Rufusly
Chrome extension

CaseFlow AI privacy policy

This policy covers the CaseFlow AI browser extension only. CaseFlow AI is made by Rufusly, and signs in to your Rufusly account, which is why it connects to rufusly.ai and why this policy lives here. The Rufusly web app is covered by our main privacy policy, which applies alongside this one.

Last updated: 24 August 2026  ·  Effective immediately

1. The short version

The extension adds a side panel to Amazon Seller Central. When you ask it a question, it reads a small, fixed set of fields from the page you are on so its answer is about your actual order or listing rather than a generic one.

Buyer personal data never leaves the page. Names, delivery addresses, email addresses, phone numbers and payment details are not read, not sent to Rufusly, and never reach an AI model.

Nothing runs until you ask. The extension reads the page when you send a message in the panel, not continuously in the background.

One seller, one account. Your data is never shown to another Rufusly customer, and is never used to train an AI model.

CaseFlow AI is Rufusly. The extension is the Rufusly product for Seller Central. Where this policy says data goes to Rufusly, that is the same company that publishes CaseFlow AI, not a third party.

2. You must be signed in, and how that works

The extension does nothing useful without a Rufusly account. Every request it makes is checked against your Rufusly session on our servers, and a request without a valid session is refused before anything is read or processed. Installing the extension without an account gives you a panel that asks you to sign in, and nothing else.

The extension never asks for, reads, or stores a password. Not your Amazon password, not your Rufusly password, not a security question or a PIN. It has no way to see any of them.

What it does rely on is the sign-in cookie your browser already holds for rufusly.ai. When the panel makes a request, your browser attaches that cookie, exactly as it does when you use the Rufusly website. That cookie is what proves you are signed in, so it is fair to say the extension transmits an authentication credential, and we declare it as such on the Chrome Web Store. Two things are worth being precise about:

  • The extension cannot read the cookie’s contents. Your browser handles it.
  • It is only ever sent to rufusly.ai, never to Amazon and never anywhere else. The extension refuses to call any other address.

The extension does not sign you in, cannot create an account, and cannot change your password. If you are signed out, it says so and sends you to the website.

3. What the extension reads

When you send a message from the side panel, the extension reads the fields below from the Seller Central page in front of you and sends them with your question. This is a fixed list held in our code, not a general page capture: any field not on this list is discarded before the request is sent, including one added by a page we did not expect.

FieldExampleWhy
Screen typeorder, listingDecides which kind of help is relevant
Marketplaceamazon.co.ukRules and support routes differ by marketplace
Order ID and item ID203-9643893-7866703Amazon requires the exact ID on any case
Order status and dateShipped, 12 August 2026Deadlines and eligibility depend on both
Fulfilment channelFBA or FBMChanges the answer on refunds and reimbursements
SKU and ASINVF-BAR-12Identifies the product on a case or an invoice
Product titleEnergy Bar, 12 packDescribes the item on an invoice
Unit price, order total, currency, quantity£4.99, GBP, 2Needed to produce a correct invoice
On-screen noticeAmazon’s own cancellation bannerExplains what Amazon has already told you
Page path/orders-v3/order/…Where you are. The query string is removed

Your own typed message is sent as well, because it is the question being answered. Every field above, and your message, is scanned for email addresses, phone numbers and UK postcodes, which are removed before anything reaches an AI model. That scan is a second line of defence: the extension should never pick up those details in the first place.

4. What it never reads

  • Buyer names
  • Delivery or billing addresses
  • Buyer email addresses and phone numbers
  • Payment card details, bank details, or any part of them
  • Your Amazon or Rufusly password, a security question, or a PIN. See section 2 for how sign-in works without them
  • Buyer messages and buyer-seller correspondence
  • Any page outside Amazon Seller Central. The extension has no access to your other tabs, your browsing history, or your bookmarks

The extension runs only on Seller Central and on rufusly.ai. It is not installed into, and cannot read, any other site you visit.

5. Where the data goes

The fields above are sent to Rufusly’s servers, which pass your question and that context to Anthropic’s Claude models to produce the answer, the case draft, or the invoice you asked for.

WhoWhat they receiveWhere
RufuslyYour question and the page fields listed aboveUnited Kingdom and European Union
AnthropicThe same, with personal data already removedUnited States, under standard contractual clauses
SupabaseSupport case drafts you choose to saveEuropean Union

Anthropic does not retain prompts sent through our account for model training. We do not train any model on your data, and we do not use one seller’s data to answer another seller’s question. Rufusly’s assistant draws on reference answers our own team has written, which contain no customer content at all.

6. What is stored, and for how long

In your browser

Support case drafts waiting to be filed are held in your browser’s session storage so the panel can show them while you work. Chrome clears that storage when you close the browser. Nothing is written to your hard drive by the extension.

On our servers

A support case you choose to draft is saved to your Rufusly account, so you can see it on the Support cases page and track whether Amazon has answered. It holds the case text, the SKU and ASIN it concerns, and the Amazon case ID once you tell us what it is. Chat messages in the panel are not stored after the conversation ends.

Case records are kept while your account is open and deleted when you close it. You can ask us to delete them sooner at any time.

7. Permissions, and why each one

PermissionWhy it is needed
Seller Central accessTo show the side panel there and read the fields listed in section 3 when you ask a question
rufusly.ai accessTo check you are signed in and to fetch your answer
sidePanelThe panel itself. This is the whole interface
storageTo hold case drafts in session storage until you file them
tabsTo open the Amazon help page for a case you asked to file, and to notice when a filed case gets its Amazon case ID
scriptingTo type your approved case draft into Amazon’s support form. It fills the form and stops. It never presses send

The extension never submits anything to Amazon on your behalf. It fills the form, then hands control back so you can read the draft and decide. Send, submit and start-chat controls are explicitly excluded from anything it will click.

8. What we do not do

  • No analytics, tracking pixels, or session recording in the extension
  • No advertising, and no data sold or shared with data brokers
  • No use of your data to train AI models, ours or anyone else’s
  • No sharing of your data with other Rufusly customers
  • No reading of pages outside Seller Central and rufusly.ai
  • No transfer of your data to any third party except the processors named in section 5

9. Your rights

Under UK GDPR you can ask us for a copy of the personal data we hold about you, ask us to correct or delete it, object to how we use it, or ask us to restrict that use. Email hello@rufusly.ai and we will respond within one month.

Uninstalling the extension stops all data collection immediately. It does not delete case records already saved to your Rufusly account, which you can delete from the app or by asking us.

You can also complain to the Information Commissioner’s Office at ico.org.uk if you think we have handled your data badly.

10. Who we are

LUMINOUS EMPORIUM LTD (company number 16201976), 124-128 City Road, London, EC1V 2NX, United Kingdom

Email: hello@rufusly.ai

Security: security@rufusly.ai

If we change what the extension reads or where that data goes, we will update this page and its date before the change reaches the published extension.