This privacy policy defines the legal framework for the collection, use and processing of personal data of users (hereinafter "the User") of wp2ai.io, developed by webNdev (hereinafter "the Company"). It complies with the General Data Protection Regulation (GDPR) No. 2016/679.
Article 1 — Data collected
In the context of the newsletter subscription, the Company collects the following data:
- Email address
- Registration date
- Registration source (wp2ai website or app)
This data is necessary to send you communications related to wp2ai. No other data is collected without your explicit consent.
Article 2 — Product data (connected WordPress sites)
When you connect a WordPress site to wp2ai via our plugin, the Company processes the following data to provide the Service:
- Site identification: connector ID, site name, WordPress and plugin versions
- Content data: post ID, title, slug, excerpt, content (raw and plain text), status, post type, editor used, language, featured image and alt text, internal link status
- SEO metadata: title, description, and their source
- Integrity data: a SHA-256 hash of the content, a one-way cryptographic transformation from which the original content cannot be reconstructed, used solely to detect changes
- Action data: the result of AI-driven actions applied to your content, as well as connection and disconnection events
- Authentication data: a SHA-256 hash of your connector secret, never the secret in plain text; the Company itself never has access to its actual value
This data is processed solely to provide the Service's core features (content monitoring, AI-assisted actions, quality validation) and is never sold to third parties or used for advertising purposes.
Where this data includes personal data relating to your own visitors, authors or subscribers, the Company acts as a data processor on your behalf, under the conditions set out in Article 5 of the Terms of Service.
Article 3 — Purpose of processing and legal bases
Newsletter data (Article 1) is used, on the basis of your consent, exclusively to:
- Send you information about product progress
- Manage your newsletter subscription
Product data (Article 2) is used, on the basis of the performance of the contract between you and the Company, to provide the Service's features: monitoring your WordPress content, AI-assisted actions, quality control and change detection.
Your data is not used for advertising purposes and is never sold to third parties.
Article 4 — Retention period
Newsletter data is retained for as long as necessary for the purposes described above, and for a maximum of 3 years from the registration date. In the event of unsubscription, this data is deleted within 30 days.
Product data (Article 2) is retained for the duration of your subscription, and deleted immediately upon deletion of your account, subject to any data the Company may be required to retain under its legal obligations (accounting, tax or litigation-related).
Article 5 — Sub-processors and transfers outside the European Union
The Company uses Brevo (formerly Sendinblue) for email management; this provider hosts and processes data exclusively within the European Union (France, Germany, Belgium). The Service also relies on Supabase for database and backend functions, hosted on AWS infrastructure in the eu-west-3 region (Paris, France), as well as Paddle (Paddle.com Market Ltd) for payment processing, as our Merchant of Record. The site also uses Google Analytics (Google LLC) for audience measurement, described in Article 7.
Some of this data may therefore be transferred outside the European Union: to the United Kingdom (Paddle), on the basis of the European Commission's adequacy decision of 28 June 2021, renewed on 19 December 2025; to the United States (Google LLC), on the basis of the Data Privacy Framework adequacy decision of 10 July 2023. These transfers are therefore covered by an adequacy decision and do not require additional contractual safeguards under the GDPR.
Article 6 — User rights
In accordance with the GDPR, you have the following rights over your personal data:
- Right of access — obtain a copy of your data
- Right of rectification — correct inaccurate data
- Right to erasure — request deletion of your data
- Right to object — object to processing
- Right to data portability — receive your data in a structured format
The right of access and portability apply to data concerning your account and your use of the Service. They do not extend to the editorial content of your connected WordPress sites, which is not personal data concerning you and remains accessible directly from WordPress at any time; a light index of that content (titles, statuses, dates) is nonetheless included in any export.
Access to your data, its portability, and account deletion are available as self-service directly from your account, under Settings. For these rights as for the others, you can also contact us at: support@wp2ai.io. Any request will be processed within 30 days.
Article 7 — Cookies and analytics
wp2ai.io uses Google Analytics (Google LLC) to measure audience and improve user experience. This service places cookies that collect pseudonymised data about your browsing (pages visited, session duration, approximate geographic origin), retained for a maximum period of 13 months.
These cookies are only placed after your consent, expressed via the cookie banner displayed on your first visit. You can withdraw your consent at any time by clicking "Cookie settings" in the footer.
No advertising or cross-site tracking cookies are used. To learn more about how Google processes this data, see Google's privacy policy.
Article 8 — Contact and complaints
For any questions regarding data protection: support@wp2ai.io
You may also lodge a complaint with your local data protection authority.
Last updated
This privacy policy was last updated on 7 September 2026.