Privacy Policy
This policy discloses exactly what data is processed by the Trust Signal Auditor WordPress plugin and the optional external api.cylvox.com Apply Fix service.
Our Core Privacy Commitment
Minimal data footprint, no stealth tracking, no visitor profiling.
No Visitor Tracking
Zero frontend scripts or cookies placed on your visitors.
Local Execution
Audits run inside your WordPress instance without external servers.
Opt-In AI Only
Data sent to API only when you click “Apply Fix”.
1. What Data Is Collected & Processed
We distinguish strictly between the Free Local Scan and the Optional Apply Fix Service:
A. Free Core Plugin Scan
The standard diagnostic scan (auditing indexability, author bio length, display name formats, and JSON-LD schema presence) executes 100% locally on your WordPress server.
Gravatar Probe: To verify whether an author has an active avatar, the plugin issues an HTTP HEAD request directly from your server to Gravatar (https://secure.gravatar.com/avatar/[md5_hash]). Only the cryptographic MD5 hash of the author's email address is sent. No other site data, visitor data, or personal details leave your server.
B. Optional Apply Fix Service (api.cylvox.com)
When you explicitly request an AI remediation suggestion, the plugin transmits the following scoped metadata payload to https://api.cylvox.com:
- Post / Page Title: To provide context for schema headline generation.
- Author Display Name: To construct accurate Person schema and author bio drafts.
- Current Schema Type: To format the recommended JSON-LD patch correctly.
2. When and How Data Is Transmitted
Data is transmitted to external servers only when all of the following conditions are met:
- A site administrator has entered and saved a valid API key in the plugin settings.
- A site administrator manually navigates to a flagged audit issue and clicks the “Apply Fix (AI)” button.
The plugin does not execute automated background calls or scheduled data synchronization to external endpoints.
3. Purpose of Processing
The payload received by api.cylvox.com is processed exclusively to generate structured remediation suggestions:
- Synthesizing professional author bio drafts optimized for E-E-A-T clarity.
- Synthesizing valid, Schema.org-compliant JSON-LD markup snippets (Person, Article, TechArticle).
The generated outputs are returned back to your browser session for your manual review and approval before any change is written to your WordPress database.
4. Third-Party Sub-processors & External Services
To deliver these functionalities, the following third-party service providers are utilized:
| Entity | Role / Purpose | Data Transmitted | Privacy Link |
|---|---|---|---|
| Gravatar (Automattic Inc.) | Avatar image presence check | MD5 email hash only | Automattic Privacy |
| Anthropic PBC | AI model inference sub-processor | Title, author name, schema type | Anthropic Privacy |
| Cylvox Solo Studio | API operator & hosting | API key, request metadata | Terms of Service |
5. Data Retention Policy & Zero Training Guarantee
Zero Training: We guarantee that customer request payloads (post titles, author names, or generated snippets) sent to api.cylvox.com and upstream AI sub-processors are never used to train public machine learning models.
Ephemeral Server Logs: Operational server access logs (containing IP address, API key ID, and response status codes) are retained on api.cylvox.com for a maximum of 30 days strictly for rate-limiting enforcement, abuse mitigation, and security diagnostics, after which they are permanently purged.
6. Site Owner Rights & Data Erasure Requests
As a site owner using Trust Signal Auditor, you have the right to:
- Request immediate revocation and deletion of your API key.
- Request deletion of any operational debug log entries associated with your API key from our server records.
- Completely remove all local plugin data at any time by uninstalling the plugin via your WordPress admin (which deletes all local transients and options).
To submit a data deletion request, email our engineering team at hello@cylvox.com with your API key reference. Requests are processed within 48 hours.
7. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact the product maintainer:
Cylvox Solo Studio
Product: Trust Signal Auditor
Email: hello@cylvox.com
Website: https://www.cylvox.com