Last updated: April 24, 2026
This Privacy Policy explains what data WPFolks collects about you, how we use it, who we share it with, and what rights you have over it.
We’ve tried to write this in plain English. Where legal terms are necessary, we’ve kept them as short as possible.
Who we are
WPFolks (“WPFolks”, “we”, “us”, or “our”) is a free community platform for WordPress people, operated by Ankit Panchal, an individual based in Pune, India.
You can reach us at hello@wpfolks.org for any privacy-related question, request, or complaint.
What data we collect
Data you give us
- Account: your name, email address, username, and password (stored as a one-way hash — we can’t see your actual password).
- Profile: bio, location, skills, social links, availability-for-hire status, website URL, and anything else you choose to add.
- Content: posts, comments, plugin submissions, job listings, resource submissions, upvotes, reactions, and messages.
- Communications: anything you send us by email, contact form, or reply to our transactional emails.
Data we collect automatically
- Usage: which pages you visit, how long you stay, which features you use.
- Device: your browser, OS, device type, approximate location from IP (city-level only).
- Logs: IP address, timestamps, referring URL, and request headers. Retained for 90 days for security and abuse-prevention purposes.
Data from third parties
- WordPress.org: if you connect your wp.org account, we import your public contribution data (plugins, themes, badges, support answers, team memberships). This is all publicly available on WordPress.org; we just pull it into your WPFolks profile so you don’t have to type it out.
- Email providers: bounce notifications and unsubscribe signals from our email sender (Brevo — see sub-processors below).
Why we process your data (and on what legal basis)
Under the GDPR (and similar laws), we can only process your personal data when we have a lawful basis. Ours are:
| What we do | Why | Lawful basis |
|---|---|---|
| Create and maintain your account | To give you the service you signed up for | Contract (Art. 6(1)(b) GDPR) |
| Display your profile publicly | Platform requires public profiles by design | Contract + Legitimate interest |
| Send transactional emails (welcome, password reset, verification) | Essential service communication | Contract |
| Send the weekly newsletter | You opted in | Consent (Art. 6(1)(a) GDPR) |
| Prevent spam and abuse | Protect the community and platform | Legitimate interest |
| Analytics and product improvement | Understand what’s useful | Legitimate interest (opt-out available) |
| Moderate content | Enforce our Community Guidelines | Legitimate interest |
| Respond to legal requests | Comply with law | Legal obligation |
You can withdraw consent for anything consent-based at any time (see Your rights below).
Who we share data with
We do not sell your personal data, ever. We share it only with:
Service providers (sub-processors)
These are the companies we use to run WPFolks. Each is bound by a data-processing agreement:
| Provider | What they handle | Location |
|---|---|---|
| WordPress.com (Atomic) / hosting provider | Site hosting, database, file storage | Global CDN + US data centers |
| Brevo (sendinblue.com) | Transactional emails, newsletter delivery | France / EU |
| Google Analytics | Usage analytics |
We review sub-processors annually. If we change a sub-processor, we’ll update this page.
Other people who can see your data
- Public profiles, submissions, and posts are visible to the entire internet by design. If you don’t want something public, don’t post it.
- Moderators can see all content, including content you’ve deleted, for up to 30 days after deletion (for abuse investigations).
- Law enforcement, if we receive a legally-valid request. We publish a transparency note any time we hand over data (scrubbed to protect users’ identities where possible).
International data transfers
WPFolks is operated from India, and uses service providers located in the European Union, United States, and globally (via CDN). If you are an EU/EEA or UK resident, your data may be transferred to countries outside your home region.
We rely on Standard Contractual Clauses (SCCs) published by the European Commission to protect these transfers where required.
How long we keep your data
| Data type | Retention |
|---|---|
| Active account data | For as long as your account is open |
| After account deletion | Permanently deleted within 30 days, except legal-obligation records (see below) |
| Server / security logs | 90 days |
| Financial or legal records (if any) | 7 years (legal requirement) |
| Deleted content in the feed | Removed immediately from public view; purged from backups within 35 days |
| Backups | Rolling 30-day encrypted backups |
When you delete your account, your submissions (plugins, events, resources) remain visible but are re-attributed to “Deleted member.” Your feed posts and comments are replaced with your username showing as “Deleted member.” This preserves the community history while removing your personal identifiers.
Your rights
Depending on where you live, you have some or all of these rights:
- Access — request a copy of your data.
- Correct — ask us to fix inaccurate data.
- Delete — ask us to delete your account and data (we honor this).
