Skip to document
wptr
PrivacyTermsData deletion

Legal

Privacy Policy

This policy explains how WPTR processes information when you use our website, account, AI features, and connected-service functionality. It is written for the service as it operates today.

Last updated: August 23, 2026

On this page

  1. Operator and scope
  2. Information we process
  3. Connected services
  4. Meta Platform Data
  5. Google API User Data
  6. AI processing
  7. Sharing and processors
  8. Retention and security
  9. Rights and contact

Operator and scope

WPTR is operated by CREAUP LLC, Wyoming, United States. CREAUP LLC is the operator of WPTR and, where applicable, the data controller for personal information processed through the service. You can contact us at hello@wptr.com.

This policy applies to wptr.com, WPTR accounts, the WPTR API and application features, AI/chat functionality, and the third-party services you choose to connect to WPTR.

Information we process

Account and service information

When you create and use an account, WPTR processes your email address, password hash, optional display name, account and plan state, session information, credit and usage records, billing customer and subscription status records where applicable, and timestamps associated with your account activity. Stripe processes payment-card and transaction information through its hosted payment pages; WPTR does not receive or store full payment-card numbers.

Workspace, chat, and uploaded content

WPTR stores the Businesses and Websites you configure, including Website names, hostnames, canonical URLs, ownership/verification state, and connection metadata. Authenticated conversations and their messages are stored so they can be reopened in your workspace. Files, images, code, and other attachments you upload are stored privately with their file metadata and association to your workspace or chat.

Some transient guest-session information may be used to operate a guest experience where that experience is enabled. Guest chat content is not retroactively added to an account merely because a visitor later registers.

Technical and security information

We and our infrastructure may process technical information needed to operate and protect the service, such as request timestamps, IP or network information made available by the request or hosting environment, browser/device information, session identifiers, error and security events, and usage diagnostics. We use this information for authentication, reliability, abuse prevention, debugging, and service operation.

Connected services

You may explicitly connect third-party services to a Website in your WPTR workspace. Current integrations include WordPress/WooCommerce, Google Analytics, Google Search Console, Google Ads, Meta Ads, and GitHub where configured. The exact connection, property, repository, customer, or ad account remains under your control; WPTR does not use one Website's connection as a fallback for another Website.

We use connected-service information to provide the feature you ask for, such as read-only reporting, Website verification, bounded diagnostics, or a user-requested AI answer. Connection credentials are handled server-side. Disconnect controls may stop future use of a connection, but their exact effect differs by service; see Data Deletion Instructions for the available paths and deletion requests.

Meta Platform Data

Meta Ads access is read-only

WPTR uses Facebook Login for Business / Meta OAuth only to connect Meta Ads. It is not WPTR's primary account-login method. The current integration uses the ads_read permission and does not create, edit, pause, delete, or otherwise modify ads, campaigns, ad sets, budgets, targeting, or Meta account settings.

If you choose to connect Meta Ads, WPTR may process Meta identifiers needed for the OAuth flow; encrypted access credentials; selected ad account ID, name, currency, timezone, and status; and the bounded reporting data the integration reads. That reporting data can include campaign, ad set, and ad IDs/names; spend, impressions, reach, frequency, clicks, CTR, CPC, CPM; Meta-reported actions and action values; and placement/device performance dimensions when requested.

We use Meta Platform Data to authenticate and authorize the connection, let you select an authorized ad account, provide read-only reports, and answer your requested AI questions about that data. Access is scoped to the authenticated WPTR user, the selected Website, and its selected Meta advertising account. WPTR does not sell Meta Platform Data.

The current implementation keeps Meta Ads requests server-side, stores the connection per Website, and encrypts the stored OAuth credential. It also uses Meta's app-secret proof mechanism for server-side Graph requests. We do not expose those credentials to the browser.

Google API User Data

Google Analytics and Google Search Console use user-authorized, read-only access. WPTR's current Google Ads product features use user-authorized access solely for read-only reporting in WPTR; they do not make advertising changes. Depending on the service you connect, WPTR may process selected Google account, property, stream, site, or customer metadata and the reporting data needed for the requested feature. Google Analytics reporting can include analytics and measurement data; Search Console reporting can include site and search-performance data; and Google Ads reporting can include customer, campaign, and performance data.

We use this data only to operate the relevant connection, let you make a selection, show requested read-only reports, verify connection health, and support user-requested WPTR analysis. Google credentials are processed server-side. Google Analytics and Search Console support credential revocation on applicable disconnect paths; other disconnects stop WPTR's local use of the connection as implemented. You may also request deletion through our Data Deletion Instructions.

Google API Services User Data Policy

WPTR's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

AI processing

WPTR uses a configured AI provider to answer questions and analyze information you provide or explicitly connect. Information necessary to answer a request, including relevant chat text, permitted attachment context, or minimized connected-service results, may be transmitted to that provider for processing. WPTR configures its current OpenAI requests with provider-side storage disabled.

AI output can be inaccurate, incomplete, or unsuitable for a particular situation. You should review material recommendations before relying on them for technical, advertising, financial, legal, tax, or other business decisions.

Sharing and service providers

We share information only as needed to provide and secure WPTR, to comply with law, or in connection with a lawful business transaction. Current implementation and deployment documentation identify the following infrastructure and processing-provider roles:

  • Railway for API, PostgreSQL, and private object-storage infrastructure;
  • Vercel for web application hosting and delivery;
  • OpenAI for configured AI processing.
  • Stripe for hosted checkout, subscription billing, payment processing, and customer billing management.

Separately, WPTR communicates with the platforms you choose to connect, such as Google, Meta, WordPress/WooCommerce, or GitHub, to provide their respective user-authorized integration functions. Those platforms are independent services governed by their own terms and privacy policies; they are not described here as WPTR processors merely because you choose to connect them.

WPTR does not sell personal information or connected-platform data. We may disclose information to professional advisers, authorities, or other parties when required by law or necessary to protect rights, safety, and security. If WPTR is involved in a merger, acquisition, or asset transfer, information may be transferred as part of that transaction, subject to applicable law.

Retention and security

We retain information for as long as reasonably necessary to provide WPTR, maintain the requested connection, meet legal, accounting, security, and dispute-resolution obligations, and enforce our terms. WPTR stops using a credential for a locally disconnected connection. Whether a credential is locally cleared or provider access is revoked differs by integration; see Data Deletion Instructions for the current behavior. Records may remain in backups for their normal lifecycle.

We use reasonable technical and organizational measures designed to protect information. Current safeguards include server-side credential handling, encrypted OAuth credentials for supported Google and Meta connections, private object storage, owner-scoped access checks, opaque HttpOnly session cookies, and password hashing. No method of storage or transmission is completely secure, and we do not claim a specific security certification.

Your rights, international transfers, and contact

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where applicable. You can also revoke a connected-service authorization through the service's disconnect controls or the provider's own settings. To make a request, email hello@wptr.com. We may ask for reasonable information to verify the request.

CREAUP LLC is based in the United States, and our providers may process information in countries other than yours. Those countries may have different data-protection laws. We do not represent that a particular transfer framework applies in every case.

WPTR is a professional service and is not intended for children under 18. We do not knowingly seek to collect personal information from children under 18. For deletion details, visit Data Deletion Instructions.

WPTR is operated by CREAUP LLC, Wyoming, United States. Questions: hello@wptr.com

Terms of ServicePrivacy PolicyCookie PolicyData Deletion