Privacy Policy
Effective July 25, 2026
Update Machine provides WordPress plugin updates and license services. We process only the data described in this policy to deliver and secure those services. Optional feature telemetry is limited to small, reviewed, predefined values, can be turned off, and must not include site content, personal identifiers, or secrets.
What this policy covers
Update Machine is a service operated by DontPressThis LLC (“we,” “us,” or “our”). This policy explains how we handle information from updatemachine.com, WordPress plugins that connect to Update Machine, customer accounts, purchases, licenses, and support.
Information we process
Updates and licensing
We process information needed to register sites, check for updates, deliver plugin files, and enforce licenses:
- site URL, plugin slug and version, SDK version, and update-check time and result;
- site keys, license credentials, license status, licensed site URL, and activation environment;
- IP address, user agent, and basic request and error details used for security, rate limiting, delivery, and troubleshooting; and
- for customers and administrators, email address, display name, password hash, subscription identifiers and status, and support communications.
Payment card details are handled by Stripe and are not stored by Update Machine. Turning off optional telemetry does not stop update and licensing requests themselves. Those requests still include authentication data, your site's domain, and standard HTTP metadata.
Optional update and feature telemetry
When sharing is enabled, a plugin may send:
- site URL and site name;
- plugin, SDK, WordPress, and PHP versions;
- WordPress environment type, multisite status, and site-level or network-level activation scope; and
- a versioned snapshot of declared plugin features using only booleans, bounded numbers, and small predefined choices.
Feature schemas are code-reviewed and registered on the server before data is accepted. Unknown, nested, malformed, oversized, or unregistered values are dropped. Authenticated feature snapshots replace the prior snapshot for that scoped installation; repeated checks do not create additional install counts.
Older SDK integrations may also send a deprecated legacy usage snapshot containing up to 20 flat booleans, bounded numbers, or short sanitized strings in a payload no larger than 2 KB. New integrations must use code-reviewed typed feature schemas. Plugin authors are not permitted to place personal data, content, URLs, or secrets in the legacy snapshot.
Data optional telemetry must not include
Beyond the fields listed above, optional feature telemetry is not permitted to include:
- posts, pages, comments, recipes, products, feeds, media, titles, excerpts, or search terms;
- emails, usernames, display names, IP addresses, or other personal identifiers;
- license keys, site keys, tokens, nonces, credentials, or hashes of secrets;
- arbitrary URLs, paths, query strings, referrers, CSS selectors, or free-form text; or
- user, post, order, category, or other customer-controlled IDs, timestamps, click histories, or event streams.
Your telemetry choice
Plugin integrations may use one of three labeled modes:
- Opt out (on by default): optional sharing starts enabled and an authorized administrator can turn it off.
- Opt in (off by default): optional sharing starts disabled and is enabled only after an authorized administrator chooses it.
- Disabled: the plugin does not collect or send optional telemetry.
Older integrations use opt-out behavior unless telemetry has been disabled in code. The setting remains available after onboarding. When sharing is disabled, the Update Machine SDK does not run optional callbacks and sends no optional telemetry in the update-check body. Updates, integrity checks, registration, and licensing continue to work.
On WordPress multisite, a network-active plugin reports once for the network and its choice is managed in Network Admin. A plugin activated separately on sites uses a separate choice and identity for each site.
Disabling future collection does not immediately delete previously collected data. Existing records expire under the retention periods below. For implementation details, see the feature telemetry contract.
How we use information
- deliver, authenticate, and verify plugin updates;
- activate and manage licenses and subscriptions;
- protect the service, enforce rate limits, and investigate errors or abuse;
- measure version adoption, feature adoption, multisite scope, and sanitized failure rates; and
- operate customer accounts, billing, transactional email, and support.
We do not sell personal information or use plugin telemetry to build advertising profiles.
Website analytics and cookies
The updatemachine.com website uses Google Tag Manager to load Google Analytics 4. The site and its providers may use cookies or similar browser storage for analytics, authenticated sessions, checkout, security, and preferences. A license key you enter on the account page may be kept in that browser's session storage for the current session.
Service providers and disclosure
We use service providers to operate Update Machine, including:
- Vercel for application hosting;
- Neon for managed PostgreSQL database hosting;
- Cloudflare R2 for plugin release-file storage;
- Stripe for checkout, subscriptions, and billing;
- Resend for transactional email;
- Google Tag Manager for website measurement; and
- Slack for internal operational notifications.
We engage these providers to process information in order to deliver their services to us. Some providers, such as Stripe and Google, also process data under their own privacy policies. We may also disclose information when required by law, to protect users or the service, or as part of a business transfer. Aggregated fleet analytics available to authorized administrators do not include individual feature snapshots, site keys, or license keys.
Retention
- typed feature snapshots are excluded from reporting and deleted after 30 days without a check-in;
- we keep only the current and previous day of per-install daily staging data;
- aggregate feature history, telemetry outcome codes, update-check logs, and error logs may be retained for up to 90 days;
- download logs may be retained for up to 180 days;
- unreferenced telemetry schemas may be removed 180 days after last observation;
- base site registration records and the latest deprecated legacy usage snapshot may be kept while the site remains registered, although legacy dashboard rollups include only sites seen within 30 days; and
- account, license, billing, security, and support records are kept while needed to provide the service, meet legal obligations, resolve disputes, and prevent abuse.
Security
We use safeguards appropriate to the service, including encrypted transport, hashed or encrypted credentials where applicable, access controls, bounded telemetry schemas, and integrity verification for plugin packages. No system can guarantee absolute security.
Your requests
You may ask about, correct, or request deletion of information associated with you or your site, subject to security verification and records we must retain. Contact hi@dontpressthis.com. Site and network administrators can change optional telemetry sharing from the relevant plugin's settings or onboarding screen.
Changes to this policy
We may update this policy as the service changes. We will post the revised policy here and change the effective date. Material changes to optional telemetry will also be reflected in the applicable plugin disclosure or consent control.