MageCopilotMageCopilot← Back to home

Privacy Policy

Effective date: January 1, 2026 · Last updated: July 29, 2026

This Privacy Policy explains how MageCopilot ("we", "us", "our") processes information in connection with the MageCopilot module ("the Software", "the Module") for Magento 2 and Adobe Commerce, as well as our official website (magecopilot.com). By installing, accessing, or using the Software, you accept the practices described in this policy.

1. Self-Hosted Architecture and Local Data Sovereignty

MageCopilot operates as a self-hosted module installed directly on your own server infrastructure or cloud hosting environment (including Adobe Commerce Cloud). We do not run central data collection servers, remote analytics databases, or telemetry aggregators.

MageCopilot does not transmit to us, centralize, or store on our systems:

  • Customer Personally Identifiable Information (PII) including names, email addresses, phone numbers, or delivery addresses.
  • Payment card data, bank account numbers, or transaction tokens.
  • Store sales history, order records, catalog details, or customer database contents.
  • Magento admin credentials, session tokens, or API secrets.
  • Execution logs, prompt histories, or audit trail entries generated by the module.

2. Third-Party AI Provider Integrations

To deliver AI-assisted capabilities, MageCopilot allows administrators to connect third-party Artificial Intelligence providers using their own API credentials or endpoints. Supported providers include:

  • Google Gemini (Google LLC)
  • OpenAI (OpenAI, L.L.C.)
  • Anthropic (Anthropic, PBC)
  • Google Vertex AI (Google Cloud Platform)
  • Microsoft Azure OpenAI (Microsoft Corporation)
  • Ollama (Self-hosted local engine - 100% zero-egress)

When prompts are submitted, sanitized prompt context (such as indexer states, cache statuses, cron execution records, or sanitized error log excerpts) is sent directly from your server to your chosen provider API. Each third-party AI provider processes data under its own terms of service and privacy policy. You are solely responsible for reviewing and accepting third-party provider policies before adding API keys to the module configuration.

3. Zero-Trust PII Sanitization Engine

Prior to transmitting prompt context to any external AI provider endpoint, MageCopilot automatically executes an internal sanitization layer (DataSanitizer). This engine automatically detects, masks, or strips:

  • Admin and database passwords, authentication secrets, and session tokens.
  • API keys, private tokens, and authorization headers.
  • Customer PII including email addresses, personal names, phone numbers, and street addresses.
  • Financial card numbers, payment tokens, and sensitive customer parameters.

This sanitization operates automatically within the module core to maintain data privacy before external API dispatch.

4. Zero-Egress Local Operation (Ollama & Strict Privacy Mode)

For organizations requiring complete data isolation, MageCopilot supports self-hosted local execution using Ollama. In this configuration, all model inference occurs locally on your infrastructure, and zero bytes leave your server environment.

Additionally, store administrators can enable Strict Privacy Mode within the module settings to disable all outbound external prompt transmissions across all providers.

5. Local Security Audit Logs

All activities performed by MageCopilot - including CLI command execution, automated workflow triggers, auto-healing playbooks, and administrator chat queries - are recorded in the local database table magecopilot_security_audit on your server. These logs remain strictly on your infrastructure and are never transmitted to MageCopilot.

6. Subscription Billing and License Data

Subscription management and payment processing for Pro and Enterprise editions are handled by our Merchant of Record (Paddle). We do not store or process credit card numbers or raw payment instruments on our servers. Payment handling is subject to Paddle Privacy Policy.

We retain basic account information (such as administrator contact name, business email address, transaction identifiers, and license status) for subscription fulfillment, cryptographic license key generation, and customer support. License validation is verified locally using Ed25519 cryptography without external network calls.

7. Website Cookies and Technical Data

Our official website (magecopilot.com) does not utilize invasive tracking cookies, cross-site profiling pixels, or third-party behavioral advertising scripts. Standard server logs may record basic HTTP request metadata (IP address, user agent, requested URI) strictly for infrastructure security, rate limiting, and denial-of-service defense.

8. Data Rights (GDPR / CCPA / International Regulations)

Subject to applicable law, users have the right to request access to, correction of, or deletion of the subscription contact data we hold. To exercise these rights regarding subscription records, submit a request to [email protected]. Requests will be acknowledged within 48 hours and processed within 30 days.

9. Data Security Measures

We apply industry-standard technical measures to secure subscription records and cryptographic licensing assets. API keys stored within your Magento database are encrypted at rest using Magento EncryptionKey service. Because the module executes within your environment, maintaining underlying server security, database permissions, and operating system access controls remains your responsibility.

10. Policy Updates

We may amend this Privacy Policy periodically. Active subscribers will be notified of material changes via email. Continued use of the Software following notification constitutes acceptance of the revised policy terms.

11. Contact Information

For questions or privacy inquiries, contact our team:

MageCopilot
Email: [email protected]
Website: https://magecopilot.com