Privacy
Anvil is a product of Tybrite Labs. This page describes what Anvil collects and why. It is a working summary and will be expanded before general availability.
What we hold
An account (your email and name), the storefronts you build, and the credentials you connect so a storefront can reach your store.
Your commerce credentials are encrypted before they are stored. The secret key and signing secret that let a storefront take orders are held with AES-GCM-256 encryption, each under a key derived separately for that record, and they are never sent to a browser — not to yours, and not to a shopper's. They are decrypted only on our servers, at the moment a storefront needs to sign a request to your store. The publishable key, which is built to be public and can only read, is the single credential that reaches a browser.
What your storefront collects
A storefront Anvil builds reports its own errors back to us so faults can be found and fixed. Those reports carry the failure and where it happened — never cart contents, addresses, payment details, or anything identifying a shopper.
Your store's data
Your catalogue, orders and customers live in Galactic Core, not in Anvil. Anvil reads them to build and maintain your storefront; it does not copy them elsewhere.
Getting in touch
Questions about any of this: support@tybritelabs.com.