Who this policy covers
FluentAuth is a product of WPManageNinja LLC (“WPManageNinja”, “we” or “us”). This policy covers fluentauth.com and the information sent to us through FluentAuth's optional services or support. Our registered office is 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Contact us through WPManageNinja's contact page with “FluentAuth privacy” in your message.
FluentAuth also runs on independently operated WordPress sites. The operator of each site decides which features to enable, what information to collect and how long to retain it. That operator's privacy notice applies to its processing. Installing the plugin does not give us routine access to that site's database, accounts or login logs.
This notice describes the features FluentAuth supports. Data handling depends on the installed version, configuration and connected services.
Information handled by this website
You can browse the product pages and documentation without creating an account. Our hosting and delivery provider, Cloudflare, processes connection information needed to serve and protect the website. This can include IP address, requested URL, request time, browser information and security or error information. Infrastructure records are distinct from the plugin logs on your WordPress site.
The current website configuration has Google Analytics disabled and newsletter forms disabled. Product images, reviewer avatars, fonts and site scripts are served locally. Reviewer avatars are copies of public profile images linked to their original reviews, so viewing a testimonial does not make a Gravatar request.
If newsletter signup is made available, the form sends the supplied name, email address and source page to our FluentCRM system. Its browser storage flag remembers that a signup was submitted. You may unsubscribe from marketing messages using their unsubscribe link; this does not necessarily erase suppression records or other records that must be retained. Any future analytics or additional tracking will need an updated notice and applicable choices before it is enabled.
If you contact us, we receive the contact details, message and attachments you provide. We use them to respond, investigate issues and maintain the relevant support record. Public posts on WordPress.org or GitHub are visible under those platforms' rules. Do not post passwords, recovery codes, API keys or private user logs in public support threads.
Information stored on a site using FluentAuth
The following information is stored in the site's WordPress database or filesystem as needed for enabled features. The site operator and authorised maintainers control access.
- Accounts and authentication: account identifiers, names and email addresses used to sign in or register; verification and magic-link state; and the status of pending or completed authentication.
- Activity logs: submitted username, matched account identifier where available, IP address, reported browser or operating system, login method, result, timestamp, error details and related event metadata. Failed attempts may contain a username that does not belong to a real account. Supported site-activity and recovery events also record what happened and the operator where available.
- Two-factor methods: enrolment records, authenticator secrets and recovery-code hashes. Protection of stored authenticator secrets depends on the version and encryption configuration. Treat database access and backups as sensitive.
- Passkeys: public-key credentials, credential identifiers and associated registration and usage metadata. FluentAuth does not receive the authenticator's private key, fingerprint, face scan or device-unlock PIN. A user's passkey provider may separately sync credentials under its own terms.
- Security configuration: IP rules, role selections, redirect destinations, email templates, notification recipients, provider credentials and other settings you supply.
- File monitoring and recovery: file paths, comparison results, reference hashes, baseline records, findings and recovery records. Baseline and quarantine features can retain local file data. These files and their backups remain part of the site's own storage.
Cookies and browser storage on plugin-enabled sites
WordPress uses authentication cookies to maintain signed-in sessions. FluentAuth can also use temporary cookies for pending verification, social-login state and post-login destinations. The admin interface can store a theme preference in browser storage. These functional uses are different from advertising tracking.
Enabled providers may use their own cookies or storage. In particular, Google One Tap loads Google's client script on pages where the feature is enabled, which can create a connection to Google before someone clicks a sign-in button. The site owner is responsible for explaining these integrations and providing any choices required for their site.
When information leaves the WordPress site
- Email delivery: verification messages, magic links, account messages, notifications and digests pass through the site's configured mail provider to their recipients. Message content can include account, login or security-event information.
- Google, GitHub and Facebook: enabled social sign-in exchanges authentication requests and credentials with the selected provider. The site receives identity information needed for the integration, including email address, name and provider identifiers as applicable. It uses this information to match an account or create one when registration is allowed. Provider processing is governed by the notices of Google, GitHub and Meta/Facebook.
