Privacy & data
Raqvio Agent Guardrails keeps its data in your own WordPress database. There is no Raqvio Agent Guardrails cloud service.
What is stored
Section titled “What is stored”| Data | Contents | Kept |
|---|---|---|
| Audit log | Time, agent, WordPress user ID, channel, ability, risk, decision, status, duration, a short result summary, and the ability input after redaction (how redaction works) | The retention you set, 1–365 days (default 30) |
| Agent profiles | Name, description, status, and the ID of the bound application password or user. The application password itself is never read or stored. | Until deleted |
| Catalog readiness | Score and issue list per product | Until the next scan |
| Approvals (Pro) | The request, with its full input and result encrypted at rest (libsodium); a redacted preview for the review screen is stored unencrypted | Deleted with audit retention once decided |
| Snapshots (Pro) | Product, order status, coupon, post and term fields captured for rollback | Audit retention |
| Spend ledger (Pro) | Agent, ability, risk, amount and time of each successful financial agent call, for spending budgets. No customer data. | 31 days |
| Audit seals (Pro) | One keyed hash per audit entry, for integrity verification | Removed with the entry they seal |
| Fixer suggestions (Pro) | Draft texts from your AI provider | Deleted with audit retention once applied or discarded |
| Merchant Center feed (Pro, opt-in) | An XML file in wp-content/uploads/raqvio-ag/, served only at a secret URL |
Until you disable the feed |
Expired data is removed by a daily background job.
External connections
Section titled “External connections”- Freemius — licensing and, only if you opt in, anonymous usage data.
- Email — Pro approval notifications and alerts are sent with WordPress’s own mailer to the addresses you configure (or the site admin email).
- Slack (Pro, optional) — your incoming webhook receives approval notifications and alerts, without secrets or full input.
- Your AI provider (Pro, on request) — through the WordPress AI Client when you ask the readiness fixer for suggestions. Only catalog fields are sent, never customer data.
- Your own site — the readiness scan loads one of your product pages to check for Product JSON-LD.
Raqvio Agent Guardrails makes no other external requests and loads no remote code.
Credentials
Section titled “Credentials”- The hardening check never reads AI provider keys; database presence is checked with
LENGTH()so the value never leaves MySQL. - Raqvio Agent Guardrails never ships, proxies or stores AI model keys.
Removing data
Section titled “Removing data”Deactivating keeps all data. To remove everything when the plugin is deleted, turn on Settings → Access & data → Delete all Raqvio Agent Guardrails data when the plugin is uninstalled before deleting it.
Raqvio Agent Guardrails does not currently register WordPress’s personal data export and erasure tools. Audit entries identify agents by WordPress user ID and are removed automatically at the end of the retention period.