Privacy policy — Moody Lenses app for AI assistants

What this connector receives, returns and keeps · last updated 30 September 2026

This privacy policy covers the Moody Lenses app for AI assistants: the connector that lets a shopper browse Moody Lenses's catalogue, fill a cart and reach Moody Lenses's own checkout from an assistant such as ChatGPT or Claude. It is operated by NEXVA GmbH (Curless). What happens on Moody Lenses's own checkout - the purchase, the payment, the delivery address - is governed by Moody Lenses's own privacy policy.

In short

Personal data collected

No name, postal address, phone number or payment details are collected, and the rest of the conversation is never sent here.

The prescription power chosen for each eye is health information. It is used only to choose the product variant the shopper asked for, held in their cart in memory - never written to disk or tied to a person - and deleted with the cart, at most two hours after it was last used. It reaches Shopify only as the variant in the checkout link the shopper opens.

What it is used for

To show Moody Lenses's catalogue and stock, keep the cart, build the link to Moody Lenses's own checkout, recognise the order that checkout creates, look up the one order a shopper asks about, and protect the service from abuse with rate limits. Nothing is sold, used for advertising or used to build a profile.

Who receives it

Shopify, Moody Lenses's e-commerce platform, for the catalogue, the order lookup and the checkout; Moody Lenses, which sees on an order placed through a checkout link the three attributes described below; and Amazon Web Services, which hosts the servers in Singapore. No one else.

How long it is kept

Your choices

A shopper can empty the cart at any time, on the card or by asking the assistant, and what it held is gone with it. Rights over an order - access, correction, deletion - are exercised with Moody Lenses, which holds it: support@moodylenses.com; this connector keeps no shopper record to correct or delete. About the connector itself, write to NEXVA GmbH (Curless) at ops@curless.ai.

In detail

What reaches this server

Only what a shopper types or taps as tool arguments: a search term, an option value, a product and a quantity for the cart, the checkout reference the card sends back while the shopper pays, or an order number and the email the order was placed with. The rest of the conversation is never sent.

The email is used to match and is never returned. A lookup answers only when the order number and the email both match; a wrong email and an order that does not exist give the same answer, so the tool cannot be used to confirm that an order exists.

What comes back

list_moody_lenses, get_moody_lens and get_moody_checkout_link return catalogue data only — products, options, prices, stock, images — which is personal to nobody.

get_moody_store_policies returns what the shop publishes on its own website — its returns, shipping, privacy and terms policies and its FAQ and contact pages — and takes nothing but an optional topic.

The cart tools — add_to_moody_cart, view_moody_cart and clear_moody_cart — return the cart. These are its fields in full, and the same fields ride beside every answer so the card can show the cart:

check_moody_checkout_status is asked by the card while the shopper pays, and returns only:

Every answer also carries view, merchant, logoUrl, toolNames, vocab — which screen to draw, the shop's name and logo, and this connector's own tool names and words.

lookup_moody_order returns one order, and these are its fields in full:

No name, no address, no phone number, no email and no payment details are returned — not because they are filtered out afterwards, but because the server never asks Shopify for them.

trackingUrls and statusUrl are links to Shopify and to the carrier. Opening one shows more than this connector does — a status page carries the delivery address — so they are handed over as links for the shopper to open, and their contents never pass through here.

What is kept

No shopper record is written. Nothing is sold, shared for advertising, or used to build a profile, and there is no account to sign in to.

Where it goes

Two hosts, both Shopify's: rqxbft-fw.myshopify.com for the catalogue, the single order lookup, the order a checkout reference points to and the policies the shop publishes on its website, and cdn.shopify.com for product images. A checkout link carries three cart attributes, which Shopify copies onto the order it creates: Source (always Curless), Assistant (which AI assistant, when the client says) and CurlessRef (a random reference). The merchant sees them on the order, and the reference is how the card learns that the order was paid. Nothing is sent to any other third party. Our servers are in Singapore, hosted on Amazon Web Services.

Your rights

Exercise them with Moody Lenses — they hold the order, and this connector holds no shopper record to correct or delete: support@moodylenses.com.

About the connector itself, NEXVA GmbH (Curless) is reachable at ops@curless.ai.

How it works · Moody Lenses's privacy policy · Terms of sale