Launch draft. Add the operator’s identity, verified contact, retention periods and applicable privacy-rights process before going live.
The application stores the customer name and email provided at registration, a salted password hash, session records, purchase entitlements, daily usage counts and support messages. Password hashes support account sign-in; the application does not need to retain the plaintext website password.
Customers enter their site URLs, dedicated usernames and Application Passwords in the authenticated dashboard. These credentials are stored in encrypted server state outside the public web root. OAuth state and commerce state are encrypted. The customer configuration must be protected outside the public web root using restricted access and appropriate encrypted storage or a secret manager.
Authenticated requests can return WordPress content or site metadata to the connected ChatGPT client. The WordPress user’s permissions and the requested REST endpoint determine the scope. Writing requires separate enablement and remains subject to native WordPress checks.
WordPress application passwords are not returned by the site-list tools. Information intentionally sent to ChatGPT or Stripe is also governed by those providers’ own policies and customer relationships.
The service sends the account email and order information needed to create Stripe-hosted Checkout. You enter payment details on Stripe’s payment interface. The application stores relevant payment-session references and entitlement status, not a card number.
The website uses an essential session cookie for account authentication. It is configured as Secure, HttpOnly and SameSite=Lax. This build does not add advertising pixels or third-party analytics scripts. The operator must update this page if additional tracking is introduced.
Support tickets are associated with the customer account and stored for operator review. Do not include passwords, tokens or payment credentials. The operator must define retention and deletion procedures for support, account, billing, usage and authorization records before a live launch.
To request account correction, access or deletion, use the operator’s published privacy contact. Some transaction records may need to be retained under applicable requirements; the operator must disclose the actual policy and process rather than assume one from this template.