HIFI-WP by Augmentable.ai
Pricing
How It WorksFeaturesDemosWhy HiFi-WPBlogDownloadsUse CasesTestimonials Browse all agents

Privacy Policy

How we collect, use, and protect your personal data

Last Updated: July 6, 2026

Privacy Policy Overview

HiFi WP is committed to protecting your privacy and personal data. This policy explains how we collect, use, store, and protect your information in compliance with GDPR, CCPA, PIPEDA, LGPD, PDPA, and other applicable privacy laws.

Your Privacy Rights

You have the right to access, correct, delete, and control how your personal data is used. You can exercise these rights through your account settings or by contacting us directly.

Data We Collect

Account Information

  • Email address and name
  • Firebase UID for authentication
  • Account preferences and settings
  • Subscription and billing information

Usage Data

  • API calls and usage patterns
  • Costs and billing information
  • Timestamps and session data
  • Feature usage analytics

Platform Integration

  • Connected service URLs
  • App passwords (encrypted)
  • Content and media data
  • Site configuration details

Technical Data

  • IP addresses for security
  • Browser and device information
  • Error logs and diagnostics
  • Performance metrics

Legal Basis for Processing

Service Delivery

Legal Basis: Legitimate Interest (Article 6(1)(f) GDPR)

We process your data to provide our AI-powered platform services, including content generation, automation, and technical support.

Billing and Contracts

Legal Basis: Contract Performance (Article 6(1)(b) GDPR)

We process billing information and usage data to fulfill our contractual obligations and manage subscriptions.

Security and Fraud Prevention

Legal Basis: Legitimate Interest (Article 6(1)(f) GDPR)

We process technical data and usage patterns to protect our service and prevent abuse or fraudulent activity.

Marketing Communications

Legal Basis: Consent (Article 6(1)(a) GDPR)

We only send marketing communications with your explicit opt-in consent, which you can withdraw at any time.

Data Retention

Account Data

Retention: Until account deletion + 30 days

Includes profile information, preferences, and settings.

Chat History

Retention: 2 years or until deletion request

AI conversations and generated content for service improvement.

Billing Records

Retention: 7 years (legal requirement)

Transaction records, invoices, and payment information.

Security Logs

Retention: 1 year

Access logs, security events, and audit trails.

Your Privacy Rights

Access Rights

Request a copy of all personal data we hold about you, including how it's used and who it's shared with.

Correction Rights

Update or correct any inaccurate or incomplete personal information in your account.

Deletion Rights

Request deletion of your account and associated personal data (right to be forgotten).

Data Portability

Export your data in a structured, machine-readable format to transfer to another service.

Processing Objection

Object to certain types of data processing, particularly for marketing purposes.

Consent Withdrawal

Withdraw consent for data processing where consent is the legal basis.

How to Exercise Your Rights

You can exercise these rights through your profile's "Privacy Rights" section or by contacting us at ⏳ Loading... . We will respond within 30 days.

Data Protection & Security

Encryption

  • All data encrypted at rest using AES-256
  • Data in transit protected with TLS 1.3
  • Service credentials encrypted with industry-standard methods
  • Database encryption with key rotation

Access Controls

  • Multi-factor authentication for admin access
  • Role-based access control (RBAC)
  • Regular access reviews and audits
  • Principle of least privilege enforcement

Monitoring & Auditing

  • 24/7 security monitoring and alerting
  • Comprehensive audit logging
  • Regular security assessments
  • Incident response procedures

Data Breach Response

  • Incident detection and containment procedures
  • Notification to authorities within 72 hours
  • User notification for high-risk breaches
  • Post-incident analysis and improvements

International Data Transfers

Cross-Border Processing

Your data may be processed in countries outside your jurisdiction, including the United States and European Union. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy Decisions for transfers to countries with adequate protection
  • Additional Safeguards including technical and organizational measures
  • Data Processing Agreements with all third-party processors

Third-Party Services

AI Services

OpenAI, Anthropic

Content generation and AI processing. Data processed according to their privacy policies with appropriate safeguards.

Authentication

Firebase Auth

User authentication and account management. Google's privacy policy applies to authentication data.

Payment Processing

Stripe

Secure payment processing. Stripe's privacy policy governs payment and billing data.

HiFiBots AI Agents (WordPress Plugin)

How the Plugin Handles Your Data

The official HiFiBots AI Agents plugin connects your self-hosted WordPress site to your HiFi WP account. It is designed to be private by default:

  • Nothing is sent until you opt in: no data leaves your site until you enter an API key (and a Site ID where required) and enable a specific feature.
  • No admin tracking: the plugin does not track your wp-admin usage, does not load Google Analytics, and performs no background or hidden data collection.
  • Outbound click analytics is OFF by default: it is fully optional and only runs if you explicitly enable it in the plugin settings.
  • Your API key is stored on your server in the WordPress options table and is never exposed to your site's visitors.

What the Plugin Sends, When, and Why

Data is transmitted to HiFi-WP / HiFiBots services (the API at wordpressgpt-api-325927718367.us-central1.run.app and the web app at wp.hifibots.com) only for the features you enable:

  • Connection check (admin settings): your saved API key and Site ID, to verify the account and site are valid.
  • AI publishing & REST tools (when agents post or update content): post content, titles, meta, custom post types, ACF field values, and site identifiers.
  • Riverstep inline editor (when a logged-in user runs an AI edit): the selected content fragment, the editing instruction, and optional read-only context (article title, meta description, neighboring sections).
  • Onsite chatbot (when enabled and a visitor opens chat): Site ID, site URL, page URL, page title, and chat messages.
  • Offsite AI agent / SSO launcher (when enabled): Site ID, site URL, and launch context.
  • Instant chatbot indexing (RAG) (when content changes on watched post types): post ID, post type, title, URL, and change-event metadata.
  • CTA email-capture forms (when a visitor submits an inline form): email address and CTA/campaign identifiers, proxied server-side with your API key.
  • Outbound click analytics (opt-in, OFF by default): Site ID, site URL, and anonymous click metadata for tagged monetization links. Only the public Site ID is used in the browser.

