LEGAL

Privacy Policy

What data we collect, what stays on your own server, and what we never see. Atlas MCP is built so that your content and your AI keys remain yours.

Last updated: 17 September 2026

This policy explains how AtlasAiDev (“we”, “us”) handles personal data in connection with the wpatlasmcp.com website, the Atlas MCP plugin, and any Pro licence you purchase.

Atlas MCP is unusual among AI plugins in one important respect: it is self-hosted. The plugin runs on your own WordPress server, and the vast majority of the data it touches never reaches us at all. This policy is careful to distinguish between the three.

1. Who we are

AtlasAiDev is the developer of Atlas MCP and the data controller for the personal data described in this policy. Our contact details are at the end of the page.

2. The short version

What we do not receive

We do not receive your website content, your posts, your media, your customer or order data, your WordPress user accounts, your AI provider API keys, your MCP access tokens, or your plugin activity log. All of that is stored in your own WordPress database on your own server.

We also do not receive the prompts you send to an AI model or the responses it returns. Those travel directly between your server and the AI provider you have configured.

What we do receive is limited to the things we genuinely need: your details when you buy a licence, your messages when you contact support, and ordinary web server information when you visit this website.

3. Data the plugin stores on your own site

The plugin stores the following in your own WordPress database. You control it, you can delete it, and we cannot see it.

WhatWhere it lives
AI provider API keysYour WordPress options table, on your server
OAuth clients, access tokens, and consent recordsYour WordPress database
Activity log of AI tool calls, including the user and role each ran asYour WordPress database
Workflows, prompts, and module settingsYour WordPress database
Generated content and generation historyYour WordPress database

If you are a site owner using Atlas MCP, you are the controller of that data in respect of your own users and customers. Your obligations to them under data protection law are yours, not ours, and you should reflect the plugin’s behaviour in your own privacy notice where relevant.

Uninstalling the plugin removes its data from your site according to the uninstall behaviour described in the plugin documentation.

4. AI providers and your content

Atlas MCP connects to third-party AI providers — OpenAI, Google, and Anthropic — using API keys that you supply. When a request is made, the relevant content is sent from your server directly to that provider.

  • We are not in that path. Nothing is proxied or routed through our systems.
  • Each provider’s own privacy policy and data retention terms govern what happens to that content.
  • You are billed directly by the provider and hold the account relationship with them.
Worth reading before you connect a store

If you enable WooCommerce abilities, order and customer data can be sent to your chosen AI provider as part of a request. Check that provider’s terms against your own obligations before exposing store data, and grant only the abilities you actually need.

Similarly, when you connect an MCP client such as Claude, ChatGPT, Cursor, or Gemini, the content exchanged in that session is handled under the terms of whoever operates that client.

5. Website visitors

When you visit wpatlasmcp.com, our web server records standard technical information in its logs, including your IP address, browser type, operating system, the pages you requested, referring page, and the date and time of the request. This is ordinary server operation, used to keep the site running, secure, and performant.

Cookies

We use cookies that are strictly necessary to operate the site, including those set by WordPress and by our caching layer. If we introduce analytics or marketing cookies in future, we will update this policy and request consent where the law requires it.

You can block or delete cookies in your browser settings, though some parts of the site may not work as intended if you do.

6. Purchases and licences

Pro licences are sold through Freemius, which acts as the merchant of record. When you buy a licence, Freemius collects and processes the data needed to complete the transaction, which typically includes your name, email address, billing details, country, and IP address.

We never see or store your full payment card number. Card data is handled by Freemius and its payment processors on PCI-compliant infrastructure.

What we receive from Freemius is limited to what we need to service your licence: your name, email address, licence key, plan, site activations, and purchase and renewal history.

If you opt in during plugin activation, the Freemius SDK may also share anonymised diagnostic and usage information with us, such as your WordPress and PHP versions and which features are in use. This is optional, you are asked before it happens, and declining does not affect how the plugin works.

7. Support requests

When you email us or post on the WordPress.org support forum, we process what you send us: your name and email address, the content of your message, and any screenshots, logs, or site details you include.

If you grant us temporary administrative access to your site to diagnose a problem, we will use it only for that purpose and only for as long as needed. We ask that you revoke the access once the issue is closed, and we recommend creating a temporary account rather than sharing your own credentials.

8. Why we process data, and on what basis

PurposeLawful basis
Delivering licences, updates, and support you have paid forPerformance of a contract
Responding to enquiries and support requestsLegitimate interests, or performance of a contract
Keeping the website secure and operationalLegitimate interests
Meeting tax, accounting, and legal obligationsLegal obligation
Optional diagnostic data, and any marketing emailConsent, which you may withdraw at any time

We do not sell or rent your personal data, and we do not use it for automated decision-making that produces legal effects.

9. Who we share data with

We share personal data only with service providers who help us run the business, and only to the extent needed:

  • Freemius — payments, licensing, and invoicing.
  • Our web host and email provider — hosting this site and handling correspondence.
  • WordPress.org — where you use the free plugin or the public support forum, under the WordPress Foundation’s own privacy practices.

We may also disclose data where required by law, or to establish, exercise, or defend legal claims.

10. International transfers

We operate from Bangladesh, and our service providers operate in other countries including the United States and the European Union. Using our services means your data may be transferred to and processed in countries outside your own, under appropriate safeguards where the law requires them.

11. How long we keep data

  • Purchase and licence records — for as long as the licence is active, and afterwards for as long as tax and accounting law requires.
  • Support correspondence — typically up to three years, so we can pick up the thread on a recurring issue.
  • Server logs — a short rolling period for security and troubleshooting.
  • Temporary site access — used only for the duration of the ticket.

12. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to processing, to receive a portable copy, and to withdraw consent where processing relies on it.

To exercise any of these, email contact@atlasaidev.com. We will respond within one month. If you are in the EU or UK and are unhappy with our response, you may complain to your local data protection authority.

Note that data stored inside your own WordPress installation is under your control, not ours, so requests about that data should be handled by you directly.

13. Security

We use HTTPS across this website, limit access to customer records to those who need it, and rely on established providers for payments and licensing rather than handling card data ourselves.

No system is perfectly secure. Within the plugin itself, security depends substantially on your own configuration: grant the narrowest access that does the job, review connected MCP clients periodically, revoke what you no longer use, and keep the plugin updated.

14. Children

Our products and this website are intended for site owners and developers, and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

15. Changes to this policy

We may update this policy as the product or our processors change. The current version is always the one published here, and the date at the top records when it last changed. Material changes will be highlighted on this page.

16. Contact

For any question about this policy or about the data we hold, get in touch.

AtlasAiDev

AddressDhaka 1207, Bangladesh

Your site, your data, your keys

Atlas MCP runs on your own server. Install the free version and see exactly what it stores, before you pay for anything.

Scroll to Top