Legal
Privacy Policy
Pressbotics is a publishing rail between your AI agents and your WordPress sites. This page describes exactly what the system stores, who else processes it, and how to get rid of it.
Last updated 13 September 2026. Questions: info@pressbotics.com. This page describes how the Pressbotics service actually behaves; it is not legal advice and has not yet been reviewed by a lawyer.
What we store
- Account and authentication. Your email address and authentication state, handled by Supabase. If you enable multi-factor authentication, the TOTP secret is stored encrypted at rest.
- Workspaces and sites. The workspaces you belong to and the WordPress site records you connect: site URL, display name, connection status, and cached site metadata such as category and tag names used to help agents pick the right ones.
- WordPress credentials — encrypted. Application Passwords and plugin connection secrets are encrypted with a key held only by the publishing rail. They are never returned to the browser, never included in API responses, and never written to logs. Pressbotics staff cannot read them.
- Agent keys — hashes only. When you issue an agent key we store a one-way hash. The raw key is shown to you once at creation and is not recoverable afterwards, by you or by us.
- Action history. Every publish, update and approval an agent proposes: the proposed content, the approval decision, the outcome, timestamps, and the resulting WordPress post reference. This is the audit trail that makes the approval gate meaningful.
- Support and feedback. Reports you file and the messages exchanged in that thread.
- Security events. Sign-in attempts, rate-limit trips, and rejected API calls, with the originating IP address, kept to detect abuse.
What we do not do
- We do not crawl, read or copy the contents of your WordPress site beyond what is needed to carry out an action you or your agent requested, and the small amount of site metadata described above.
- We do not sell your data or share it with advertisers.
- We do not train any model on your content, your posts, or your support messages.
- We do not store raw agent keys or plaintext WordPress credentials.
Third parties we use
Pressbotics relies on the following processors. Each one receives only what it needs to do its job.
- Supabase — database, authentication and file storage. Holds essentially all account and workspace data described above.
- Stytch — the OAuth authorization server used when an AI agent connects to your workspace. Receives the identifiers needed to issue and revoke those grants.
- Stripe — payments and subscriptions. Receives your billing details directly; Pressbotics never sees or stores full card numbers.
- Linear — support ticketing. When you file a report, its contents and your workspace reference are copied into a Linear issue so the team can reply.
- SignupGate — signup abuse prevention. Receives signup signals such as email address and IP to score new registrations.
- DeepSeek — the model provider behind the in-app assistant. Plainly: when you talk to the assistant, your messages and the relevant workspace context are sent to a third-party model provider for processing. If you would rather that not happen, do not use the assistant.
- Railway and Cloudflare — hosting, networking and DNS for the application and the publishing rail.
The full list, with the categories of data each one receives and where it processes them, is on the subprocessors page. Business customers who need written processing terms should read the Data Processing Addendum.
The in-app assistant is an AI system
Stated plainly, as the EU AI Act's Article 50 transparency obligations (in force since 2 August 2026) require:
- The assistant in the dashboard is an AI system. You are talking to a large language model, not to a member of the Pressbotics team.
- Your messages, and the workspace context sent with them — site names, plan, summaries of recent actions — are transmitted to DeepSeek, a third-party model provider, for processing. Do not use the assistant if you would rather that did not happen.
- The assistant can propose configuration changes and draft actions, but it never acts on your workspace without your explicit confirmation. Publishing still passes through the same approval gate as everything else.
- It can be wrong. Check anything consequential before you confirm it.
- Do not paste secrets into it — passwords, API keys, agent keys or WordPress credentials. They would be sent to the model provider and stored in the conversation.
How long we keep things
Where we have not defined a fixed period, the table says so rather than inventing a number. Deleting your workspace removes everything marked as workspace-scoped below, immediately and irreversibly.
| Data | Retention |
|---|---|
| Account and authentication records | Retained while the account is active. Deleted when you delete your account. |
| Workspace and site records | Retained while the account is active; deleted with the workspace. |
| Encrypted WordPress credentials | Deleted as soon as you disconnect or delete the site, and with the workspace on account deletion. Not retained beyond that point in any form. |
| Agent key hashes | Retained until you revoke the key, then kept as a revoked record while the account is active so the audit trail still resolves. Deleted with the workspace. |
| Action and approval history | Retained while the account is active — it is the audit trail behind the approval gate, so we do not expire it on a timer. Deleted with the workspace. |
| Feedback and support messages | Retained while the account is active and deleted with the workspace. The corresponding Linear issue persists under Linear's own retention and is not deleted by us. |
| SignupGate abuse checks | Transient. The check runs once at signup and the result is not stored beyond the security_events record it produces; SignupGate is not queried again afterwards. |
| Security events (sign-ins, rate-limit trips, rejected calls, with IP) | Retained while the account is active for abuse investigation. Deleted when the account is deleted. |
| Webhook delivery log | Retained as an operational audit record of inbound support deliveries. No fixed expiry defined; it holds event type, issue reference and match outcome, not message bodies. |
| MFA secrets and recovery codes | Encrypted or hashed, retained while MFA is enabled. Cleared the moment you turn MFA off. |
| Images you upload for publishing | Transit only, never retained beyond the window. An upload link expires 60 minutes after your agent creates it. An uploaded file is deleted the moment it reaches your WordPress media library, and in any case within 24 hours. We are not a media host — your site's library is the system of record. We also strip embedded metadata, including GPS location, before storing the file at all. |
| Billing records | Subscription state kept while the account is active for accounting; invoices and payment records are retained by Stripe under Stripe's own retention rules, which we cannot shorten. |
Deleting your account, and exporting first
You can do both yourself. In the dashboard, under Settings, "Download your data" produces a JSON file containing your account email, workspace, sites, action history, feedback threads and usage — deliberately without any credential or key material. The danger zone below it deletes the workspace: sites and their stored credentials, agent keys, action history, feedback and any active subscription.
Deletion is immediate and irreversible, and it does not touch anything already published on your WordPress site. That content is yours and stays exactly where it is — deleting your Pressbotics account does not unpublish a single post.
Prefer to have us do it? Email info@pressbotics.com from your account address. Either way, records held by Stripe for financial reporting and issues already created in Linear follow those providers' retention rules.
You can also disconnect an individual site or revoke an agent key at any time from the dashboard, which takes effect immediately.
Cookies and similar technologies
Strictly necessary cookies keep you signed in and remember your cookie choice. Nothing in the functional, analytics or marketing categories loads unless you consent, and you can change that at any time from the “Cookie settings” link in the footer. The full list of what can be set and by whom is on the Cookie Policy.
Who we are, and contact
The data controller is PressBotics, LLC, 2125 Biscayne Boulevard, Miami, FL 33137, United States.
Privacy questions and data requests: info@pressbotics.com. This page describes system behaviour as implemented; it is not legal advice.

