Privacy policy
DPPress is built so that most of your data never leaves your own server. This page says exactly what does, and what happens to it.
Last updated July 20, 2026
What this policy covers
This policy covers dppress.io: the website, the account area, the licence service and the AI service that the DPPress plugin can call.
It does not cover the passports themselves. The free DPPress plugin creates, stores and serves them entirely from your own WordPress site. We never receive them and we cannot read them.
The data controller is the publisher named in the legal notice.
What we store, and why
- Your email address
- To create your account and sign you in. Signing in uses a one-time code sent to that address, so there is no password to store.
- Your name and profile picture
- Only if you choose to sign in with Google, which passes them to us. Sign in by email and we never receive them.
- Your site's domain
- Stored as the bare host name, for example example.com. Used to activate your licence on that site and to meter AI usage. We never store full addresses, paths or page URLs.
- Your subscription
- Your Stripe customer and subscription identifiers, your plan, its status and the end of the current period, so your account can show what you have and the plugin can unlock it.
- AI usage counters
- For each AI request: which operation, which model, how many tokens went in and out, and how many credits it cost. Never the product text itself.
- Credit purchases
- The amount, the currency and the Stripe checkout identifier, so a top-up is credited once and only once.
What we never store
- No password. Signing in uses a one-time code, or Google.
- No card number, and no part of one. Payment happens on Stripe's own pages, which we never see.
- No billing address and no VAT number on our side. Stripe collects them to work out the tax and keeps them; when you open your billing page we read your invoices from Stripe live and store nothing locally.
- No IP address and no browser user agent in our application. Our hosting and authentication providers keep their own technical logs, as any host does.
- No analytics, no advertising tag, no tracking pixel, no third-party script. Even the fonts are served from our own domain rather than from Google Fonts.
- No product catalogue, no order, and nothing at all about your own customers.
- No prompt and no AI answer. What the AI reads is not written down anywhere on our side.
The AI feature, specifically
The free plugin makes no network request at all until you click an AI button. If you never use the AI, your site never contacts us.
When you do click, the plugin sends that one product's text (its title, its descriptions, its categories and its attribute values) to our service, together with your site's domain so the free sample and your Pro credits can be counted.
Our service passes that text to Anthropic's Claude API, which produces the suggestions and returns them. Anthropic receives the product text only: not your domain, not your licence key, not your account. The text is not used to train models.
Neither the text sent nor the suggestions returned are stored by us. All we write down are the counters described above.
Who processes data on our behalf
- Supabase
- Database and authentication. Holds your account, subscription, licence and usage counters, on AWS in Frankfurt (eu-central-1).
- Vercel
- Hosting for the website and the account area.
- Resend
- Delivers the sign-in email. Receives your address and the one-time code, nothing else.
- Stripe
- Payments and invoicing. Collects and keeps your billing details. We never see your card.
- Anthropic
- Produces the AI suggestions. Receives only the product text, as described above.
- Only if you choose to sign in with Google.
Cookies
There is no cookie banner because there is nothing to consent to. The only cookies we set are the ones that keep you signed in, plus one that remembers your language.
They are strictly necessary to provide a service you asked for, and they are used for nothing else. No cookie on this site measures an audience or follows you anywhere.
Where your data is held
The database and the authentication service run on AWS in Frankfurt, Germany (eu-central-1), inside the European Union.
Several of these providers are companies established in the United States. Where data reaches them, the transfer relies on the European Commission's standard contractual clauses, which each of them publishes as part of its data processing agreement.
How long we keep it
Your account, subscription, licence and usage counters are kept for as long as your account exists. We do not run an automatic purge, and we would rather say so than promise a delay we do not enforce.
Ask us to delete your account and we delete it, together with everything attached to it. Invoices are the exception: Stripe keeps them for the accounting period the law requires.
The counters for the free AI sample are kept against a site's domain, with no account attached, so that the same site cannot claim the free sample twice.
Your rights
You can ask for a copy of your data, have it corrected, have it deleted, object to its processing, or ask for it in a portable form. Write to the address below and we will answer within one month.
If you believe your data has been mishandled, you can complain to the CNIL, the French data protection authority, at cnil.fr.
Changes to this policy
If this policy changes in a way that matters, the date at the top changes with it. The plugin's page on wordpress.org links here, so the version you are reading is always the current one.
Contact
For anything on this page, including a request about your own data, write to contact@dppress.io