# Privacy Policy — release draft

**Product:** International Press Zone
**Status:** DRAFT — DATA-FLOW / LEGAL REVIEW REQUIRED
**Technical alignment review:** 2026-08-19

This file is an internal privacy-policy draft aligned to the current plugin architecture. It does not claim compliance with any law by itself. Final controller/processor roles, lawful bases, retention periods, transfer mechanisms, subprocessors, contact details, and data-subject procedures require review against the production Press.Zone service and applicable law.

## Current plugin data flows

Based on the current plugin implementation, connected features can send the following classes of data to Press.Zone:

### Connect/account flow

The plugin can send or derive information needed to connect a WordPress site, including:

- site URL/site identity;
- plugin/client identity;
- OAuth/PKCE authorization values and redirect information;
- backend-issued site identifier;
- account/subscription requests and status calls.

The backend-issued per-site credential is stored server-side in WordPress in encrypted form and is used to authenticate service requests. It is not intended to be displayed as a customer activation key.

### Translation flow

When a user invokes connected AI translation, the plugin can send selected translation material to Press.Zone, including content such as:

- title, excerpt, body, or string text selected for translation;
- source and target language;
- translation tone/options;
- request/job identifiers and site context required to process and reconcile the job.

Final privacy language must therefore not claim that post content or translations are never transmitted to Press.Zone.

### Operational requests

The plugin can make authenticated status, job, account, package/update, exception, heartbeat, or similar operational calls required by supported features. The final inventory must be verified against the production backend paired with the release candidate.

## Payment data

The plugin repository must not claim a payment processor or payment-data flow that is not live. Stripe production clearance is pending. Once cleared, final privacy text must describe the actual Stripe integration and distinguish data handled directly by the processor from data retained by Press.Zone.

## Data the final policy must enumerate

Before publication, document from production evidence:

- account profile data collected by Press.Zone;
- site identifiers/URLs and connection metadata;
- translation content and job metadata;
- usage/metering and entitlement data;
- billing/subscription metadata retained by Press.Zone;
- logs, security/audit events, IP/network metadata, and retention;
- support communications;
- cookies/session data used by the hosted Connect/account surfaces;
- every production subprocessor and transfer location/mechanism.

## Security statements

Only security controls verified in the production service should be promised. Avoid categorical or quantitative claims such as continuous monitoring, fixed incident-response times, named certifications, or encryption guarantees unless current evidence supports them.

## User/customer responsibilities

Final policy and documentation should explain that the WordPress site owner remains responsible for the content they choose to send for translation and for configuring WordPress access/permissions appropriately.

## Required approval before go-live

- [ ] Production backend data-flow inventory completed.
- [ ] Stripe/payment data flow added after production clearance.
- [ ] Subprocessor list verified from actual production vendors.
- [ ] Retention/deletion behavior verified rather than copied from historical drafts.
- [ ] Controller/processor roles and lawful bases approved by qualified privacy/legal reviewer.
- [ ] Data-subject request contact/process approved and operational.
- [ ] Published policy version/date recorded in the release receipt.
