BetterShield

Personal data: what BetterShield keeps, exports and erases

4 min read

What BetterShield keeps about the people on your site, the text it suggests for your privacy policy, and how WordPress’s export and erase tools handle it.

Protecting a site means keeping some records about the people on it, such as who signed in and from which network. BetterShield answers to WordPress’s own privacy tools for all of them: the Policy Guide, Export Personal Data and Erase Personal Data. There is nothing to switch on.

What is kept about people

IP addresses are never stored whole. BetterShield keeps the network instead: the first three groups of an IPv4 address (a /24), or the first four of an IPv6 address (a /64).

RecordHow long it is keptOn an erasure request
Sign-in attempts under the account’s username: when, how, the outcome, the networkTwo daysRemoved
Activity log rows where the account acted: what happened, its name at the time, the network30 days, or 90 with UltraKept, with the name and network removed
Two-factor: the secret behind the app’s codes, and hashes of the backup codesUntil two-factor is turned offRemoved, which turns two-factor off
Passkeys: the device name, when added and last used, and the public half of the keyUntil the passkey or the account is removedRemoved
The network each open session started fromUntil the session endsKept; WordPress removes it with the account
The date the account last signed inUntil the account is deletedKept
The last username tried from an address that was locked outUntil 30 days after the lockout endsKept
Incident evidence naming the account by number, never by nameWhile the incident is open; once handled, 30 days, or 180 with UltraKept
Assistant connections the account approved, and ability calls run as itUntil revoked; calls for the log’s retentionKept
Small marks, such as a recent password confirmation or a dismissed noticeVariesRemoved

With Record supported previous values on (see Activity log), earlier values it captures can include an email address; they stay until BetterShield is uninstalled with its records removed. Ultra adds trusted browsers and the start of a two-factor deadline, and an erasure removes both.

Your privacy policy

BetterShield adds suggested text to Settings › Privacy › Policy Guide, under BetterShield, ready to copy into your policy. It says what is recorded and for how long, how export and erasure requests are handled, and which outside services the site contacts.

The list of services follows what is switched on when you open the guide: WordPress.org always; Pwned Passwords only while Refuse passwords found in known breaches is on; WPDeveloper’s usage service only while Share usage data is on. Your published policy does not change by itself, so copy the text again after turning one of those on or off. See What BetterShield contacts.

Export someone’s data

In Tools › Export Personal Data, the file WordPress builds includes BetterShield’s records for that person, in groups such as BetterShield activity, BetterShield account (last sign-in, and whether two-factor is on), BetterShield sessions, BetterShield passkeys, BetterShield sign-in attempts and BetterShield incident evidence.

A last group, What BetterShield keeps about you, lists each kind of record held about that account, with why it is kept, how long, and what an erasure would do. Times are in UTC, and networks are labeled as networks so nobody reads them as an address.

Erase someone’s data

In Tools › Erase Personal Data, BetterShield removes what belongs to the person and keeps what belongs to the site’s security record, taking the person out of it where it can:

  • Removed: passkeys, sign-in attempts, two-factor (the person sets it up again if they keep the account), and the small marks above. With Ultra, trusted browsers and the two-factor deadline go too.
  • Kept, with the person taken out: activity rows lose the name and network but say what happened. Changes an assistant prepared or the person allowed lose who asked and who allowed.
  • Kept as they are: the last sign-in date, lockout records, incident evidence and the other records marked kept above.

The answer WordPress shows for the request says what was kept, and why. A security log that could be emptied on request is one an intruder holding that account could empty.

Rewriting activity rows would break their daily seals, so BetterShield seals those days again, and the log still reads as intact.

Site Health

Tools › Site Health › Info has a section, BetterShield: what it keeps about people, with one line per kind of record, how long it is kept and whether an erasure removes it. It describes the records without anyone’s data in them. See Dashboard and Site Health.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield