LEGAL
Privacy Policy
What data Respira collects, what stays on your WordPress site, and how your data rights work under the GDPR. Respira is established in the EU, so this is the baseline rather than a regional variant.
Quick navigation
1. Introduction
This Privacy Policy explains what Respira for WordPress and Respira AER collect, what stays on your WordPress site, how the direct MCP and hosted AER paths differ, how we use data, and your GDPR rights.
We aim to keep this policy clear and practical.
2. Data Flow at a Glance
2.1 Direct plugin and MCP connections
- Your actual page/post content and code.
- Your database content and most site-specific data.
- Theme and plugin internals unless explicitly transmitted by your own actions.
When your own AI client calls the MCP endpoint on your WordPress site, the conversation and the WordPress content returned by tools do not pass through Respira's servers. Respira still processes account and licensing data and, when you use browser sign-in, OAuth authorization metadata.
2.2 Respira AER, the hosted workspace
Respira AER is a different data path. To keep threads, continue runs, show receipts and support cloud hand-off, AER processes and stores the prompts, attachments, selected site context, tool calls and tool results used in the workspace. This data is scoped to your Respira account. AER sends the prompt and context needed for a run to the AI provider you select under that provider's terms and privacy policy.
Provider API keys saved for AER are encrypted at rest and decrypted only for a run. Respira does not sell conversation data or use customer prompts, attachments or WordPress content to train AI models.
2.3 What We Collect
- Account identifiers (such as email).
- License and plan data for paid accounts.
- Site connection metadata (for licensing and account management).
- Operational telemetry (for example, counts of actions and diagnostics).
- When you use AER: threads, attachments, tool activity, run records, approvals and the site context returned for the run.
2.4 Third-Party AI Services
If you connect AI tools (such as ChatGPT, Claude, Cursor, Windsurf, or similar), prompts/content you send to those services are handled under their terms and privacy policies, not ours.
You control what you send and are responsible for complying with those third-party AI service terms.
3. Information We Collect
3.1 Information You Provide
- Account details (email and profile details you choose to provide).
- License and billing identifiers for paid plans.
- Site URL and activation metadata needed to manage your plan.
- AER prompts, files, provider credentials and workspace settings when you choose to use AER.
3.2 Automatically Collected Information
- Usage telemetry (for example counts of page/post operations and similar aggregate signals).
- Error and diagnostics logs needed to keep the service reliable and secure.
- Security and access logs for abuse prevention.
The distinction matters: the direct plugin and MCP route does not send conversations or WordPress content through Respira. Respira AER is a hosted workspace and does process the prompts, attachments and site data a run needs.
In either route, content you choose to give an AI provider is governed by that provider's terms and privacy policy. Use direct MCP when keeping Respira out of the content path is the priority.
4. How We Use Information
- Provide authentication, licensing, and account features.
- Run AER threads, tool calls, approvals, receipts, background work and requested reports.
- Operate and improve platform reliability and support.
- Detect abuse, fraud, and security issues.
- Provide customer support and critical service communications.
- Meet legal and regulatory obligations.
5. Processors and Third-Party Services
We use trusted service providers to run Respira. These providers process data on our behalf for specific purposes:
- Supabase: Auth, primary Postgres, file storage, edge functions. EU (Ireland, eu-west-1)
- Vercel: Hosting, edge network, serverless function execution. EU + global
- Google Analytics 4: Aggregate page-view + event analytics. Global (with EU IP truncation)
- Reddit Ads: Ad conversion measurement for Respira's Reddit campaigns. US
- PostHog: Product analytics inside the dashboard. EU (eu.i.posthog.com)
- Customer.io: In-app messaging and journeys. EU
- Chatwoot: Live chat support widget. EU (Chatwoot self-hosted)
- Resend: Transactional and broadcast email delivery. EU
- LemonSqueezy (retired): Retired. Legacy payment and subscription billing. Global
- Polar: Payment + subscription billing. EU
- Anthropic: Customer-selected AER inference, marketing generation, and AI-assisted engineering and support. US (with EU SCCs)
- Google (Gemini API): Customer-selected AER inference and image generation for social and marketing visuals. Global (with EU SCCs)
- OpenAI: Customer-selected AER inference and fallback image generation for social and marketing visuals. US (with EU SCCs)
- OpenRouter: Optional customer-selected routing for AER model inference. Global (EU-only routing is an enterprise option)
- ElevenLabs: Sage, the support agent on the website and dashboard. US (with EU SCCs)
- Sentry: Error tracing and reliability monitoring. EU (de.sentry.io)
- Frankfurter (ECB): USD → EUR FX rate for the Earn page. EU
Analytics and messaging providers in that list only process data where you have consented, via the cookie preferences widget. A retired provider receives no new data; it stays listed because historic records it still holds are within scope of an access or erasure request.