What the Plugin Does NOT Do

  • Track wp-admin activity or which admin pages you visit
  • Load Google Analytics or third-party trackers into wp-admin
  • Collect any data before a feature is configured and enabled
  • Expose your API key to public visitors

Your Responsibility as a Site Owner

If you enable visitor-facing features (onsite chatbot, offsite AI agent, CTA forms, or outbound click analytics), you act as the data controller for your visitors' data. You are responsible for maintaining your own privacy notice and obtaining any consent required in your jurisdiction before those features process visitor data.

Cookies & Tracking

Essential Cookies

Required for basic functionality including authentication, security, and service delivery. These cannot be disabled.

Analytics Cookies

Help us understand how you use our service to improve performance and user experience. You can opt-out through cookie settings.

Advertising Cookies

Set only with your consent when we run advertising campaigns (Meta Pixel, Microsoft Advertising). Used to measure ad performance and may share data with those platforms. Opt out any time via cookie settings or the "Do Not Sell or Share My Personal Information" link in the footer.

Categories of Personal Information We Collect & Share

CCPA/CPRA Disclosure

For California residents: the table below lists the categories of personal information (as defined by the California Consumer Privacy Act) we have collected in the preceding 12 months, with examples and the categories of recipients. We do not sell personal information for money. If you enable Advertising cookies, identifiers and internet activity may be shared with advertising partners for cross-context behavioral advertising — you can opt out at any time via the "Do Not Sell or Share My Personal Information" link in the footer, the cookie settings panel, or a Global Privacy Control (GPC) browser signal, which we honor.

CategoryExamples we collectDisclosed to
IdentifiersName, email address, account ID, IP addressService providers (hosting, authentication); advertising partners only with Advertising-cookie consent
Customer recordsBilling details processed by our payment processor (we never store full card numbers)Payment processor (Stripe)
Commercial informationSubscription plan, purchase and usage historyService providers (billing, analytics)
Internet / network activityPages visited, feature usage, interactions with our AI agentsAnalytics provider (Google Analytics, consent-gated); advertising partners only with Advertising-cookie consent
Coarse geolocationCountry/region derived from IP address, used for privacy-law complianceNot disclosed
Professional informationOrganization name, connected WordPress site URLsService providers (hosting)
InferencesProduct-usage patterns used to improve the serviceNot disclosed

Sources, Purposes & Retention

We collect this information directly from you (account signup, service use, support requests) and automatically through the service (usage logs and cookies you have consented to). We use it to deliver and secure the service, process billing, provide support, measure and improve the product, and — only with your Advertising-cookie consent — measure ad campaigns. Retention periods per data type are listed in the Data Retention section above. We do not knowingly collect or share personal information of consumers under 16 years of age, and we do not use or disclose sensitive personal information for purposes that would require a right to limit under the CPRA.

Regional Privacy Laws

GDPR (European Union)

Full compliance with the General Data Protection Regulation, including all rights and protections for EU residents.

CCPA (California)

California Consumer Privacy Act compliance, including rights to know, delete, and opt-out of data sales.

PIPEDA (Canada)

Personal Information Protection and Electronic Documents Act compliance for Canadian users.

LGPD (Brazil)

Lei Geral de Proteção de Dados compliance for Brazilian users with equivalent rights and protections.

Policy Updates

Notification Process

This privacy policy may be updated periodically to reflect changes in our practices or legal requirements. We will:

  • Notify you via email for material changes
  • Provide 30 days notice before changes take effect
  • Update the "Last Updated" date at the top of this policy
  • Maintain previous versions for reference

Continued use of our service after policy updates constitutes acceptance of the new terms.

Privacy Questions?

HiFi WP support team is ready to help you succeed. Whether you need technical assistance, have billing questions, or want to explore partnership opportunities, we're here for you.

Customer Support

Email: arvind@augmentable.ai

Response Time: Within 4 hours (30 minutes for emergencies)

Available: 24/7 for critical issues

For technical issues, integration problems, API questions, platform troubleshooting, emergency outages, privacy concerns, legal matters, and compliance questions. For critical system issues, include [EMERGENCY] in your subject line.

Billing & Refunds

Email: arvind@augmentable.ai

Response Time: Within 24 hours

Available: Monday-Friday, 9 AM - 6 PM EST

For subscription questions, payment issues, refunds, billing inquiries, dispute resolution, and Stripe payment support. We currently accept credit/debit cards via Stripe only.

Business Inquiries & Partnerships

Email: arvind@augmentable.ai

Response Time: Within 48 hours

Available: Monday-Friday, 9 AM - 5 PM EST

For partnership discussions, enterprise engagements, integrations, marketing collaborations, and other business-related opportunities.

BlogHow It WorksBrowse AgentsDownloadsPricingPrivacy PolicyTerms of ServiceCancellations/Refunds/DisputesBilling & PricingAbout UsContact

© 2026 Augmentable.ai