Privacy Policy

Last updated: 2026-05-28. This page explains what data we collect, why, how long we keep it, and your rights.

1. What we collect

From your WordPress site: nothing automatically. Files, database rows, and post content stay on your host. The plugin only sends content to our server when you explicitly trigger an AI action.

From the AI session: when you chat with the AI we send your chat messages, the relevant code or file contents you reference, and the tool calls the agent decides to make. These pass through our server, are sent to the LLM provider (OpenAI / Anthropic / DeepSeek / etc.), and the response comes back.

What we store on our server:

What we do NOT store: we don't keep persistent copies of your full WordPress files, your database contents, or full LLM response bodies beyond the session memory window.

2. Why we collect it

3. Who we share it with

4. Retention

5. Your rights

You can at any time:

Email [email protected] for any of these. We respond within 30 days.

6. GDPR / EU users

If you're in the EU/EEA/UK, GDPR applies. Our legal basis for processing chat content is legitimate interest (Art. 6(1)(f)) — providing the AI service you asked for. Aggregation for product improvement also relies on legitimate interest, with the opt-out described above. Billing is processed under contractual necessity (Art. 6(1)(b)).

We do not currently transfer personal data outside the EEA except to LLM providers (US-based, covered by Standard Contractual Clauses) and Stripe (covered by their published GDPR adequacy commitments).

7. California (CCPA / CPRA)

California residents have the same access / correction / deletion rights as listed above. We do NOT sell or share personal information for cross-context behavioral advertising. We don't have a "Do Not Sell" link because we don't sell.

8. Children

WordVibe is not directed to anyone under 16. We don't knowingly collect data from children. If you believe we have data from a child, email us and we will delete it.

9. Security

Account passwords are stored as scrypt hashes. License keys and chat content sit in a SQLite database on the server's encrypted volume. Server access requires an SSH key. We don't currently encrypt chat content at rest with per-user keys — on our roadmap. Connections to the server are HTTPS with Let's Encrypt certificates.

Breach notification: if we believe your data has been accessed by an unauthorized party, we will notify you within 72 hours of confirmation, by email.

10. Changes to this policy

Material changes will be announced by email and on this page with a new "Last updated" date. Continued use after the change means you accept it.

11. Contact

Data Protection lead: [email protected]. Postal: [LEGAL ADDRESS — to be filled].

Heads up: this is a first-draft template. Legal-address and jurisdiction-specific clauses will be filled in, and the document reviewed by counsel, before WordVibe scales past initial soft-launch.