This list is generated from the same source as the Trust Center, so the two cannot drift apart. The Trust Center carries the fuller detail per provider: processing region, cookies set, lawful basis, SCC posture, and the DPA on file with its date.
If Respira processes personal data on your behalf and your organisation needs an Article 28 processor agreement, the Data Processing Agreement is published in full.
6. Data Retention
We keep personal and operational data only as long as needed for service delivery, security, legal obligations, and legitimate business operations.
- Paid plans: Extended retention for operational history where applicable.
- AER threads: Stored so you can return to the workspace. Deleting a thread removes its active stored conversation; account-deletion requests cover the account's AER data, subject to security, backup and legal retention requirements.
Retention periods can be adjusted for legal compliance, fraud prevention, or support obligations.
7. Your Rights (GDPR and Similar Laws)
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or export your personal data.
To request deletion or exercise your rights, email word@respira.press.
We aim to respond within 30 days for standard GDPR requests, unless a lawful exception applies.
8. Security
We use technical and organizational safeguards to protect data in transit and at rest.
No system is perfectly secure. You are also responsible for securing your own devices, WordPress admin accounts, API keys, and hosting environment.
9. Cookies and Tracking
Respira groups every cookie and tracking technology into four categories. EU / EEA / UK visitors see a consent widget at the bottom-right of the screen before any non-essential category fires; visitors outside that region can open the same widget at any time via the "Cookie preferences" link in the footer.
- Essentials: always on. Supabase auth tokens
(
sb-*-auth-token), affiliate attribution (respira_aff,ls_aff), and the session middleware that keeps you signed in. These can't be switched off because the site wouldn't work without them. - Analytics: opt-in. Google Analytics 4
(
_ga,_ga_F55E0B1KNX) on every page plus PostHog (ph_*) on marketing and dashboard pages only. Anonymous-ish session counts so we can tell which pages work. - Attribution: opt-in. The
respira_acqfirst-touch cookie plus an ai-referral flag. Tells us whether a chatbot, newsletter, or post brought you here, without tying it to identifiable session data. This category also covers the Reddit pixel (_rdt_uuid,rdt_cid), which measures visits, sign-ups and purchases that came from a Reddit ad. For a sign-up or purchase, Respira's server also reports the conversion to Reddit with a SHA-256 hash of your email address and account id, your IP address and browser user agent. In the EU, EEA and UK none of this is sent unless you turn the attribution category on. - Messaging: opt-in. Customer.io
(
_cio*) for in-app messages and Chatwoot (cw_*) for live chat support. Off by default; on means we can answer you in the app.
The complete sub-processor list with regions, retention, and data-processing addenda lives at /trust-center. Manage your choices any time via the footer link or directly through your browser.
10. International Transfers
Where data is transferred across borders, we use appropriate safeguards required by applicable law.
11. Children
The service is not intended for children under 18, and we do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this policy over time. Material updates are published on this page with a new "Last updated" date.
13. Contact
Service provider: Respira for WordPress, operated by Mihai Dragomirescu (Brașov, Romania).
- Email: word@respira.press
- Website: https://www.respira.press