YakWP AI chatbot for WordPress — feature overview

Privacy Policy — YakWP WordPress Chatbot Plugin

Privacy Policy

Last updated: July 2026

Who We Are

YakWP is developed and operated by Oliver Djoric, an individual based in Cuprija, Serbia. Contact us via our contact page.

Data Collection

YakWP is a self-hosted WordPress plugin. All data is stored on your own server. We do not collect, transmit, or store any data from your website, except for license key verification.

What the Plugin Stores Locally

  • Your AI provider API key in the WordPress database
  • Chat conversations in a dedicated database table (auto-deleted after your configured retention period)
  • Plugin configuration settings
  • License key for activation verification
  • Trial registration email, consent timestamp, and expiration date

Data Sent to Third-Party Services

  • Chat messages are sent to your chosen AI provider (Google Gemini, OpenAI, or OpenRouter) to generate responses. These providers process data according to their own privacy policies.
  • License key and site URL are sent to yakwp.com for activation verification.
  • Optional: conversation data can be forwarded to your own n8n webhook for CRM integration, email automation, or other workflows.

Visitor Information

When a visitor uses the chat widget:

  • Their messages and AI responses are stored in your WordPress database
  • A session cookie is used to maintain conversation context during the session
  • IP addresses may be temporarily stored for rate limiting (stored as transient data, auto-deleted)
  • If they provide an email address via the lead capture feature, it is stored and emailed to the site administrator
  • No tracking cookies or third-party analytics are used by the plugin

AI Disclosure

The chat widget includes an optional “Powered by AI” notice to inform visitors they are interacting with an AI system. Site operators are responsible for ensuring this notice is displayed where required by applicable law, including the EU AI Act.

Data Retention

Conversation records are automatically removed after your configured retention period (default: 30 days). You can adjust this in Settings. Rate limiting data (IP addresses) is stored as WordPress transients and auto-expires.

Data Subject Rights (GDPR)

As a self-hosted plugin, data controllership sits with the site operator, not YakWP. If you operate a site using YakWP, you are the data controller. You must:

  • Provide visitors with access to their conversation data upon request
  • Delete conversation data upon request within 30 days
  • Allow visitors to object to processing
  • Include appropriate privacy notices on your site

YakWP provides tools to help you comply: configurable retention periods, conversation export, and database-level deletion.

Email Consent (Free Trial)

When you register for a free YakWP Pro trial, you provide your email address voluntarily. Your email is used solely to:

  • Send your license key
  • Send a reminder when your trial is about to expire
  • Send one follow-up email after trial expiration with an option to purchase

We do not sell, share, or transfer your email to third parties. Your email and consent timestamp are stored in the WordPress database on your own server.

Security

YakWP is self-hosted on your WordPress installation. We do not have access to your server, database, or API keys. Security of your WordPress installation, database, and hosting environment is your responsibility. We make commercially reasonable efforts to address reported issues, but cannot guarantee the plugin is free from all defects.

International Data Transfers

Chat messages sent to AI providers (Google, OpenAI, OpenRouter) may be processed outside your country. Google processes data according to its global infrastructure, OpenAI primarily in the US, and OpenRouter routes to various providers. By configuring an AI provider in YakWP, you acknowledge that chat data will be transmitted to that provider for processing.

Changes to This Policy

We may update this Privacy Policy at any time. Changes will be posted on this page with an updated date. Continued use of the Plugin after changes constitutes acceptance of the revised Policy.

Contact

For privacy inquiries or data subject requests, contact us via our contact page.