LEGAL
Privacy Policy
Effective date: September 5, 2026
PostToWP helps you create and send WordPress post drafts using the AI providers and WordPress website you choose. This policy explains what information the service handles and why.
Information you provide
When you create an account, Supabase processes your sign-in information, such as your email address or Google account identity. In Account Settings, you may provide API keys, a WordPress site URL, WordPress username, and a WordPress Application Password. You may also provide topics, research notes, images, SEO details, and article content.
How PostToWP uses information
PostToWP uses your connection details only to perform requested actions: generating content through the selected AI provider, accessing your selected WordPress site, and creating or publishing the post you approve. Your API keys and WordPress Application Password are encrypted before storage. Generated drafts and uploaded images are used to complete the current request.
Third-party services
PostToWP relies on Supabase for authentication and settings storage. When you generate a draft, the selected provider—such as OpenAI or OpenRouter—receives the prompt and relevant research material needed for that request. When you send a post, WordPress receives the post content and media. Those services have their own privacy practices.
Data retention and choices
Your saved connection information remains in your account until you replace it or delete your account in Account Settings. Deleting your account permanently removes your saved connection information and PostToWP sign-in account. Your sign-in session is retained in your browser’s local storage so you can return without signing in again. It remains there until you sign out, clear this site’s browser data, or the session expires. If you need help with deletion, email support@posttowp.com from the address associated with your account.
Security
We use reasonable administrative and technical measures to protect information, including encryption for saved credentials. No internet service can guarantee absolute security, so keep your API keys and WordPress credentials private and use a dedicated WordPress user with only the access it needs.
Changes and contact
We may update this policy as PostToWP evolves. The effective date above will be updated when material changes are made. Questions can be sent to support@posttowp.com.