Privacy.
The plain-English version of how we operate. Plain-spoken because we want you to actually read it.
What we store, where
Your store data — products, posts, customers, orders — lives on your WordPress install. We never copy it to our servers in bulk. The agents read it via the WordPress REST API at runtime and discard it once the task completes.
What we do store: agent run logs, performance metrics, optional brain knowledge graph entries you choose to ingest, billing records, and license activations. All of it lives in a Supabase Postgres database in us-east-1.
Sub-processors
We use a small number of third-party services. The current list:
- Supabase — database, auth, vector store. us-east-1.
- Vercel — dashboard hosting + edge functions.
- Stripe — payment processing. PCI-DSS Level 1.
- Resend — transactional email (license delivery, alerts).
- Trigger.dev — agent scheduling and durable execution.
- Your chosen AI providers — Anthropic, OpenAI, Google Gemini, MiniMax. You bring your own keys; tokens are sent directly from our infrastructure to theirs.
See the full sub-processor list at openwpagent.com/sub-processors. We'll email you in advance when we add a new one.
Social media integrations
When you connect a social media account to OpenWPAgent — Facebook, Instagram, LinkedIn, TikTok, Threads, X, Pinterest, and other supported platforms — we receive an OAuth access token from that platform. We use the token solely to publish posts you have composed in our dashboard to your own connected account. We store the token encrypted at rest in Supabase (us-east-1) and never share it with third parties. You can disconnect at any time from your dashboard, which immediately revokes our access.
For each connected platform, we may also read your basic profile info (display name, profile photo, follower count) for display in our dashboard, and read engagement data (likes, comments) on posts you have published through us.
ChatGPT app and public website reviews
When you use the OpenWPAgent app in ChatGPT, OpenAI sends us the public website URL you ask us to review and your confirmation that you are authorized to review it. We read public website content, response headers, TLS information, robots.txt, sitemap files, and public WordPress REST signals only to produce the requested report. We do not request or receive WordPress credentials, private dashboard data, payment information, or the rest of your ChatGPT conversation.
Homepage design reviews use Firecrawl to render the submitted public page at desktop and mobile sizes. These app requests disable Firecrawl render caching and do not request screenshots. OpenWPAgent does not intentionally persist the submitted URL or tool result after the app call completes. Firecrawl may process the public URL, rendered page content, and operational metadata under its own retention and privacy terms; Vercel and OpenAI may also process limited request or operational metadata under their respective policies.
You can avoid this processing by not invoking the app. For privacy questions or deletion requests involving other OpenWPAgent account data, email privacy@openwpagent.com.
Leads and marketing
When you run the free WordPress audit and ask us to email you the report, we collect your email address, an optional first name, the site URL you submitted, your confirmation that you are authorized to audit that site, and basic campaign attribution (which ad, link, or page brought you to us).
We use this to deliver the audit report you requested and to send occasional product emails about OpenWPAgent. Where consent is the applicable legal basis we rely on the consent you give when you submit the form; delivery of the report you asked for is carried out to perform that request. You can withdraw consent at any time using the one-click unsubscribe link in every email, which stops marketing email without affecting reports you have already requested.
We never sell your information, and we do not transfer it to data brokers, advertising networks, or data exchanges. Contact details collected through an advertisement are used only to provide the audit that the advertisement offered — we do not merge them into unrelated mailing lists. Audit leads are held in a dedicated marketing audience, separate from any other list.
We keep lead records for as long as needed to deliver the report and operate our marketing, and delete them on request. To access, correct, or delete your information, or to object to marketing, email privacy@openwpagent.com.
Data export and deletion
You can export every byte of your data from your dashboard at any time. Deletion is permanent and irreversible — we comply with GDPR Article 17 (right to erasure) within 30 days of request.
Cookies and tracking
The marketing site and dashboard use Vercel Web Analytics to measure page visits and key funnel events such as audit completion, signup, plugin download, site connection, and approval decisions. We do not send audit URLs, email addresses, license keys, auth tokens, or other entered content with those events. The dashboard also uses first-party Supabase auth cookies for session management, and we keep limited first-touch campaign attribution in first-party browser storage for up to 90 days.
On the marketing site (openwpagent.com) we also use Google Analytics 4 and the Meta (Facebook) pixel to understand how people find and move through the site, and to measure which ads lead to signups. These set cookies in your browser, including Meta's _fbp and _fbc identifiers. We do not use session recording or heatmap tools, and we never attach your name, email address, or anything you type into a form to these analytics events. Page URLs are recorded without query strings, so checkout and authentication tokens are not captured.
You can decline. The banner on your first visit records your choice, and declining turns these off. You can change your mind by clearing this site's data in your browser, which will bring the banner back. We also honor a browser Global Privacy Control signal by blocking Google Analytics and Meta advertising tracking.
When you request a free audit report, our server reports a Lead event to Meta's Conversions API only when advertising tracking is permitted. The report includes one-way cryptographic hashes of the email address and optional name you submitted, the Meta cookie identifiers above when present, and standard request data such as IP address and browser user agent. The matching browser and server events share an identifier so Meta can count the lead once.
When you buy a plan, our server reports the purchase to Meta's Conversions API so we can measure advertising accurately. That report contains the purchase amount and a one-way cryptographic hash of your email address — never the address itself — together with the Meta cookie identifiers above if they are present. We send this from our server rather than your browser because checkout finishes on a different subdomain.
On the dashboard (app.openwpagent.com) there are no advertising cookies at all — only Vercel Web Analytics and the first-party Supabase cookie that keeps you signed in.
Contact
Privacy questions: privacy@openwpagent.com. We aim to respond within two business days.