This Privacy Policy explains how Developer Sentinel ("we", "us") collects, uses, and shares information when you use our website and service (the "Service"). We act as a data controller for account data and as a data processor for the WordPress site data you connect.
1. Data we collect
- Account data: email, name, hashed password or OAuth identifiers, workspace settings.
- Site connection data: URL, API keys/tokens you provide, plugin version, environment metadata.
- Operational data: incidents, diagnostics, logs, audit trail, and AI-generated reports.
- Billing data: processed by our payment provider (Stripe); we store customer/subscription IDs only.
- Technical data: IP address, user-agent, timestamps, and cookies strictly necessary for auth.
2. How we use it
- To provide, secure, and improve the Service.
- To detect, diagnose, and (with your approval) fix incidents on your connected sites.
- To send transactional emails (security alerts, billing receipts, incident reports).
- To comply with legal obligations and prevent abuse.
3. Legal bases (GDPR)
- Contract — to deliver the Service you signed up for.
- Legitimate interest — security, fraud prevention, product analytics.
- Consent — non-essential cookies and marketing emails.
- Legal obligation — accounting and tax records.
4. Sharing
We share data only with sub-processors needed to run the Service:
- Cloud hosting and database providers
- AI model providers (for diagnostics; prompts/logs may include site metadata you connect)
- Stripe (billing)
- Email delivery providers
We never sell personal data.
5. Retention
Account data is kept while your account is active and up to 90 days after deletion. Incident logs and audit records are retained for up to 12 months. Billing records are kept for the period required by tax law (typically 7 years).
6. Your rights
Under GDPR/UK-GDPR you can access, rectify, delete, restrict, or port your data, and object to processing. See our GDPR notice for how to exercise these rights.
7. Security
We use TLS in transit, encrypted storage at rest, scoped API tokens, RLS in our database, and audit logging. No system is 100% secure; report issues to security@wpsentinel.dev.
8. Contact
Privacy questions: privacy@wpsentinel.dev.