Respirafor WordPress
Products
Products
Plugin
The WordPress plugin + MCP server that runs the whole Respira stack.
Resonance · New
Persistent site memory for your AI, with enforced rules.
Earn · New
Bill clients from a position of knowledge. AI cost per site, per tool, with the multiplier on top.
Claude Cowork plugin · New
Edit live WordPress sites from inside Claude. 17 builders, snapshots, one-click rollback.
Inhale: MCP Abilities · Free
Free plugin. Decide which WordPress abilities your AI assistant can see.
Respira ARC · Free
Free WooCommerce plugin. Product feeds in six formats, a store llms.txt, and an AI-readiness score.
WooCommerce Add-on
105 tools for products, orders, feeds, and storefront design intelligence.
MCP Server
Model Context Protocol spec and 320+ tool catalog.
Tools Catalog
Every tool, all 320+, filterable by builder, license tier, and safety.
CLI · New
Modern WordPress CLI for AI coding agents. One npm install.
SDK · New
Build add-ons + agent integrations on top of the Respira platform.
Skills
42 open-source AI workflows and migration recipes.
Playbooks · New
Typed JSON workflows the agent crystallizes into reusable tools.
Abilities
The 150+ WordPress Abilities Respira registers, browsable and searchable.
ADA & WCAG Scanner
Accessibility compliance checks and automated fixes.
The leading AI infrastructure layer for WordPress. See all products
Integrations
Integrations
Page builders
Elementor Divi 4 & Divi 5 Bricks Builder Oxygen Flatsome Breakdance See all builders →
AI coding agents
Claude Desktop & Claude Code Cursor Codex
Featured
Elementor + Angie Divi 5 Migration Copilot Flatsome · WooCommerce Claude Desktop & Claude Code Cursor setup wizard Respira CLI
Same seatbelt · every assistant · every builder See all integrations
About
About Respira · choose your path or meet the team
Find your path
WordPress UserBuild without code fear AI CuriousGuided AI for WordPress AgencyScale multi-site operations Vibe CoderBuild at the speed of thought DeveloperAI co-pilot for complex stacks DesignerFigma → WordPress, direct
Trust & story
Roadmap LiveShipped, planned, and vote on what's next Meet the founderThe story behind Respira Case studiesReal production workflows ReleasesChangelog · every release Book a call Cal.comTalk with Mihai, the founder ManifestoBuild sites that breathe · sign it Press kitLogos, wordmark, release KVs
Category creator · leading AI infrastructure for WordPress See all paths
Pricing Docs
Blog
Account
Dashboard Sites Earn with Respira Affiliate Billing Settings
Sign in Start free
Respira
Start free
U Account

Account

Dashboard Sites Earn with Respira Affiliate Billing Settings

Explore

Pricing Docs Blog
Products
PluginCore plugin + MCP server ResonancePersistent site memory for your AI, with enforced rules EarnBill from a position of knowledge Claude Cowork pluginEdit live WordPress sites from inside Claude Inhale: MCP AbilitiesFree plugin. Decide which abilities your AI sees. Respira ARCFree plugin. Product feeds + llms.txt for AI shopping. WooCommerce Add-on105 tools for products, orders, feeds MCP ServerModel Context Protocol · 320+ tools Tools CatalogEvery tool in 22 categories CLIModern WordPress CLI for AI agents SDKBuild add-ons + agent integrations Skills42 open-source AI workflows PlaybooksJSON workflows agents author at runtime Abilities150+ WordPress Abilities, browsable ADA & WCAG ScannerAccessibility compliance See all products →
Integrations
Elementor + Angie Divi 5 Migration Copilot Claude Desktop & Claude Code Cursor Codex Respira CLI See all integrations →
About
WordPress User AI Curious Agency Vibe Coder Developer Designer Meet the founder Manifesto Press kit Case studies Releases Book a call
Sign in

LEGAL

Data Processing Agreement

The Article 28 agreement that applies when Respira processes personal data on your behalf. It is offered as a standing agreement, so you do not have to wait on a signature to have one in place.

