Privacy Policy

Summar AI WordPress Plugin — Privacy Policy

Last updated: 2026-03-09

This Privacy Policy explains what data may be processed by the independent developer in connection with the Summar AI WordPress plugin (the “Plugin”).

Important: Most content and interaction data is processed on the Site Owner’s WordPress site and/or sent from the Site Owner’s site to their chosen AI provider (e.g., OpenAI) using the Site Owner’s API key. This policy focuses on what may reach the Developer’s services (if any).

1) Scope

This policy covers:

  • data processed by Summar AI service endpoints (e.g., operational handshake and optional telemetry),
  • support communications you send to the Developer.

This policy does not replace:

  • your AI provider’s privacy policy (e.g., OpenAI),
  • the Site Owner’s own website privacy policy.

2) High-level data flow

Depending on configuration/version, the Plugin may interact with:

  1. AI provider (e.g., OpenAI) via BYOK (Bring Your Own Key): Visitor question + relevant page content may be sent from your site to the provider.
  2. Summar AI service endpoints (Developer-operated):
    • Handshake: used for operational checks (e.g., plan/limits).
    • Telemetry (optional, opt-in): aggregated usage metrics, only if enabled.
  3. Google Fonts (if enabled): Visitors’ browsers may request fonts directly from Google.

3) Data processed by the Developer

3.1 Handshake (operational checks)

The Plugin may send limited site-level information to the Developer’s endpoint, such as:

  • anonymised site identifier, basic technical metadata (e.g., plugin version).

Purpose: operational checks (e.g., usage limits), abuse prevention, basic compatibility.

3.2 Telemetry (optional, opt-in)

If the Site Owner explicitly enables telemetry, the Plugin may send aggregated metrics, such as:

  • request counts, response counts,
  • success/error counts,
  • latency statistics (e.g., average/median),
  • cache hit/skip metrics,
  • basic environment info (WordPress/PHP/plugin version),
  • a site identifier (site URL and/or install/site tag).

Not intended to be sent in telemetry:

  • full visitor questions,
  • full page content,
  • full generated answers,
  • admin settings content.

Note: This describes telemetry payload intent. Your own infrastructure (CDN/WAF/proxies/server logs) may separately record requests; those logs are controlled by you.

3.3 Support communications

If you contact the Developer by email, the Developer will process:

  • your email address,
  • message contents and attachments you provide (including diagnostics).

Purpose: respond to support requests, troubleshoot issues.

4) Google Fonts (Visitor → Google)

If Google Fonts are loaded, Visitors’ browsers may connect to:

  • fonts.googleapis.com
  • fonts.gstatic.com

Those requests may include technical data like IP address. This connection is between the Visitor and Google (not the Developer).

Depending on your jurisdiction, you may need consent/disclosure. Consider self-hosting fonts or disabling external font loading if required.

5) Purposes of processing

The Developer processes data to:

  • keep the Plugin operational (handshake/limits),
  • improve stability and performance (telemetry, if enabled),
  • prevent abuse,
  • provide support.

6) Legal bases (general)

Depending on jurisdiction, common bases may include:

  • legitimate interests (security, stability, abuse prevention),
  • consent (telemetry opt-in),
  • performance of a contract / requested support (where applicable).

Site Owners remain responsible for their own legal bases and notices to Visitors.

7) Sharing of data

The Developer may share data only as necessary with:

  • infrastructure providers (hosting, CDN, monitoring) to operate the service,
  • authorities if legally required.

The Developer does not sell telemetry/handshake data for advertising purposes.

8) Retention

Handshake / operational logs: up to 30 days
Used for service reliability, delivery checks, rate limiting, debugging, and abuse prevention. These logs are kept as short as reasonably possible and are not intended to store page content or question/answer text.

Telemetry metrics (if enabled): up to 12 months
Used for product analytics such as request counts, latency, error rates, version usage, and similar operational statistics. After this period, data may be deleted or retained only in an aggregated and/or anonymized form for longer-term trend analysis.

Support emails and support-related correspondence: for as long as needed to resolve the issue, and then for up to 12 months afterward where reasonably necessary for follow-up, recordkeeping, or dispute prevention.

9) Security

The Developer uses reasonable safeguards (access controls, least privilege, encryption in transit where applicable). No system is 100% secure.

10) Your rights

Depending on your jurisdiction, you may request access, correction, deletion, restriction, or objection.

To make a request, contact the Developer using the details below.

11) Contact

  • Email: contact@summar-ai.com
  • Website: summar-ai.com

12) Changes

This policy may be updated over time. The latest version will be posted on this page.