Skip to content
Atomic Site Manager
How it works Features Commands Data Pricing FAQ
Sign in Get started
Legal

Privacy Policy

Atomic Site Manager is a connector. It only sends what it needs to show you your sites and carry out the commands you queue. This page lists every category, exactly.

Last updated: 31 August 2026 Effective: 31 August 2026 Applies to the plugin and the dashboard

On this page

  1. 1. Who we are
  2. 2. What this covers
  3. 3. Account data
  4. 4. Data from connected sites
  5. 5. What we never collect
  6. 6. When data is sent
  7. 7. Why we process it
  8. 8. IndexNow (optional)
  9. 9. Backups stay on your server
  10. 10. Sharing and sub-processors
  11. 11. Retention and deletion
  12. 12. Security
  13. 13. Your rights
  14. 14. If you manage client sites
  15. 15. Children
  16. 16. Changes
  17. 17. Contact

1. Who we are

Atomic Site Manager is operated by Oyorox ("we", "us"). We provide two things: a free, GPL-licensed WordPress plugin (the connector) and a hosted dashboard (the service) at atomic-site-manager-web.vercel.app.

For personal data processed through your account, Oyorox is the data controller. For data belonging to the WordPress sites you connect, see section 14.

Before publishing: replace this paragraph with your registered company name, legal address, company number, and — where required — your EU/UK representative and Data Protection Officer contact. Have the finished text reviewed by a qualified lawyer in your jurisdiction. This document is a well-researched starting point, not legal advice.

2. What this policy covers

This policy covers three surfaces:

  • This marketing website, atomicsitemanager.com.
  • Your Atomic Site Manager account and dashboard.
  • The Atomic Site Manager connector plugin installed on your WordPress sites.

It does not cover third-party sites we link to, your own WordPress sites' privacy practices, or your hosting provider.

3. Account data

When you create an account, we process:

CategoryExamplesSource
IdentityName, email address, password hashYou, at sign-up
BillingPlan, billing address, tax ID, payment statusYou and our payment processor
UsageCommands queued, sites added, sign-in timestamps, IP addressGenerated as you use the dashboard
SupportMessages you send us and our repliesYou

We do not store full payment card numbers. Card details are handled directly by our payment processor and never reach our servers.

4. Data the connector sends from your sites

Nothing is sent until you paste a Site Key and click Connect. An installed but unconnected plugin transmits nothing at all. Once connected, the connector sends:

CategoryWhat it contains
Site identitySite name, site URL, home URL, locale, timezone, and whether the install is multisite
EnvironmentWordPress, PHP, MySQL, and web server versions; whether WP_DEBUG and SSL are enabled
InventoryInstalled plugins and themes with names, slugs, versions, authors, and active state
UpdatesAvailable core, plugin, theme, and translation updates
HealthMemory usage and limit, disk usage and free space, uploads directory path, active theme
UsersWordPress user accounts and roles — user login, email address, display name, assigned roles, and registration date, for up to 200 users per site
Command resultsThe outcome and any error message produced by a command you queued
CredentialsYour Site Key and the site token issued in exchange for it

The user list is the sensitive one. It includes the email addresses of everyone with an account on a connected site. It powers remote user management and one-click admin login. If that is not acceptable for a given site, do not connect it.

5. What we never collect

The connector does not send, and the service does not receive:

  • Post, page, or custom post type content
  • Comments
  • Media files or uploads
  • Passwords or password hashes from your WordPress sites
  • Visitor analytics, session recordings, or tracking data
  • Backup archives — those are written to your own server only

The connector also cannot be used to remove itself. Remote deactivate and delete of Atomic Site Manager is blocked in the command runner, so the service can never lock you out of your own site.

6. When data is sent

  • On connect — once, when you submit your Site Key.
  • On heartbeat — every 60 seconds by default, via WP-Cron, and whenever you press Send heartbeat now. The service may adjust the interval.
  • On command result — after the dashboard runs a command on the site.
  • On magic login — once per one-click login, to verify the token issued.
  • On disconnect — once, when you disconnect from the settings page.

All requests use HTTPS. Plain HTTP is accepted only for localhost and private LAN addresses, so the plugin can be developed against a local backend.

7. Why we process it, and on what basis

PurposeData usedLawful basis (UK/EU GDPR)
Provide the serviceAccount, site identity, inventory, health, usersPerformance of a contract
Run your commandsCommand payloads and resultsPerformance of a contract
BillingAccount and billing dataPerformance of a contract; legal obligation
Security and abuse preventionIP addresses, sign-in and command logsLegitimate interests
SupportSupport messages, account dataLegitimate interests
Product improvementAggregated, non-identifying usage countsLegitimate interests

We do not sell personal data, and we do not use your data to train machine learning models.

