Privacy Policy

Last updated: September 2026

Overview

SwiftlyMCP (“we”, “our”, “us”) is a product by SwiftlyWP. This policy explains what data we collect when you use the SwiftlyMCP relay server and WordPress plugin, how we use it, and your rights regarding that data.

What we collect

  • •Account information — email address used to sign in to the SwiftlyMCP relay server.
  • •Site connection data — your WordPress site URL, stored so the relay can route requests to the correct site.
  • •Encrypted credentials — WordPress Application Passwords are encrypted with AES-256-GCM before storage. We never store your WordPress login password.
  • •Usage data — daily tool call counts for rate limiting and plan enforcement. We do not log the content of your requests or responses.
  • •Payment information — if you upgrade to a paid plan, payment is processed by our third-party payment provider. We do not store credit card numbers.

What we do not collect

  • •We do not read, store, or log your WordPress content (posts, pages, products, orders).
  • •We do not access your AI conversations. The relay passes tool calls between your AI client and your WordPress site without reading the content.
  • •We do not sell or share your data with third parties for advertising purposes.

How the relay works

The SwiftlyMCP relay server acts as a bridge between your AI client (Claude, ChatGPT, etc.) and your WordPress site. When your AI executes a tool:

  1. 1Your AI client sends the tool call to the relay server.
  2. 2The relay decrypts your site credentials, forwards the request to your WordPress REST API, and returns the response.
  3. 3Credentials are decrypted only in memory for the duration of the request and are never written to logs.

WordPress plugin

The SwiftlyMCP WordPress plugin runs entirely on your server. It stores a shared secret and connection status in your WordPress database. The activity log (recording which tools were used) is stored locally in your database and is never sent to our servers. On uninstall, all plugin data is removed including the activity log table, options, and Application Passwords.

Data retention

Account data is retained as long as your account is active. If you disconnect your site, stored credentials are deleted immediately. If you delete your account, all associated data (sites, credentials, usage records) is permanently removed.

Security

We use AES-256-GCM encryption for credentials, HTTPS for all communications, rate limiting to prevent abuse, and regular security reviews. The relay server enforces admin-only access and validates all requests against WordPress Application Passwords.

Your rights

You can disconnect your site and delete your account at any time. If you have questions about your data or want to request data export or deletion, contact us at our contact page.

Changes

We may update this policy from time to time. Significant changes will be communicated via the SwiftlyMCP website. Continued use of SwiftlyMCP after changes constitutes acceptance of the updated policy.