Data Sharing Permissions
If you opt in to usage tracking, the WPChat plugin sends the data below to our servers on a periodic schedule. We use it to prioritise features, fix the bugs that affect the most users, and understand which hosting environments need better support.
Usage tracking is off by default. You can turn it on or off at any time from WPChat → Settings → Data Sharing Consent.
What we collect
Your site environment
- Site URL
- WordPress version, multisite flag, number of WordPress sites (count only)
- PHP version
- Server software string (e.g.
Apache/2.4.x) - Locale, timezone offset
- Total WordPress user count (count only — no names, emails, or IDs)
Your theme
- Theme name, version, and author
Other plugins installed on your site
- Names, versions, and authors of plugins currently active. No plugin settings or licence info.
WPChat plugin usage
- Plugin version, edition (free or pro tier)
- License tier and status, license expiry date
- Number of configured agents and chatbots
- Number of conversations in the current reporting window (count only — never the content of conversations)
- Number of connected channels (e.g. web widget, Facebook Messenger, WhatsApp)
- Number of knowledge-base entries (count only — never the text of entries)
- Feature toggles enabled (smart search, AI summarisation, automated routing, etc.)
- Whether the
api.wpchat.comintegration is configured - Custom-template flags (yes/no)
Weekly activity (current 7-day window only — counters reset after each report)
- API error count broken down by category (authentication, rate limit, permission denied, server error)
- The last 10 error messages, with tokens and credentials automatically stripped before sending
- Admin events (setup wizard started/completed, settings page viewed, upgrade prompt shown)
- Number of days the plugin was actively used this week
- Average admin session duration (measured client-side)
What we never collect
- Names, email addresses, or any personally identifiable information about your site visitors or chat users
- The content of chat conversations, messages, or transcripts
- The content of knowledge-base entries
- Database contents
- Access tokens, API keys, or licence keys
- Visitor IP addresses (on our servers we store only one-way hashed IPs for fraud prevention — never raw addresses)
- Anything from your site’s
wp-config.php, files on disk, or environment variables
How we collect, transmit, and store the data
- Frequency. Once per week, at a randomised day and time so we spread load across our infrastructure. The report is sent in the background via WordPress cron and never blocks the admin UI or any user-facing chat interaction.
- Transmission. HTTPS POST to a WPChat-controlled API. Each site is identified by a server-issued token established on a one-time registration call — not by your URL alone.
- Built-in safeguards.
- Access tokens and credentials are automatically stripped from any error messages before sending.
- Reports larger than 2 MB are dropped rather than sent.
- Only WordPress administrators can change the tracking setting.
- All admin-side actions are protected by WordPress nonces (CSRF protection).
- Only specifically whitelisted plugin settings are captured — never arbitrary database contents.
- Storage. Google Cloud, US region. Encrypted in transit (TLS 1.2+) and at rest.
- Aggregation. Internal dashboards for trend analysis. Never sold to third parties. Never used for advertising.
- Sub-processors. Google Cloud Platform (infrastructure). If WPChat sends data to AI providers (OpenAI, Anthropic, etc.) for smart search or summarisation features, those providers will be listed in our Privacy Policy.
- Retention. Rolling 24 months. Older records are deleted automatically.
How to opt out
- In the plugin: WPChat → Settings → Data sharing consent → Disabled. The change takes effect immediately.
- Or contact us — see below — and we will delete all data associated with your site URL within 30 days.
Contact
Email [email protected] with your site URL to ask questions, request a copy of your data, or request deletion. We respond within 30 days.
Last updated: May 20, 2026