Legal
Privacy Policy
This policy explains how WPTR processes information when you use our website, account, AI features, and connected-service functionality. It is written for the service as it operates today.
Operator and scope
WPTR is operated by CREAUP LLC, Wyoming, United States. CREAUP LLC is the operator of WPTR and, where applicable, the data controller for personal information processed through the service. You can contact us at hello@wptr.com.
This policy applies to wptr.com, WPTR accounts, the WPTR API and application features, AI/chat functionality, and the third-party services you choose to connect to WPTR.
Information we process
Account and service information
When you create and use an account, WPTR processes your email address, password hash, optional display name, account and plan state, session information, credit and usage records, billing customer and subscription status records where applicable, and timestamps associated with your account activity. Stripe processes payment-card and transaction information through its hosted payment pages; WPTR does not receive or store full payment-card numbers.
Workspace, chat, and uploaded content
WPTR stores the Businesses and Websites you configure, including Website names, hostnames, canonical URLs, ownership/verification state, and connection metadata. Authenticated conversations and their messages are stored so they can be reopened in your workspace. Files, images, code, and other attachments you upload are stored privately with their file metadata and association to your workspace or chat.
Some transient guest-session information may be used to operate a guest experience where that experience is enabled. Guest chat content is not retroactively added to an account merely because a visitor later registers.
Technical and security information
We and our infrastructure may process technical information needed to operate and protect the service, such as request timestamps, IP or network information made available by the request or hosting environment, browser/device information, session identifiers, error and security events, and usage diagnostics. We use this information for authentication, reliability, abuse prevention, debugging, and service operation.
Connected services
You may explicitly connect third-party services to a Website in your WPTR workspace. Current integrations include WordPress/WooCommerce, Google Analytics, Google Search Console, Google Ads, Meta Ads, and GitHub where configured. The exact connection, property, repository, customer, or ad account remains under your control; WPTR does not use one Website's connection as a fallback for another Website.
We use connected-service information to provide the feature you ask for, such as read-only reporting, Website verification, bounded diagnostics, or a user-requested AI answer. Connection credentials are handled server-side. Disconnect controls may stop future use of a connection, but their exact effect differs by service; see Data Deletion Instructions for the available paths and deletion requests.
Meta Platform Data
If you choose to connect Meta Ads, WPTR may process Meta identifiers needed for the OAuth flow; encrypted access credentials; selected ad account ID, name, currency, timezone, and status; and the bounded reporting data the integration reads. That reporting data can include campaign, ad set, and ad IDs/names; spend, impressions, reach, frequency, clicks, CTR, CPC, CPM; Meta-reported actions and action values; and placement/device performance dimensions when requested.
We use Meta Platform Data to authenticate and authorize the connection, let you select an authorized ad account, provide read-only reports, and answer your requested AI questions about that data. Access is scoped to the authenticated WPTR user, the selected Website, and its selected Meta advertising account. WPTR does not sell Meta Platform Data.
The current implementation keeps Meta Ads requests server-side, stores the connection per Website, and encrypts the stored OAuth credential. It also uses Meta's app-secret proof mechanism for server-side Graph requests. We do not expose those credentials to the browser.
Google API User Data
Google Analytics and Google Search Console use user-authorized, read-only access. WPTR's current Google Ads product features use user-authorized access solely for read-only reporting in WPTR; they do not make advertising changes. Depending on the service you connect, WPTR may process selected Google account, property, stream, site, or customer metadata and the reporting data needed for the requested feature. Google Analytics reporting can include analytics and measurement data; Search Console reporting can include site and search-performance data; and Google Ads reporting can include customer, campaign, and performance data.
We use this data only to operate the relevant connection, let you make a selection, show requested read-only reports, verify connection health, and support user-requested WPTR analysis. Google credentials are processed server-side. Google Analytics and Search Console support credential revocation on applicable disconnect paths; other disconnects stop WPTR's local use of the connection as implemented. You may also request deletion through our Data Deletion Instructions.
AI processing
WPTR uses a configured AI provider to answer questions and analyze information you provide or explicitly connect. Information necessary to answer a request, including relevant chat text, permitted attachment context, or minimized connected-service results, may be transmitted to that provider for processing. WPTR configures its current OpenAI requests with provider-side storage disabled.
AI output can be inaccurate, incomplete, or unsuitable for a particular situation. You should review material recommendations before relying on them for technical, advertising, financial, legal, tax, or other business decisions.
Retention and security
We retain information for as long as reasonably necessary to provide WPTR, maintain the requested connection, meet legal, accounting, security, and dispute-resolution obligations, and enforce our terms. WPTR stops using a credential for a locally disconnected connection. Whether a credential is locally cleared or provider access is revoked differs by integration; see Data Deletion Instructions for the current behavior. Records may remain in backups for their normal lifecycle.
We use reasonable technical and organizational measures designed to protect information. Current safeguards include server-side credential handling, encrypted OAuth credentials for supported Google and Meta connections, private object storage, owner-scoped access checks, opaque HttpOnly session cookies, and password hashing. No method of storage or transmission is completely secure, and we do not claim a specific security certification.
Your rights, international transfers, and contact
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where applicable. You can also revoke a connected-service authorization through the service's disconnect controls or the provider's own settings. To make a request, email hello@wptr.com. We may ask for reasonable information to verify the request.
CREAUP LLC is based in the United States, and our providers may process information in countries other than yours. Those countries may have different data-protection laws. We do not represent that a particular transfer framework applies in every case.
WPTR is a professional service and is not intended for children under 18. We do not knowingly seek to collect personal information from children under 18. For deletion details, visit Data Deletion Instructions.