Privacy Policy
Last updated: September 6, 2026
This Privacy Policy explains how Viz (“Viz,” “we,” “us”) handles information in connection with the website at vizwp.com, the accounts you create with us, and the Viz WordPress plugin. This document is meant to be read in plain language.
1. Overview
Viz is a WordPress plugin and service that identifies and classifies the traffic reaching your site (humans, search engines, and AI bots), credits conversions to the AI assistants that sent the visitor, and registers tools AI agents can use on your pages. The plugin runs on your own WordPress installation, and by default the data it produces stays in your own database. We only receive that data if you explicitly opt in to our optional cloud features.
We do not sell personal information. We do not load third-party advertising or tracking scripts inside the plugin.
2. Three contexts: website, free tools, and plugin
Information flows through three distinct situations:
- The website and your account (vizwp.com). When you visit our marketing site or create an account, we act as the data controller for the limited information described below.
- Our free tools. When you use a free tool such as Peekabot, the AI Readiness Audit or WebMCP Check, you submit a URL to us and we fetch and analyze that page or site. We are the controller for what that produces. Section 4 covers this in full.
- The plugin on your site. When the plugin logs your visitors’ requests, that data is written first to your own WordPress database. You are the controller of your visitors’ data. If you enable optional cloud sync, we process the synced data on your behalf as a processor, under these terms and any applicable data processing agreement.
3. Information we collect
Account and website information
- Account details you provide at sign-up: name, email address, and your site URL. Passwords are stored only as salted hashes.
- Billing information for paid plans is handled by Paddle.com, our Merchant of Record and payment processor. We never receive or store your full card details. See Paddle's privacy policy at paddle.com/legal/privacy.
- Website usage such as pages viewed, approximate region derived from IP, and basic device or browser information. Analytics cookies are set only if you accept them. See section 5.
- Free tool submissions, described in section 4: the URL you ask us to scan, and your email address if you ask us to send you a report.
- Support communications you send us by email or other channels.
Information processed by the plugin
On your site, the plugin records request metadata so it can classify traffic. This typically includes the request URL, timestamp, user agent, referrer, and IP address, along with the resulting classification. This data is stored in your database. You control whether human visitors are logged, whether administrators are excluded, and the retention window.
The plugin also prints two small first-party inline scripts on your pages, with no external requests: one records landings from an AI assistant and sets the consent-gated attribution cookie described in section 5; the other registers WebMCP tools in browsers that support the standard. Calls to those tools are logged on your site as agent requests, and a contact request an agent submits through them is stored as a lead in your own database, never on our servers.
Optional cloud-sync data
If you opt in to cloud features, the plugin transmits classified event data to us so we can provide cross-site bot intelligence and remote dashboards. Delivery is batched and HMAC-signed. You can disable cloud sync at any time.
Optional Google integration
If you connect Google Analytics or Search Console, we access aggregate reporting data (traffic and search query reports) to display it in your dashboard and improve prompt discovery. OAuth tokens are stored server-side only and are deleted when you disconnect. Viz's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Free tools (Peekabot, the AI Readiness Audit and WebMCP Check)
Peekabot at vizwp.com/tools/peekabot lets anyone submit a URL and see how a given crawler reads that page. The AI Readiness Audit at vizwp.com/tools/aeo-audit lets anyone submit a site address and get a structural readiness score across up to twelve of its pages. WebMCP Check at vizwp.com/tools/webmcp-check lets anyone submit a page address and see which WebMCP tools that page registers for AI agents; the page is loaded once in a headless browser that records tool registrations and never invokes a tool. You do not need an account for any of them, and we do not ask who you are.
What a scan or audit records
When a scan completes we store the URL you submitted, the bot you chose, the grade and category scores, the summary measurements (such as how many images carry a description and how large the page markup is), the approximate country the request came from, and the referring page. When an audit completes we store the address you submitted, the canonical host it resolved to, the score and grade, the count of findings by severity, how many pages were analyzed, whether the site runs WordPress, an SEO plugin or WooCommerce, the HTTP status the homepage gave an AI crawler, the approximate country, and the referring page. When a WebMCP check completes we store the address you submitted, the address it resolved to, the verdict, the names of the tools found and how each was detected, whether the site runs WordPress, WooCommerce or Viz, whether the browser load completed, the approximate country, and the referring page; we do not store the page, its scripts or the tools' input schemas. Failed scans, audits and checks are recorded the same way with the reason they failed. We keep these records to understand how the tools are used and to improve them.
We do not store your IP address against a scan, and we do not store the content of the page we fetched. The screenshots taken during a scan are returned to your browser and are not retained by us.
Please only scan URLs you are authorized to scan. A URL can itself reveal information, so avoid submitting addresses that contain private tokens or personal data.
If you ask us to email a report
Emailing yourself a report is entirely optional and the tool is fully usable without it. If you do, we store your email address alongside the scan, audit or check it relates to, which tool you used, and a record of whether the send succeeded.
The report email itself is sent because you asked for it. Separately, you may tick a box that reads "Also send me occasional email about AI visibility and AI readiness." That box is unticked by default, we record the time and IP address of that consent as evidence that it was given, and every such email carries an unsubscribe link. Unsubscribing is honored regardless of how you got on the list.
6. How we use information
- To provide, operate, secure, and improve the website and the service.
- To create and manage your account and authenticate you.
- To process payments and manage subscriptions.
- To deliver optional cloud features, including aggregated, cross-site bot intelligence.
- To respond to your support requests and communicate service notices.
- To detect, prevent, and address fraud, abuse, and security incidents.
- To comply with legal obligations.
7. Legal bases for processing
Where the GDPR or similar laws apply, we rely on the following legal bases: performance of a contract (to provide the service you request), our legitimate interests (to secure and improve the service, including keeping records of free tool scans), your consent (analytics cookies, marketing email, and optional cloud sync), and compliance with legal obligations. Sending you a report you asked for is performance of your request, not marketing, and does not depend on the marketing consent box.
9. Data retention
We retain account information for as long as your account is active and as needed to provide the service, then for a limited period to meet legal, tax, and security requirements. For plugin data stored on your own site, you set the retention window. For cloud-synced data, we retain it for the period described in your plan or until you delete it or close your account. IP addresses of human visitors in cloud-synced data are anonymized after 30 days.
For our free tools: scan records are deleted after 12 months. If you asked us to email you a report, we keep that record, including your email address, until you unsubscribe or ask us to delete it, and then only as long as needed to prove we honored that request.
10. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, HMAC-signed cloud delivery, hashed passwords, access controls, and least-privilege practices. No method of transmission or storage is perfectly secure, but we work to protect your information and to respond promptly to incidents.
11. International transfers
We may process and store information in countries other than your own. Where required, we use appropriate safeguards, such as standard contractual clauses, for international transfers of personal data.
12. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing or withdraw consent. If you are in the European Economic Area or the United Kingdom, these rights arise under the GDPR. If you are a California resident, you have rights under the CCPA and CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information; we do not sell or share personal information as those terms are defined.
To exercise any of these rights, contact us using the details below. We will not discriminate against you for exercising your rights, and you may have the right to lodge a complaint with your local supervisory authority.
13. Children
The service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us so we can delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the service after an update means you accept the revised policy.
15. Contact us
If you have questions about this Privacy Policy or our data practices, contact us at shikhar@sortcamp.com.
The data controller is Shibusa Ventures Private Limited, Ward No. 9 Gadarpur, Udham Singh Nagar, Rudrapur, Uttarakhand, India, 263152.