Privacy, security and accessibility
Gatehouse sees your AI traffic, so you should know exactly what it does with it, and what it doesn't claim. Here is everything, in plain language.
Privacy
Gatehouse does not send your data anywhere. It has no account, no tracking, no analytics and no "phone home". Everything it records stays in your own WordPress database.
Uninstalling Gatehouse deletes its database tables, settings and scheduled tasks. Deactivating keeps them, so you can switch it back on.
What Gatehouse stores, in detail →
Security
- Administrators only. Every screen and every REST endpoint requires the
manage_optionscapability, and requests from the dashboard use WordPress's own nonces. - No public pages. Gatehouse adds no front-end pages, forms or public endpoints. It works through WordPress's AI Client hooks and HTTP API.
- Your keys stay where they are. Gatehouse never reads, copies or logs API keys.
- Database access uses parameterised queries.
- Checked with WordPress's Plugin Check, which reports no errors. Gatehouse has not had an independent security audit.
Privacy laws
Gatehouse gives you tools that help when your site uses AI. It doesn't make a site compliant on its own.
- Know what goes out: the Privacy page shows which plugins send personal data to which providers, and the AI data map exports it as a spreadsheet for your records of processing or risk assessments.
- Send less: redaction, per plugin, reduces the personal data that reaches AI providers.
- Access and erasure: Tools → Export Personal Data includes a person's AI requests, and Tools → Erase Personal Data anonymises them.
- Transparency: Gatehouse adds a suggested paragraph to Settings → Privacy → Policy Guide.
- Storage limitation: automatic deletion after your chosen retention period.
Gatehouse doesn't replace your agreement with your AI providers about how they handle the data you send. Read their data processing terms.
Accessibility
The dashboard is built to work with the keyboard and screen readers:
- Everything works with the keyboard. Detail panels keep focus inside until you close them with Esc.
- Every chart has a Table view.
- Status is shown with text and icons, never by colour alone.
- Animations stop when your system asks for reduced motion.
- Screens are checked with an automated accessibility checker (axe-core) in light and dark mode.
Automated checks don't catch everything, and Gatehouse hasn't had a formal accessibility audit. If something doesn't work with your assistive technology, please tell us: we treat it as a bug.
External services
Gatehouse can connect to one outside service, and only if you turn it on:
- OpenRouter's public model list (
openrouter.ai/api/v1/models), to keep model prices current. It's off until you turn on "Update prices automatically". It's a plain daily download that sends no site address, user data, usage data or API keys. OpenRouter privacy policy.
Your plugins' AI calls go only to the providers they already use, as they would without Gatehouse.
Reporting a problem
Security issues: please report them privately using GitHub's private vulnerability reporting, not in public.
Other issues: open an issue on GitHub.