# Personal data: what BetterShield keeps, exports and erases

What BetterShield keeps about the people on your site, the text it suggests for your privacy policy, and how WordPress’s export and erase tools handle it.

Protecting a site means keeping some records about the people on it, such as who signed in and from which network. BetterShield answers to WordPress’s own privacy tools for all of them: the Policy Guide, **Export Personal Data** and **Erase Personal Data**. There is nothing to switch on.

## What is kept about people

IP addresses are never stored whole. BetterShield keeps the network instead: the first three groups of an IPv4 address (a /24), or the first four of an IPv6 address (a /64).

| Record | How long it is kept | On an erasure request |
|---|---|---|
| Sign-in attempts under the account’s username: when, how, the outcome, the network | Two days | Removed |
| Activity log rows where the account acted: what happened, its name at the time, the network | 30 days, or 90 with Ultra | Kept, with the name and network removed |
| Two-factor: the secret behind the app’s codes, and hashes of the backup codes | Until two-factor is turned off | Removed, which turns two-factor off |
| Passkeys: the device name, when added and last used, and the public half of the key | Until the passkey or the account is removed | Removed |
| The network each open session started from | Until the session ends | Kept; WordPress removes it with the account |
| The date the account last signed in | Until the account is deleted | Kept |
| The last username tried from an address that was locked out | Until 30 days after the lockout ends | Kept |
| Incident evidence naming the account by number, never by name | While the incident is open; once handled, 30 days, or 180 with Ultra | Kept |
| Assistant connections the account approved, and ability calls run as it | Until revoked; calls for the log’s retention | Kept |
| Small marks, such as a recent password confirmation or a dismissed notice | Varies | Removed |

With **Record supported previous values** on (see [Activity log](/docs/activity-log/)), earlier values it captures can include an email address; they stay until BetterShield is uninstalled with its records removed. Ultra adds trusted browsers and the start of a two-factor deadline, and an erasure removes both.

## Your privacy policy

BetterShield adds suggested text to **Settings › Privacy › Policy Guide**, under **BetterShield**, ready to copy into your policy. It says what is recorded and for how long, how export and erasure requests are handled, and which outside services the site contacts.

The list of services follows what is switched on when you open the guide: WordPress.org always; Pwned Passwords only while **Refuse passwords found in known breaches** is on; WPDeveloper’s usage service only while **Share usage data** is on. Your published policy does not change by itself, so copy the text again after turning one of those on or off. See [What BetterShield contacts](/docs/what-bettershield-contacts/).

## Export someone’s data

In **Tools › Export Personal Data**, the file WordPress builds includes BetterShield’s records for that person, in groups such as **BetterShield activity**, **BetterShield account** (last sign-in, and whether two-factor is on), **BetterShield sessions**, **BetterShield passkeys**, **BetterShield sign-in attempts** and **BetterShield incident evidence**.

A last group, **What BetterShield keeps about you**, lists each kind of record held about that account, with why it is kept, how long, and what an erasure would do. Times are in UTC, and networks are labeled as networks so nobody reads them as an address.

## Erase someone’s data

In **Tools › Erase Personal Data**, BetterShield removes what belongs to the person and keeps what belongs to the site’s security record, taking the person out of it where it can:

- **Removed:** passkeys, sign-in attempts, two-factor (the person sets it up again if they keep the account), and the small marks above. With Ultra, trusted browsers and the two-factor deadline go too.
- **Kept, with the person taken out:** activity rows lose the name and network but say what happened. Changes an assistant prepared or the person allowed lose who asked and who allowed.
- **Kept as they are:** the last sign-in date, lockout records, incident evidence and the other records marked kept above.

The answer WordPress shows for the request says what was kept, and why. A security log that could be emptied on request is one an intruder holding that account could empty.

Rewriting activity rows would break their daily seals, so BetterShield seals those days again, and the log still reads as intact.

## Site Health

**Tools › Site Health › Info** has a section, **BetterShield: what it keeps about people**, with one line per kind of record, how long it is kept and whether an erasure removes it. It describes the records without anyone’s data in them. See [Dashboard and Site Health](/docs/dashboard-and-site-health/).

## Related

- [What BetterShield contacts](/docs/what-bettershield-contacts/)
- [Activity log](/docs/activity-log/)
- [General settings](/docs/general-settings/)
- [Dashboard and Site Health](/docs/dashboard-and-site-health/)
