GoPublishBack to connector
Connector policy

GoPublish WordPress Connector Privacy Policy

Effective August 15, 2026

This policy supplements the GoPublish Privacy Policy and describes the remote connector at mcp.gopublish.io.

Data we process

How data is used and stored

Submitted article content and supported SEO metadata are sent only to the WordPress site you select. Article Markdown is rendered as safe Classic HTML or Gutenberg blocks. Approved public images are downloaded with private-network and size protections, while approved inline images are decoded and validated in memory; when you request optimization, eligible image bytes are compressed before being sent to that site's Media Library. GoPublish does not place article bodies, SEO values, or image bytes in connector operation records, signed export plans, or export audit history. Resulting content and media are stored on your WordPress server under its policies. Audit records contain operational metadata such as account, opaque site ID, content/media ID, type, status, editor type, request ID, edit URL, and time.

OAuth access, refresh, authorization-code, authorization-request, email-code, and WordPress-connection-attempt secrets are stored only as one-way hashes. Email codes expire after ten minutes and are single-use. A prepared export plan is a signed, short-lived token bound to the user and exact normalized export; it expires after 15 minutes and is not stored server-side. A separate one-way content fingerprint is retained in the 90-day idempotency record so the same key cannot be reused for different content. WordPress Application Passwords and existing plugin keys are encrypted under GoPublish's connection system. Google ID tokens are verified during login and are not persisted by the connector.

Sharing and subprocessors

Data is shared only as needed with Google Identity Services or ZeptoMail for sign-in, PostHog for authenticated-page product analytics and session replay (including a pseudonymous account identifier and verified email), Crisp for authenticated support chat (including your verified email), the public image host you select when using a URL, your selected WordPress host, GoPublish's configured TinyPNG or Imagify provider when you request image optimization, and GoPublish infrastructure, security, and observability providers that operate the service. GoPublish does not sell connector data, use it for advertising, or use submitted content to train generalized AI models.

Retention

Firestore TTL deletion is asynchronous, so expired records may remain briefly while no longer being accepted by the service.

Your choices

You can revoke the connector in your MCP client, revoke GoPublish under WordPress Profile → Application Passwords, disconnect a WordPress site in GoPublish, or request access/deletion of account data. Revocation prevents future token use; content and media already created on your WordPress site remain under your control.

Contact

For privacy or deletion requests, email advait@gopublish.io. See also the GoPublish Terms of Service.