Privacy
Short version: an e-mail address so you can sign in, a name so we can address you, and counts of what the plugin has translated. No trackers, no advertising, no profiling, and none of your content.
Last updated 4 September 2026
Who is responsible
Brandforward, trading as WPGlotty (Hoofdveste 10, 3992 DG Houten, the Netherlands), is the controller for the personal data described here. You can reach us at [email protected].
This page covers the website at wpglotty.com and the licence server the WPGlotty plugin talks to. It does not cover your own WordPress website, where you are the controller, or your AI provider, with whom you have your own relationship.
What we collect, and why
| What | Why | On what basis |
|---|---|---|
| E-mail address | Signing in, and telling you about the plugin you use | Performing our agreement with you |
| First and last name | Addressing you as a person rather than an address | Performing our agreement with you |
| IP address of a sign-in attempt | Rate limiting, so nobody can use the form to send mail at strangers | Our legitimate interest in a service that is not abused |
| Licence key, and the domain it is activated on | Deciding whether a site may translate | Performing our agreement with you |
| Counts reported by the plugin | Showing you what your sites have done, and telling us whether the product works | Our legitimate interest in knowing whether it is used |
The counts are strings found, strings translated, words sent, dollars spent, which provider and model did the work, and the plugin and WordPress versions. Nothing about a visitor to your site, and nothing about a person.
What we never receive
- Your content, your source text, or any translation of it
- URLs beyond the domain the licence is already activated on
- Your WordPress users, your customers, or anybody who visits your site
- Your API keys for Claude, DeepL or OpenAI, unless you ask us to keep them (see below)
Translation happens between your server and the provider you chose, on your own key. It does not pass through us, and we could not read it if we wanted to.
Provider keys, if you ask us to keep them
There is an optional store on your licence page for your Claude, DeepL or OpenAI key, so that several sites can collect one key instead of you pasting it into each. It is off unless you use it, and nothing about the plugin needs it.
If you do use it: the key is strongly encrypted before it is stored. It is tied to your account, so a stored key cannot be moved to somebody else's, and it is never shown again to anybody, including us. Your page shows the provider, the last four characters and the date.
Collecting it takes two things: a site on one of your licences, and a code you get from your account page that lasts fifteen minutes. Every collection and every refusal is listed there and e-mailed to you. Delete the key and it is gone from our side immediately; sites that already collected it keep their own copy, which they store encrypted in WordPress.
Cookies
Two are strictly necessary and neither is used to follow anybody: a session cookie that keeps you signed in, and a cookie holding the single fact that somebody is signed in, so that a page built in advance can offer a dashboard link instead of a sign-up button. Those are set whether you agree or not, because without them you cannot sign in.
Beyond those we use Google Tag Manager for two things, and neither happens until you say so. Statistics tell us which pages get read and where people give up. Advertising tells us whether an advert we paid for led anybody here.
Both start switched off. We use Google's consent mode, so the tag is present but measures nothing until you choose, and if you choose only what is necessary, it stays that way. You can change your mind at any time through , and your choice is remembered in your own browser rather than on our servers.
Who else sees it
These are the only parties that process personal data on our behalf.
| Who | For what | Where |
|---|---|---|
| Supabase | Accounts, licences and usage counts | Ireland (EU) |
| Cloudflare | Serving the site, blocking abuse, and storing the plugin download | EU and United States, under the EU standard contractual clauses |
| Elastic Email | Sending the sign-in link and account e-mail | EU and United States, under the EU standard contractual clauses |
We do not sell personal data, and we do not share it with anybody for their own purposes.
How long we keep it
- An account that was created but never confirmed is deleted an hour later
- An account you delete is gone immediately, along with its licences and its statistics
- Statistics for a site are deleted when that site is released from a licence
- Sign-in attempt records, which hold an address and an IP, are kept briefly for rate limiting
- Anything we are required to keep for tax or accounting is kept for as long as that requires
What you can ask for
You may ask us for a copy of your data, to correct it, to delete it, to restrict what we do with it, to hand it over in a portable form, and to object to processing we base on a legitimate interest. You can delete your own account from your account page without asking anybody.
Write to [email protected] and you will hear back within a month. If you think we have it wrong, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Security
Passwords do not exist here, because signing in is a link sent to your address, so there is no password of yours for us to lose. Administrative access requires a second factor. Data is encrypted in transit and at rest by our hosting providers.
If we ever suffer a breach that puts your rights at risk, we will tell you and the authority, as the law requires.
Changes
When this document changes in a way that matters, the date at the top changes and we e-mail account holders. Older versions are in the site's public repository history.