Skip to main content
Login Join
Legal

Privacy Policy

What data we collect, how we use it, and how you can get a copy or delete it.

Last updated: April 24, 2026

This Privacy Policy explains what data WPFolks collects about you, how we use it, who we share it with, and what rights you have over it.

We’ve tried to write this in plain English. Where legal terms are necessary, we’ve kept them as short as possible.

Who we are

WPFolks (“WPFolks”, “we”, “us”, or “our”) is a free community platform for WordPress people, operated by Ankit Panchal, an individual based in Pune, India.

You can reach us at hello@wpfolks.org for any privacy-related question, request, or complaint.

What data we collect

Data you give us

Data we collect automatically

Data from third parties

Why we process your data (and on what legal basis)

Under the GDPR (and similar laws), we can only process your personal data when we have a lawful basis. Ours are:

What we doWhyLawful basis
Create and maintain your accountTo give you the service you signed up forContract (Art. 6(1)(b) GDPR)
Display your profile publiclyPlatform requires public profiles by designContract + Legitimate interest
Send transactional emails (welcome, password reset, verification)Essential service communicationContract
Send the weekly newsletterYou opted inConsent (Art. 6(1)(a) GDPR)
Prevent spam and abuseProtect the community and platformLegitimate interest
Analytics and product improvementUnderstand what’s usefulLegitimate interest (opt-out available)
Moderate contentEnforce our Community GuidelinesLegitimate interest
Respond to legal requestsComply with lawLegal obligation

You can withdraw consent for anything consent-based at any time (see Your rights below).

Who we share data with

We do not sell your personal data, ever. We share it only with:

Service providers (sub-processors)

These are the companies we use to run WPFolks. Each is bound by a data-processing agreement:

ProviderWhat they handleLocation
WordPress.com (Atomic) / hosting providerSite hosting, database, file storageGlobal CDN + US data centers
Brevo (sendinblue.com)Transactional emails, newsletter deliveryFrance / EU
Google AnalyticsUsage analytics

We review sub-processors annually. If we change a sub-processor, we’ll update this page.

Other people who can see your data

International data transfers

WPFolks is operated from India, and uses service providers located in the European Union, United States, and globally (via CDN). If you are an EU/EEA or UK resident, your data may be transferred to countries outside your home region.

We rely on Standard Contractual Clauses (SCCs) published by the European Commission to protect these transfers where required.

How long we keep your data

Data typeRetention
Active account dataFor as long as your account is open
After account deletionPermanently deleted within 30 days, except legal-obligation records (see below)
Server / security logs90 days
Financial or legal records (if any)7 years (legal requirement)
Deleted content in the feedRemoved immediately from public view; purged from backups within 35 days
BackupsRolling 30-day encrypted backups

When you delete your account, your submissions (plugins, events, resources) remain visible but are re-attributed to “Deleted member.” Your feed posts and comments are replaced with your username showing as “Deleted member.” This preserves the community history while removing your personal identifiers.

Your rights

Depending on where you live, you have some or all of these rights:

To exercise any right, email hello@wpfolks.org from the email address on your account. We respond within 30 days.

EU / EEA / UK residents: you can also file a complaint with your local data protection supervisory authority. We’d appreciate the chance to resolve it first, but the choice is yours.

California residents (CCPA/CPRA): you have specific rights under California law, including the right to know, delete, correct, and opt-out of sale/share of personal information. We do not sell or share personal information as defined under CCPA.

India residents (DPDP Act, 2023): you have rights under India’s Digital Personal Data Protection Act, including the right to access, correction, erasure, and grievance redressal.

Cookies

We use a small number of cookies. Here’s the full list:

NamePurposeDurationCategory
wordpress_logged_in_*Keeps you signed inSession + 14 daysEssential
wp-settings-*Remembers your admin preferences1 yearEssential
wpfolks_community_notice_v2Remembers that you dismissed a notice1 yearEssential

Essential cookies are always on (the site doesn’t work without them). WPFolks uses only essential cookies necessary to operate the platform. We do not use tracking or analytics cookies.

You can clear cookies at any time in your browser settings.

Children

WPFolks is not intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child has given us their data, email hello@wpfolks.org and we’ll delete the account.

Security

We use TLS encryption for all traffic, bcrypt password hashing, rate-limiting on login attempts, two-factor authentication (for admin accounts), and regular dependency updates. No system is ever 100% secure, but we take this seriously.

If you discover a security issue, please email security@wpfolks.org before disclosing publicly. We aim to acknowledge reports within 48 hours.

Changes to this policy

We may update this policy. Material changes will be notified via:

Continued use after the notice period constitutes acceptance.

Contact

The WPFolks app

The WPFolks app for iOS and Android talks to this same site, so everything above applies. This section covers what is different on a phone.

Account and sign-in

The app uses the same account as the website: your name, email address, username and avatar. You can sign in three ways: email and password, Continue with Google, or Sign in with Apple. When you use Google or Apple, they tell us your name and email address so the account can be created or matched. We never see your Google or Apple password.

Location

Location is optional and the app works fully without it. If you allow it, approximate coordinates are stored on your account and used for two things: showing you folks near you, and telling you about events nearby. It is approximate on purpose, and it is never shown to anyone as a precise position.

You can turn it off at any time with the Nearby folks switch in app Settings, which stops you appearing to others. Your location is deleted when you delete your account.

Push notifications

If you allow notifications, your device gives us a push token which is stored on your account and used to deliver messages through Expo, the service that runs the app. Every type of notification can be switched off individually in the app. Tokens are removed when you sign out of a device and when you delete your account.

App sessions

Each time you sign in on a device, the app creates a named session for that device rather than storing your password. You can see every active session and revoke any of them from Settings. Revoking one signs that device out immediately.

Photos on your device

The app asks for photo library access for two reasons only: to save a Photo Directory image you chose to download, and to upload an image you chose for your profile or a post. Nothing is read from your library, scanned, or uploaded unless you pick it.

Services the app relies on

Keeping and deleting your data

Your data is kept while your account exists. You can delete your account yourself from the app or the website, without asking anyone. The account deletion page explains exactly what is removed, what stays without your name on it, and how long it takes.

Age

WPFolks is for folks aged 16 and over. The app is not directed at children and we do not knowingly collect data from anyone under 16.

Privacy questions about the app

Write to hello@wpfolks.org, or use the support page.