Privacy Policy
How we collect, use, and protect your information when you use TalkToWP.
In short
TalkToWP collects only the monitoring data your WordPress plugin sends — uptime status, response times, plugin lists, and security headers. We never store your WordPress admin password or database credentials. We never sell your data to anyone. You can request a full export or deletion of your data at any time by emailing [email protected].
1. Introduction
Beyondt Consultancy & Services Pvt. Ltd. ("Company", "we", "us", or "our") operates TalkToWP ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service, you consent to the practices described in this policy.
2. Information We Collect
2.1 Personal Information
- Email address
- Name (optional)
- Payment information — processed and stored by Dodo Payments (our Merchant of Record). We do not store your card or payment details directly.
2.2 WordPress Site Data
- WordPress version and configuration
- Installed plugin and theme information
- Server performance metrics
- Error logs and debug information
- Security status indicators
- SSL certificate status
- Database statistics
2.3 Usage Data
We automatically collect certain information when you access the Service: IP address and browser type, device information, pages visited and features used, and time and date of visits.
3. How We Use Your Information
We use collected information to provide and maintain WordPress monitoring services, detect and alert you to site health and security issues, generate AI-powered insights and plain-English explanations, send transactional alerts, process payments, improve the Service, and meet legal obligations.
3.1 Collective Plugin Intelligence
TalkToWP analyses anonymised, aggregated patterns across all sites in our network to improve issue detection. No domain names, site identifiers, client information, or personally identifiable data are ever included in this analysis.
4. Third-Party Services & Sub-processors
| Service | Purpose | Data Shared |
|---|---|---|
| Dodo Payments | Payment processing, billing | Name, email, payment details |
| Supabase | Authentication and database | Email, account data, monitoring data |
| Anthropic | AI-powered issue analysis | Anonymised error data only. No PII. Not used for model training. |
| Cloudflare | CDN, DDoS protection | IP addresses, request metadata |
| Resend | Email delivery | Your email and notification content |
| AI assistants you connect | Answering your questions about your sites, at your direction | The data described in section 8 |
| Google PageSpeed | Performance analysis | Public site URLs only |
AI Assistants You Connect: where you connect a third-party AI assistant, the data described in section 8 is disclosed to that provider at your direction and under their terms. Connected AI assistants are chosen by you and are not a fixed list; they are not sub-processors we appoint.
We do not sell your personal information to any third party.
5. Lawful Basis for Processing (GDPR)
We process your personal data on the following legal bases: contract performance (delivering the Service), legitimate interests (fraud prevention, security, service improvement), legal obligation (compliance with applicable law), and consent (where you have provided it explicitly).
6. Your Rights
EEA / UK residents (GDPR / UK GDPR)
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a machine-readable format
- Restriction: Request restriction of processing
- Objection: Object to processing based on legitimate interests
California residents (CCPA)
- Know: Request disclosure of personal information collected
- Delete: Request deletion of personal information
- Opt-out of sale: We do not sell your personal information
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
7. Access to Your WordPress Site
By default the TalkToMonitor plugin only reads your site. It collects the technical data described above and sends it to us for analysis; it makes no changes to your site of any kind.
7.1 AI Site Actions
AI Site Actions is disabled by default. It can only be switched on by a site administrator, inside your own WordPress admin, after confirming an acknowledgement. While it is off, every action endpoint in the plugin refuses immediately.
When you enable it, requests signed with your site's API key may:
- Apply plugin, theme and WordPress core updates, activate or deactivate a plugin, and clear caches
- Create, edit, publish and delete posts, pages and block templates
- Create, edit and delete WooCommerce products, and update order status or add order notes
-
Read files from your WordPress directory, and write files inside
wp-content/ - Issue a single-use link, valid for 60 seconds, that signs you into your own wp-admin as an administrator
Each of these groups is granted separately, per site, from your TalkToWP dashboard, and the switch inside your WordPress admin overrides all of them.
Content you create or edit through these actions is stored on your own site; we retain only a record of the action performed, its outcome, and the time.
7.2 What the plugin can never do
Regardless of which permissions you grant, the plugin cannot install
plugins or themes from an arbitrary source, delete plugins or
themes, change users or roles, run database queries, or write
outside wp-content/. It refuses to read or write
wp-config.php, .env files,
.htpasswd and private keys, so your database
credentials and WordPress security keys are never transmitted to us.
8. Connecting an AI Assistant
TalkToWP can be connected to a third-party AI assistant — such as Claude or ChatGPT — through the Model Context Protocol (MCP). No assistant has access until you connect one yourself and approve it on our sign-in screen.
What the assistant can read. Once connected, an assistant acting on your behalf can retrieve: your site names and addresses; WordPress, PHP, plugin and theme inventories; hosting, SSL and caching configuration; uptime and response-time history; performance metrics; security posture including headers, WAF and DNS records; incidents, including error text and any analysis generated for them; activity logs; pending updates and aggregated plugin reliability data; the contents of files in your WordPress directory, excluding the credential files listed in 7.2; account-level totals across your sites; and the record of any action performed, with its status and outcome.
Where that data goes. It is transmitted to the AI provider you connected, and from that point it is handled under that provider's privacy policy and retention terms, not ours. We do not control how they store, process, train on or retain it. Connect only providers whose terms you accept.
What the assistant can change. Nothing, unless you have separately enabled AI Site Actions and granted the relevant permission group. Writing a file to your site additionally requires you to approve each request from your TalkToWP dashboard; an assistant cannot approve its own.
What we store about the connection. When a client connects we record the authorisation grant and its access tokens, the client name, version and platform the connecting application reports, a per-session identifier, and the times it connected and last checked in. We use this only to show you which applications are connected and to let you disconnect them.
Revoking access. You can disconnect any application from the MCP page in your TalkToWP dashboard. Access stops within one minute. Disconnecting does not delete data the provider already received — request that from them directly.
9. International Data Transfers
Your data may be processed in countries other than India, including the United States and the European Union, by the sub-processors listed above. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required.
10. Data Security
We implement bank-level encryption in transit (TLS/SSL), encryption at rest, secure API key authentication, role-based access controls, and regular security reviews. In the event of a data breach, we will notify you and relevant authorities as required by applicable law.
11. Data Retention
- Incident logs and monitoring history: Retained while your account exists
- Account data: Retained until you explicitly request deletion
- Payment records: Retained as required by applicable tax regulations (typically 7 years)
To request deletion, contact [email protected].
12. Cookies and Tracking
We use essential cookies (required for login sessions), preference cookies (remember your settings), and analytics cookies (understand aggregate Service usage). You can control cookies through your browser settings.
13. Children's Privacy
Our Service is not directed to individuals under 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, please contact us immediately.
14. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated by updating the "Last updated" date and, where appropriate, by email notification.
15. Contact & Data Controller
Beyondt Consultancy & Services Pvt. Ltd.
Saltlake, Kolkata 700091, West Bengal, India
Email:
[email protected]
16. Grievance Officer
In accordance with the Information Technology Act, 2000, our Grievance Officer can be contacted at the address above. We aim to acknowledge grievances within 24 hours and resolve them within 30 days.