Version 1.0 · August 5, 2026
Processor establishment Brașov, Romania (European Union)
To put it in place Email word@respira.press. A counter-signed PDF is available on request.
1. Scope2. Roles3. Processing4. Instructions5. Confidentiality6. Security7. Sub-processors8. Transfers9. Data subject rights10. Breach11. Audit12. Return + deletion13. GeneralAnnex IAnnex IIAnnex III

1. Scope and how this becomes binding

This Data Processing Agreement (the "DPA") is entered into between Respira, operated by Mihai Dragomirescu, established in Brașov, Romania ("Respira", "Processor"), and the customer identified in the applicable subscription or order ("Customer", "Controller"). It forms part of, and is governed by, the Terms of Service (the "Agreement").

This DPA applies to the extent Respira processes personal data on the Customer's behalf in the course of providing Respira for WordPress, the Respira MCP server, the Respira dashboard, and related add-ons (together, the "Service"), and to the extent Regulation (EU) 2016/679 ("GDPR") or the UK GDPR applies to that processing.

The Customer accepts this DPA by written notice to word@respira.press identifying the account it applies to. No counter-signature is required for it to take effect, and a counter-signed copy is available on request at no charge. Where the Customer has its own DPA or an executed Article 28 agreement with Respira, that document prevails over this one to the extent of any conflict.

If a term here does not work for your organisation, say which one and why. A single operator can amend a contract faster than a company can, and most requests are reasonable.

2. Roles of the parties

The parties have distinct roles depending on the data in question, and it is worth being precise rather than blanket-labelling everything.

  • Respira as processor. For personal data contained in or reachable through the Customer's connected WordPress sites, and for material the Customer submits through support, Respira acts as processor on the Customer's documented instructions.
  • Respira as controller. For the Customer's own account data, being the data needed to create and administer the account, authenticate users, bill the subscription, secure the Service, and meet Respira's legal obligations, Respira acts as controller. That processing is described in the Privacy Policy rather than governed by this DPA.
  • Customer as controller. The Customer determines the purposes and means of processing carried out through the Service, including which sites are connected, which agents are authorised, and what those agents are instructed to do.

Where the Customer is itself a processor acting for its own client, for example an agency operating a site on behalf of an end customer, Respira acts as sub-processor and this DPA applies as though references to the Controller were references to that client, with the Customer warranting it has the authority to enter into it.

3. Subject matter, duration, nature and purpose

Required by Article 28(3). The full description is in Annex I. In summary:

  • Subject matter. Provision of the Service: connecting AI agents to the Customer's WordPress sites, and reading, creating and modifying content on those sites at the Customer's direction.
  • Duration. The term of the Agreement, plus the retention periods in clause 12.
  • Nature and purpose. Hosting, transmission, structured transformation, storage of operational metadata, diagnostics, and support.
  • Where the Customer's site content lives. Content of a connected WordPress site is processed by the Respira plugin on the Customer's own server, and page snapshots taken before an edit are stored in the Customer's own WordPress database. That content is not routinely transmitted to or stored by Respira. It reaches Respira only where the Customer sends it in a support request, or where it appears incidentally in an error diagnostic.

4. Processing on documented instructions

Respira processes personal data only on the Customer's documented instructions, including for international transfers, unless required to do otherwise by Union or Member State law, in which case Respira will inform the Customer of that requirement before processing unless the law prohibits it on important grounds of public interest.

The Agreement, this DPA, the Customer's configuration of the Service, and the calls the Customer's authorised agents and users make through it together constitute the Customer's documented instructions.

For the avoidance of doubt, instructions issued by an AI agent that the Customer has connected and authorised are the Customer's instructions. The Customer is responsible for what it authorises an agent to do, for the scope it grants that agent, and for reviewing the result. Respira provides access profiles and per-tool permission controls, approval workflows, snapshots, and an audit log as the means to exercise that control, and recommends they be configured before granting write access to a site containing personal data.

Respira will inform the Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law.

5. Confidentiality

Respira ensures that persons authorised to process personal data are bound by an appropriate duty of confidentiality, and limits access to those who need it to provide the Service, to support the Customer, or to meet a legal obligation.

