Privacy Policy
Last updated September 25, 2026
This policy covers earlygoose.com, the EarlyGoose WordPress plugin and the hosted application at app.earlygoose.com. EarlyGoose is operated by Barabash D., Private Entrepreneur, registered in Ukraine at Ukraine 49107, province Dnipropetrovsk, city Dnipro, 14N Vysokovoltna st, ap. 12("EarlyGoose", "we" or "us"). You can reach us through our contact form about this policy or your personal data.
1. Our role and the information this policy covers
We are the controller of personal data we use to manage accounts, subscriptions, support, our website and service-wide reference and analysis records whose purposes we determine. When a customer submits personal data in site files or reports for us to process on their behalf, the customer determines the purpose of that processing and we act as their processor. A site owner or agency is responsible for having authority to submit that data and for informing the people concerned.
We receive information from you, connected WordPress sites, people who invite you to a team or send you a report, and our billing and email providers. Technical data such as file paths, source code and site addresses can contain personal or confidential information.
2. Free Scan and WordPress.org requests
Using Free Scan does not require a EarlyGoose account and does not send code, scan results or telemetry to EarlyGoose. Scans run when an administrator starts them. The plugin stores the latest report, scan progress, settings and caches in your WordPress database. A new scan replaces the previous report. Uninstalling the plugin removes its local data.
During a scan, the plugin requests reference checksums from api.wordpress.org and downloads.wordpress.org. Requests identify the WordPress version and locale or the plugin slug and version. WordPress's default HTTP User-Agent also includes your site URL and WordPress version, and the receiving server sees your server's IP address. These requests do not contain file contents or reports. See the WordPress.org privacy policy.
If you choose Email report, your site sends the report, recipient addresses and any note through its own WordPress mail system and mail provider. EarlyGoose receives a copy only if you address one to us. Reports can include paths, code excerpts and configuration details.
3. Accounts and connected sites
- Account information: email address, name, optional profile image, authentication information, preferences, team membership and invitations. Profile images are served from public image URLs, so do not upload a confidential image.
- Google sign-in: if you choose this option, Google and our authentication service process the sign-in and provide the account identifier and profile information authorized through that flow, such as your name, email address and profile image. We do not receive your Google password.
- Connection information: site name, site URL, WordPress admin URL, connection tokens and credentials, connection status and last check-in time. Starting a connection opens the app with your admin URL and a temporary token.
- Site inventory and configuration: WordPress, PHP and database versions, memory limits, plugin and theme names, versions and authors, active status, update settings, environment and debugging settings, administrator counts, and other setup observations. For Update Analyzer, this includes the updates WordPress reports as available, their automatic-update settings, the WordPress and PHP requirements plugins declare, and when WordPress last checked for updates.
- Scan information: file paths, sizes and fingerprints, scan times and triggers, coverage, detector results, line numbers, code excerpts, findings, analysis results and actions such as dismissing a finding, changing monitoring settings or changing automatic-update settings.
The site sends this data after an administrator connects it to Monitoring. Check-ins normally run every five minutes through WordPress scheduled tasks. Scans also run on the configured schedule, after enabled site-change events or when requested. Actual timing depends on your hosting and WordPress scheduling. Update information comes from checks WordPress already performs. The plugin does not start additional update checks.
Authenticated exchanges and uploads are initiated by the plugin. When you request work in the app, EarlyGoose may also send an empty wake-up request to the plugin's public REST endpoint so it checks in sooner. That request carries no credentials or scan instructions. Monitoring does not require remote login or direct access to your database. If an authorized member confirms a change to automatic-update settings in the app, the plugin receives the request at its next check-in, applies it through WordPress's own settings and reports the result.
4. Uploaded code and AI analysis
Monitoring requests selected files for comparison and analysis. These can include modified or additional files and custom or commercial code without a public reference. A first scan can require substantial uploads. Files do not have to contain a confirmed problem to be selected. The plugin excludes wp-config.php from file uploads and does not upload a database export. It does read local database values to produce setup facts and the optional WooCommerce counts described below.
Update Analyzer uses the same uploads. To check an available update, EarlyGoose collects the active code that could depend on it: custom and commercial plugins, must-use plugins, active themes and your changes to WordPress.org plugins. This includes plugins you trusted to skip code checks, because an update can still affect them. Inactive plugins are not collected for this purpose. EarlyGoose's servers download the official release of the update from WordPress.org to compare it. Those downloads do not include information about your site.