- File references and packages: integrity checks, original-file previews and recovery can request checksums, files or packages from WordPress.org and its repositories, or the official WordPress GitHub mirror. Requests reveal ordinary connection information and the requested software version or file path to the destination. These operations do not upload your site's file contents.
- Other configured integrations: custom code, filters, other plugins and site-configured authentication services can change destinations or behaviour. The site owner must account for those changes in its notice.
Optional scan-report service
Manual file checks do not require registration with our alert service. If an administrator registers or connects the service, the plugin sends registration or connection information to the configured endpoint, normally dash.fluentauth.com.
Registration includes the supplied display name and email address, site URL, admin URL and site title. Connecting with an account API key sends that key for authentication and obtains a site-scoped credential. Subsequent reports include service credentials, the associated email address, site details, changed file and folder paths, and relevant extension or unpublished-version information. Paths can themselves contain identifying information.
Reports support the requested alert and reporting service. They do not include file contents or the site's general login-log database. Requests also expose normal connection information to the receiving service. Hosting and email-delivery providers involved in the service process information needed to operate and deliver it.
Resetting or disconnecting the service clears the local connection configuration and stops further reports through that connection. It is not a promise that previously received reports, delivered emails or service records have been erased. Contact us to request access or deletion of information already sent to our service.
Purposes and responsibilities
We use information provided to us to deliver requested services, respond to support and privacy requests, maintain security, prevent abuse and meet applicable legal obligations. Where applicable law requires a legal basis, these purposes may rely on performing the requested service, legitimate interests in operating and securing it, consent for optional marketing, or a legal obligation. The relevant basis depends on the activity and applicable law.
The site operator determines the purposes and legal basis for local login protection, account management and monitoring. Using FluentAuth does not by itself make a site compliant with privacy law. Site owners should minimise collection, restrict access, select retention periods and describe enabled integrations in their own privacy notices.
Information may be disclosed to service providers needed for delivery and support, when legally required, or where necessary to investigate abuse or protect rights. We do not receive your local plugin logs merely because you install FluentAuth. External provider processing, hosting locations and international transfers depend on the services actually used; contact us for information about a particular WPManageNinja service.
Retention and deletion
Local login-log retention is configurable, with a default of 30 days. Scheduled cleanup depends on the site's scheduled tasks running. Other records, such as credentials, settings, baselines and quarantine files, have separate lifecycles. Do not assume that deactivating the plugin or deleting a WordPress user removes every plugin table, file, log entry or backup.
Deleting failed-attempt history can affect limits derived from that history. Preserve records needed for an investigation before making changes. The site owner should review database records, local files, backups and connected providers when handling an erasure request.
For information held by us, retention should be limited to the period needed for the relevant service, support, security and applicable legal obligations. Disconnection, unsubscribing and erasure are different actions. Ask us about the retention or deletion of a specific service record; this notice does not promise a fixed deletion deadline for all records or backups.
Privacy requests, including social-login data
Depending on your location and the applicable law, you may have rights to access, correct, delete or obtain a copy of your information, restrict or object to processing, withdraw consent, or complain to a data-protection authority. Withdrawal of consent does not affect processing already carried out lawfully.
For an account on an independently operated WordPress site, contact that site's owner. This includes an account created through Facebook, Google or GitHub. Disconnecting a provider in its account settings does not automatically erase an existing WordPress account or activity records.
For information held by WPManageNinja, use our contact page. Identify FluentAuth, the relevant site or service and the request, without sending secrets. We may need to verify your identity and authority before disclosing or deleting records. Legal obligations and the rights of others may limit a request.
Changes and related policies
We will update this notice when the described processing changes and revise the date above. Material changes requiring further notice or consent will be handled as required by applicable law. See our terms and conditions for use of the website and services and WPManageNinja's privacy notice for interactions on its separate website.