Data, privacy and retention
Exactly what leaves your server, what is stripped before it does, and how long anything is kept.
The short version: ChangeTrace collects what changed and what it cost you, not who your customers are. Nothing at all is sent before you connect.
What gets sent
Plugin activated, deactivated, updated or deleted (name and version, with from → to on an
update); theme changed; WordPress core updated; PHP version changed.
What is stripped before sending
All of this happens on your server, before anything travels:
- Around forty sensitive key names are replaced with
[redacted]— password, secret, token, authorization, api_key, cookie, nonce, cvv, ssn, credit_card, card_number, iban, email, phone, first_name, last_name, address, postcode, dob, form_data, form_values and more, matched recursively through nested data. - Email addresses inside text become
[redacted-email]. - Runs of 12 or more digits become
[redacted-number]. - URLs lose their query string and fragment.
- Everything is size-capped — 8 KB per event, 2,048 characters per value.
Uptime checks
Alongside the plugin, ChangeTrace requests your homepage every five minutes from outside your hosting, identifying itself in the user agent. It stores the status code and what the failure looked like — not the page content.
Performance measurement
On paid plans, ChangeTrace measures your public pages with Google PageSpeed Insights. Your page URL is sent to Google as part of that. Nothing runs in your visitors' browsers. Performance impact →
AI
Nothing is sent to an AI provider unless you press a button. When you do, the evidence for that incident is sent to the configured provider.
With ChangeTrace AI, that is ChangeTrace's provider. With your own key, it is your provider, under your agreement with them.
How long things are kept
| Data | Kept for |
|---|---|
| Events and metrics | Your plan's window — 7 days on Free |
| Uptime check history | 30 days |
| Raw performance samples | 30 days |
| Incidents and ranked causes | Not automatically deleted |
| AI conversations | Not stored at all |
Deletion runs nightly at 3:00 AM UTC and is unconditional — it is both a plan feature and the mechanism that stops data accumulating forever.
Your rights and controls
Stop collection — disconnect or deactivate the plugin. Effective immediately.
Delete your data — delete the site in the dashboard. Permanent, and removes events, metrics, incidents and uptime history.
Remove it from WordPress — deleting the plugin clears every option it stored, both scheduled jobs, and the stored token.
Privacy policy text — the plugin registers suggested wording under Settings → Privacy → Policy Guide, which you can paste into your own policy.
Personal data
The plugin does not export or erase visitor personal data through WordPress's privacy tools, because it does not store any. Customer identities never leave your server.
Where your data lives
Sent over HTTPS to ChangeTrace's API. Your site token is stored on your site and only ever sent as an authorization header; ChangeTrace keeps a hash of it, never the token itself.

