Last updated: September 2026
SwiftlyMCP (“we”, “our”, “us”) is a product by SwiftlyWP. This policy explains what data we collect when you use the SwiftlyMCP relay server and WordPress plugin, how we use it, and your rights regarding that data.
The SwiftlyMCP relay server acts as a bridge between your AI client (Claude, ChatGPT, etc.) and your WordPress site. When your AI executes a tool:
The SwiftlyMCP WordPress plugin runs entirely on your server. It stores a shared secret and connection status in your WordPress database. The activity log (recording which tools were used) is stored locally in your database and is never sent to our servers. On uninstall, all plugin data is removed including the activity log table, options, and Application Passwords.
Account data is retained as long as your account is active. If you disconnect your site, stored credentials are deleted immediately. If you delete your account, all associated data (sites, credentials, usage records) is permanently removed.
We use AES-256-GCM encryption for credentials, HTTPS for all communications, rate limiting to prevent abuse, and regular security reviews. The relay server enforces admin-only access and validates all requests against WordPress Application Passwords.
You can disconnect your site and delete your account at any time. If you have questions about your data or want to request data export or deletion, contact us at our contact page.
We may update this policy from time to time. Significant changes will be communicated via the SwiftlyMCP website. Continued use of SwiftlyMCP after changes constitutes acceptance of the updated policy.