← ncdLabs
Assureby ncdLabs
Privacy

What stays on your WordPress site

Assure is a technical compliance plugin that runs on your WordPress installation. Audit results, evidence, settings, and visitor consent preferences are stored locally. The plugin does not send usage telemetry to ncdLabs.

Where the plugin runs

Your site

Discovery, audits, consent banners, enforcement, remediation, and the admin UI execute on your WordPress host and in visitors' browsers.

Your database and uploads

Audit results, evidence, activity logs, and plugin settings live in your WordPress database. Installed framework pack catalogs are stored under wp-content/uploads/assure/frameworks/.

Information the plugin may store

Depending on how you configure Assure, the plugin may keep:

When using the native consent banner, visitor consent choices are stored in the visitor's browser (localStorage) on your site's origin.

No telemetry by default

The Assure plugin does not send usage statistics, error reports, or analytics to ncdLabs. Discovery and audit scans request your own site's public pages and REST API; those results are not uploaded to ncdLabs.

Uninstalling Assure deletes plugin database tables, settings, scheduled events, and uploaded framework pack files under wp-content/uploads/assure/. This cannot be undone.

Optional external connections

Assure contacts external services only in the cases below — and only when you use the related feature.

Pack activation (ncdlabs.com)

When you import a purchased compliance pack, Assure sends your unlock key, framework identifier, and site URL to verify the Stripe purchase and bind the license to one site.

Browser verification (optional)

When importing a pack, Assure may call the ncdLabs provisioning API to enable hosted browser verification. If configured, audits and discovery may send scan targets to your browser verification service.

Google Analytics OAuth (optional)

When you connect Google Analytics from Manage → Integrations, Assure may use Google OAuth and the Google Analytics Admin API. If you have not configured your own OAuth client, Assure uses an ncdLabs OAuth proxy.

Optional deactivation feedback

When an administrator deactivates the plugin, WordPress may show an optional feedback dialog. You can skip it and deactivate without answering. Closing the dialog cancels deactivation.

If you choose Submit & deactivate, the plugin emails your selected reason and any comments you type to feedback+assure@ncdlabs.com using your site’s normal WordPress mail configuration (wp_mail). Feedback is used only to improve the product.

A separate checkbox (unchecked by default) lets you include diagnostic versions with that email: plugin version, WordPress version, and PHP version. Your site URL and admin email are never included. If you leave the checkbox unchecked, only the reason and comments you entered are sent.

ncdLabs site privacy

Pack purchases, licensing API calls, and optional OAuth proxy traffic are handled under the ncdLabs site privacy policy. Stripe processes payments under Stripe's privacy policy.

Questions

Email privacy questions about Assure or pack licensing.