Last updated September 2026. This describes exactly what WPGuard collects from a monitored WordPress site and from you as a workspace owner — written to match what the product actually does, not generic boilerplate.
Once you install the WPGuard agent on a site, it reports the following to our dashboard, on a 5-minute check-in cycle:
We never collect, request, or store your WordPress admin password or any other site credential. The agent's security model is built specifically so that no such credential is ever needed.
To create and operate your WPGuard account: your name, email address, and (if you enable it) a two-factor authentication secret. If you subscribe, PayPal processes your payment details directly — we receive only a subscription ID and billing status, never your card or bank information.
Events, heartbeats, and alerts are retained for 180 days by default, after which they're automatically cleaned up. Account information is kept for as long as your account is active, and removed on request after account deletion, subject to what we're legally required to retain for billing records.
Only members of your workspace, according to their assigned role (owner, admin, viewer, or client). We do not sell or share monitoring data with third parties. Vulnerability-matching data is pulled from public feeds (such as the Wordfence Intelligence feed) — this is a one-way lookup against your site's software versions, not a transmission of your data to that provider.
Sensitive fields — including your per-site signing keys and any configured notification channel credentials (Slack/Telegram tokens, etc.) — are encrypted at rest. See our Security page for the full technical model.
You can export or delete your workspace's data, or disconnect a monitored site (which stops all further data collection from it immediately), at any time from the dashboard. Contact us via the Contact page for anything this doesn't cover.