Respira is operated by a single person. Access to production data is therefore held by that person and by the sub-processors listed in Annex III, and by no one else.

6. Security of processing

Respira implements appropriate technical and organisational measures under Article 32, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects. The measures in force are listed in Annex II.

Respira may update those measures over time provided the update does not materially reduce the overall level of security. Annex II is maintained as the current statement of measures rather than a frozen snapshot.

7. Sub-processors

The Customer gives general written authorisation for Respira to engage sub-processors, subject to this clause.

  • The sub-processors engaged as at the date of this DPA are listed in Annex III, and the same list with fuller detail per vendor is maintained publicly at the Trust Center.
  • Respira imposes on each sub-processor data protection obligations no less protective than those in this DPA, by written contract, and remains fully liable to the Customer for the performance of that sub-processor's obligations.
  • Respira will give the Customer at least 30 days' notice before adding or replacing a sub-processor. To receive that notice, email word@respira.press asking to be added to the sub-processor notification list.
  • The Customer may object to a new sub-processor on reasonable data protection grounds within that 30 day period. The parties will discuss the objection in good faith. If it cannot be resolved, the Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of any prepaid fees for the unused remainder of the term.

8. International transfers

Respira is established in Romania and the Service's primary data store is located in the European Union (Frankfurt). The default position is therefore that personal data stays in the EEA.

Where a sub-processor listed in Annex III processes personal data outside the EEA, that transfer is made under the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, incorporated by reference into the relevant sub-processor agreement, together with any supplementary measures identified as necessary by a transfer impact assessment. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum applies to those clauses.

The processing region of each sub-processor is stated in Annex III and on the Trust Center.

9. Assistance with data subject rights and Articles 32 to 36

Taking into account the nature of the processing, Respira assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests to exercise rights under Chapter III of the GDPR, being access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making.

Where a data subject contacts Respira directly regarding data processed on the Customer's behalf, Respira will not respond to the substance of the request. It will refer the data subject to the Customer and notify the Customer without undue delay.

Respira also assists the Customer in ensuring compliance with Articles 32 to 36, covering security of processing, breach notification, data protection impact assessments, and prior consultation, taking into account the nature of processing and the information available to Respira.

This assistance is provided at no additional charge, except where a request is manifestly unfounded, excessive, or repetitive, in which case Respira may charge a reasonable fee notified in advance.

10. Personal data breach

Respira notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed on the Customer's behalf.

The notification describes the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Where the full picture is not available within 72 hours, Respira provides what is known and follows up in phases rather than delaying the first notification.

Notification is sent by email to the account contact and, where the breach is not confined to a single account, posted publicly on the Trust Center.

11. Audit and information

Respira makes available to the Customer the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.

In practice, and proportionate to a single-operator service, this means:

  • The published Trust Center and Annex II of this DPA are the standing documentation of measures and sub-processors, and are kept current.
  • Respira responds to a written security questionnaire or information request once per twelve month period at no charge, within 30 days.
  • An on-site or remote inspection may be conducted on 30 days' written notice, no more than once per twelve month period unless a breach or a supervisory authority requires otherwise, during business hours, subject to confidentiality undertakings, and conducted so as not to disrupt the Service or compromise the confidentiality of other customers' data. The Customer bears its own costs and Respira's reasonable costs for inspections beyond the annual questionnaire.

Respira does not hold a SOC 2 or ISO 27001 certification and does not claim one. The documentation above is offered in place of an audit report, and this is stated plainly so that it is not discovered late in a procurement process.

12. Return and deletion

On termination or expiry of the Agreement, Respira deletes or returns all personal data processed on the Customer's behalf, at the Customer's choice, and deletes existing copies, unless Union or Member State law requires storage.

  • Export. The Customer may request a machine-readable export of its account, sites, telemetry and billing history at any time during the term and for 30 days afterwards.
  • Deletion. Absent an export request, active data is deleted within 30 days of termination, and residual copies in backups age out within a further 30 days under the backup rotation described in Annex II.
  • Retained by law. Billing and transaction records are retained for the period required by Romanian and EU accounting and tax law. Those records are retained for that purpose alone.
  • Content on the Customer's own site. Content and snapshots stored in the Customer's WordPress database are under the Customer's control and are not deleted by Respira. Deactivating the plugin leaves them in place.

