Privacy & Data Transparency

Privacy Policy

This policy discloses exactly what data is processed by the Trust Signal Auditor WordPress plugin and the optional external api.cylvox.com Apply Fix service.

Effective Date: August 16, 2026Version: 1.0.0WordPress.org Compliant

Our Core Privacy Commitment

Minimal data footprint, no stealth tracking, no visitor profiling.

No Visitor Tracking

Zero frontend scripts or cookies placed on your visitors.

Local Execution

Audits run inside your WordPress instance without external servers.

Opt-In AI Only

Data sent to API only when you click “Apply Fix”.

1. What Data Is Collected & Processed

We distinguish strictly between the Free Local Scan and the Optional Apply Fix Service:

A. Free Core Plugin Scan

The standard diagnostic scan (auditing indexability, author bio length, display name formats, and JSON-LD schema presence) executes 100% locally on your WordPress server.

Gravatar Probe: To verify whether an author has an active avatar, the plugin issues an HTTP HEAD request directly from your server to Gravatar (https://secure.gravatar.com/avatar/[md5_hash]). Only the cryptographic MD5 hash of the author's email address is sent. No other site data, visitor data, or personal details leave your server.

B. Optional Apply Fix Service (api.cylvox.com)

When you explicitly request an AI remediation suggestion, the plugin transmits the following scoped metadata payload to https://api.cylvox.com:

  • Post / Page Title: To provide context for schema headline generation.
  • Author Display Name: To construct accurate Person schema and author bio drafts.
  • Current Schema Type: To format the recommended JSON-LD patch correctly.
🔒 Explicitly Excluded: We DO NOT collect post body text, unpublished drafts, visitor IPs, website analytics, database credentials, or WordPress administrator passwords.

2. When and How Data Is Transmitted

Data is transmitted to external servers only when all of the following conditions are met:

  1. A site administrator has entered and saved a valid API key in the plugin settings.
  2. A site administrator manually navigates to a flagged audit issue and clicks the “Apply Fix (AI)” button.

The plugin does not execute automated background calls or scheduled data synchronization to external endpoints.

3. Purpose of Processing

The payload received by api.cylvox.com is processed exclusively to generate structured remediation suggestions:

  • Synthesizing professional author bio drafts optimized for E-E-A-T clarity.
  • Synthesizing valid, Schema.org-compliant JSON-LD markup snippets (Person, Article, TechArticle).

The generated outputs are returned back to your browser session for your manual review and approval before any change is written to your WordPress database.

4. Third-Party Sub-processors & External Services

To deliver these functionalities, the following third-party service providers are utilized:

EntityRole / PurposeData TransmittedPrivacy Link
Gravatar (Automattic Inc.)Avatar image presence checkMD5 email hash onlyAutomattic Privacy
Anthropic PBCAI model inference sub-processorTitle, author name, schema typeAnthropic Privacy
Cylvox Solo StudioAPI operator & hostingAPI key, request metadataTerms of Service

5. Data Retention Policy & Zero Training Guarantee

Zero Training: We guarantee that customer request payloads (post titles, author names, or generated snippets) sent to api.cylvox.com and upstream AI sub-processors are never used to train public machine learning models.

Ephemeral Server Logs: Operational server access logs (containing IP address, API key ID, and response status codes) are retained on api.cylvox.com for a maximum of 30 days strictly for rate-limiting enforcement, abuse mitigation, and security diagnostics, after which they are permanently purged.

6. Site Owner Rights & Data Erasure Requests

As a site owner using Trust Signal Auditor, you have the right to:

  • Request immediate revocation and deletion of your API key.
  • Request deletion of any operational debug log entries associated with your API key from our server records.
  • Completely remove all local plugin data at any time by uninstalling the plugin via your WordPress admin (which deletes all local transients and options).

To submit a data deletion request, email our engineering team at hello@cylvox.com with your API key reference. Requests are processed within 48 hours.

7. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact the product maintainer:

Cylvox Solo Studio

Product: Trust Signal Auditor

Email: hello@cylvox.com

Website: https://www.cylvox.com

Paste a URL and I'll take a look.
Wisp finds the dark corners search engines skip — noindexed pages, missing bios, broken schema — and lights them up.
Homepage only · free · nothing leaves your site
Free SEO Scan