Privacy Policy

Last updated September 2026. This describes exactly what WPGuard collects from a monitored WordPress site and from you as a workspace owner — written to match what the product actually does, not generic boilerplate.

Never collected
WordPress admin passwords
Site content or page data
Actually collected
Login/user/plugin security events
File hashes, not file contents

What we collect from a monitored site

Once you install the WPGuard agent on a site, it reports the following to our dashboard, on a 5-minute check-in cycle:

  • System information: WordPress, PHP, and MySQL versions; the site's URL; the agent's own version and a hash of its files.
  • Security events: login attempts (username, IP address, whether the user-agent matched a known bot pattern), user creation/deletion/role changes, plugin and theme activation/deactivation, core updates, and changes to a fixed list of security-relevant WordPress options.
  • Inventory: the list of installed plugins/themes/mu-plugins, their versions, and whether each is present on disk versus reported by WordPress itself.
  • File hashes: cryptographic hashes (not contents) of WordPress core, plugin, and theme files, compared against official checksums.

We never collect, request, or store your WordPress admin password or any other site credential. The agent's security model is built specifically so that no such credential is ever needed.

What we collect from you

To create and operate your WPGuard account: your name, email address, and (if you enable it) a two-factor authentication secret. If you subscribe, PayPal processes your payment details directly — we receive only a subscription ID and billing status, never your card or bank information.

How long we keep it

Events, heartbeats, and alerts are retained for 180 days by default, after which they're automatically cleaned up. Account information is kept for as long as your account is active, and removed on request after account deletion, subject to what we're legally required to retain for billing records.

Who can see your data

Only members of your workspace, according to their assigned role (owner, admin, viewer, or client). We do not sell or share monitoring data with third parties. Vulnerability-matching data is pulled from public feeds (such as the Wordfence Intelligence feed) — this is a one-way lookup against your site's software versions, not a transmission of your data to that provider.

Security of stored data

Sensitive fields — including your per-site signing keys and any configured notification channel credentials (Slack/Telegram tokens, etc.) — are encrypted at rest. See our Security page for the full technical model.

Your rights

You can export or delete your workspace's data, or disconnect a monitored site (which stops all further data collection from it immediately), at any time from the dashboard. Contact us via the Contact page for anything this doesn't cover.