Privacy
What we hold about you, what the SDK holds about other people's sites, and the line between them.
Last updated
Two different questions
This product handles two kinds of personal data and it is worth separating them before anything else, because they carry different risks and different promises.
The first is your account — you are our customer, we know who you are, and we hold what an account needs.
The second is the sites running your plugin, if you use the telemetry SDK. Those people are not our customers and have not agreed to anything with us. Everything collected there is opt-in, anonymous by default, and the subject of its own data dictionary.
Your account
| What | Why |
|---|---|
| Your name and email address | To have an account and to send what you asked us to send. |
| Which plugins you track, your keywords, competitors and alert rules | They are the product. Nothing here is shared, published, or visible on a public profile. |
| Your subscription tier, status and renewal date | To decide what you can see. Card details are handled by the payment processor and never reach us. |
| Product events — signing up, adding a plugin, viewing an estimate, checking out | To measure whether the product works: how many people get to a first useful number, and how long it takes. A closed allowlist, and no site or customer data may be written to it. |
| The campaign parameters on the link you first arrived by, if there were any | To know which advertising brought someone to the product. Captured once, when the account is created, and never updated afterwards. Most accounts have none of this, because most people do not arrive from an ad. |
Public plugin profiles
Public plugin pages are built from what WordPress.org already publishes: the rounded install bucket, rating, review count, downloads and version dates. They never carry the granular install estimate, your keywords, your competitors, your alerts, your goals, or anything identifying about you — including on pages for plugins you track.
A public page reveals nothing about whether anybody is tracking that plugin.
What the SDK collects about other people's sites
Nothing, until the site owner opts in. After that, two separate streams: anonymous telemetry that cannot be traced to a site address, and — only if an administrator separately chooses to send it — deactivation feedback, which does carry the site address and shows them the whole payload first.
The two can never be joined. No row carries both an anonymous install ID and a site address, which is what would otherwise let the anonymous stream be unmasked. The data dictionary lists every field of both.
Never collected
- Administrator or customer email addresses
- IP addresses
- Order, customer or page content
- Passwords, API keys or any credential
- Raw server or error logs
- Frontend visitor behaviour
- The site address in the anonymous telemetry stream — it is refused there, and kept only in deactivation feedback
Analytics on this site
This site can load Google Tag Manager, and does so only when a container has been configured for the deployment — an unset container means no script and no events, so a deployment that has not decided about analytics does not quietly start collecting.
The events it sends carry a plugin slug and nothing about you: no identifier, no fingerprint, no cross-site tracking. That is a deliberate floor. It would be incoherent to demand opt-in consent from the sites we measure while tracking our own readers more closely than that.
Campaign parameters
If you reach this site from an advertisement, the link usually carries parameters naming the campaign — utm_source, utm_medium, utm_campaign, utm_term, utm_content, utm_id — or an identifier from the ad network that placed it: gclid, gbraid, wbraid, dclid, srsltid, msclkid, rdt_cid or fbclid. A ref, via, partner or aff parameter is the same thing on a partner or affiliate link, which we write ourselves rather than an ad network adding it.
Those values, and only those, are stored in cookies on your browser for 30 days, and are added to links from this site to the member app so they survive the move between the two. If you then create an account, they are recorded on it once, so we can tell which advertising brought people to the product. A later visit never changes what was recorded: what is kept is how the account began.
No identifier of our own is set alongside them, nothing is read from these cookies except those names, and they are never added to links leaving for anywhere else — so they are not a way of following you around the web. They are erased with the rest of your account, and they are included in the data export.
How long anything is kept
| Data | Kept for | Notes |
|---|---|---|
| Raw telemetry events | 90 days | A ceiling, not a fixed term. A project configured with a shorter window is pruned to that window instead, by a separate sweep — the per-project setting used to be decorative and is now applied. |
| Install estimates, and rank history for your own plugins | 180 days | The trend history behind your charts and goals. |
| Rank history for a competitor you watch | 90 days | Half the window of your own rows, because the question a competitor series answers — are they gaining on me — is answered by recent movement, and because these are the rows that multiply: sixty competitors across a hundred keywords. |
| Directory index snapshots | 2 days | Working data for the daily sync, not history. |
| Alert firing log | 30 days | Enough to answer "why did I get that email". |
| AI drafts, once responded to or dismissed | 90 days | Pending drafts are not pruned — they are still yours to act on. |
| Background job records | 30 days | Diagnostics rather than history. This table grows with the work, not with the customers. |
| Deactivation feedback | Until deleted | Kept until the project owner deletes it. It is not an event stream — it is a message someone chose to send, and it is bounded by how rarely anyone deactivates. |
| Your account, plugins, keywords and alerts | Until deleted | Kept while the account exists. Expiry locks access to protected figures; it deletes nothing. |
Deletion runs daily and in batches. A row is measured from when we received it rather than from the timestamp the sending site put on it — a remote clock is not something we can verify, and retention is a promise about how long we hold data.
The telemetry window is a ceiling, not a fixed term: a project set to a shorter retention period is pruned to that period instead. This is worth stating because it was once not true — the per-project setting existed as a column nothing read, so a project configured for 30 days kept its data for 90. It is now applied by its own sweep.
Expiry of a trial or subscription locks access to protected figures; it deletes nothing. Install history keeps accruing while an account is inactive, so unlocking returns those days rather than starting from the day you came back. Keyword rank collection does stop while an account is inactive and resumes on unlock, so there is a gap in rank history for that period and no gap in install history.
Sharing
We do not sell personal data and we do not share it for advertising. Data reaches third parties only where the service requires it.
- Payment processor — To take a payment and to tell us that it succeeded. Card details go to them and never reach us.
- Email provider — To deliver the alerts, digests and account emails you asked for.
- Hosting provider — They run the servers this product is stored and served from.
- Analytics provider — Google, through Tag Manager, and only on deployments where a container is configured. It receives page views and the funnel events described above, which carry a plugin slug and no identifier for you.
Your rights
You can export or delete a telemetry project and all of its data from its dashboard at any time. For access to, correction of, or deletion of anything else — including closing your account — write to [email protected].
If you use the SDK, you are the one with the relationship to the site owners running your plugin. Requests from them about their own site should reach us through you, and we will act on them.