For the WP errorHandle WordPress plugin and the errorHandle hosted AI
service. Last updated 5 October 2026.
This page describes the WP errorHandle plugin specifically. It is narrower
than, and additional to, the general errorHandle privacy policy.
The short version
WP errorHandle can work three ways, and what leaves your site depends
entirely on which you choose. The plugin contacts errorHandle only if
you explicitly choose to use our hosted AI. Installing it, activating
it, opening its screens or running its automations never contacts us.
- Offline planner — nothing leaves your site at all.
- Your own API key (BYOK) — requests go straight from your
server to your AI provider. errorHandle is not involved, receives nothing and
counts nothing. - errorHandle hosted AI — described in full below.
Choosing hosted AI
On first run the plugin asks which you want and shows what hosted AI would
send, before you decide. You have to press a button to agree; there is no
pre-ticked box, and typing a command is not treated as agreement. You can
change the choice afterwards in the plugin’s Settings, and choosing anything
else stops the traffic rather than merely relabelling it.
What is sent when you use hosted AI
When your site registers
- Your site’s address, reduced to a canonical form (scheme,
www.
and port removed), plus the full home URL so we can tell you where to publish
the ownership proof. - Your WordPress version, PHP version and plugin version.
- Whether the site reports itself as production, staging or local.
We then ask your site to prove it is yours: we issue a single-use token,
your site publishes it at one public address for up to fifteen minutes, and we
read it back. This is the same check a certificate authority makes before
issuing an HTTPS certificate. It exists so that knowing your domain is not
enough for somebody else to claim your free commands.
When you ask for a plan
- The text of your request.
- A short description of your site that the plugin assembles — page titles
and slugs it believes are relevant to what you asked, and the names of the
actions available. Your page content is not sent unless your request itself
contains it, for example when you paste code in.
That is forwarded to our AI provider, Anthropic, which
generates the plan. Anthropic processes it under their own terms; we do not
permit it to be used for training.
If you confirm an email address
Confirming an address unlocks the remaining seven commands. The address is
sent to us and the confirmation email is delivered through
Microsoft Graph from [email protected].
What we keep, and what we do not
We keep:
- Your site’s canonical address, its classification, and an encrypted secret
used to verify that requests really come from your site. - How many commands you have used of your ten, and how many generation
attempts. - Per command: the outcome, whether it counted, how many attempts it took,
and approximate token counts. Token counts are measured by our own server. - If you confirmed an address: a one-way hash of it, and an encrypted copy.
The hash is how we recognise the same account; the encrypted copy is how we
send to it.
We do not keep:
- Your requests. They pass through our service to Anthropic and are not
written down. - Your pages, posts, products, orders, customers or any site content.
- Your WordPress usernames, passwords or user list.
- Your AI provider API keys. If you use your own key it never reaches us at
all; it is encrypted in your own database. - Your IP address. Rate limiting uses a keyed one-way hash of it, truncated,
which cannot be reversed to an address and is deleted after two days.
This is not a promise about our intentions — the database has no column
capable of holding a prompt, page content, an API key, a user list or an IP
address.
How long we keep it
- Entitlement records — for as long as the free allowance
exists. They are what make the ten commands a lifetime figure, so deleting
them on request would hand out a fresh ten. - Unused confirmation links — deleted seven days after they
expire. - Rate-limit counters — deleted after two days.
Security
- Everything is sent over HTTPS.
- Requests from your site are signed with a secret only your site and our
server hold. The secret itself is never transmitted and is encrypted at rest
in your database. - The errorHandle API key used to reach Anthropic stays on our server and is
never sent to your site. - When our service fetches the ownership proof from your site it refuses
redirects, refuses private, loopback, link-local and cloud-metadata addresses,
caps the response and times out quickly. - Our database runs on a private network interface and is not reachable from
the internet.
Sub-processors
| Who | What for | What they receive |
|---|---|---|
| Anthropic | Generating plans | Your request text and the site description described above |
| Microsoft (Graph) | Sending the confirmation email | Your email address |
| Amazon Web Services | Hosting the service | Data in transit and at rest, as above |
Your choices
- Switch to your own key, or to the offline planner, at any time in
Settings. Hosted AI then stops being contacted. - Ask us what we hold for your site, or ask us to delete it, by writing to
[email protected]. Deleting
an entitlement record releases the associated free commands, so we will tell
you that before doing it. - Uninstalling the plugin removes its data from your WordPress database. It
does not delete the entitlement record on our side, because that record is
what stops a reinstall granting another ten commands.
Children
WP errorHandle is a tool for website administrators and is not directed at
children.
Changes
If we broaden what is sent or kept, the plugin asks for your agreement
again rather than carrying forward consent you gave to something narrower.
Contact
errorHandle LLC —
[email protected]