Privacy Policy
This service processes information needed to authenticate users, link accounts to connected WordPress sites, issue and validate OAuth tokens, route AI tool requests, troubleshoot failures, and protect the relay from abuse. When operated for multiple sites, this server may act as a shared identity provider and may be a data controller or processor under applicable privacy laws.
Information processed
Depending on configuration, this may include account identifiers, user IDs, email addresses, connected site names and URLs, site keys, site secrets, OAuth client metadata, token metadata, scopes, consent records, IP addresses, request timestamps, user-agent data, email-code login events, and relay diagnostic metadata.
AI and relay activity
When you use shared GPT or MCP relay features, requests may be routed between the AI client, this relay server, and connected WordPress sites. Tool calls can expose site content or metadata according to the permissions granted by the connected site and authenticated user.
Cross-site account linking
Turnkey account linking can associate one user account with multiple client WordPress sites. This can reveal which sites are linked to the account, when authorizations occur, and which scopes or relay permissions were granted.
Logs and retention
The service may store operational logs for diagnostics, security, rate limiting, abuse prevention, authorization audits, token issuance, token validation, and relay activity. Administrators can configure log retention and whether expanded error details are stored.
Third-party services
AI clients, WordPress sites, hosting providers, email providers, external MySQL account databases, SMTP services, and browser-based OAuth flows may process data under their own terms and privacy policies. Review those policies before connecting accounts or production sites.
Your controls
Users and administrators can revoke OAuth tokens, disconnect linked sites, suspend access, and remove or rotate credentials. Contact the service operator for access, correction, export, deletion, retention, or data processing requests where applicable.

