GoPublish WordPress Connector Privacy Policy
Effective August 15, 2026
This policy supplements the GoPublish Privacy Policy and describes the remote connector at mcp.gopublish.io.
Data we process
- Your verified email, used to load an existing GoPublish account or create a free one after policy acceptance.
- Your GoPublish account ID, plan/export allowance, and metadata for eligible connected WordPress sites.
- The WordPress username and revocable Application Password returned by your site after you approve the connection. The Application Password is encrypted at rest and is never exposed to the MCP client.
- The title, Markdown body, excerpt, slug, meta title, meta description, status, schedule, editor type, taxonomy and media IDs, selected site ID, and idempotency key you intentionally submit.
- Public image URLs or inline image bytes processed in transit when you approve a media upload or optional optimization.
- Operational security data that infrastructure providers may process, such as IP address, user agent, request time, and error telemetry.
- After you sign in, authenticated connector and WordPress connection pages may use PostHog session replay to help diagnose usability problems. Input values are masked, displayed account and site details are masked, and URL query strings are removed before capture. Public and pre-login pages are not recorded.
- The authorization pages load Crisp for support chat. After authentication, GoPublish gives Crisp your verified email so support conversations can be associated with your account. Crisp may also process technical connection data and information you choose to send in a support conversation.
How data is used and stored
Submitted article content and supported SEO metadata are sent only to the WordPress site you select. Article Markdown is rendered as safe Classic HTML or Gutenberg blocks. Approved public images are downloaded with private-network and size protections, while approved inline images are decoded and validated in memory; when you request optimization, eligible image bytes are compressed before being sent to that site's Media Library. GoPublish does not place article bodies, SEO values, or image bytes in connector operation records, signed export plans, or export audit history. Resulting content and media are stored on your WordPress server under its policies. Audit records contain operational metadata such as account, opaque site ID, content/media ID, type, status, editor type, request ID, edit URL, and time.
OAuth access, refresh, authorization-code, authorization-request, email-code, and WordPress-connection-attempt secrets are stored only as one-way hashes. Email codes expire after ten minutes and are single-use. A prepared export plan is a signed, short-lived token bound to the user and exact normalized export; it expires after 15 minutes and is not stored server-side. A separate one-way content fingerprint is retained in the 90-day idempotency record so the same key cannot be reused for different content. WordPress Application Passwords and existing plugin keys are encrypted under GoPublish's connection system. Google ID tokens are verified during login and are not persisted by the connector.
Sharing and subprocessors
Data is shared only as needed with Google Identity Services or ZeptoMail for sign-in, PostHog for authenticated-page product analytics and session replay (including a pseudonymous account identifier and verified email), Crisp for authenticated support chat (including your verified email), the public image host you select when using a URL, your selected WordPress host, GoPublish's configured TinyPNG or Imagify provider when you request image optimization, and GoPublish infrastructure, security, and observability providers that operate the service. GoPublish does not sell connector data, use it for advertising, or use submitted content to train generalized AI models.
Retention
- Authorization requests: up to 30 minutes; authorization and email codes: up to 10 minutes.
- Incomplete WordPress connection attempts: up to 15 minutes. Signed export plans expire after 15 minutes and are not stored server-side.
- Access tokens: up to 1 hour.
- Refresh tokens and token-family security records: up to 30 days.
- Inactive dynamically registered OAuth clients: up to 365 days since last use.
- Encrypted WordPress credentials: until the site is disconnected, the account is deleted, or a valid deletion request is completed.
- Connector idempotency operation records and their one-way content fingerprints: up to 90 days.
- Export audit metadata: retained with the GoPublish account until account deletion or a valid deletion request.
Firestore TTL deletion is asynchronous, so expired records may remain briefly while no longer being accepted by the service.
Your choices
You can revoke the connector in your MCP client, revoke GoPublish under WordPress Profile → Application Passwords, disconnect a WordPress site in GoPublish, or request access/deletion of account data. Revocation prevents future token use; content and media already created on your WordPress site remain under your control.
Contact
For privacy or deletion requests, email advait@gopublish.io. See also the GoPublish Terms of Service.