Privacy Policy
Last updated: August 19, 2026
This policy explains what WPRun collects when you use the site and the sandbox service, why we collect it, and what you can ask us to do with it.
1. Who We Are
WPRun operates this site and the sandbox service, and is the controller of the data described here. You can reach us at mail@wp.run.
2. What We Collect
You give us:
- your email address and password when you create an account (the password is held by our identity provider, never by us in readable form);
- your name, email address and message when you use a contact or support form;
- your email address if you join the MCP early-access list.
We collect automatically:
- your IP address, which reaches our servers through Cloudflare and is passed to our sandbox backend so that per-network limits on free sandboxes can be applied;
- a guest identifier for visitors without an account, used for the same limits;
- standard request data your browser sends — user agent, language, referring page;
- product analytics: pages viewed, sessions, clicks and form interactions, and the interface language you use.
About your sandboxes: we hold the technical record of each one — its address, chosen WordPress and PHP versions, requested plugins and themes, creation time and expiry.
3. How We Use It
To run the service and provision sandboxes; to apply plan limits fairly; to authenticate you and keep your session; to answer your messages; to bill paid plans; to understand which parts of the product are used and improve them; and to meet legal obligations.
We do not sell your data, and we do not use it to build advertising profiles.
4. Legal Bases
Where the GDPR applies, we rely on: performance of a contract (running the service and your account), legitimate interests (security, abuse prevention, product analytics, applying free-plan limits), consent where we ask for it, and legal obligation where the law requires us to keep records.
5. How Long We Keep It
Account data is kept while your account exists and is deleted when you close it. Sandbox records are kept while the sandbox lives and for a short period afterwards for operational purposes. Messages sent through our forms are kept as long as needed to deal with the request. Analytics data is retained by our analytics provider under its own retention schedule. Billing records are kept for as long as tax and accounting law requires.
6. Your Rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to another provider. Write to mail@wp.run and we will answer within the time the law allows. If you are in the EU or UK and are not satisfied, you may complain to your local data protection authority.
7. What Lives Inside a Sandbox
A sandbox is yours to fill, and its URL works for anyone who has the link. We do not inspect its content, and we do not treat it as private — so do not put production secrets, payment details, or personal data about other people into one. When the sandbox expires, everything in it is deleted permanently, including anything you placed there.
8. Children
The service is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us data, write to us and we will delete it.
9. International Transfers
Our providers operate in the United States and elsewhere, so your data may be processed outside your country. Where the GDPR applies, those transfers rely on the safeguards the law provides, such as standard contractual clauses.
10. Other Sites
This site links to other sites, and sandboxes can reach anything on the internet. We are not responsible for the privacy practices or the content of sites we do not operate.
11. Changes
We may update this policy. The date at the top of this page shows the current version.
12. Contact
Questions about this policy, or a request about your data: mail@wp.run, or the contact form.