Google user data in the WP Foreman app
This section covers the WP Foreman web app at app.wpforeman.com and the Google data it can access when you connect a Google account. It applies in addition to the policy above.
What we access
When you connect Google Analytics, WP Foreman requests read-only access (the analytics.readonly permission) and your Google email address. We read the list of Google Analytics accounts and GA4 properties you can see, so you can pick one for each website, and aggregated reports for the properties you choose: visitors, pageviews, sessions, engagement, traffic sources, top pages, devices, and countries and cities. We never change anything in Google Analytics.
When you store backups in Google Drive, we use the drive.file permission, which only lets us see and manage the backup files WP Foreman itself creates. We cannot see any other file in your Drive.
How we use it
Only to provide features you use: traffic on your dashboard and website pages, and the traffic section of client reports you create. Drive access is used only to upload, list and delete WP Foreman’s own backup files on the schedule you set.
Who we share it with
We do not sell Google user data or use it for advertising. We share it only as needed to run the features you use: our hosting and infrastructure providers; our AI provider (Anthropic), which receives aggregated traffic numbers to write the summary paragraph of a client report or to answer a question you ask the Foreman, and which does not use this data to train its models; and the recipients you choose when you email a client report.
How we protect it
Access tokens are encrypted at rest (AES-256), all connections use HTTPS, and your data is only visible to your account and your team.
Retention and deletion
Tokens are kept only while the connection exists. Disconnecting in Settings › Analytics or Settings › Backup storage deletes them immediately and cancels WP Foreman’s access on your Google account. Fetched numbers are cached for up to one hour. A 7-day traffic summary per website is kept for your dashboard. Numbers saved in a client report stay until you delete that report. Our encrypted database backups roll off after 14 days. To delete your account and all of its data, contact us through wpforeman.com/contact. You can also remove WP Foreman’s access at any time at myaccount.google.com/permissions.
Limited Use
WP Foreman’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.