Last updated: July 2026
This Privacy Policy explains what data wptaskify collects and how we use it. We aim to collect only what we need to run the Service.
1. Data we collect
- Account data: your email address and a securely hashed password.
- WordPress connection data: the site URL, username, and an Application Password - the Application Password is encrypted with AES-256 at rest.
- Shopify connection data: if you connect a Shopify store, we store your store domain and an Admin API access token (encrypted at rest) so the app can read and update your products, collections, pages, blog content, discounts and theme content for SEO. See the Shopify section below.
- Usage data: basic logs of actions taken (for your activity feed, billing, and abuse prevention).
- Payment data: handled by our payment provider, Razorpay. We do not store your full card details. For Indian customers we may store your GSTIN (only if you provide it) so we can issue a valid tax invoice.
2. How we use your data
To provide and secure the Service, connect your site to AI, process payments, send account emails (verification, password reset), and improve the product.
3. AI processing
When you use the AI, your instructions and relevant site content are sent to your chosen AI provider (Claude or ChatGPT) and, for images, to Google Gemini, to produce the requested result. Their handling of that data is governed by their own privacy policies.
4. Google Analytics & Search Console (optional connection)
If you choose to connect your Google account, wptaskify requests access to your Google Analytics and Google Search Console data using these scopes:
analytics.readonly- read-only access to your Google Analytics 4 reports (sessions, pageviews, top pages, traffic sources).webmasters- to read your Search Console data (search queries, clicks, impressions, positions, URL indexing status and canonicals via the URL Inspection API, and sitemap status) and, only when you or your AI assistant explicitly ask, to submit or resubmit a sitemap. This never forces or requests indexing of any page.
We use this access only to show you, and let your chosen AI assistant summarise, your own traffic, search performance and indexing status inside wptaskify. The only write action we ever perform is submitting/resubmitting a sitemap when you explicitly request it; we never otherwise write to, modify, or delete anything in your Google account, and we do not use this data for advertising. We store an encrypted Google refresh token so we can fetch this data on your behalf.
Limited Use: wptaskify's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect your Google account at any time from your dashboard, which removes our stored token; you can also revoke access at myaccount.google.com/permissions.
5. Shopify stores
If you install wptaskify from the Shopify App Store or connect a Shopify store, we request only the permissions needed for SEO and content work: read and write access to products, content (pages, blogs, articles), price rules (discounts) and themes, and read access to store locations. We use this to read and improve your store's SEO - product titles, descriptions, meta, schema, alt text, collections, blog content and theme SEO markup.
We do NOT request access to your orders or your customers. wptaskify does not read, store, or process order data or customer personal data from Shopify. The app focuses only on products, content and SEO.
We store your store domain and an encrypted Admin API access token so the app can perform the actions you request. If you uninstall the app, we stop using this access. You can request deletion of your stored data at any time by contacting us.
GDPR / data requests: we support Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact). Because we do not store customer personal data from Shopify, a customer data or redaction request is acknowledged and has no stored customer data to return or delete; a shop-redaction request removes your store's connection data from our systems.
6. Pinterest (optional connection)
If you choose to connect your Pinterest business account, wptaskify uses the Pinterest API only to help you market your own content on your own Pinterest account. You authorize the connection through Pinterest's OAuth, and we store an encrypted access/refresh token so we can act on your behalf when you ask us to.
With your Pinterest connection, and only on your request, the app can: read your boards, create boards, and publish pins (an image, title, description and a link back to your own website) to your account. We use this access solely to create and manage pins for your account.
We do not collect other people's Pinterest data, we do not read your followers or private messages, and we do not sell or share your Pinterest data. You can disconnect Pinterest at any time from your dashboard (which removes our stored token), and you can also revoke access from your Pinterest account settings. To request deletion of any stored Pinterest connection data, contact us.
7. Facebook and Instagram (optional connection)
If you choose to connect a Facebook Page or an Instagram professional account, wptaskify uses Meta's APIs only to help you publish and manage your own content on your own accounts. You authorize the connection through Meta's login, and we store an encrypted access token so we can act on your behalf when you ask us to.
From Meta we receive only what is needed to provide the service: the list of Pages or Instagram accounts you manage, an access token for the ones you select, and the posts, comments and basic statistics for content published through us. With your connection, and only on your request, the app can: show you your connected accounts, publish posts, photos, videos, Reels and Stories, show you the comments and performance figures for those posts, and reply to comments.
We do not sell, share or transfer this information to anyone else, we do not use it for advertising, and we do not use it to build audience profiles. Access tokens are encrypted at rest, and each customer can reach only the accounts they connected themselves. You can disconnect an account at any time from your dashboard, which removes our stored access to it, and you can also revoke access at facebook.com/settings. To request deletion of any stored Meta connection data, contact us.
8. Data sharing
We do not sell your data. We share data only with the service providers needed to run wptaskify (hosting, database, email, payments, AI) and when required by law. Data obtained from Google APIs, and data obtained from Meta (Facebook and Instagram), is not shared beyond providing that feature to you.
9. Security
Credentials are encrypted, accounts are isolated, and access is restricted. No system is perfectly secure, but we take reasonable measures to protect your data.
10. Your rights
You can access, correct, or delete your account data, and disconnect your sites, at any time. To request deletion, contact us.
11. Contact
Privacy questions? Reach us via the contact page.