GoPublish Claude Connector Privacy Policy
Effective August 14, 2026
This policy supplements the GoPublish Privacy Policy and describes the remote connector at api.gopublish.io.
Data we process
- Your verified Google email, used to load an existing GoPublish account or create a free one after policy acceptance.
- Your GoPublish account ID, plan/export allowance, and metadata for eligible connected WordPress sites.
- The WordPress username and revocable Application Password returned by your site after you approve the connection. The Application Password is encrypted at rest and is never exposed to Claude.
- The title, Markdown body, optional excerpt, slug, selected site ID, and idempotency key you intentionally send through the draft tool.
- Operational security data that infrastructure providers may process, such as IP address, user agent, request time, and error telemetry.
How data is used and stored
Submitted article content is processed to render safe HTML and is sent only to the WordPress site you select. GoPublish does not place the article body in connector operation records or export audit history. The resulting draft is stored on your own WordPress server under its policies. Audit records contain operational metadata such as account, opaque site ID, post ID, draft status, request ID, edit URL, and time.
OAuth access, refresh, authorization-code, authorization-request, and WordPress-connection-attempt secrets are stored only as one-way SHA-256 hashes. A one-way content fingerprint is retained in the 90-day idempotency record so the same key cannot be reused for different content. WordPress Application Passwords and existing plugin keys are encrypted under GoPublish's connection system. Google ID tokens are verified during login and are not persisted by the connector.
Sharing and subprocessors
Data is shared only as needed with Google Identity Services for sign-in, your selected WordPress host to create the draft, and GoPublish infrastructure, security, and observability providers that operate the service. GoPublish does not sell connector data, use it for advertising, or use submitted content to train generalized AI models.
Retention
- Authorization requests: up to 30 minutes; authorization codes: up to 10 minutes.
- Incomplete WordPress connection attempts: up to 15 minutes.
- Access tokens: up to 1 hour.
- Refresh tokens and token-family security records: up to 30 days.
- Inactive dynamically registered OAuth clients: up to 365 days since last use.
- Encrypted WordPress credentials: until the site is disconnected, the account is deleted, or a valid deletion request is completed.
- Connector idempotency operation records and their one-way content fingerprints: up to 90 days.
- Export audit metadata: retained with the GoPublish account until account deletion or a valid deletion request.
Firestore TTL deletion is asynchronous, so expired records may remain briefly while no longer being accepted by the service.
Your choices
You can revoke the connector in Claude, revoke GoPublish for Claude under WordPress Profile → Application Passwords, disconnect a WordPress site in GoPublish, or request access/deletion of account data. Revocation prevents future token use; drafts already created on your WordPress site remain under your control.
Contact
For privacy or deletion requests, email advait@gopublish.io. See also the GoPublish Terms of Service.