- Portability — get your data in a machine-readable format (JSON export from your dashboard).
- Object — object to processing based on legitimate interest.
- Restrict — ask us to pause processing while a dispute is resolved.
- Withdraw consent — for anything you consented to (newsletter, analytics).
- Not be subject to solely automated decision-making — we don’t make consequential decisions about you via automation.
To exercise any right, email hello@wpfolks.org from the email address on your account. We respond within 30 days.
EU / EEA / UK residents: you can also file a complaint with your local data protection supervisory authority. We’d appreciate the chance to resolve it first, but the choice is yours.
California residents (CCPA/CPRA): you have specific rights under California law, including the right to know, delete, correct, and opt-out of sale/share of personal information. We do not sell or share personal information as defined under CCPA.
India residents (DPDP Act, 2023): you have rights under India’s Digital Personal Data Protection Act, including the right to access, correction, erasure, and grievance redressal.
Cookies
We use a small number of cookies. Here’s the full list:
| Name | Purpose | Duration | Category |
|---|---|---|---|
wordpress_logged_in_* | Keeps you signed in | Session + 14 days | Essential |
wp-settings-* | Remembers your admin preferences | 1 year | Essential |
wpfolks_community_notice_v2 | Remembers that you dismissed a notice | 1 year | Essential |
Essential cookies are always on (the site doesn’t work without them). WPFolks uses only essential cookies necessary to operate the platform. We do not use tracking or analytics cookies.
You can clear cookies at any time in your browser settings.
Children
WPFolks is not intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child has given us their data, email hello@wpfolks.org and we’ll delete the account.
Security
We use TLS encryption for all traffic, bcrypt password hashing, rate-limiting on login attempts, two-factor authentication (for admin accounts), and regular dependency updates. No system is ever 100% secure, but we take this seriously.
If you discover a security issue, please email security@wpfolks.org before disclosing publicly. We aim to acknowledge reports within 48 hours.
Changes to this policy
We may update this policy. Material changes will be notified via:
- Email to your registered address
- A visible banner on the site for at least 14 days
- Updated Last updated date at the top
Continued use after the notice period constitutes acceptance.
Contact
- Privacy questions: hello@wpfolks.org
- Data requests (access, delete, correct, export): hello@wpfolks.org
- Security issues: security@wpfolks.org
- Postal address: T5, 808, Godrej Nurture, Mamurdi, Pune
The WPFolks app
The WPFolks app for iOS and Android talks to this same site, so everything above applies. This section covers what is different on a phone.
Account and sign-in
The app uses the same account as the website: your name, email address, username and avatar. You can sign in three ways: email and password, Continue with Google, or Sign in with Apple. When you use Google or Apple, they tell us your name and email address so the account can be created or matched. We never see your Google or Apple password.
Location
Location is optional and the app works fully without it. If you allow it, approximate coordinates are stored on your account and used for two things: showing you folks near you, and telling you about events nearby. It is approximate on purpose, and it is never shown to anyone as a precise position.
You can turn it off at any time with the Nearby folks switch in app Settings, which stops you appearing to others. Your location is deleted when you delete your account.
Push notifications
If you allow notifications, your device gives us a push token which is stored on your account and used to deliver messages through Expo, the service that runs the app. Every type of notification can be switched off individually in the app. Tokens are removed when you sign out of a device and when you delete your account.
App sessions
Each time you sign in on a device, the app creates a named session for that device rather than storing your password. You can see every active session and revoke any of them from Settings. Revoking one signs that device out immediately.
Photos on your device
The app asks for photo library access for two reasons only: to save a Photo Directory image you chose to download, and to upload an image you chose for your profile or a post. Nothing is read from your library, scanned, or uploaded unless you pick it.
Services the app relies on
- Expo, to deliver push notifications to your device.
- Google and Apple, when you use their sign-in buttons.
- Gravatar, which serves profile images by an anonymised hash of an email address.
- WordPress.org, for plugin, theme and Photo Directory information. Public data only.
- OpenAI, for two things: checking posts automatically for content that breaks the community guidelines, and writing the daily WordPress trivia questions. No personal data is sent for trivia.
- WordPress.com, which hosts the site.
Keeping and deleting your data
Your data is kept while your account exists. You can delete your account yourself from the app or the website, without asking anyone. The account deletion page explains exactly what is removed, what stays without your name on it, and how long it takes.
Age
WPFolks is for folks aged 16 and over. The app is not directed at children and we do not knowingly collect data from anyone under 16.
Privacy questions about the app
Write to hello@wpfolks.org, or use the support page.