AI Data and Privacy

AI Insights is disabled by default and does nothing until you switch it on and enter your own API key. This page documents exactly what leaves your store when you do.

Which service is contacted

You choose one provider and supply your own key. Requests are sent directly from your store to that provider and are billed to your own account with them. Nothing is routed through zorem.com, and no data is sent to any provider you have not configured.

ProviderEndpointTerms and privacy
Anthropic (Claude)api.anthropic.comanthropic.com/legal/consumer-terms · anthropic.com/legal/privacy
OpenAI (ChatGPT)api.openai.comopenai.com/policies/terms-of-use · openai.com/policies/privacy-policy
Google (Gemini)generativelanguage.googleapis.comai.google.dev/gemini-api/terms · policies.google.com/privacy

What is sent

There are three summaries. Two send aggregate numbers only. The third sends customer-written text and has its own separate setting.

Overview summary — numbers only

The date range, your store currency, monthly and annual recurring revenue for the current and previous period, counts of new / cancelled / ended subscriptions, renewal order count and revenue, and churn-risk band totals.

Forecast summary — numbers only

The forecast horizon in days, your store currency, the gross amount and number of renewals scheduled in that window, the expected collectable amount and its range, your renewal success rate as a percentage, how many months of history that rate is based on, and the amount and count of renewals belonging to high-risk subscriptions.

Cancellation themes — contains customer-written text

If you switch on cancellation feedback, customers are shown an optional question on their account page after they cancel. Enabling the separate Group answers with AI setting sends those written answers to your chosen provider to be grouped into themes.

Before anything is sent, each answer is stripped of email addresses, web links and any run of seven or more digits (phone numbers, card numbers, account references), and is truncated to 500 characters. No subscription IDs, customer IDs, names or dates accompany the text.

Both settings are off by default and either can be used without the other — you can collect feedback and read it yourself without ever sending it anywhere.

What is never sent

  • No customer names, email addresses, user IDs, order IDs, addresses or payment details.
  • No product names, and no product or order records.
  • Your API key is never sent to zorem.com.

When a request happens

A request is only made when you click Generate, Regenerate or Group answers on a report, or when you use Test connection on the settings screen. Cancellation feedback is never sent unless you have explicitly enabled that specific setting.

Key storage

Your API key is encrypted before it is written to your own database, using a secret derived from your site’s own WordPress salts. After saving, the key is never sent back to your browser — the settings screen shows only a masked hint.

Churn-risk scoring

Churn-risk scoring is calculated entirely on your own server and never contacts an external service, whether or not AI Insights is enabled. It is a deterministic weighted sum, not a model.