13. General

  • Order of precedence. In the event of conflict, this DPA prevails over the Agreement in respect of the processing of personal data.
  • Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, to the extent permitted by applicable law. Nothing here limits any liability that cannot be limited by law, including a data subject's rights under Article 82.
  • Changes. Respira may update this DPA where required by law, by a supervisory authority, or to reflect a change in the Service. Material changes are notified by email to accounts that have accepted it, at least 30 days before they take effect.
  • Governing law. This DPA is governed by the laws of Romania, and the courts of Brașov, Romania have exclusive jurisdiction, without prejudice to any mandatory jurisdiction under applicable data protection law.
  • Contact. word@respira.press for anything in this document, including acceptance, the sub-processor notification list, a security questionnaire, or a counter-signed copy.

Annex I · Description of processing

Categories of data subjects.

  • The Customer's personnel and authorised users of the Service.
  • Individuals whose personal data appears in the content of a connected WordPress site, to the extent that content is transmitted to Respira in a support request or an error diagnostic. Depending on the site, this may include the Customer's own registered users, commenters, customers, or newsletter subscribers.

Categories of personal data.

  • Identification and contact data: name, email address.
  • Account and authentication data: user identifier, authentication tokens, API keys, plan and subscription state.
  • Connection metadata: site URL, WordPress and plugin versions, active page builder, server capability information.
  • Usage and audit data: tool calls made, timestamps, outcome and error state, and entries in the audit log recording which agent performed which action.
  • Diagnostic data: stack traces, request paths and status codes, with PII scrubbing applied by default.
  • Billing data: billing name, address, and payment method tokens, held by the payment processor.
  • Support content: whatever the Customer chooses to include in a support request.

Special categories of data.

The Service is not designed for, and the Customer should not deliberately route, special category data under Article 9 or criminal conviction data under Article 10. Where such data exists in the content of a connected site, it is processed on the Customer's own server as described in clause 3, and the Customer remains responsible for the lawfulness of that processing.

Frequency. Continuous for the duration of the Agreement.

Duration. The term of the Agreement plus the retention periods in clause 12.

Annex II · Technical and organisational measures

The measures in force under Article 32, and the current state of each.

  • Encryption. TLS 1.3 in transit. AES-256 at rest on the primary data store.
  • Data residency. Primary database, authentication and file storage in the European Union (Frankfurt, eu-central-1).
  • Access control. Authorisation enforced at the database layer through Postgres Row-Level Security, with reads scoped to the authenticated user unless an explicit administrative gate applies. Authentication by magic link or OAuth.
  • Agent scoping. Access profiles and per-tool permission switches, enforced server-side at the same chokepoint for both the REST layer and the abilities handler, so a client cannot bypass them by ignoring the advertised tool list.
  • Change integrity. Page snapshots taken before builder writes, approval workflows for live edits, and write receipts reporting whether stored data actually changed.
  • Audit logging. Actions recorded in an append-only audit log, each row sealed with an HMAC chained from the previous row so that editing or deleting a row is detectable at that row. Chain verification is available on demand.
  • Secret management. Secrets held in environment configuration, never shipped in client bundles, rotated quarterly.
  • Backups and recovery. Daily point-in-time recovery with 30 day retention on the primary database.
  • Monitoring. Error and reliability events collected in the EU region with PII scrubbing enabled by default. Uptime monitoring on public endpoints.
  • Data minimisation. Recorded per sub-processor in Annex III and published per vendor on the Trust Center, stating the smallest set of personal data each one receives.
  • Pseudonymisation. Analytics identifiers are the account's opaque user identifier rather than direct identifiers where the vendor supports it. Session replays mask input fields.

Annex III · Authorised sub-processors

Current as of August 5, 2026. This annex is generated from the same source as the Trust Center table and the processor list in the Privacy Policy, so the three cannot disagree.

