App Bloat Clear: Privacy Policy
Effective date: 8 October 2026
1. Who we are
App Bloat Clear is a Shopify app run by tinysprout.in. It finds code that uninstalled apps left in your theme.
- Site: https://bloatclear.tinysprout.in
- Contact: bloatclear@tinysprout.in
- Legal entity and address: Tiny Sprouts Creations, No. 54, 1st Main, KGS Layout, Vijaynagar Extn., Bengaluru, Karnataka 560040, India
2. What we access
App Bloat Clear asks for three read-only permissions. It cannot change anything in your store.
read_themes: lets us read your theme files so we can scan them.read_online_store_pages: lets us check which pages use which templates, so we don't flag code that is in use.read_products: lets us check which products use which templates, for the same reason.
We also load your public storefront pages (home page, one product, one collection and the cart). We do this to measure what app code loads.
App Bloat Clear never edits your live theme. You apply every change yourself.
3. What we store and for how long
Your theme files are read only while a scan or a ZIP build runs. We don't keep copies of them, with four kinds of stored copies. We store the leftover app-code hunks inside findings. Your fix plans hold the planned edits, including the replacement text for changed lines. We also keep cleaned theme ZIPs, which are full copies of your theme. Each ZIP expires 24 hours after it's created. After that it can't be downloaded and is deleted, at the latest within 48 hours. During a scan we also make temporary working copies of theme files. All are in the table.
| What | Why | How long |
|---|---|---|
| Shop domain, install and uninstall dates, status, whether the store is a Shopify development store | To run the app for your store | Until we process shop/redact (see section 6) |
| Shopify login session | To keep you signed in to the app | Deleted when you uninstall the app |
| Scan results: theme name and ID, file names, summaries | To show you what was found | Until we process shop/redact |
| Scan evidence and cost data: sizes, request counts | To show what each leftover costs your store | Until we process shop/redact |
| Leftover app-code hunks inside findings | To show you what to remove and build your fix steps | Until we process shop/redact |
| Your fix plans: the findings you selected; the planned edits, including the replacement text for changed lines; and the list of your theme's file names and checksums used to detect changes | To prepare your cleanup | All of it is deleted when you uninstall and Shopify sends the deletion request (shop/redact) |
| Cleaned theme ZIP files | So you can download your cleaned theme | Expires 24 hours after it's created; after that it can't be downloaded and is deleted, at the latest within 48 hours |
| Temporary working copies of theme files made during a scan | To run the scan | Deleted when the scan finishes; at the latest within 48 hours |
| Billing record: shop domain, purchase ID, status, test flag, date and amount | To remember your lifetime licence | Kept after shop/redact |
| Anonymised learning data: file names and hosts only, with no shop identity | To improve how well we recognise apps | Kept, stored without your shop's identity |
Weekly, for stores that have the app installed, we check whether your published theme's files changed. If they did, we re-scan it and show new leftover code as a banner in the app. Those scan results are stored like a manual scan.
The hunks in the table are short pieces of code that an app left behind in your theme. They may be shown to you in the app. They are not your whole theme.
4. What we never collect
- Customer data. We don't request customer scopes.
- Order data. We don't request order scopes.
- Payment card details. Payment goes through Shopify.
If Shopify sends a customers/data_request or customers/redact request, we reply that we hold no customer data.
5. Sub-processors
| Provider | What for |
|---|---|
| Cloudflare | Hosting, storage, and Cloudflare Workers Logs (operational logs, no theme content) |
| Shopify | Platform and billing |
6. Data deletion
- When you uninstall, we mark your shop as inactive and delete your login sessions.
- Shopify sends us a
shop/redactrequest 48 hours after uninstall. - When we receive it, we delete your shop records, any remaining sessions, scans, findings, fix plans and ZIPs.
- We keep one minimal billing record: shop domain, purchase ID, status, test flag, date and amount. We keep it so your lifetime licence still works if you reinstall.
- Each ZIP expires 24 hours after it's created. After that it can't be downloaded and is deleted, at the latest within 48 hours.
7. Security
- Every app page checks a Shopify session token.
- We verify the signature on every Shopify webhook.
- ZIP download links are signed and tied to your shop. They expire after 24 hours.
- Our secrets are stored as platform-managed secrets (Wrangler), not in code.
- Our permissions are read-only and kept to the minimum we need.
No system is perfectly secure. We can't promise absolute security.
8. Your rights and contact
Depending on where you live, you may have rights to access, correct or delete your data. Uninstalling the app starts deletion as described in section 6. For anything else, email bloatclear@tinysprout.in. Applicable law: the laws of India, including the Digital Personal Data Protection Act, 2023. Regulator: the Data Protection Board of India. If you live in the EU, the UK or another region with its own data protection law, you can also contact your local data protection authority.
9. Changes
We may update this policy. We will post the new version at https://bloatclear.tinysprout.in with a new effective date. If a change is material, we will tell you in the app.