Privacy for POM AI integrations
POM AI sends only the data needed for the selected AI task from the WordPress site to the POM AI account service, which may use a task-appropriate processing provider. The exact payload differs by feature.
Examples include:
- prompts, company context, requested language, and existing content for writing;
- source and target content for translation;
- image descriptions, source images, reference images, or public media URLs for image tasks;
- recorded audio, duration, and language context for transcription.
MCP WordPress administration is separate: MCP requests and responses are processed by the connected site and recorded in its MCP audit log. The user’s external AI client may also process the content sent to it under that client’s own terms.
Developer responsibilities
- Send the minimum content needed for the outcome.
- Exclude credentials, private keys, payment data, health data, and unnecessary personal information.
- Obtain the rights and notices required for source text, images, voices, and customer data.
- Keep generated output under human review.
- Avoid exposing raw remote responses or request bodies in public logs.
- Use the documented redacted support fields when diagnosing a problem.
POM AI documentation does not promise a universal provider, retention period, or geographic processing location. If a project requires those guarantees, obtain the current applicable service and privacy terms before processing sensitive material.
Related guides: POM AI privacy overview, MCP audit privacy, and safe support information.