← MAI WordPress

Privacy Policy

How MAI handles data

Data MAI processes

When you connect a WordPress site, MAI processes the site's URL, site name, Bridge and protocol versions, connection state, and the permission scopes you enable. When you use the plugin, MAI may process WordPress page and post content, Elementor element data, media metadata and images you explicitly ask to import, and WooCommerce catalog data needed for the requested task.

Authentication and security data

MAI uses OAuth 2.1 for supported AI clients. Authorization codes, access tokens, refresh tokens, and operation tickets are stored only as cryptographic hashes where persistence is required. Per-site Bridge secrets and supported rollback snapshots are encrypted at rest. MAI also records limited operational audit data needed to validate actions, diagnose failures, and support rollback.

How data is used

Data is used only to authenticate the connected account, identify the selected WordPress site, carry out the user's requested read or write operation, enforce permissions and concurrency safeguards, validate results, maintain security, and provide support. MAI does not sell personal data or use connected WordPress content for advertising or behavioral profiling.

Data MAI does not intentionally request

The public MAI plugin does not require hosting passwords, database passwords, SSH credentials, WordPress administrator passwords, payment card data, or a user's full ChatGPT conversation history. Users should not provide these items in tool inputs or support requests.

Third-party services

The MAI control plane is hosted on Vercel and stores control-plane data in Neon Postgres. The connected WordPress site remains on the site owner's existing hosting provider. When a user explicitly imports an image from a public HTTPS URL, the connected WordPress site contacts that source to download the image.

Retention and control

Connection, permission, audit, and security records are retained only as needed to operate and secure the service. Site owners can disconnect the Bridge and revoke local capabilities. OAuth access can be revoked by disconnecting the MAI integration in the client. Retention may also be subject to legal or security requirements.

Questions

For privacy or security questions, use the publisher support channel listed on the support page or in the plugin directory listing.