Effective May 13, 2026 — Last updated May 13, 2026
This Privacy Policy explains how Algorismus LLC (“Algorismus,” “we,” “us,” or “our”), the company that operates the WPOS.ai product family (the “Service”), collects, uses, shares, and protects information about you. WPOS.ai is the renamed successor to the product previously known as “WPCursor”; certain legacy hostnames (wpcursor.com, api.wpcursor.com, app.wpcursor.com) and the WordPress plugin slug (wpcursor-ewb) remain in use for backward compatibility and are covered by this Policy.
If you do not agree with this Policy, do not use the Service.
wpcursor-ewb) installed on customer WordPress sites.app.wpcursor.com).api.wpcursor.com).admin.wpcursor.com).3801 Hulen Street, STE 201, Fort Worth, TX 76107)3801 Hulen Street, STE 201, Fort Worth, TX 76107)For the purposes of the EU/UK General Data Protection Regulation (GDPR / UK GDPR), Algorismus is the data controller for account and billing data, and a data processor for content you process through the Service (your prompts, your WordPress site data, and the content the AI generates on your behalf).
This Policy applies to:
app.wpos.ai, admin.wpos.ai, marketing sites at wpos.ai).api.wpos.ai).wpcursor-ewb) when installed on your WordPress site and configured against the Service.This Policy does not apply to (a) third-party WordPress sites you visit or own that happen to have the plugin installed but are not interacting with our backend, (b) third-party services we link to, or (c) data you process locally on your own infrastructure without transmitting it to our backend.
| Category | Examples | Purpose |
|---|---|---|
| Account identifiers | Name, email address, password hash, OAuth subject (Google), profile photo URL | Authentication, account recovery, support |
| Billing data | Plan, credit balance, Stripe customer ID, last-4 of payment instrument, billing address, VAT/Tax ID | Payment processing, invoicing, tax compliance |
| Site registration data | WordPress site URL, site name, WordPress admin user, license key, domain-lock fingerprint | License validation, anti-abuse, support |
| Prompts and instructions | The natural-language instructions you send to the AI assistant | Generating responses and performing the tasks you request |
| Uploaded content | Files, images, design references, screenshots, scraped pages you upload to your workspace | Performing the requested task |
| Support communications | Messages to support@wpos.ai, in-app chat, bug reports | Responding to and resolving your inquiry |
When the wpcursor-ewb plugin is installed and authenticated against our backend, it transmits the following on your behalf:
test, beta, public).We do not routinely transmit your WordPress users’ personal data, customer orders, or database tables that are not directly involved in a task you requested. You — the WordPress site administrator — are the controller of your site’s data and choose what the AI may access by selecting it in the plugin UI.
| Category | Examples | Source |
|---|---|---|
| Device / connection | IP address, browser, OS, device type, language, referrer | Web server logs, browser headers |
| Cookies & local storage | Session cookie (claude.sid), CSRF token, UI preferences (e.g., wpcAdminEnv), Stripe + PostHog cookies | Browser |
| Telemetry | Page views, feature usage, error events, performance metrics | PostHog product analytics |
| Operational logs | Backend request logs, MCP tool invocations, container lifecycle events | Application servers |
We use the information described above to:
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Account, billing, plugin operation | Contract (Art. 6(1)(b)) |
| Security, anti-abuse, telemetry | Legitimate interests (Art. 6(1)(f)) |
| Marketing email | Consent (Art. 6(1)(a)) — withdrawable |
| Tax, accounting | Legal obligation (Art. 6(1)(c)) |
Algorismus does not train its own AI models. AI capabilities are provided by Anthropic, PBC (the maker of Claude) under a commercial API agreement. Anthropic’s commercial API terms prohibit using your inputs and outputs to train Anthropic’s models by default, and we do not opt in to any program that would change that. We also do not sell or license your content to any other AI vendor for training.
When you send a prompt, we forward to Anthropic:
Anthropic processes the request, returns a response, and (per its commercial API terms) retains the data only as long as needed for trust-and-safety review and abuse detection. See Anthropic’s privacy policy at https://www.anthropic.com/legal/privacy.
AI-generated content is provided “as is.” It may be inaccurate, incomplete, or unsuitable for your use case. You are responsible for reviewing it before publishing to your site, sending to customers, or relying on it for any decision.
As between you and us, you own the AI-generated output produced for your account, subject to the Terms of Service. Note that under current U.S. copyright law, purely AI-generated content may not be eligible for copyright protection regardless of who paid for it. We make no representation about copyrightability of AI output.
The Service includes a headless-browser feature (“Steel Browser”) that lets the AI navigate to URLs you specify, take screenshots, and extract content for design reference. When you invoke this feature:
You must not use this feature to access content you are not authorized to access.
Each paid license is locked to a specific WordPress domain. To enforce this, the plugin sends your site’s normalized domain (e.g., example.com, without www. or scheme) to our backend on activation and on each AI-write request. The domain is stored against your license record. You can change the licensed domain through the admin dashboard, subject to anti-abuse limits.
