Documentation / Security and Privacy

Security and Privacy

Updated February 20, 2026

Your Data Stays on Your Server

Agent Builder runs entirely within your WordPress installation. Your site data, configuration, and content never pass through our servers. We do not collect telemetry, analytics, or usage data.

What Goes to the AI Provider?

When you chat with an assistant, the conversation (your messages and the assistant’s responses) is sent to your chosen AI provider (OpenAI, Anthropic, or xAI) for processing. This includes:

  • Your message text
  • The assistant’s system instructions
  • Context the assistant gathers (e.g., post content it reads to answer your question)

Each provider has its own privacy policy:

API Key Security

Your AI provider API key is:

  • Stored in your WordPress database (encrypted using WordPress salt keys)
  • Never displayed in full in the admin interface (masked with asterisks)
  • Never sent to our servers
  • Never included in audit logs

Plugin Security Features

Reporting a Security Issue

If you discover a security vulnerability, please email [email protected]. Do not open a public GitHub issue. We respond within 48 hours.