Privacy Policy
This policy explains how PILOTLAB LLC, a Wyoming limited liability company ("we", "us"), handles personal data when you use WPMate (the website at wpmate.ai, the dashboard, the MCP connector and the WPMate Connector WordPress plugin). We are the controller of account and billing data. For content on your WordPress sites, we process it on your behalf and only to carry out what you or your AI assistant ask.
What we collect
- Account data: your email address and a hashed password.
- Connected sites: each site's address, name, WordPress and plugin versions, and a per-site signing secret.
- Activity: a log of tool calls (which action, which site, short details such as a post id or title, and the result), approvals you grant or reject, and daily usage counts.
- Site content in transit: when your AI assistant reads or changes a post, setting or plugin, that content passes through our servers to and from your site. We do not keep copies of it beyond what appears in the activity log and approval details (for example, the text of a post waiting for your approval).
- AI assistant connections: the name of each AI client you authorize and the access tokens issued to it (stored hashed).
- Billing: handled by Stripe. We store your Stripe customer and subscription ids, plan, status and renewal date. We never see or store your full card number.
- Technical data: IP address and browser information in server logs, kept for security and abuse prevention.
Cookies
We use one essential cookie to keep you signed in to the dashboard. We do not use advertising or cross-site tracking cookies.
How we use data
- To provide the Service: running the actions you request, showing approvals and activity, enforcing plan limits.
- To bill you and manage your subscription.
- To keep the Service secure and prevent abuse.
- To send service emails such as receipts, security notices and changes to these policies. We do not sell personal data.
AI assistants
When you connect an AI assistant such as Claude or ChatGPT, the results of tool calls (for example, the text of a post) are returned to that assistant. Its provider handles that data under its own terms and privacy policy, which you agreed to separately.
Who we share data with
- Stripe for payments.
- Hosting and infrastructure providers that run our servers and send email.
- Authorities when required by law, or to protect our rights and the safety of others.
Our servers may be located in the United States or other countries. Where required, we use appropriate safeguards for international transfers.
How long we keep data
- Account, site and billing records: while your account is open, and billing records as long as tax law requires.
- Activity and approval records: up to 12 months.
- Expired sign-in sessions, codes and tokens: deleted automatically.
Your rights
You can ask us to access, correct, export or delete your personal data, or object to how we use it, by emailing support@wpmate.ai. Depending on where you live (for example the EU, UK or California) you may have additional rights, including the right to complain to your data protection authority. Disconnecting a site in the dashboard immediately stops WPMate from accessing it.
Security
Passwords and tokens are stored hashed, every request to your site is signed and expires after five minutes, and connections use HTTPS. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as the law requires.
Children
WPMate is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
We will post updates here and email account holders about material changes.
Contact
PILOTLAB LLC, Wyoming, USA · support@wpmate.ai