This policy covers the CaseFlow AI browser extension only. CaseFlow AI is made by Rufusly, and signs in to your Rufusly account, which is why it connects to rufusly.ai and why this policy lives here. The Rufusly web app is covered by our main privacy policy, which applies alongside this one.
On this page
The extension adds a side panel to Amazon Seller Central. When you ask it a question, it reads a small, fixed set of fields from the page you are on so its answer is about your actual order or listing rather than a generic one.
Buyer personal data never leaves the page. Names, delivery addresses, email addresses, phone numbers and payment details are not read, not sent to Rufusly, and never reach an AI model.
Nothing runs until you ask. The extension reads the page when you send a message in the panel, not continuously in the background.
One seller, one account. Your data is never shown to another Rufusly customer, and is never used to train an AI model.
CaseFlow AI is Rufusly. The extension is the Rufusly product for Seller Central. Where this policy says data goes to Rufusly, that is the same company that publishes CaseFlow AI, not a third party.
The extension does nothing useful without a Rufusly account. Every request it makes is checked against your Rufusly session on our servers, and a request without a valid session is refused before anything is read or processed. Installing the extension without an account gives you a panel that asks you to sign in, and nothing else.
The extension never asks for, reads, or stores a password. Not your Amazon password, not your Rufusly password, not a security question or a PIN. It has no way to see any of them.
What it does rely on is the sign-in cookie your browser already holds for rufusly.ai. When the panel makes a request, your browser attaches that cookie, exactly as it does when you use the Rufusly website. That cookie is what proves you are signed in, so it is fair to say the extension transmits an authentication credential, and we declare it as such on the Chrome Web Store. Two things are worth being precise about:
The extension does not sign you in, cannot create an account, and cannot change your password. If you are signed out, it says so and sends you to the website.
When you send a message from the side panel, the extension reads the fields below from the Seller Central page in front of you and sends them with your question. This is a fixed list held in our code, not a general page capture: any field not on this list is discarded before the request is sent, including one added by a page we did not expect.
| Field | Example | Why |
|---|---|---|
| Screen type | order, listing | Decides which kind of help is relevant |
| Marketplace | amazon.co.uk | Rules and support routes differ by marketplace |
| Order ID and item ID | 203-9643893-7866703 | Amazon requires the exact ID on any case |
| Order status and date | Shipped, 12 August 2026 | Deadlines and eligibility depend on both |
| Fulfilment channel | FBA or FBM | Changes the answer on refunds and reimbursements |
| SKU and ASIN | VF-BAR-12 | Identifies the product on a case or an invoice |
| Product title | Energy Bar, 12 pack | Describes the item on an invoice |
| Unit price, order total, currency, quantity | £4.99, GBP, 2 | Needed to produce a correct invoice |
| On-screen notice | Amazon’s own cancellation banner | Explains what Amazon has already told you |
| Page path | /orders-v3/order/… | Where you are. The query string is removed |
Your own typed message is sent as well, because it is the question being answered. Every field above, and your message, is scanned for email addresses, phone numbers and UK postcodes, which are removed before anything reaches an AI model. That scan is a second line of defence: the extension should never pick up those details in the first place.
The extension runs only on Seller Central and on rufusly.ai. It is not installed into, and cannot read, any other site you visit.
The fields above are sent to Rufusly’s servers, which pass your question and that context to Anthropic’s Claude models to produce the answer, the case draft, or the invoice you asked for.
| Who | What they receive | Where |
|---|---|---|
| Rufusly | Your question and the page fields listed above | United Kingdom and European Union |
| Anthropic | The same, with personal data already removed | United States, under standard contractual clauses |
| Supabase | Support case drafts you choose to save | European Union |
Anthropic does not retain prompts sent through our account for model training. We do not train any model on your data, and we do not use one seller’s data to answer another seller’s question. Rufusly’s assistant draws on reference answers our own team has written, which contain no customer content at all.
Support case drafts waiting to be filed are held in your browser’s session storage so the panel can show them while you work. Chrome clears that storage when you close the browser. Nothing is written to your hard drive by the extension.
A support case you choose to draft is saved to your Rufusly account, so you can see it on the Support cases page and track whether Amazon has answered. It holds the case text, the SKU and ASIN it concerns, and the Amazon case ID once you tell us what it is. Chat messages in the panel are not stored after the conversation ends.
Case records are kept while your account is open and deleted when you close it. You can ask us to delete them sooner at any time.
| Permission | Why it is needed |
|---|---|
| Seller Central access | To show the side panel there and read the fields listed in section 3 when you ask a question |
| rufusly.ai access | To check you are signed in and to fetch your answer |
sidePanel | The panel itself. This is the whole interface |
storage | To hold case drafts in session storage until you file them |
tabs | To open the Amazon help page for a case you asked to file, and to notice when a filed case gets its Amazon case ID |
scripting | To type your approved case draft into Amazon’s support form. It fills the form and stops. It never presses send |
The extension never submits anything to Amazon on your behalf. It fills the form, then hands control back so you can read the draft and decide. Send, submit and start-chat controls are explicitly excluded from anything it will click.
Under UK GDPR you can ask us for a copy of the personal data we hold about you, ask us to correct or delete it, object to how we use it, or ask us to restrict that use. Email hello@rufusly.ai and we will respond within one month.
Uninstalling the extension stops all data collection immediately. It does not delete case records already saved to your Rufusly account, which you can delete from the app or by asking us.
You can also complain to the Information Commissioner’s Office at ico.org.uk if you think we have handled your data badly.
LUMINOUS EMPORIUM LTD (company number 16201976), 124-128 City Road, London, EC1V 2NX, United Kingdom
Email: hello@rufusly.ai
Security: security@rufusly.ai
If we change what the extension reads or where that data goes, we will update this page and its date before the change reaches the published extension.