For each WordPress site you connect, we create an isolated workspace on our servers containing your .mcp.json configuration, uploaded files, scraped pages, and AI conversation history. Workspaces are:
Conversation history is retained for the lifetime of your account or until you delete it (see §13).
| Cookie / storage | Purpose | Type | Duration |
|---|---|---|---|
claude.sid, claude.sid_dev | Authenticated session | Strictly necessary | Session / 30 days |
| CSRF token | Anti-CSRF protection | Strictly necessary | Session |
wpcAdminEnv (localStorage) | Live/Dev API toggle in admin dashboard | Strictly necessary | Until cleared |
| Stripe cookies | Payment processing, fraud detection | Strictly necessary | Per Stripe |
PostHog cookies (ph_*) | Product analytics | Analytics | Up to 1 year |
You can disable non-essential cookies in your browser. Disabling strictly necessary cookies will prevent the Service from working.
We share information only with the categories of recipients below, under written agreements that require confidentiality and appropriate safeguards.
| Subprocessor | Purpose | Data | Region |
|---|---|---|---|
| Anthropic, PBC | AI model inference (Claude API) | Prompts, conversation context, tool outputs | United States |
| Stripe, Inc. | Payments, subscriptions, invoicing, tax | Billing data, payment instrument tokens | United States, EEA |
| Amazon Web Services, Inc. (AWS) | Compute, storage, networking | All categories at rest | United States (3801 Hulen Street, STE 201, Fort Worth, TX 76107 — us-east-1 / us-west-2) |
| Steel Browser (steel-dev) | Headless browser for AI navigation | URLs you specify, rendered screenshots | Self-hosted on AWS |
| PostHog, Inc. | Product analytics, telemetry | Pseudonymous event data | United States / EU (per project config) |
| Google LLC | OAuth sign-in (optional) | Email, name, profile photo | United States |
| Email provider | Transactional email delivery | Email address, message body | (3801 Hulen Street, STE 201, Fort Worth, TX 76107 — Resend / Postmark / SES) |
| GitHub, Inc. | Plugin update distribution (release CI) | Plugin ZIPs, version metadata | United States |
We will update this list when subprocessors change and, where required by contract, provide advance notice.
We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined by the California Consumer Privacy Act.
Algorismus is based in the United States; engineering operations are in Pakistan; subprocessors are primarily in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other jurisdictions whose data-protection laws may differ from your own.
Where required, we rely on:
A copy of the SCCs is available on request at privacy@wpos.ai.
We employ technical and organizational measures designed to protect your information, including:
UpdateChecker).No system is perfectly secure. If you discover a vulnerability, please email security@wpos.ai (3801 Hulen Street, STE 201, Fort Worth, TX 76107) — we operate a coordinated-disclosure program.
| Data | Retention |
|---|---|
| Account and billing records | Lifetime of account + 7 years (tax, accounting) |
| Conversation history & workspaces | Lifetime of account, or until you delete in-app |
| Credit transactions, usage stats | 7 years |
| Operational logs (web, app, container) | 90 days rolling |
| Email logs (transactional) | 12 months |
| Marketing opt-outs / suppression list | Indefinitely (to honor your opt-out) |
You can delete individual conversations and uploaded files in-app at any time. To delete your account, email privacy@wpos.ai or use the “Delete account” action in Settings (where available). We will delete or anonymize your personal data within 30 days, except where retention is required by law (e.g., invoices), in which case we will isolate it from production use.
Depending on where you live, you may have the following rights:
To exercise any right, email privacy@wpos.ai. We will respond within 30 days (extendable by 60 days for complex requests) and may need to verify your identity.
In the preceding 12 months, we have collected the categories of personal information listed in §3 for the business purposes listed in §4. We have disclosed identifiers, commercial information, internet activity, and inferences to the subprocessors listed in §10.1 for those business purposes. We have not sold or shared personal information for cross-context behavioral advertising. California residents have the right to know, delete, correct, opt out of sale/sharing (not applicable to us), and limit use of sensitive personal information, and we will not discriminate against you for exercising these rights.
If you reside in Virginia, Colorado, Connecticut, Utah, Texas, or another state with a comprehensive privacy law, you have rights substantially similar to those in §14 and §14.1. Texas residents specifically: you may exercise these rights under the Texas Data Privacy and Security Act.
The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please email privacy@wpos.ai and we will delete it.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you. AI-assisted features generate content at your request; they do not autonomously approve, deny, or restrict access to services.
Our Service does not respond to “Do Not Track” browser signals. We honor opt-outs of analytics via the cookie controls described in §9.
We may update this Policy from time to time. When we do, we will revise the “Last updated” date and, for material changes, notify you by email or via an in-app notice at least 14 days before the change takes effect (unless a shorter period is required by law). Your continued use of the Service after the effective date constitutes acceptance.
Algorismus LLC
3801 Hulen Street, STE 201, Fort Worth, TX 76107
Privacy: privacy@wpos.ai
Legal: legal@wpos.ai
Security: security@wpos.ai
Support: support@wpos.ai