| Flow | Path | Stored by us? |
|---|---|---|
| AI text/image generation | Your device → AI provider (your own key) | No — never touches our servers |
| Outbound Shopify / Printify / Gelato API calls | Your device → platform | No |
| Your designs, listing drafts, shop catalog | Local SQLite on your machine | No |
| Database backups | Local only (your machine) | No |
| Etsy API calls | Your device → our proxy → Etsy | Transit only — not stored (proxy adds Etsy's shared secret, which can't ship in the app) |
| Shopify sign-in (OAuth code exchange) | Your device → our intermediary → Shopify | Transit only — token relayed back and stored encrypted on your device |
| Order webhooks (Shopify / Printify / Gelato) | Platform → our relay → your offline app | Yes, briefly — queued ≤ 7 days, then auto-deleted |
| Shopify mandatory GDPR webhooks | Shopify → our compliance endpoint | Yes — audit log retained 7 years (regulatory requirement) |
| Design staging for print providers | Your device → your own Backblaze B2 bucket | No (your bucket; 36-hour auto-delete) |
| Data | Retention |
|---|---|
| Order/fulfilment webhook relay (Shopify/Printify/Gelato) | 7 days, auto-deleted |
| Shopify GDPR compliance webhook audit log | 7 years (append-only) |
| Design staging files (your B2) | 36 hours, auto-deleted |
| Local database backups | 30 days (on your machine) |
| License records | Licence term + 12 months |
| Local order/customer data | On your machine until you redact/wipe (configurable retention available) |
MockupFlow requests the minimum OAuth scopes needed, and deliberately does not request payment, billing, customer-list, or marketing scopes. The full per-scope breakdown and justification for Etsy and Shopify is documented in the Privacy Policy §7 (Etsy) and §8 (Shopify).
DRAFT — this technical reference is provided for transparency and review; confirm specifics with us before relying on it for a formal security assessment.