8. IndexNow (optional, off by default)

IndexNow is a search-engine notification protocol sponsored by Microsoft Bing, Yandex, Seznam.cz, Naver, and Yep. The connector can ping it so newly published content is discovered quickly. Data is sent to indexnow.org only when all three of these are true, all of which are off or empty on a default install:

  1. The built-in SEO engine is enabled.
  2. IndexNow and instant indexing are enabled.
  3. An IndexNow key is set.

When they are, one request is sent each time a post moves into the published status for the first time, containing your site's hostname, the permalink of that post, your IndexNow key, and the URL of the key verification file. No personal data, post content, or visitor data is sent to IndexNow. Their handling of request data is governed by the IndexNow terms.

9. Backups stay on your server

Database and uploads backups created from the dashboard are written to a wp-content/asm-backups folder on your own server. The connector does not upload backup archives to the service. We receive only metadata — that a backup exists, when it was made, and how large it is.

Because those archives sit inside your web root, make sure your server blocks direct access to that folder and that your own retention and encryption practices cover it.

10. Sharing and sub-processors

We share data only with providers that help us run the service, and only as needed:

ProviderPurposeData involved
HostingRunning the API and dashboardAll service data
DatabaseStoring account and site recordsAll service data
Payment processorSubscriptions and invoicesName, email, billing details
Email deliveryTransactional emailName, email address
Error monitoringDiagnosing failuresTechnical logs, may include IP

Before publishing: replace the rows above with your actual named sub-processors, their locations, and the safeguards used for any transfer outside the UK/EEA (for example Standard Contractual Clauses). Regulators expect names, not categories.

We may also disclose data where legally required, or to protect the rights, safety, and property of Oyorox, our users, or the public. If the business is acquired, data may transfer as part of that transaction; we will tell you before it becomes subject to a different policy.

11. Retention and deletion

  • Heartbeat and health data — kept while the site is connected, so you can see history and trends.
  • Command logs — kept for the life of the account as an audit trail.
  • Disconnecting a site — the connector clears its stored credentials on this site automatically, including when the service revokes the site. Data already collected is removed from the dashboard when you delete the site record.
  • Closing your account — account and site data is deleted within 30 days, except records we must keep for tax and accounting purposes.
  • Backups of our own systems — deleted data may persist in encrypted system backups for up to 90 days before rotating out.

12. Security

  • All traffic between the connector, the API, and the dashboard uses HTTPS.
  • Each site authenticates with a token issued in exchange for its Site Key; tokens are scoped to that one site.
  • Passwords are stored hashed, never in plain text.
  • Access to production systems is limited to staff who need it.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as required by law.

13. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent where consent is the basis. Residents of California and other US states with privacy statutes have comparable rights, including the right not to be discriminated against for exercising them.

To exercise any of these, email privacy@oyorox.com. We respond within 30 days. You also have the right to complain to your local data protection authority.

14. If you manage sites for clients

When you connect a site you manage for someone else, you are typically the data controller for that site's user data and we act as your data processor. That means:

  • You are responsible for having a lawful basis to connect the site and share its user list with us.
  • You should tell your client that user names, emails, and roles are transmitted to a third-party management dashboard.
  • We process that data only on your documented instructions, as set out in our Terms of Use.

If you need a signed Data Processing Agreement, contact privacy@oyorox.com.

15. Children

The service is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.

16. Changes to this policy

We may update this policy as the product changes. The "Last updated" date at the top always reflects the current version. For material changes — a new data category, a new purpose, or a new sub-processor handling site data — we will notify account holders by email before the change takes effect.

17. Contact

Privacy questions and rights requests: privacy@oyorox.com
General support: support@oyorox.com
Company: Oyorox

See also our Terms of Use. The plugin's full external-services disclosure is also published in its readme.txt on the WordPress.org plugin directory.

Atomic Site Manager

A lightweight WordPress connector and a hosted dashboard for running updates, backups, security, and SEO across every site you manage.

Product

  • Features
  • Commands
  • Pricing
  • How it works
  • Data transparency

Resources

  • FAQ
  • Dashboard
  • Get the plugin
  • About IndexNow

Company

  • Oyorox
  • Terms of Use
  • Privacy Policy
  • Contact support

© 2026 Oyorox. Atomic Site Manager is released under GPL-2.0-or-later.

  • Terms
  • Privacy
  • License