  • Supabase · Auth, primary Postgres, file storage, edge functions.
    Region: EU (Frankfurt, eu-central-1) · Transfer safeguard: SCCs 2021/914
    Data received: Email, hashed password, user metadata (preferences), license records, telemetry events. No payment data (handled by LemonSqueezy / Polar).
  • Vercel · Hosting, edge network, serverless function execution.
    Region: EU + global · Transfer safeguard: SCCs 2021/914
    Data received: Request headers (IP, UA, country), routing metadata. No request bodies stored beyond function log retention (24h on the hobby tier, 7d on Pro).
  • Google Analytics 4 · Aggregate page-view + event analytics.
    Region: Global (with EU IP truncation) · Transfer safeguard: SCCs 2021/914
    Data received: Truncated IP, user agent, anonymised client id, page path, event name, optional user_id (Supabase UUID) when logged in.
  • PostHog · Product analytics inside the dashboard.
    Region: EU (eu.i.posthog.com) · Transfer safeguard: SCCs 2021/914
    Data received: Distinct id = Supabase user UUID, email, plan tier, is_trial. Inputs masked in session replays. No payment data, no chat content.
  • Customer.io · In-app messaging and journeys.
    Region: EU · Transfer safeguard: SCCs 2021/914
    Data received: Anonymous visitor id (cookie-bound) or email when logged in. Message impressions, clicks. No content payloads beyond what is needed for delivery.
  • Chatwoot · Live chat support widget.
    Region: EU (Chatwoot self-hosted) · Transfer safeguard: SCCs 2021/914
    Data received: Visitor identifier, chat transcript, optional email if you start a conversation. Inactive sessions purge.
  • Resend · Transactional and broadcast email delivery.
    Region: EU · Transfer safeguard: SCCs 2021/914
    Data received: Recipient email, subject, body, delivery + open + click events. Bodies retained 14 days.
  • Polar · Payment + subscription billing.
    Region: EU · Transfer safeguard: SCCs 2021/914
    Data received: Billing email, billing address, payment method tokens. No browser cookies on respira.press.
  • Anthropic · Marketing copy generation, plus AI-assisted engineering and support.
    Region: US (with EU SCCs) · Transfer safeguard: SCCs 2021/914
    Data received: Marketing generation sends product and release text only, with no user identifiers. Support and engineering sessions see only the records needed for the ticket in hand: typically an account email, plan, site list, and error detail. No payment card data, and no content from your WordPress site unless you send it in a ticket yourself.
  • Google (Gemini API) · Image generation for social and marketing visuals.
    Region: Global (with EU SCCs) · Transfer safeguard: SCCs 2021/914
    Data received: A text prompt describing the visual, plus brand assets. No user identifiers, no customer data.
  • OpenAI · Fallback image generation for social and marketing visuals.
    Region: US (with EU SCCs) · Transfer safeguard: SCCs 2021/914
    Data received: A text prompt describing the visual. No user identifiers, no customer data.
  • Sentry · Error tracing and reliability monitoring.
    Region: EU (de.sentry.io) · Transfer safeguard: SCCs 2021/914
    Data received: Stack traces, breadcrumbs, request metadata (path, status). Email + user_id only when explicitly attached to a captured exception.
  • Frankfurter (ECB) · USD → EUR FX rate for the Earn page.
    Region: EU · Transfer safeguard: not applicable, EU processing
    Data received: None. Server-side only, requests a public exchange-rate JSON.

Retired. The following receive no new personal data. They are listed because records they still hold remain within the scope of an access or erasure request.

  • LemonSqueezy · Retired. Legacy payment and subscription billing.
    Region: Global · Historic records only: billing email, name, billing address, and payment method tokens from orders placed before the move to Polar. No new data is sent. Raw card numbers were never held here.
Summarize with Google AI Mode
Independent · respira.press · v8.5 shipped

The AI infrastructure layer for WordPress.

One protocol. Plugin, MCP server, CLI, and SDK, so any AI tool you already use can edit, ship, and roll back changes on a real WordPress site, safely.

/plugin /mcp /cli /cowork /sdk /tools /skills
N · 0° S · 180° W · 270° E · 90°
  • 2,227
    Connected sites
  • 17 builders
    Page-builder coverage
  • 100%
    Snapshot · roll back
  • EU·FFM
    Data-resident
Respira Respira for WordPress

The AI infrastructure layer for WordPress, open, neutral, ecosystem-friendly.

