Privacy Policy
Last updated: August 19, 2026
Royal Plugins ("we", "us", or "our") operates the royalplugins.com website and develops WordPress plugins. This Privacy Policy explains how we collect, use, and protect your information.
Information We Collect
Website Visitors:
- Standard server logs (IP address, browser type, pages visited)
- Email address if you subscribe to our newsletter
- Information you provide when contacting support
Customers (Premium Plugin Purchases):
- Name and email address
- Billing information (processed securely by Stripe)
- Purchase history and license keys
- Site URLs where licenses are activated
- Support ticket history
Plugin Users:
- Our plugins do not collect personal data by default
- Royal MCP stores API keys locally in your WordPress database
- Activity logs are stored locally on your server, not transmitted to us
- Premium plugins verify license status by contacting our server (site URL and license key only)
How We Use Information
- To provide and improve our services
- To process purchases and manage subscriptions
- To send product updates, renewal reminders, and announcements
- To respond to support requests
- To verify license status and prevent unauthorized use
- To analyze website usage and improve user experience
Payment Processing
We use Stripe to process payments. When you make a purchase:
- Your payment card details are sent directly to Stripe and never touch our servers
- We receive only the last 4 digits of your card for reference
- Stripe may collect additional information as described in their privacy policy
We store your name, email, and purchase history to manage your licenses and subscriptions.
Third-Party Services
Royal MCP Plugin: When you configure AI platforms in Royal MCP, your WordPress content may be shared with those services according to their privacy policies:
- Anthropic (Claude) Privacy Policy
- OpenAI Privacy Policy
- Google Privacy Policy
- Mistral AI Privacy Policy
No data is sent to any AI service until you explicitly configure and enable a connection.
Data Storage & Security
- Website data is stored on secure servers
- Plugin data remains on your WordPress installation
- API keys are stored in your WordPress database (wp_options table)
- We recommend using HTTPS and keeping WordPress updated
Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Unsubscribe from marketing communications
- Lodge a complaint with a supervisory authority
Cookies
Our website uses minimal cookies for essential functionality. We do not use tracking cookies or third-party advertising cookies.
Children's Privacy
Our services are not directed to children under 13. We do not knowingly collect personal information from children.
Chrome Extensions
This section applies to browser extensions published by Royal Plugins on the Chrome Web Store, specifically:
- SEObolt SEO Checker — on-page SEO analysis
- Royal Links Audit — link classification and affiliate/tracking/security audit
- Royal Access Accessibility Checker — WCAG accessibility audit
Page Analysis
All analysis is performed locally in your browser using client-side JavaScript. Page content, HTML, meta tags, headings, links, and accessibility attributes are read from the active tab only when you click the extension icon, and are never transmitted to our servers or any third party.
Anonymous Usage Analytics
SEObolt SEO Checker (version 1.1.0 and later) only. Starting with version 1.1.0, SEObolt SEO Checker sends anonymous product usage events to help us improve the product. These events include: install/update/uninstall, popup opens, scan completions (with aggregate score and counts of passing/warning/failing checks), scan errors, and outbound link clicks. We also send the hostname (e.g. "example.com") of scanned pages — never full URLs, query strings, or page content. Each install is identified by a randomly-generated anonymous ID stored locally; no email, account, IP logging, or personal data is attached. Analytics are processed by PostHog Inc. (US Cloud) under their privacy policy.
Royal Links Audit and Royal Access Accessibility Checker do not collect or transmit any usage data. These extensions do not send analytics, do not use a unique install ID, and have no outbound network connections. All analysis runs entirely on your device.
Permissions
Our extensions request only the minimum permissions required to function:
- activeTab (all three extensions) — allows the extension to read the current page only when you click the extension icon. No background access to any other tabs or browsing activity.
- scripting (all three extensions) — allows the extension to inject the analysis script into the current page to parse its HTML structure.
- storage (SEObolt SEO Checker only) — stores the anonymous analytics ID locally on your device so repeat sessions can be grouped into the same install. No data leaves your device via this permission. Royal Links Audit and Royal Access Accessibility Checker do not request this permission.
Opting Out of SEObolt Analytics
To disable SEObolt SEO Checker analytics, uninstall the SEObolt extension. Uninstalling also triggers an anonymous uninstall event and opens a feedback page at seobolt.io; no data beyond the anonymous ID is sent. Royal Links Audit and Royal Access Accessibility Checker have no analytics to opt out of.
Updates
If future versions of any of our extensions add features that connect to external services (such as optional account integration), this privacy policy will be updated before those features are released, and the connection will require explicit user opt-in.
SEObolt & Google API Data
This section applies to SEObolt (WordPress plugin and SaaS dashboard at app.seobolt.io) and covers our compliance with the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account to SEObolt, we request the following OAuth scopes and access only the accounts and properties you explicitly authorize:
- Google Search Console (webmasters): keyword rankings, impressions, clicks, average position, sitemaps, and property list. Write access is used only when you click "Submit Sitemap" or "Delete Sitemap."
- Google Analytics 4 (analytics.readonly): aggregated report data (traffic, top pages, sources, device/country) and your GA4 property list. Read-only — we never write, modify, or delete GA4 data.
- Google URL Indexing API (indexing): submit URLs on demand when you click "Push to Google for indexing."
- Basic profile (userinfo.email, userinfo.profile): your Google account email and profile to associate the connection with your SEObolt user record.
Google user data is used solely to provide user-facing features in your SEObolt dashboard. Data is fetched on-demand, cached briefly (~5 min) for performance, transmitted over HTTPS/TLS, and OAuth tokens are encrypted at rest on SOC 2-compliant infrastructure.
We do not: transfer Google user data to any third party (including our AI provider integrations OpenAI, Anthropic, Google Gemini, DeepSeek); use it to train or improve AI/ML models; use it for advertising, credit, or lending decisions; sell it. Human access is restricted to the account holder and to authorized personnel only where necessary for security, legal compliance, or with your explicit consent.
Data is retained while your account is active and deleted within 30 days of account deletion. You can revoke SEObolt's access at any time from your Google Account permissions page.
Plugin Telemetry
Some of our WordPress plugins (currently Royal AI Firewall) can send anonymous weekly usage data if you opt in from the plugin's Settings. Off by default.
The payload includes plugin version, WordPress + PHP version, an opaque one-way hash of your site URL (used only to count unique installs), and small feature-usage counters. Never included: your site URL, email addresses, IP addresses, log contents, or visitor data. Endpoint: my.royalplugins.com/wp-json/rp-telemetry/v1/<plugin>/report.
Retention: raw payloads 90 days, aggregated statistics indefinitely, per-site fingerprints purged after 12 months of no reports. Opt-out any time in the plugin's Settings.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date.
Contact Us
If you have questions about this Privacy Policy, please contact us at:
Email: privacy@royalplugins.com