← Back to home

Privacy Policy

Last updated: July 6, 2026

Protsy ("we", "us") helps Etsy sellers create and manage listings with AI assistance. This policy explains what data we collect, why, and what your rights are.

What we collect

Account data: your email address and password (stored as a hash by our authentication provider, Supabase).

Etsy store data: when you connect a store via Etsy OAuth, we store encrypted access tokens, your shop name and ID, and the listings, orders and shop statistics needed to operate the service. We only request the OAuth scopes the features require.

Content you provide: product photos, descriptions, prompts and templates you upload or write in the app.

How we use it

To run the product: drafting listings, generating photos, syncing your catalog and orders, and producing reports about your own shop.

Text you submit and listing context are sent to Anthropic (Claude API) to generate titles, descriptions and tags. Photos and prompts are sent to fal.ai to generate images. These providers process the data to return results; we do not sell your data to anyone.

Social media sharing (Pinterest)

You can optionally connect your own Pinterest business account to share your product listings as Pins. When you connect via Pinterest OAuth, we store an encrypted access token and your Pinterest username and account ID. We request only the scopes the feature needs: reading your boards (so you can choose where to pin), creating a single Pin, reading a Pin's status, and reading your basic account info.

We publish a Pin only to your own account, only after you review and approve the content. The app never posts automatically or on behalf of other users. For each shared listing we keep a record of the Pin (its ID, the board, the caption and status) so you can see what was shared. We do not read or collect any other Pinterest data, and we do not sell or share this data.

Disconnecting Pinterest deletes its stored token. Our use of Pinterest data complies with the Pinterest Developer Guidelines and Terms.

Social media sharing (Instagram & Facebook)

You can optionally connect your own Meta (Facebook) account to share your product listings to a Facebook Page and a linked Instagram Business/Creator account. When you connect via Facebook Login, we store an encrypted access token and the identifiers of the Page and Instagram account you select (Page ID and name, Instagram account ID and username). We request only the scopes the feature needs: managing posts on the Pages you own and publishing content to your linked Instagram account.

We publish a post only to your own Page or Instagram account, only after you review and approve the content. The app never posts automatically or on behalf of other users. For each shared listing we keep a record of the post (its ID, the network, the caption and status). The image we publish is fetched by Meta from a public URL of your product photo. We do not read or collect any other Facebook or Instagram data, and we do not sell or share this data.

Disconnecting Meta deletes its stored token. Our use of Facebook and Instagram data complies with the Meta Platform Terms and Developer Policies.

Video sharing (YouTube)

You can optionally connect your own YouTube channel to upload your product videos. When you connect via Google sign-in, we store an encrypted access token and your channel ID and name. We request only the scopes the feature needs: uploading a video to your channel, and reading your basic channel info (so we can show which channel is connected).

We upload a video only to your own channel, only after you review and approve the title and description. The app never uploads automatically or on behalf of other users. The video file is fetched from a public URL of your product video. For each upload we keep a record (its video ID, title/description and status). We do not read, collect or modify any other YouTube data.

Protsy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Disconnecting YouTube deletes its stored token.

Secondary sales channel (Shopify)

You can optionally connect your own Shopify store to publish your listings there as products. When you connect via Shopify OAuth, we store an encrypted access token and your store domain. We request only the scopes the feature needs: creating and updating products, reading products, and reading and writing inventory levels and locations so stock quantities stay accurate.

We create or update a product only in your own store, only after you review and approve the listing. The app never publishes automatically or on behalf of other users. We do not access your Shopify customers, orders, or any other protected customer data — the integration is limited to product catalog and inventory management. For each product sent we keep a record (its Shopify product ID and status) so you can see what was pushed.

Disconnecting Shopify deletes its stored token. Our use of Shopify data complies with the Shopify API License and Terms of Use.

Where it lives

Data is stored in Supabase (PostgreSQL, hosted in the cloud) and the app is served by Vercel. Etsy, Shopify, Pinterest, Meta and Google/YouTube OAuth tokens are encrypted at rest with AES-256-GCM. Row-level security ensures each account can only read its own rows.

Third-party processors

Supabase (database, auth, storage) · Vercel (hosting) · Stripe (payments) · Anthropic (AI text generation) · fal.ai (AI image generation) · Etsy (store API) · Shopify (secondary sales channel API). If you connect social platforms such as Pinterest, Meta (Facebook/Instagram), TikTok or YouTube for sharing, those integrations receive only the content you explicitly choose to share. Each processor receives only what is needed for its function.

Cookies

We use essential session cookies to keep you signed in, and minimal analytics cookies to understand feature usage. We do not use advertising or cross-site tracking cookies. See our Cookie Policy at /cookies for details.

Retention & deletion

Your data is kept while your account is active. Disconnecting a store deletes its tokens; deleting your account removes your stores, drafts, jobs and reports from our active systems within 30 days. You can delete your account directly in Account → Danger Zone, or submit a request at /data-deletion.

Your rights

Depending on where you live (GDPR, KVKK and similar laws), you can request access to, correction of, or deletion of your personal data, and you may object to or restrict certain processing. Email us at support@protsy.io and we will respond within 30 days.

Contact

Questions about this policy or your personal data? Email us at support@protsy.io.