Start free
Product /01
  • Plugin
  • Earn
  • Claude Cowork Plugin
  • Inhale: MCP Abilities Free
  • Respira ARC Free
  • WooCommerce Add-on
  • MCP Server
  • Tools Catalog
  • CLI
  • SDK
  • Skills Marketplace
  • ADA & WCAG Scanner
  • Pricing
  • Roadmap Live
  • Reviews
  • Releases
  • Book a call
Documentation /02
  • Getting Started
  • Prompt Book New
  • Installation Guide
  • Page Builders
  • CLI Docs
  • MCP Explained
  • Release Notes
  • Blog
  • Support ↗
Builder MCPs
  • Gutenberg
  • Elementor
  • Divi
  • Bricks
  • WPBakery
  • Oxygen
  • Beaver Builder
  • Breakdance
  • Flatsome
Resources /03
  • What is MCP?
  • WooCommerce MCP Comparison
  • For AI Agents
  • Case Studies
  • Press kit
Guides
  • Edit WordPress with AI, safely
  • AI WordPress for agencies
  • AI WordPress for freelancers
  • Connect multiple sites
  • Fix accessibility with AI (ADA/WCAG)
  • The recovery half of agentic WordPress
Reading
  • Respira vs the official WooCommerce MCP
  • WordPress.com AI & Respira
  • Working with Elementor AI
  • Respira & CodeWP
  • All Articles
Community /04
  • Discord ↗
  • Slack ↗
  • GitHub Hub ↗
  • Discussions ↗
  • Community
  • Wiki ↗
  • Affiliates / Partners
  • npm Package ↗
  • Read the Manifesto
▢ Respira Ecosystem
  • respira.cafe
  • itworks.now
  • centerstudio.io New
Latest from the blog
  • Aug 3
    Your AI forgets your site every session. Resonance remembers. Every Respira site now carries a persistent memory for AI agents: conventions the agent honors in every session, and rules the plugin enforces at the write path. It also reads the Knowledge experiment WordPress core is building toward, on real production sites today.
  • Jul 29
    How to check and fix wp2shell in WordPress (CVE-2026-60137 and CVE-2026-63030) The exact affected WordPress versions, what updating does and does not prove, which compromise indicators deserve investigation, and how Respira 8.1 turns a fleet scan into an approval-gated fix and verification receipt.
  • Jul 28
    MCP 2026-07-28 is final. What changes for WordPress and Respira? The stable specification removes protocol sessions, adds server discovery, hardens authorization, and formalizes extensions. Respira 8.1 implements it with a tested legacy path, while Webflow MCP 2.0 shows why production governance matters.
  • Jul 27
    How to edit your WordPress site from Slack with Viktor Add your WordPress site or WooCommerce store to Viktor as a custom MCP server and edit it by typing a message in Slack or Microsoft Teams. Step by step, with the exact link to paste, the access levels worth thinking about, and the shared-channel setup for agencies working with clients.
  • Jul 26
    Respira 8.0 Canopy brings Full Site Editing to AI assistants Canopy adds native WordPress Full Site Editing, now usually called the Site Editor, alongside sixteen page builders: block templates, synced patterns, navigation and design tokens. It also fixes two bugs found by auditing the safety layer itself.
  • Jul 19
    Best WordPress MCP servers in 2026: a practical comparison A WordPress MCP server lets an AI assistant read and edit your live site. What actually separates the options in 2026: builder coverage, safety and recovery, connection paths, and hosting model.

Independent AI infrastructure for WordPress. Not affiliated with Automattic or WordPress.org.

© 2026 Respira Privacy · Terms · Security · Trust Center · Fair Usage · Disclaimer · Made in Europe
Lines of code updated through Respira

10,803,283

Aggregate telemetry across 2,228 connected WordPress sites, counted from signed tool events and deduplicated by operation ID. Your content never leaves your server.