We use Anthropic's API for AI code analysis. Depending on the check, Anthropic receives selected source code, file paths, package information, existing analysis summaries and relevant technical context such as the WordPress version. For Update Analyzer, it also receives excerpts of the official release being compared. Source code and excerpts may contain names, email addresses, credentials or other sensitive information. We do not guarantee that those details are automatically removed before analysis.
Identical file contents, fingerprints, comparison baselines and analysis results may be stored once and reused across sites to avoid repeating the same work. An observed copy of custom or commercial code can contribute to a comparison baseline. This does not make it an official release from its author. We do not provide other customers with access to your account or a download of your uploaded source files.
AI results support a review of software. They are not used to make decisions about people that have legal or similarly significant effects. Anthropic processes API content under its commercial terms and applicable data-processing terms. Its retention rules are separate from EarlyGoose's storage cleanup described below.
5. Email checks, WooCommerce and report sharing
- Email delivery checks: when enabled or manually requested, the plugin sends test messages through your site’s mail system to EarlyGoose-controlled inboxes. Our receiving providers process the message and its delivery metadata, which can include the sender address, mail headers and sending-server details. EarlyGoose records the test token, timing and delivery outcome.
- Mail-failure monitoring: when enabled, the plugin reports that WordPress encountered a sending failure so an email check can be requested. It does not forward the failed message’s body, subject or recipient list.
- WooCommerce monitoring: when enabled, the plugin reads order statuses locally and sends aggregate counts indicating stuck pending orders or payment failures. These monitors do not send individual order records, customer information or payment details.
- Reports and invitations: we process the names and email addresses you supply, optional report notes, and the reports or invitations sent. Shared report recipients are saved for future suggestions. Connected reports, alerts and invitations are sent through our email provider. People you invite can access site information according to their assigned role.
6. Billing, support and website use
When you purchase a subscription, the payment provider identified at checkout processes payment information under its own privacy notice. We use subscription and billing information to manage your account, including identifiers, plan, price, currency, billing interval, renewal and cancellation dates, and payment or subscription status. We do not receive your full card number or card security code.
Contact messages include your name, email address and message. We use them to respond and keep a record of the conversation. If you join an early-access list, we process the details you submit, including any optional information about your role, site count, pricing preferences or WordPress issues, to manage early access and understand your needs.
Our hosting and service providers process technical request data such as IP addresses, browser details, request times, URLs and errors to deliver and protect the Service.
7. Cookies and browser storage
The application uses browser storage to keep you signed in and remember preferences. The website uses session storage to cache pricing, and the app can remember your selected plan. Payment providers may use cookies or similar technologies during checkout for payment processing and fraud prevention, as explained in their privacy notices. Clearing or blocking necessary storage may sign you out or affect these features.
When configured, Google Tag Manager loads on our marketing website and may load Google Analytics 4 after you allow statistics cookies through CookieHub. Analytics helps us understand page visits and website use, using browser and device information, network information such as your IP address, and cookie identifiers. We do not enable advertising personalization or Google signals. We do not use Hotjar or session recordings, and we do not install these analytics tools in the signed-in application. See Google's privacy policy.
CookieHub shows the consent banner and stores your cookie choice. You can open Cookie settings in the website footer anytime to change or withdraw that choice. Rejecting non-essential cookies does not affect access to EarlyGoose. Changing your choice stops future optional collection in this browser. It does not automatically delete information already collected.
8. Why we process personal data
Where the GDPR or similar laws require a legal basis, we rely on:
- Performance of a contract: creating and managing your account, providing requested monitoring, reports and support, and administering your subscription. We cannot provide account-based features without the information needed to operate them.
- Legitimate interests: securing and troubleshooting the Service, preventing misuse, responding to business inquiries, maintaining useful comparison and analysis records, and communicating with authorized team members and report recipients. We consider the impact on the people concerned and their right to object.
- Consent: optional marketing or early-access communications and non-essential cookies or analytics where consent is required. You can withdraw consent without affecting earlier lawful processing.
- Legal obligations: keeping required business records, responding to lawful requests and meeting applicable accounting or tax requirements.
For customer data processed on a customer's behalf, we follow their instructions and the applicable processing agreement. The customer is responsible for its own legal basis.
9. Who receives information
- Supabase supports authentication, databases, file storage and backend processing. Vercel hosts the website and application frontend and processes delivery and request information, including requests to website forms.
