← ncdLabs
Site Access Policies
Privacy

What stays on your WordPress site

ncdLabs Site Access Policies is an access-control plugin that runs on your WordPress installation. By default it does not contact ncdLabs or any other external server.

Where the plugin runs

Your site

Policies, challenges, sessions, and the admin UI execute on your WordPress host and browser. PePper guidance stays in wp-admin with no telemetry.

Your database

Plugin tables and options store policies, vault credentials, passkeys, sessions, audit events, and settings under your WordPress database prefix.

Information the plugin may store

Depending on how you configure it, the plugin may keep:

Challenge pages evaluate the visitor’s request (host, path, method, and allowlisted plugin cookies) to decide whether to allow access. That evaluation happens on your server.

No automatic connections to ncdLabs

The Free plugin does not send usage statistics, license checks, or analytics to ncdLabs. Free features work without a license key. Premium is a separate companion plugin you install when purchased. Premium entitlement is configured locally in wp-config.php (WPAPM_PREMIUM_SKU) — the plugin does not phone home to verify licenses.

Language packs are handled by WordPress core’s normal translation updates. This plugin does not fetch language packs from WordPress.org on activation or during admin requests.

Password hashes and private keys are never transmitted in cloud backups. Cloud backup only reports success after your configured transport accepts the payload (HTTP 2xx or an explicit integration hook).

Optional deactivation feedback

When an administrator deactivates the plugin, WordPress may show an optional feedback dialog. You can skip it and deactivate without answering. Closing the dialog cancels deactivation.

If you choose Submit & deactivate, the plugin emails your selected reason and any comments you type to feedback+siteaccesspolicies@ncdlabs.com using your site’s normal WordPress mail configuration (wp_mail). Feedback is used only to improve the product.

A separate checkbox (unchecked by default) lets you include diagnostic versions with that email: plugin version, WordPress version, and PHP version. Your site URL and admin email are never included. If you leave the checkbox unchecked, only the reason and comments you entered are sent.

Optional integrations you turn on

If you configure outbound features (typically via Premium), the plugin sends only what that service needs to the endpoint or provider you choose:

Those providers’ own privacy terms apply to data they receive. Outbound URLs are validated to reduce accidental SSRF risk; you remain responsible for the destinations you enable.

Purchases on ncdlabs.com

Buying Premium on the marketing site is separate from the plugin runtime. Checkout, receipts, and download fulfillment follow the ncdLabs site privacy notice (Stripe payment processing, purchase email, analytics on product pages).

WordPress privacy tools

The plugin registers with WordPress personal data export and erase hooks so site owners can include related records when handling Tools → Export / Erase Personal Data requests for a user email. Exports may include sessions, passkeys, authorized-user links, access-group memberships, and audit events attributable to that user (credential secrets are never exported).

Erasure deletes or anonymizes user-bound sessions, passkeys, authorized users, and access-group memberships. Audit events are anonymized (not deleted) under an explicit security retention policy so incident history remains available without retaining personal identifiers. Shared policies, vault passwords used by other users, and other users’ credentials are never erased.

Uninstall

Uninstall defaults to preserving plugin data so reactivation does not wipe policies. A complete uninstall mode (when selected) removes plugin tables and options, including license-related options where applicable.

Your choices

Changes

We may update this page when the product changes. The date below is the current version of this notice.

Last updated: September 11, 2026