AI Data & Privacy

This page sets out exactly what leaves your store when AI Insights is on. In short: the report’s own figures and the breakdown tables it shows — never customer names, email addresses or addresses.

Until you save an API key, the plugin makes no AI requests of any kind. Even with a key saved, a report only calls the AI service when its own Show insights summary switch is on.

What is sent

When a report with insights is built — for the scheduled email, a test email or the report builder preview — the plugin sends one request to the service you selected. It contains:

  • The store currency, the report interval (daily, weekly…), and the start and end of this period and the previous one.
  • Each total the report shows, with its value for this period, the previous period and the percentage change.
  • The rows of each breakdown table the report shows — for example product, variation and category names, coupon codes, country, state and city names, order statuses and payment method names, each with its figures.
  • The same totals for up to six earlier periods, so the summary can say things like “best week in 6”.
  • For periods of 2 to 31 days, one line per day with the date, weekday, net revenue, number of orders, refunds and coupon discounts.
  • The text of any unusual-movement callouts, so the summary does not repeat them word for word.

Test connection sends only a fixed test sentence and none of your data. With Gemini, the plugin also asks Google which models your key can use, at most once a day.

What is never sent

DataSent?
Customer namesNever
Customer email addresses or phone numbersNever
Billing or shipping street addressesNever
Order IDs or order numbersNever
The Order details and Refunded order details tablesNever — they list individual customers, so they are always left out, even when the report shows them
Report name, subject line and recipient addressesNever
Totals and breakdown tables you switched off in the reportNever
Payment or card details, IP addressesNever
One honest caveat about small numbers. Totals are not personal data in the ordinary case. But a breakdown row covering a single order — for example a city that produced one order in the period — effectively discloses that order’s value and location at city level. No name, street address or contact detail is ever attached. If you sell into very low-volume cities or states and treat this as confidential, leave the city and state breakdowns out of reports that use insights.

Where it goes

Data goes to the single service you selected, directly from your server to its API. It does not pass through zorem, and zorem never receives it.

ServiceEndpointTerms and privacy
Anthropic (Claude)api.anthropic.comCommercial terms · Privacy policy
Google (Gemini)generativelanguage.googleapis.comGemini API terms · Privacy policy

What your service does with it

Once the request reaches the service, its terms apply, not ours. Two things are worth checking on your own account:

  • Whether your data is used to train models. Paid API plans generally do not train on submitted data by default, but free tiers can differ — Google’s free Gemini API tier is used to improve their products, the paid tier is not. If this matters to you, use a paid key.
  • How long requests are kept. Services usually hold API requests for a limited time for abuse monitoring. The window is set in their policy, not by this plugin.
If you are in the EU or UK. Both services may process requests outside your region, so turning on AI Insights is a transfer of store data to a third-country processor. If your organisation keeps a record of processing or needs a data processing agreement, that agreement is with your chosen AI service, not with zorem.

What is stored on your own site

WhereWhatKept for
WordPress optionsYour chosen service, model, the on/off setting and your API key (one per service)Until you change or remove them
WordPress transientsThe written headline, summary and next steps for each report period24 hours (15 minutes after a failed request); cleared whenever the AI Insights tab is saved
WordPress transients (Gemini only)The list of models your key can use24 hours
WooCommerce → Status → Logs, source sre-logA line when a summary is skipped, with the report number and the service’s error messageAs your WooCommerce log retention

Your API key, the report data sent and the answers returned are not written to any log.

How to stop it completely

To…Do this
Stop AI for one reportTurn off Show insights summary in that report’s Report Settings.
Stop AI for every report, keeping the keyTurn off Use the AI features at WooCommerce → Email Reports → AI Insights and save. No further requests are made.
Stop this store using your keyClick Remove next to the saved key. It is deleted from your database.
Stop the key being billed at allRevoke the key in the service’s console — Anthropic or Google AI Studio. Removing it from WordPress only stops this store using it.
Billing is directly between you and your chosen AI service. zorem does not process, proxy or see any of these requests, and adds no charge of its own.