Privacy Policy
What data we collect, what stays on your own server, and what we never see. Atlas MCP is built so that your content and your AI keys remain yours.
Last updated: 17 September 2026
This policy explains how AtlasAiDev (“we”, “us”) handles personal data in connection with the wpatlasmcp.com website, the Atlas MCP plugin, and any Pro licence you purchase.
Atlas MCP is unusual among AI plugins in one important respect: it is self-hosted. The plugin runs on your own WordPress server, and the vast majority of the data it touches never reaches us at all. This policy is careful to distinguish between the three.
1. Who we are
AtlasAiDev is the developer of Atlas MCP and the data controller for the personal data described in this policy. Our contact details are at the end of the page.
2. The short version
We do not receive your website content, your posts, your media, your customer or order data, your WordPress user accounts, your AI provider API keys, your MCP access tokens, or your plugin activity log. All of that is stored in your own WordPress database on your own server.
We also do not receive the prompts you send to an AI model or the responses it returns. Those travel directly between your server and the AI provider you have configured.
What we do receive is limited to the things we genuinely need: your details when you buy a licence, your messages when you contact support, and ordinary web server information when you visit this website.
3. Data the plugin stores on your own site
The plugin stores the following in your own WordPress database. You control it, you can delete it, and we cannot see it.
| What | Where it lives |
|---|---|
| AI provider API keys | Your WordPress options table, on your server |
| OAuth clients, access tokens, and consent records | Your WordPress database |
| Activity log of AI tool calls, including the user and role each ran as | Your WordPress database |
| Workflows, prompts, and module settings | Your WordPress database |
| Generated content and generation history | Your WordPress database |
If you are a site owner using Atlas MCP, you are the controller of that data in respect of your own users and customers. Your obligations to them under data protection law are yours, not ours, and you should reflect the plugin’s behaviour in your own privacy notice where relevant.
Uninstalling the plugin removes its data from your site according to the uninstall behaviour described in the plugin documentation.
4. AI providers and your content
Atlas MCP connects to third-party AI providers — OpenAI, Google, and Anthropic — using API keys that you supply. When a request is made, the relevant content is sent from your server directly to that provider.
- We are not in that path. Nothing is proxied or routed through our systems.
- Each provider’s own privacy policy and data retention terms govern what happens to that content.
- You are billed directly by the provider and hold the account relationship with them.
If you enable WooCommerce abilities, order and customer data can be sent to your chosen AI provider as part of a request. Check that provider’s terms against your own obligations before exposing store data, and grant only the abilities you actually need.
Similarly, when you connect an MCP client such as Claude, ChatGPT, Cursor, or Gemini, the content exchanged in that session is handled under the terms of whoever operates that client.
5. Website visitors
When you visit wpatlasmcp.com, our web server records standard technical information in its logs, including your IP address, browser type, operating system, the pages you requested, referring page, and the date and time of the request. This is ordinary server operation, used to keep the site running, secure, and performant.
Cookies
We use cookies that are strictly necessary to operate the site, including those set by WordPress and by our caching layer. If we introduce analytics or marketing cookies in future, we will update this policy and request consent where the law requires it.
You can block or delete cookies in your browser settings, though some parts of the site may not work as intended if you do.
6. Purchases and licences
Pro licences are sold through Freemius, which acts as the merchant of record. When you buy a licence, Freemius collects and processes the data needed to complete the transaction, which typically includes your name, email address, billing details, country, and IP address.
We never see or store your full payment card number. Card data is handled by Freemius and its payment processors on PCI-compliant infrastructure.
What we receive from Freemius is limited to what we need to service your licence: your name, email address, licence key, plan, site activations, and purchase and renewal history.
If you opt in during plugin activation, the Freemius SDK may also share anonymised diagnostic and usage information with us, such as your WordPress and PHP versions and which features are in use. This is optional, you are asked before it happens, and declining does not affect how the plugin works.
7. Support requests
When you email us or post on the WordPress.org support forum, we process what you send us: your name and email address, the content of your message, and any screenshots, logs, or site details you include.
If you grant us temporary administrative access to your site to diagnose a problem, we will use it only for that purpose and only for as long as needed. We ask that you revoke the access once the issue is closed, and we recommend creating a temporary account rather than sharing your own credentials.
8. Why we process data, and on what basis
| Purpose | Lawful basis |
|---|---|
| Delivering licences, updates, and support you have paid for | Performance of a contract |
| Responding to enquiries and support requests | Legitimate interests, or performance of a contract |
| Keeping the website secure and operational | Legitimate interests |
| Meeting tax, accounting, and legal obligations | Legal obligation |
| Optional diagnostic data, and any marketing email | Consent, which you may withdraw at any time |
We do not sell or rent your personal data, and we do not use it for automated decision-making that produces legal effects.
9. Who we share data with
We share personal data only with service providers who help us run the business, and only to the extent needed:
- Freemius — payments, licensing, and invoicing.
- Our web host and email provider — hosting this site and handling correspondence.
- WordPress.org — where you use the free plugin or the public support forum, under the WordPress Foundation’s own privacy practices.
We may also disclose data where required by law, or to establish, exercise, or defend legal claims.
10. International transfers
We operate from Bangladesh, and our service providers operate in other countries including the United States and the European Union. Using our services means your data may be transferred to and processed in countries outside your own, under appropriate safeguards where the law requires them.
11. How long we keep data
- Purchase and licence records — for as long as the licence is active, and afterwards for as long as tax and accounting law requires.
- Support correspondence — typically up to three years, so we can pick up the thread on a recurring issue.
- Server logs — a short rolling period for security and troubleshooting.
- Temporary site access — used only for the duration of the ticket.
12. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to processing, to receive a portable copy, and to withdraw consent where processing relies on it.
To exercise any of these, email contact@atlasaidev.com. We will respond within one month. If you are in the EU or UK and are unhappy with our response, you may complain to your local data protection authority.
Note that data stored inside your own WordPress installation is under your control, not ours, so requests about that data should be handled by you directly.
13. Security
We use HTTPS across this website, limit access to customer records to those who need it, and rely on established providers for payments and licensing rather than handling card data ourselves.
No system is perfectly secure. Within the plugin itself, security depends substantially on your own configuration: grant the narrowest access that does the job, review connected MCP clients periodically, revoke what you no longer use, and keep the plugin updated.
14. Children
Our products and this website are intended for site owners and developers, and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this policy
We may update this policy as the product or our processors change. The current version is always the one published here, and the date at the top records when it last changed. Material changes will be highlighted on this page.
16. Contact
For any question about this policy or about the data we hold, get in touch.
Your site, your data, your keys
Atlas MCP runs on your own server. Install the free version and see exactly what it stores, before you pay for anything.