Progress → 11,000,000

196,717 lines to next milestone

Respira icon Respira for WordPress
Public live telemetry

The independent AI infrastructure layer for WordPress. Duplicate-first, audited, privacy-preserving.

v8.5.7 · shipped Aug 4, 2026
Pages

166,187

Created3,463 Edited166,187 +2,005 / 24h
Posts

21,075

Created5,531 Edited21,075 +353 / 24h
Sites connected

2,228

 
MCP events

268,060

Since Mar 7268,060 +3,190 / 24h

Usage trends

Last 45 days · pages · posts · lines (×100)
Lines (×100) Pages Posts

AI tools editing WordPress

268,060 MCP events
Tracked since March 7, 2026 · 2,228 sites
Claude Code Claude Code
75%
97,037 events
Claude Desktop Claude Desktop
8%
9,729 events
Claude Cowork Claude Cowork
7%
8,611 events
Cursor Cursor
6%
7,258 events
Codex Codex
4%
5,007 events
Windsurf
<1%
579 events

Page builders

Builder presence across sites
Elementor 614 26%
Divi 487 21%
Beaver Builder 360 15%
Gutenberg 163 7%
Bricks 130 6%
Breakdance 105 5%
Oxygen 80 3%
WPBakery 63 3%
Flatsome Ux Builder 49 2%
Kadence Blocks 28 1%
Spectra 22 1%
Wpbakerytagdiv 12 1%
Seedprod 10 0%
Thrive Architect 9 0%
Generateblocks 8 0%
Brizy 7 0%
Kadenceblocks 2 0%
Greenshift 1 0%
Wpbakery Tagdiv 1 0%
Not detected 181 8%

Not detected = no recognized builder.

Global activity

Global activity — last 53 weeks.

Each cell = one day of MCP events across all connected sites · UTC

Streak—days
Best day—events
Today—events
MonWedFri
Less More See full telemetry →
Telemetry is counted from signed tool events and deduplicated by operation ID, refreshed every 60 seconds. Respira never reads or transmits your WordPress content. Only operation outcomes.
All systems normal If you read all the dots, we should probably talk. cal.com/mihai-love
cookies. the legal kind. one click and i'll get out of your way.

what you'd actually be saying yes to

tune your cookie preferences

essentials stay on regardless. the rest is opt-in. nothing fires until you tap save.

  • essentials

    the cookies that make logging in work and remember which partner sent you. switching these off would just break the site, so the law does not let me make you opt out.

    always on
    10 vendors listed
    • Supabase EU (Frankfurt, eu-central-1) sb-*-auth-token DPA →
    • Vercel EU + global server-side only DPA →
    • Resend EU server-side only DPA →
    • LemonSqueezy Global server-side only DPA →
    • Polar EU server-side only DPA →
    • Anthropic US (with EU SCCs) server-side only DPA →
    • Google (Gemini API) Global (with EU SCCs) server-side only DPA →
    • OpenAI US (with EU SCCs) server-side only DPA →
    • Sentry EU (de.sentry.io) server-side only DPA →
    • Frankfurter (ECB) EU server-side only
  • analytics

    ga4 plus posthog on marketing and dashboard pages. i count pageviews, cta clicks and where things break. anonymous beyond your supabase user id.

    2 vendors listed
    • Google Analytics 4 Global (with EU IP truncation) _ga, _ga_F55E0B1KNX DPA →
    • PostHog EU (eu.i.posthog.com) ph_* DPA →
  • attribution

    first-touch source on a /respira_acq cookie, plus a flag if an ai chatbot referred you. helps me figure out what is working without turning you into a tracking pixel statue.

  • messaging

    customer.io for in-app notes, chatwoot when you click the support bubble. off by default. on means i can actually answer you in the app.

    2 vendors listed
    • Customer.io EU _cio* DPA →
    • Chatwoot EU (Chatwoot self-hosted) cw_* DPA →

full sub-processor list and how each piece of data is used: trust center · cookie policy

See What AI Says

LLM-ready prompts about Respira MCP + WebMCP

Ask your favorite AI

Opens in a new tab. These prompts are designed to teach LLMs what Respira can do.

Question copied! Paste it in Gemini