 random bytes, are stored hashed, expire after 7 days, can be revoked, and are pinned to one version of the change.

Data retention

DataKept for
Store memory, rules and theme index after disconnect30 days
Theme copies made by Kobold30 days after they stop being live (for rollback)
QA screenshots and reports90 days
Customer personal datanever stored

Shopify's shop/redact request deletes a store's data.

Status

Service status and incident notes are posted here and emailed to workspace owners.

Privacy

We process the minimum needed to run Kobold: your account, your workspace, and the theme files of stores you connect. Questions: hello@usekobold.com.

Terms

Kobold is provided under the Kobold terms of service you accept at sign-up.

Cookies

The marketing site and help center use no tracking cookies. The app uses essential cookies for sign-in only.

On this page