- Anthropic processes the code and context needed for AI analysis, as described in section 4.
- Resend delivers support messages, invitations, reports and notifications, and stores early-access contacts. Resend and, where configured, Postmark receive email-check messages.
- Payment providers process purchase and billing information as described in section 6. Google processes information when you choose Google sign-in or consent to website analytics, as described in sections 3 and 7.
- Your authorized team members and the recipients you choose receive the information you make available to them.
We may also disclose information when required by law, to protect legal rights or prevent fraud, or as part of a business transfer subject to appropriate confidentiality and privacy protections. We do not sell personal data or provide uploaded code to third parties for their own marketing.
10. International processing
Our current primary Supabase project is hosted in London, United Kingdom. EarlyGoose is operated from Ukraine. Vercel distributes frontend content globally, and our providers may process information in the United States, the European Economic Area and other countries where they operate. We may add or change infrastructure regions, including replicas, and will update this policy when those changes materially affect the information provided here. Storing data in one region does not mean all support, email, billing or AI processing stays in that region. Where applicable law requires safeguards for an international transfer, these must include an applicable adequacy decision or contractual safeguards such as the European Commission's Standard Contractual Clauses and, where relevant, the UK addendum. Contact us for information about the safeguards applicable to your data.
11. Retention and deletion
- Local reports: the plugin keeps the latest Free Scan report on your server until it is replaced, cleared by connecting, or removed on uninstall.
- Connected site records: we retain account data, site configuration, scan history and findings while needed to provide the Service. Disconnecting, uninstalling the plugin or ending a subscription does not automatically delete cloud records. Site owners can delete or reset a site in the app, and users can request account deletion in account settings or contact us.
- Uploaded source files: identical contents are shared in storage. Our scheduled cleanup removes a stored file when no site’s recorded current files reference it and it is not needed by an unfinished scan or a site’s latest failed scan. A disconnected site’s last recorded state can therefore keep a file in storage until the site is reset, deleted or a later scan replaces that reference. Deletion is performed by background cleanup, not immediately when a file changes on your site.
- Update analysis inputs: copies of the code prepared for an update check are removed once its analysis is collected. Results keep the excerpts they cite.
- Upload archives: removed after successful unpacking. Interrupted processing can leave temporary uploads requiring cleanup.
- Cached analysis: file fingerprints, comparison baselines and cached analysis results are retained separately for reuse and are not automatically deleted when source files or an account are deleted. Results may include paths or excerpts. If they contain your personal data, you can request its deletion or restriction.
- Support and early-access records: kept while needed to answer inquiries, manage access and maintain relevant correspondence, or to honor unsubscribe requests. You can ask us to remove information that is no longer needed.
- Business records, logs and backups: retained for applicable legal obligations, security, recovery and dispute resolution. Provider-held copies follow the relevant provider’s retention arrangements and are not necessarily erased at the same time as live application data.
We do not promise that account deletion immediately erases every copy held by us, an email recipient or a provider. We assess deletion requests against the purpose of the remaining data and applicable legal requirements. Account deletion first confirms cancellation of your recorded subscriptions. If that confirmation fails, your account and sites are kept so you can retry or contact us for help.
12. Your choices and rights
You can use Free Scan without connecting, change available monitoring settings, disconnect a site, manage team access, or delete a site or account. For privacy requests, use our contact form. We may need to verify your identity and authority over the data before responding.
Depending on your location and the processing involved, you may have rights to access, correct, erase or receive a portable copy of your personal data, restrict processing, object to processing based on legitimate interests, and withdraw consent. You can object to direct marketing at any time through an unsubscribe option or by contacting us. Withdrawing from optional communications does not stop necessary service or billing notices.
We respond within the period required by applicable law, generally one month for GDPR requests, with any permitted extension explained to you. You may complain to your local data protection authority. In the UK, you can contact the Information Commissioner's Office. If we process your information for a site owner, we may refer the request to that owner and assist them in responding.
13. Security, children and policy updates
We use access controls, authenticated plugin requests and protected upload links to help protect information. No system provides absolute security. Keep credentials out of source code where possible and share reports only with intended recipients.
The hosted Service is intended for adults managing WordPress sites. We do not knowingly collect personal data from children under 16. Contact us if you believe a child has provided personal data so we can investigate and arrange deletion where appropriate.
We will update the date above when this policy changes. For material changes, we will also provide a prominent notice or contact account holders as appropriate. Where a change requires consent, we will obtain it before applying that change.