Privacy Policy
Last updated: March 4, 2026
1. Introduction
WPControl ("we", "us", "our") operates the WPControl service at wpcontrol.dev. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service.
2. Information We Collect
Account Information
When you create an account via Google or GitHub OAuth (through Clerk), we receive and store:
- Email address
- Display name
- Profile image URL
- Authentication provider user ID
WordPress Site Credentials
To connect your WordPress sites, you provide:
- WordPress site URL
- WordPress username
- WordPress Application Password
These credentials are stored securely in our database and used exclusively to execute API requests to your WordPress sites on your behalf.
Usage Data
We automatically collect:
- API call logs (tool name, timestamp, success/failure, response time)
- Monthly usage aggregates for billing purposes
Payment Information
Payment processing is handled by Freemius. We do not store credit card numbers, bank account details, or other payment instruments. Freemius may collect payment information under their own privacy policy.
3. How We Use Your Information
- To provide and maintain the Service
- To authenticate your identity and manage your account
- To connect to and manage your WordPress sites via the MCP protocol
- To track usage for plan limits and billing
- To send service-related notifications (account changes, billing, security alerts)
- To improve the Service and develop new features
- To detect and prevent fraud, abuse, or security incidents
4. Data Storage and Security
Your data is stored on:
- Supabase (PostgreSQL) — account data, site credentials, usage logs. Hosted in the Asia-Pacific region with encryption at rest.
- AWS Lightsail — API server in the ap-northeast-2 (Seoul) region.
- Vercel — dashboard frontend hosting.
- Clerk — authentication and session management.
We implement industry-standard security measures including encrypted data transmission (TLS), Row Level Security (RLS) on database tables, and secure credential storage. WordPress Application Passwords are stored encrypted in the database.
5. Data Sharing
We do not sell your personal information. We share data only with:
- Freemius — payment processing
- Clerk — authentication services
- Supabase — database hosting
- Your WordPress sites — we transmit API requests using your provided credentials
We may disclose information if required by law, court order, or to protect our rights and safety.
6. Data Retention
- Account data: retained while your account is active, deleted within 30 days of account termination.
- API usage logs: retained for 90 days, then automatically deleted.
- Monthly usage aggregates: retained for 12 months for billing history.
- Webhook event logs: retained for 60 days after processing.
7. Your Rights
You have the right to:
- Access your personal data through the dashboard
- Update your account information
- Delete your account and all associated data
- Export your data upon request
- Revoke WordPress site connections at any time
To exercise these rights, contact us at support@wpcontrol.dev.
8. Cookies and Tracking
Our Service uses essential cookies for authentication and session management (via Clerk). We do not use third-party advertising trackers or analytics cookies. Freemius may use cookies for payment processing as described in their privacy policy.
9. International Data Transfers
Your data may be processed in different regions depending on the service provider (Korea, Japan, United States). We ensure all third-party providers maintain adequate data protection standards.
10. Children's Privacy
The Service is not intended for children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or dashboard notification. The "Last updated" date at the top reflects the most recent revision.
12. Contact Us
For privacy-related questions or requests, contact us at support@wpcontrol.dev.