Privacy — draft, under review

Almost all of it stays on your own server.

SiteHelm is a plugin that runs inside your WordPress install. Its logs, its snapshots and its credentials live in your database, on your hosting, under your control.

This draft is published for review and is not yet in force. It will carry an effective date once it has been checked by someone qualified to check it.

Section 1 — this website

wpsitehelm.com

This site is static pages. It sets no cookies of its own, runs no analytics script, embeds no third-party trackers, and has no forms, accounts or comment sections.

The host that serves these pages keeps ordinary web server logs, which typically include an IP address, a timestamp, the page requested and a user-agent string. Those logs are used to keep the site running and are not combined with anything else.

Following a link from this site to a checkout page, to the source repository, or to any other external service takes you to that service’s own privacy terms.

Section 2 — the plugin

What SiteHelm stores on your site

The plugin records what it does so that you can see it and undo it. All of this is written to your own WordPress database:

  • The activity ledger — which operation ran, when, against what, by which WordPress account and which connected client, and its outcome.
  • Rollback snapshots — the prior state of whatever a write changed, kept so the change can be reversed.
  • Issued credentials — which Application Passwords SiteHelm has minted, which account each acts as, and when it was last used. The password itself is stored by WordPress, in the way WordPress stores it.

The retention window for the ledger and its snapshots is a setting on the Health screen. Nothing in this list is transmitted anywhere.

Usage tracking

The plugin bundles the Freemius SDK, which powers the Account and Add-Ons screens and can also report anonymous usage data. It asks for that permission on activation and it is opt-in: decline it and the plugin works exactly the same. You can change the answer later from the plugin’s own Account screen.

What your agent sees

An AI client connected to SiteHelm reads whatever the operations it calls return — your posts, your media, your settings, and, if you have a forms plugin and grant it, form entries that visitors submitted. That content goes to whichever AI provider your client uses, under that provider’s terms, not ours. Switch a module or an operation off in the console and it stops being reachable at all.

Section 3 — buying Pro

Checkout, licences and invoices

SiteHelm Pro is sold through Freemius, which acts as the merchant of record. Freemius collects the name, email address, billing details and payment information needed to complete a purchase, issue an invoice and manage a licence. Card details are handled by Freemius and its payment processors and are never seen by us.

What reaches us from a purchase is the account and licence record Freemius keeps: an email address, the tier bought, and the sites a licence is activated on. That is used to support the licence, and for nothing else.

A licensed Pro install checks its licence with Freemius. That check identifies the site so the licence can be counted against the tier.

Section 4 — your rights

Getting your data back, or getting rid of it

The ledger and the snapshots are yours: export the history as CSV from the console at any time, shorten the retention window, or deactivate the plugin and remove its tables.

For the account and licence data Freemius holds, use the account controls in the plugin’s Account screen or contact us and we will action a request for access, correction or deletion.

Questions about any of this, or a request you would rather make in writing: hello@wpsitehelm.com.

This page is a draft published for review. It is not yet in force and does not yet carry an effective date.